Data Processing Agreement

Last updated: September 7, 2026

Important: This Data Processing Agreement ("DPA") supplements our Terms of Service for customers who process personal data of third parties (for example, race participants or other identifiable people) through the Service. It reflects the promise in our Terms of Service that, where we process personal data on your behalf, we will enter into a data processing agreement on request. To execute a signed copy for your records, contact legal@racetagger.cloud.

Parties

This DPA is entered into between you, the customer using the RaceTagger Service to process photographs and related data (the "Controller"), and Federico Pasinetti, operating as RaceTagger, based in Odolo (BS), Italy (the "Processor"), together the "Parties."

As explained in our Terms of Service, RaceTagger is the data controller for account data, telemetry and content stored on our servers in our own right. This DPA covers the separate, narrower relationship in which RaceTagger processes personal data on your behalf and on your documented instructions under Article 28 GDPR: chiefly, the photographs you submit for analysis and the reference photographs and facial feature vectors you upload to presets. Where this DPA and the Terms of Service or Privacy Policy describe the same processing differently, this DPA governs for the processing it covers.

A. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data carried out by the Processor on behalf of the Controller in the course of providing the Service, as described in the Terms of Service.

This DPA takes effect on the date the Controller creates an account (or, for a countersigned copy, on the date of signature) and remains in force for as long as the Processor processes personal data on the Controller's behalf under the Terms of Service, including after account closure for the limited period needed to complete deletion under Section K below.

B. Nature and Purpose of Processing

The Processor processes personal data on the Controller's behalf for the following purposes:

  • Analysing photographs the Controller submits, to detect race numbers, match them to participant databases, classify scenes, and write metadata back to image files;
  • Storing reference photographs and the facial feature vectors computed from them, when the Controller adds a known participant to a preset, so the preset can be reused across analyses and devices;
  • Storing analysis results (race numbers, confidence scores, participant matches, scene tags) linked to the Controller's account, and gallery images the Controller chooses to store on our infrastructure;
  • Any other processing of personal data the Controller submits through the Service that is necessary to deliver the features described in the Terms of Service.

AI model training is outside the scope of this DPA: it is not processing carried out on the Controller's instructions. When the Processor uses anonymized analysis data and image crops to improve its AI models, it does so as an independent controller on the basis of its legitimate interest, as described in the Privacy Policy, Section 3.3 — the Controller (and any data subject) may object and opt out at any time by emailing privacy@racetagger.cloud, and the Processor will cease using that data for training purposes going forward. (A self-service toggle for this in account settings is planned but not yet built — until then, opting out goes through this email, same as Privacy Policy Section 3.3.)

C. Types of Personal Data and Categories of Data Subjects

The processing under this DPA may involve the following types of personal data:

  • Images of identifiable people (faces, race numbers, bib numbers, vehicle liveries) contained in the photographs the Controller submits;
  • Names and other identifying details the Controller associates with a participant, when provided (for example, in a preset);
  • Image metadata (EXIF/IPTC), including date, camera model and GPS location if present in the file;
  • Biometric data within the meaning of GDPR Article 9. When the Controller uploads a reference photograph of a known participant to a preset, the Processor computes and stores a facial feature vector from that photograph, together with the photograph itself, on its servers for as long as the preset exists. This is special category data and its processing requires the Controller to have a valid legal basis (ordinarily the data subject's explicit consent) before uploading it. By contrast, facial feature vectors computed from the photographs the Controller analyses (as opposed to preset reference photos) are kept only on the Controller's device for the duration of the analysis and deleted when it is complete, are never transmitted to the Processor's servers, and are not covered by this storage obligation — see the Privacy Policy, Section 2.4, for the full description of both flows.

The categories of data subjects are the people depicted in the Controller's photographs: typically race and motorsport participants, but potentially any other identifiable individual captured in an image the Controller submits (bystanders, staff, spectators).

D. Obligations and Rights of the Controller

As set out in our Terms of Service, the Controller is the data controller for the photographs it processes and for the people depicted in them. The Controller is responsible for:

  • Having a lawful basis for photographing the people depicted, and, where required, informing them of the processing;
  • Having a lawful basis — ordinarily explicit consent — before uploading a reference photograph of an identifiable person to a preset, given that this creates biometric data as described in Section C;
  • Issuing instructions to the Processor that comply with applicable data protection law;
  • Responding to data subject requests concerning its own use of the Service, with the Processor's assistance as described in Section I.

The Controller may issue further documented instructions consistent with this DPA and the Terms of Service by contacting legal@racetagger.cloud.

E. Processing on Documented Instructions

The Processor will process personal data only on the Controller's documented instructions, which consist of: (i) this DPA, (ii) the Terms of Service and the configuration choices the Controller makes within the Service (for example, which sport category, presets or features to enable), and (iii) any further written instructions the Parties agree to in writing.

If the Processor believes an instruction infringes GDPR or another applicable data protection provision, it will inform the Controller before carrying it out. The Processor will immediately inform the Controller if, in its opinion, it is legally required to process data otherwise than on the Controller's instructions, unless that law prohibits such notice on important grounds of public interest.

F. Confidentiality of Personnel

The Processor ensures that any person authorised to process personal data under this DPA — including Federico Pasinetti and any collaborator or contractor with access to production systems — is bound by a duty of confidentiality, whether contractual or statutory, and has committed to keep personal data confidential.

G. Technical and Organizational Security Measures

Taking into account the state of the art, the costs of implementation, and the nature, scope and risk of the processing, the Processor implements the following measures, as also described in our Privacy Policy, Section 10:

  • Encryption of data in transit (TLS/HTTPS) and at rest;
  • Row-Level Security (RLS) policies on customer-facing database tables, so that one customer's data is not accessible to another;
  • SHA-256 hashing of device identifiers, and automatic PII sanitisation in error reports and analytics before transmission;
  • Role-based access control for administrative functions, limiting production data access to what is necessary to operate and support the Service — a small number of internal administrative tools do not yet have this control fully applied; we are addressing this as a priority;
  • Regular security reviews and dependency updates.

H. Sub-Processors

The Controller authorises the Processor to engage the following sub-processors, each bound by its own data processing agreement with the Processor. This is the subset of the sub-processors disclosed in our Privacy Policy, Section 4.1, that are involved in processing personal data on your behalf:

ProviderPurposeData SharedLocation
Supabase (PostgreSQL)Database, Auth, StorageAccount data, analysis results, preset photos and facial vectorsEU (Frankfurt)
Google Cloud Vertex AIAI image analysis (Gemini) — desktop app, website demo, our private API, and entry-list PDF parsingImage crops, PDF text, promptsEU only, never a global or non-EU endpoint. The "eu" multi-region for crop re-analysis, visual tagging, and PDF parsing, with europe-west4 as an automatic fallback only if "eu" itself is unavailable; europe-west1 for default photo analysis, the website demo, and our private API
Cloudflare (R2)Image storage (galleries)Gallery imagesEU/US (Cloudflare Inc.) — DPF + SCCs
Vercel, Inc.Website and application hostingPhotographs, preset reference photos and facial vectors, and analysis results in transit through the API routes that carry them (for example, preset-face-photos, execution-images, private-analyze)US (SCCs)
Roboflow, Inc.(a) Real-time AI image analysis (RF-DETR object detection) on the Controller's photographs, for the sport categories configured to use it instead of Google Cloud Vertex AI — engaged by the Processor as a sub-processor on the Controller's behalf; and (b) AI model training dataset management (see Section B — engaged by the Processor as controller, only for training-consented images)(a) A signed URL to the photo, for inference only; (b) downscaled image copies, filenameUS (SCCs)

Where a sub-processor is located outside the EEA, the Processor relies on Standard Contractual Clauses (SCCs) or an equivalent safeguard, as described in our Privacy Policy, Section 4.2. The Processor imposes the same data protection obligations set out in this DPA on each sub-processor, by way of a contract or other legal act, and remains fully liable to the Controller for the performance of each sub-processor's obligations.

Before engaging a new sub-processor, or replacing an existing one, for processing covered by this DPA, the Processor will notify the Controller at least 14 days in advance by email to the address associated with the Controller's account, or by direct notice to legal@racetagger.cloud on request. The Controller may object on reasonable data-protection grounds within that period by writing to legal@racetagger.cloud; if the Parties cannot resolve the objection, the Controller may terminate its use of the Service for the affected processing without penalty.

I. Assistance with Data Subject Rights

Taking into account the nature of the processing, the Processor will assist the Controller, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts the Processor directly about photographs or preset data associated with the Controller's account, the Processor will redirect the request to the Controller and, where the Controller cannot act on it directly, provide reasonable technical assistance (for example, locating and deleting the relevant preset photo and vector) on the Controller's instruction.

J. Assistance with DPIAs and Personal Data Breaches

The Processor will provide the Controller with reasonably available information about the processing under this DPA (nature, scope, security measures) to support a data protection impact assessment the Controller is required to carry out, given the risk profile associated with biometric processing described in Section C, and, if that assessment indicates a high residual risk, to support any prior consultation with a supervisory authority the Controller is required to carry out under GDPR Article 36.

If the Processor becomes aware of a personal data breach affecting data processed on the Controller's behalf, it will notify the Controller without undue delay, and in any event within 48 hours after becoming aware of it, and will provide the information reasonably necessary for the Controller to meet its own notification obligations under Articles 33 and 34 GDPR.

K. Deletion of Data at the End of the Engagement

Consistent with the retention periods described in our Privacy Policy, Section 5, the Processor will delete all personal data processed on the Controller's behalf upon termination of the Controller's use of the Service, and delete existing copies, unless applicable law requires storage of that data (for example, tax records the Processor must retain in its own right as controller). The Service does not currently offer a self-service export or return of this data as a separate deliverable; the Controller can export its own analysis results and account data at any time as described in the Privacy Policy, Section 6.5, before requesting deletion. Account deletion, including associated preset photos and facial vectors, can be initiated from account settings or by contacting privacy@racetagger.cloud, and takes effect within 30 days as described in the Privacy Policy.

L. Audits and Inspections

The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. Given the size of the Processor's operation, audits will ordinarily take the form of a written questionnaire or documentation review; an on-site or remote technical audit may be requested with reasonable advance notice (at least 30 days) and will be scheduled at a mutually convenient time, at the Controller's reasonable expense for any costs beyond the Processor's ordinary time.

M. Liability and General Terms

This DPA is governed by the same law and forum as the Terms of Service. In case of conflict between this DPA and the Terms of Service on a matter of data protection, this DPA prevails for the processing it covers. Nothing in this DPA limits either Party's liability for infringements of GDPR beyond what applicable law permits.

Contact and Signed Copies

This page constitutes the DPA offered to business customers of the Service, effective by reference from the moment you use the Service to process personal data on behalf of a third party. If you need a countersigned copy for your own records or compliance file (for example, if required by a data protection authority in your jurisdiction), contact us and we will provide one:

DPA requests and legal matters: legal@racetagger.cloud

Privacy inquiries: privacy@racetagger.cloud

Processor: Federico Pasinetti, operating as RaceTagger — Odolo (BS), Italy

Website: https://racetagger.cloud


This Data Processing Agreement is effective as of September 7, 2026, and applies alongside our Terms of Service and Privacy Policy.