
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms an integral part of the Service Agreement between:
- The Customer: The natural or legal person using the services of XclusiveVR (hereinafter: "Controller"); and
- The Processor: PVG Technologies BV, acting under the trade name XclusiveVR, The Netherlands, Chamber of Commerce number: 99645939 (hereinafter: "Processor").
1. Subject and Scope
1.1. The Processor provides a service that converts 2D video files into 3D video files (the "Services").
1.2. In the course of providing these Services, the Processor may process personal data on behalf of the Controller. This DPA ensures that such processing complies with the requirements of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Type of Personal Data and Purpose
2.1. The Processor shall process the following types of data:
- Video Content: Uploaded video files which may contain images of identifiable natural persons.
- Customer Information: Name, (billing) address, and email address for account management and administrative purposes.
- Billing Information: Payment metadata processed via Stripe.
2.2. The purpose of the processing is strictly limited to the technical conversion of video files and the necessary administration of the customer relationship.
3. Data Retention and Deletion
3.1. Video Files: The Processor applies a strict data minimization policy. All uploaded and converted video files are stored for a maximum period of 7 (seven) calendar days.
3.2. After this 7-day period, the files are permanently and irreversibly deleted from all active storage and processing systems.
3.3. Customer Information: Name and address details are retained for as long as necessary to comply with statutory (fiscal) retention obligations (typically 7 years under Dutch law).
4. Technical and Organizational Measures
4.1. The Processor shall implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
4.2. These measures include, but are not limited to, SSL/TLS encryption for data in transit and restricted access protocols for server environments.
5. Authorized Sub-Processors
5.1. The Controller grants the Processor general authorization to engage the following sub-processors for the execution of the Services:
- Cloudflare (R2): For secure object storage of video files.
- RunPod: For GPU-accelerated processing and video conversion.
- Stripe: For payment processing and billing administration.
5.2. The Processor ensures that all sub-processors are bound by data protection obligations at least as stringent as those contained in this DPA.
6. International Data Transfers
6.1. If personal data is transferred to a country outside the European Economic Area (EEA), the Processor ensures that such transfers are governed by appropriate safeguards, such as the EU Standard Contractual Clauses (SCCs) or an Adequacy Decision.
7. Data Breach Notification
7.1. In the event of a personal data breach, the Processor shall notify the Controller without undue delay, and in any event within 48 hours after becoming aware of the breach.
8. Rights of Data Subjects
8.1. Taking into account the nature of the processing, the Processor shall assist the Controller, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising data subject rights (e.g., access or deletion).
8.2. The Controller acknowledges that due to the 7-day deletion policy, video files may no longer be available for retrieval or deletion requests after that period.
9. Governing Law
9.1. This DPA is governed by the laws of The Netherlands. Any disputes arising from this agreement shall be submitted to the competent court in the district where the Processor is established.