Data Processing Agreement (IRISORA Studio)
This agreement supplements the IRISORA Studio terms and governs the processing of personal data on behalf of the studio.
As of August 2026 · Version b2b-2026-08
1. Subject matter and roles
This Data Processing Agreement under Article 28 GDPR applies between the customer (controller) and Florian Böhm, IRISORA, St.-Afra-Str. 11, 86447 Todtenweis, Deutschland (processor) for all personal data processed within IRISORA Studio.
Subject matter: technical processing of eye captures into iris master files and artworks. Duration: for the term of the IRISORA Studio account.
Categories of data subjects: the customer's end customers and the customer's team members. Categories of data: image files of eye captures, file metadata, account and contact data, usage and billing data.
2. Instructions
The processor processes personal data solely on documented instructions from the controller. The instructions are set out in this agreement and in the settings made in IRISORA Studio.
The processor informs the controller if, in its opinion, an instruction infringes data protection law.
3. Confidentiality and security
All persons authorised to process data are bound to confidentiality.
Technical and organisational measures under Article 32 GDPR: private storage buckets without public access, delivery exclusively via short-lived signed links, row level security per studio, encrypted transport, role-based access, logging of administrative access and of every file delivery.
4. Sub-processors
The controller grants general authorisation for the use of sub-processors. Currently used: Supabase (hosting, database, storage, EU), Google (generative image processing), Stripe (payment processing), Lovable (application hosting), Resend (transactional email).
The processor informs the controller of any intended change of sub-processors and gives the controller the opportunity to object.
5. Data subject rights, assistance and audits
The processor supports the controller with appropriate technical and organisational measures in responding to data subject requests and in fulfilling the obligations under Articles 32 to 36 GDPR.
The processor notifies the controller without undue delay of any personal data breach and provides the information required for the controller's own notifications.
The controller may verify compliance with this agreement; the processor provides the necessary information on request.
6. Deletion and return
After the end of the processing, the processor deletes the uploaded captures and generated files, unless there is a statutory retention obligation. Billing records are retained for the statutory retention periods.
The controller may delete individual projects and files at any time within IRISORA Studio.
