MIVALDI.
← Back to mivaldi.com
LEGAL

Data Processing Agreement

Version 1 · Updated 2026-09-06 · MIVALDI SAS, 8 Avenue Montaigne, 75008 Paris, France

Last updated: 6 September 2026 · Version 1.0

This Data Processing Agreement ("DPA") is incorporated into the MIVALDI Terms of Service. It applies where MIVALDI SAS ("Processor") processes personal data on behalf of a Customer using the MIVALDI platform ("Controller"), within the meaning of Article 28 of Regulation (EU) 2016/679 ("GDPR").

1. Subject Matter, Nature & Purpose

The Processor provides a multi-tenant portfolio and agency-management platform. Processing comprises hosting, rendering, media transformation (resizing, format conversion), edge delivery, authentication, invoicing, and related technical operations, performed solely to provide the Service under the Controller's documented instructions.

2. Duration

This DPA applies for the term of the underlying service agreement and ends upon deletion of the Controller's data in accordance with §9.

3. Categories of Data Subjects

Models and talent whose portfolios are hosted; agency staff and administrators; visitors to portfolio websites (to the extent of technical data); and counterparties to booking requests.

4. Types of Personal Data (Annex 1)

  • Identification data: names, aliases, email addresses, usernames.
  • Professional data: measurements, agencies, cities, portfolio biographies, booking details.
  • Image data: photographs and video of data subjects, including special-category data where imagery reveals ethnic origin or health characteristics, processed only with the Controller's explicit documentation of consent/releases.
  • Technical data: IP addresses, browser information, logs, timestamps.
  • Financial data: invoice details and payment references.

5. Processor Obligations (Art. 28(3))

  • Process personal data only on documented instructions of the Controller, including with regard to international transfers.
  • Ensure persons authorized to process data are bound by confidentiality.
  • Implement the technical and organisational measures set out in Annex 3 (Art. 32).
  • Assist the Controller, where feasible and taking into account the nature of processing, in fulfilling data-subject requests (Art. 15–22), data-breach obligations (Art. 33–34) and data-protection impact assessments (Art. 35).
  • Notify the Controller without undue delay (target: 48 hours) after becoming aware of a personal data breach.
  • Make available to the Controller all information necessary to demonstrate compliance and allow audits as set out in §7.

6. Subprocessors (Annex 2)

The Controller authorizes engagement of the subprocessors listed in Annex 2 (hosting, CDN/edge, payment, email, analytics). The Processor will inform the Controller of any intended changes and allow objection within 14 days; in case of objection, the Controller may terminate the affected part of the Service. Subprocessors are bound by agreements imposing obligations no less protective than this DPA.

7. Audits

Upon request no more than once per 12 months and at the Controller's cost, the Processor shall provide evidence of compliance (certifications, penetration-test summaries, audit reports). On-site audits require 30 days' notice, are limited to business hours, and must not disrupt other customers.

8. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. Nothing in this DPA limits liability that cannot be limited under the GDPR.

9. Termination & Data Deletion

On termination, the Processor shall, at the Controller's choice, return or delete all personal data within 30 days, unless EU or member-state law requires storage. The Controller may export portfolio data via the Agency Hub before deletion.

10. Governing Law

This DPA is governed by the laws of France. The courts of Paris have jurisdiction.

Annex 1 — Details of Processing

Subject matterProvision of the MIVALDI portfolio platform and Agency Hub
NatureHosting, rendering, media processing, edge delivery, authentication, billing support
PurposeOperation of the Service on behalf of the Controller
DurationTerm of service agreement + 30-day deletion window
Data subjectsAs listed in §3
Data categoriesAs listed in §4

Annex 2 — Subprocessors

SubprocessorServiceLocation
Hosting provider (contracted)Server infrastructure, storageEU
CDN / edge network (contracted)Global media caching & deliveryGlobal (SCCs)
Payment processor (contracted)Card & subscription paymentsEU
Email provider (contracted)Transactional emailEU
Analytics tool (contracted)Aggregated usage analyticsEU

Annex 3 — Technical & Organisational Measures

  • Encryption in transit (TLS 1.2+) and at rest; bcrypt password hashing.
  • Role-based access control; principle of least privilege; quarterly access reviews.
  • Multi-tenant isolation: dedicated databases, per-tenant media namespaces, hardened reverse-proxy rules.
  • Audit logging of administrative actions; log integrity monitoring.
  • Network protection: firewall with allow-listed services, rate limiting, intrusion detection.
  • Availability: automated backups (daily, 7-day retention), tested restore procedure, monitored uptime.
  • Secure development: dependency scanning, code review, penetration testing on material changes.
  • Organisational: confidentiality clauses, data-protection training, designated DPO, incident-response plan.
© 2026 MIVALDI SAS. All rights reserved. legal@mivaldi.com