Last updated: September 7, 2026
Important: This Data Processing Agreement ("DPA") supplements our Terms of Service for customers who process personal data of third parties (for example, race participants or other identifiable people) through the Service. It reflects the promise in our Terms of Service that, where we process personal data on your behalf, we will enter into a data processing agreement on request. To execute a signed copy for your records, contact legal@racetagger.cloud.
This DPA is entered into between you, the customer using the RaceTagger Service to process photographs and related data (the "Controller"), and Federico Pasinetti, operating as RaceTagger, based in Odolo (BS), Italy (the "Processor"), together the "Parties."
As explained in our Terms of Service, RaceTagger is the data controller for account data, telemetry and content stored on our servers in our own right. This DPA covers the separate, narrower relationship in which RaceTagger processes personal data on your behalf and on your documented instructions under Article 28 GDPR: chiefly, the photographs you submit for analysis and the reference photographs and facial feature vectors you upload to presets. Where this DPA and the Terms of Service or Privacy Policy describe the same processing differently, this DPA governs for the processing it covers.
The subject matter of this DPA is the processing of personal data carried out by the Processor on behalf of the Controller in the course of providing the Service, as described in the Terms of Service.
This DPA takes effect on the date the Controller creates an account (or, for a countersigned copy, on the date of signature) and remains in force for as long as the Processor processes personal data on the Controller's behalf under the Terms of Service, including after account closure for the limited period needed to complete deletion under Section K below.
The Processor processes personal data on the Controller's behalf for the following purposes:
AI model training is outside the scope of this DPA: it is not processing carried out on the Controller's instructions. When the Processor uses anonymized analysis data and image crops to improve its AI models, it does so as an independent controller on the basis of its legitimate interest, as described in the Privacy Policy, Section 3.3 — the Controller (and any data subject) may object and opt out at any time by emailing privacy@racetagger.cloud, and the Processor will cease using that data for training purposes going forward. (A self-service toggle for this in account settings is planned but not yet built — until then, opting out goes through this email, same as Privacy Policy Section 3.3.)
The processing under this DPA may involve the following types of personal data:
The categories of data subjects are the people depicted in the Controller's photographs: typically race and motorsport participants, but potentially any other identifiable individual captured in an image the Controller submits (bystanders, staff, spectators).
As set out in our Terms of Service, the Controller is the data controller for the photographs it processes and for the people depicted in them. The Controller is responsible for:
The Controller may issue further documented instructions consistent with this DPA and the Terms of Service by contacting legal@racetagger.cloud.
The Processor will process personal data only on the Controller's documented instructions, which consist of: (i) this DPA, (ii) the Terms of Service and the configuration choices the Controller makes within the Service (for example, which sport category, presets or features to enable), and (iii) any further written instructions the Parties agree to in writing.
If the Processor believes an instruction infringes GDPR or another applicable data protection provision, it will inform the Controller before carrying it out. The Processor will immediately inform the Controller if, in its opinion, it is legally required to process data otherwise than on the Controller's instructions, unless that law prohibits such notice on important grounds of public interest.
The Processor ensures that any person authorised to process personal data under this DPA — including Federico Pasinetti and any collaborator or contractor with access to production systems — is bound by a duty of confidentiality, whether contractual or statutory, and has committed to keep personal data confidential.
Taking into account the state of the art, the costs of implementation, and the nature, scope and risk of the processing, the Processor implements the following measures, as also described in our Privacy Policy, Section 10:
The Controller authorises the Processor to engage the following sub-processors, each bound by its own data processing agreement with the Processor. This is the subset of the sub-processors disclosed in our Privacy Policy, Section 4.1, that are involved in processing personal data on your behalf:
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase (PostgreSQL) | Database, Auth, Storage | Account data, analysis results, preset photos and facial vectors | EU (Frankfurt) |
| Google Cloud Vertex AI | AI image analysis (Gemini) — desktop app, website demo, our private API, and entry-list PDF parsing | Image crops, PDF text, prompts | EU only, never a global or non-EU endpoint. The "eu" multi-region for crop re-analysis, visual tagging, and PDF parsing, with europe-west4 as an automatic fallback only if "eu" itself is unavailable; europe-west1 for default photo analysis, the website demo, and our private API |
| Cloudflare (R2) | Image storage (galleries) | Gallery images | EU/US (Cloudflare Inc.) — DPF + SCCs |
| Vercel, Inc. | Website and application hosting | Photographs, preset reference photos and facial vectors, and analysis results in transit through the API routes that carry them (for example, preset-face-photos, execution-images, private-analyze) | US (SCCs) |
| Roboflow, Inc. | (a) Real-time AI image analysis (RF-DETR object detection) on the Controller's photographs, for the sport categories configured to use it instead of Google Cloud Vertex AI — engaged by the Processor as a sub-processor on the Controller's behalf; and (b) AI model training dataset management (see Section B — engaged by the Processor as controller, only for training-consented images) | (a) A signed URL to the photo, for inference only; (b) downscaled image copies, filename | US (SCCs) |
Where a sub-processor is located outside the EEA, the Processor relies on Standard Contractual Clauses (SCCs) or an equivalent safeguard, as described in our Privacy Policy, Section 4.2. The Processor imposes the same data protection obligations set out in this DPA on each sub-processor, by way of a contract or other legal act, and remains fully liable to the Controller for the performance of each sub-processor's obligations.
Before engaging a new sub-processor, or replacing an existing one, for processing covered by this DPA, the Processor will notify the Controller at least 14 days in advance by email to the address associated with the Controller's account, or by direct notice to legal@racetagger.cloud on request. The Controller may object on reasonable data-protection grounds within that period by writing to legal@racetagger.cloud; if the Parties cannot resolve the objection, the Controller may terminate its use of the Service for the affected processing without penalty.
Taking into account the nature of the processing, the Processor will assist the Controller, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts the Processor directly about photographs or preset data associated with the Controller's account, the Processor will redirect the request to the Controller and, where the Controller cannot act on it directly, provide reasonable technical assistance (for example, locating and deleting the relevant preset photo and vector) on the Controller's instruction.
The Processor will provide the Controller with reasonably available information about the processing under this DPA (nature, scope, security measures) to support a data protection impact assessment the Controller is required to carry out, given the risk profile associated with biometric processing described in Section C, and, if that assessment indicates a high residual risk, to support any prior consultation with a supervisory authority the Controller is required to carry out under GDPR Article 36.
If the Processor becomes aware of a personal data breach affecting data processed on the Controller's behalf, it will notify the Controller without undue delay, and in any event within 48 hours after becoming aware of it, and will provide the information reasonably necessary for the Controller to meet its own notification obligations under Articles 33 and 34 GDPR.
Consistent with the retention periods described in our Privacy Policy, Section 5, the Processor will delete all personal data processed on the Controller's behalf upon termination of the Controller's use of the Service, and delete existing copies, unless applicable law requires storage of that data (for example, tax records the Processor must retain in its own right as controller). The Service does not currently offer a self-service export or return of this data as a separate deliverable; the Controller can export its own analysis results and account data at any time as described in the Privacy Policy, Section 6.5, before requesting deletion. Account deletion, including associated preset photos and facial vectors, can be initiated from account settings or by contacting privacy@racetagger.cloud, and takes effect within 30 days as described in the Privacy Policy.
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Given the size of the Processor's operation, audits will ordinarily take the form of a written questionnaire or documentation review; an on-site or remote technical audit may be requested with reasonable advance notice (at least 30 days) and will be scheduled at a mutually convenient time, at the Controller's reasonable expense for any costs beyond the Processor's ordinary time.
This DPA is governed by the same law and forum as the Terms of Service. In case of conflict between this DPA and the Terms of Service on a matter of data protection, this DPA prevails for the processing it covers. Nothing in this DPA limits either Party's liability for infringements of GDPR beyond what applicable law permits.
This page constitutes the DPA offered to business customers of the Service, effective by reference from the moment you use the Service to process personal data on behalf of a third party. If you need a countersigned copy for your own records or compliance file (for example, if required by a data protection authority in your jurisdiction), contact us and we will provide one:
DPA requests and legal matters: legal@racetagger.cloud
Privacy inquiries: privacy@racetagger.cloud
Processor: Federico Pasinetti, operating as RaceTagger — Odolo (BS), Italy
Website: https://racetagger.cloud
This Data Processing Agreement is effective as of September 7, 2026, and applies alongside our Terms of Service and Privacy Policy.