MyRun.eu

Data Processing Agreement

Version 1.0 · Effective 17 July 2026

This Data Processing Agreement (“DPA”) forms part of the MyRun Terms and Conditions and applies whenever an event organizer (the “Controller”) uses the MyRun platform to upload, manage, or share event photographs containing personal data. It is entered into between the Controller and TOMTECHNOLOGY S.R.L., a company registered in Romania under no. J40/993/2021, CUI 43600181, with registered office in Bucharest, Romania (“MyRun”, the “Processor”), and reflects the requirements of Article 28 of Regulation (EU) 2016/679 (“GDPR”).

By accepting the Terms and Conditions, the Controller also accepts this DPA. A countersigned copy is available on request at [email protected].

1. Roles and scope

For personal data contained in event photographs and the data derived from them (together, “Event Data”), the organizer is the Controller and MyRun is the Processor. The organizer decides which photographs to upload, which recognition features to enable, how long galleries stay online, and who may access them; MyRun processes Event Data only to provide the services described in Annex A.

For account data of platform users (organizer logins, billing, support requests, and use of the built-in assistant), MyRun acts as an independent controller; that processing is described in the Privacy Policy and is outside the scope of this DPA.

2. Processor obligations

  • Instructions. MyRun processes Event Data only on the Controller’s documented instructions, given through the platform’s controls (uploading, enabling or disabling recognition per album, publishing, deleting) or in writing, unless processing is required by EU or Member State law, in which case MyRun informs the Controller before processing unless that law prohibits it.
  • Confidentiality. Persons authorised to process Event Data are bound by contractual or statutory confidentiality obligations.
  • Security. MyRun implements and maintains the technical and organisational measures described in Annex C (Article 32 GDPR).
  • Sub-processors. The Controller grants a general authorisation for the sub-processors listed in Annex B. MyRun will announce intended additions or replacements at least 14 days in advance (via the platform or e-mail); the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected service. MyRun imposes data protection obligations on every sub-processor equivalent to those in this DPA and remains liable for their performance.
  • Data subject rights. Taking into account the nature of the processing, MyRun assists the Controller with appropriate technical and organisational measures to respond to data subject requests (access, erasure, restriction, objection), including photo search by bib number or selfie, per-photo deletion, and gallery takedown. Requests received directly from data subjects are forwarded to the Controller without undue delay.
  • Assistance. MyRun assists the Controller with its obligations under Articles 32 to 36 GDPR, including data protection impact assessments concerning the platform, taking into account the information available to MyRun.
  • Personal data breaches. MyRun notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Event Data, providing the information reasonably needed for the Controller’s own notification duties.
  • Deletion and return. Upon expiry of the agreed gallery hosting period, upon deletion by the Controller, or upon termination of the services, MyRun deletes Event Data in accordance with Annex A, unless EU or Member State law requires further storage. Before deletion the Controller can export its photographs in bulk through the platform’s export link.
  • Audits. MyRun makes available the information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, at reasonable intervals, on reasonable notice, and under confidentiality. MyRun may first satisfy an audit request through documentation, certifications, or third-party audit reports where these reasonably address the request.

3. Biometric data (face recognition)

Face recognition is an optional feature that the Controller enables per album. When enabled, faces appearing in the photographs of that album are converted into numerical face templates (biometric data within the meaning of Article 9 GDPR) used solely to let participants find their own photographs. Templates are stored in an event-scoped index, are not shared across events or controllers, and are never used to identify a person by name, to build profiles, or to train models.

The Controller is responsible for establishing a valid legal basis (including, where required, explicit consent under Article 9(2)(a) GDPR) before enabling face recognition, and for informing participants and other persons appearing in the photographs. If a valid legal basis cannot be established for all persons concerned, the Controller should keep face recognition disabled and may use bib-number recognition instead, which does not involve biometric data.

Face templates are deleted together with the photographs they were derived from: deleting a photograph or an album removes its face templates from the event’s index, and deleting the event, the expiry of the hosting period, or the Controller’s written request removes the entire index. A selfie uploaded by a participant for search is processed transiently for the search operation and is not added to the index.

4. International transfers

Event Data is stored and processed exclusively in EU regions of the multi-cloud infrastructure listed in Annex B, including all image analysis and biometric processing, regardless of which provider performs a given operation. Where a sub-processor’s group includes non-EU entities or global edge infrastructure (Annex B), transfers are safeguarded by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

5. Liability, term, governing law

This DPA applies for as long as MyRun processes Event Data for the Controller and automatically terminates when all Event Data has been deleted. Liability is governed by the Terms and Conditions. This DPA is governed by Romanian law, without prejudice to mandatory provisions of the GDPR, and any disputes are subject to the competent courts of Bucharest, Romania. In case of conflict between this DPA and the Terms and Conditions regarding the processing of Event Data, this DPA prevails.

Annex A - Details of processing

  • Subject matter and purpose: hosting event photographs, automatic recognition of bib numbers, faces (optional, per album) and sponsor logos, participant photo search and gallery sharing, and sales/delivery of photographs where enabled by the Controller.
  • Nature: storage, image analysis (OCR, face template extraction and matching, logo detection), indexing, retrieval, display, delivery, deletion.
  • Duration: the gallery hosting period selected by the Controller, after which Event Data is deleted; the Controller can delete photographs, albums, or entire events at any time, with deletion of the associated detection results and face templates.
  • Categories of data subjects: event participants; other persons visible in event photographs (spectators, volunteers, staff); the Controller’s users and photographers.
  • Categories of personal data: photographs of identifiable persons; bib numbers and derived detections (bounding boxes, confidence scores); face templates (biometric data, only where face recognition is enabled); participant search inputs (bib number, selfie); delivery e-mail addresses for purchased or downloaded photos.

Annex B - Authorised sub-processors

  • Multi-cloud infrastructure - application hosting, storage, and image processing (including biometric processing where face recognition is enabled), EU regions only: Hetzner Online GmbH (Germany), Amazon Web Services EMEA SARL, Google Cloud EMEA Ltd. Each of these providers may perform any of the listed processing operations; Event Data always remains in EU regions regardless of which provider performs a given operation.
  • Content delivery and network security: Cloudflare, Inc. (global edge network; SCCs / EU-US Data Privacy Framework).
  • Transactional e-mail delivery: Brevo (Sendinblue SAS), France (EU).

MyRun may also perform any of the processing described in Annex A itself, on its own EU infrastructure (including its own recognition algorithms); such processing is not sub-processing and requires no change to this Annex. The current sub-processor list is always available at this page. Payment processing (Stripe) is carried out with Stripe acting on MyRun’s behalf for organizer billing and as required for photo sales; it does not receive photographs or biometric data.

Annex C - Technical and organisational measures

  • Encryption in transit (TLS) for all traffic and encryption at rest for stored objects and backups.
  • EU-only processing locations for Event Data, with regional endpoints enforced at integration level for every AI sub-processor.
  • Logical tenant separation: photographs, detections, and face indexes are scoped per organizer and per event; face indexes are never shared across events.
  • Role-based access control on organizer accounts; administrative access to production restricted to authorised personnel with audited access.
  • Signed, expiring URLs for photo delivery; private galleries and watermarking controls for unpublished content.
  • Automated deletion pipelines for hosting expiry, event purges, and face index removal; deletion propagates to derived data (detections, caches, face templates).
  • Backups with defined retention; monitoring, logging, and alerting on production systems.
  • Vendor due diligence: sub-processors bound by GDPR-compliant data processing agreements; AI sub-processors are configured so customer content is not used to train their models.

Contact

Questions about this DPA or requests for a countersigned copy: [email protected].