Zum Inhalt springen

Auftragsverarbeitungsvertrag (AVV)

Zuletzt aktualisiert: 2026-08-30

This Data Processing Agreement ("DPA") applies whenever you upload files containing personal data of other people — CCTV footage, recorded interviews, dashcam video, documents about third parties — and is entered into between you ("Controller") and F.Javier Pedrosa Ruiz ("Processor"), operator of Medianonymizer.

It forms part of, and is governed by, our Terms of Service. Where this DPA conflicts with the Terms on a matter of data protection, this DPA prevails.

1. Roles

For the content of the files you upload, you are the Controller and we are the Processor. You decide whose data is anonymised and why; we only execute that instruction.

For our own processing — your email address, billing data, website analytics — we act as Controller under our Privacy Policy. This DPA does not cover that.

If you need a signed copy, write to privacy@medianonymizer.com and we will return one countersigned.

2. Subject matter, duration, nature and purpose

Subject matter. Detection and irreversible removal of personal data from the files you submit.

Duration. For each file, from upload until deletion under clause 7. There is no ongoing storage relationship: we do not hold a repository of your data between jobs.

Nature and purpose. Automated detection (faces, voices, licence plates, identifiers, text) followed by deterministic redaction. We do not use your files to train models, build datasets, or for any purpose other than returning the anonymised result to you.

3. Types of personal data and categories of data subjects

Types of data. Whatever the submitted file contains. Typically: images of faces, voice recordings, licence plates, names, national identifiers, bank details, addresses, and any other personal data present in the document, image, audio or video.

Special categories (Art. 9). Faces and voices are biometric data. They are processed solely to anonymise them, are never used to uniquely identify anyone, and no biometric templates or embeddings are ever stored.

Categories of data subjects. Whoever appears in the files: your customers, employees, patients, passers-by, interviewees, or any third party.

4. Your instructions

We process personal data only on your documented instructions, which are given by the choices you make in the service: the file you upload, the modality, the regions you mark or unmark, and the options you select. We will inform you if, in our opinion, an instruction infringes the GDPR.

You warrant that you have a lawful basis for submitting the files, and — where legally required — the consent of the people who appear in them. Clause 3 of the Terms of Service says the same thing.

5. Confidentiality

Access to production data is limited to the people who need it to operate the service, all bound by confidentiality obligations that survive the end of their engagement.

6. Security measures (Art. 32)

  • Files never pass through the web layer. The browser uploads directly to object storage with a short-lived pre-signed URL; the control plane never receives the bytes.
  • Encryption in transit (HTTPS end to end, no HTTP fallback) and at rest in the object store.
  • Short-lived download links (5 minutes), so a leaked URL has a minimal window.
  • Irreversible redaction by design: solid fill or heavy mosaic, never a soft blur that can be reconstructed. A reversibly obscured file is still personal data.
  • No personal data in logs. The detection audit table records entity type, detector, score and location — never the detected value itself.
  • Automated deletion enforced by a scheduled sweep, independently of any single mechanism.

7. Deletion

The original file and the anonymised result are deleted within 24 hours of the result becoming available. Each free correction restarts that window, because the original is what makes a correction possible. After it elapses, both are irrecoverably deleted.

There is nothing to return at the end of the relationship, by design: nothing persists beyond that window.

8. Sub-processors

You give general written authorisation for the sub-processors listed in our Privacy Policy, which is generated from a single registry kept in step with the running system.

We impose on every sub-processor the same data protection obligations set out here, and we remain fully liable to you for their performance. We will inform you of any intended addition or replacement before it takes effect, giving you the opportunity to object.

9. International transfers

Some sub-processors are outside the EEA. Those transfers are covered by the European Commission's Standard Contractual Clauses, with Module 3 applying to the controller-to-processor-to-sub-processor chain that this DPA creates.

Video processing is pinned to data centres inside the EEA.

10. Assistance to you

Taking into account the nature of the processing, we assist you:

  • in responding to data subject requests (Arts. 12–22). In practice, the 24-hour deletion window means most requests are satisfied by the passage of time;
  • with your obligations under Arts. 32–36, including security, breach notification and data protection impact assessments;
  • by notifying you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need for your own Art. 33 notification.

11. Audits

We make available the information necessary to demonstrate compliance with Art. 28 and allow for audits, including inspections, conducted by you or an auditor you mandate. In the first instance we will provide documentation and answer written questions; on-site audits are arranged with reasonable notice and without disrupting the service.

12. Contact

Data protection contact: privacy@medianonymizer.com.

Supervisory authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es.