Last updated: 28 September 2026
This agreement forms part of the Terms of Service and is concluded by accepting them, between the photographer using SmartCull (Controller) and Foroszán Pál Márk ev., sole trader (egyéni vállalkozó) registered in Hungary, registration no. 62853549, MAGYARORSZÁG, 5700 GYULA, SZÖNYI KÖZ 1., EU VAT number HU91145804, email hello@fotovalogato.hu (Processor). It meets the requirements of Article 28(3) UK GDPR and EU GDPR.
The Processor processes, on behalf of the Controller, the uploaded photos of children and adults, the facial feature vectors derived from them (biometric data, Art. 9) and parents' contact and order data, solely to group photos by person, produce selections and provide the parent ordering interface — for as long as the Controller's account exists.
The Processor processes the data only on the Controller's documented instructions (the Controller's actions and settings in the service), does not use it for its own purposes, does not combine it with other data and does not disclose it to third parties.
Persons authorised to access the data are bound by confidentiality.
Password-protected access with strict per-account separation, HTTPS, watermarked or masked previews, server-side logging and alerting, automatic deletion of photos and face data after the retention period (30 days), servers in the EU (Hungary). Face recognition runs on our own servers; photos are not sent to third-party AI services and are not used for training.
The Controller authorises: Rackforest Kft., Budapest, Hungary (hosting); Google LLC (forwarding of our support mailbox). We will inform the Controller in advance of any new sub-processor, and the Controller may object.
Data is stored in the EU (Hungary). For UK Controllers, the UK recognises the EU/EEA as adequate, so no further safeguards are needed.
The Processor helps the Controller, as far as technically possible, to respond to data subject requests (access, erasure, rectification, withdrawal) and with security, breach notification and impact assessments. Sessions and photos can be deleted in the service at any time.
The Processor notifies the Controller without undue delay and within 48 hours at the latest after becoming aware of a breach affecting the Controller's data, with the information needed for the Controller's own notifications.
When the account ends, the Processor deletes the data (or returns it at the Controller's request), except where the law requires retention (e.g. accounting records).
The Processor makes available the information needed to demonstrate compliance and responds to reasonable audit requests.
Obtaining parental or guardian consent where required is the Controller's responsibility.