Pre-answered responses to the GDPR and Article 28 data-processor questions most commonly asked during an enterprise vendor review.
Last updated: June 24, 2026
This document answers the questions HeadshotPro is most often asked during a GDPR vendor assessment. It follows the structure of a standard Article 28 data-processor due-diligence questionnaire, so you can map our answers straight onto your own template.
Every answer here is drawn from documents you can read in full: our Data Processing Agreement (DPA), Security Overview, Security Policy, Data Management & Retention Policy, and Sub-processor list. Where an answer summarises a longer document, we link to the source.
If your questionnaire asks something not covered here, email support@headshotpro.com and we'll respond quickly.
| Question | Answer |
|---|---|
| Our role under GDPR | Processor (Customer is Controller) |
| Legal entity | Headshot Pro Photography Pte. Ltd., Singapore |
| EU Article 27 representative | iuro Rechtsanwälte GmbH t/a Prighter, Vienna |
| Data processing agreement | Public, applies automatically to all customers |
| International transfers | EU SCCs (Module Two) + UK IDTA + Swiss FADP |
| Certification | SOC 2 Type II (Security) |
| Sub-processors | Published list, with change notifications |
| AI training on customer data | Never, no exceptions |
| Breach notification | Within 48–72 hours of confirmation |
| Privacy contact | legal@headshotpro.com / support@headshotpro.com |
What is HeadshotPro's role under the GDPR — controller or processor?
HeadshotPro acts as a data processor. Your organisation is the data controller and determines the purposes and means of processing. We process personal data only on your documented instructions, as set out in our DPA.
Which legal entity is the processor, and where is it established?
Headshot Pro Photography Pte. Ltd., 7 Temasek Boulevard, #12-07, Suntec Tower One, Singapore 038987.
Do you have an EU representative under Article 27?
Yes. Our Article 27 representative is iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria (support@prighter.com).
What personal data do you process, and for whom?
We process facial photographs, names and email addresses, payment-related metadata (via Stripe; we do not store full card data), and incidental IP/device identifiers — solely to generate professional headshots for the individuals your organisation designates. Full categories are listed in Annex I of the DPA.
Do you process special-category (Article 9) data?
We process photographs only to generate AI headshots. They are not processed for the purpose of uniquely identifying a natural person and therefore do not constitute biometric data within the meaning of Article 9(1) GDPR.
On what basis do you process the data?
We process strictly as a processor under the controller's instructions and the documented purposes in the DPA. Establishing a lawful basis for the underlying processing (e.g. consent or legitimate interests of the employees photographed) is the controller's responsibility; we support you in meeting it.
Do you have a written data processing agreement that meets Article 28?
Yes. Our DPA is publicly available and applies automatically to every customer — there is nothing separate to sign. It covers all Article 28(3) requirements: documented instructions, confidentiality, security, sub-processing, assistance with data-subject rights, breach support, deletion/return, and audit rights.
Do you process personal data only on documented instructions?
Yes. We process personal data only to provide the service and on the controller's documented instructions, and we will inform you if an instruction appears to infringe the GDPR.
Are your personnel bound by confidentiality?
Yes. All personnel authorised to process personal data are bound by confidentiality obligations and complete annual security training.
Will you make information available to demonstrate compliance and allow audits?
Yes. We make our SOC 2 Type II report, penetration-test summaries, and this documentation available to support your assessment, and the DPA provides for audits in line with Article 28(3)(h).
Where is personal data stored?
Primary storage for uploaded photos and generated headshots is in the European Economic Area (Western Europe). Encrypted failover backups are replicated to the United States for disaster recovery only. Application servers run in the US. See the Security Overview.
What transfer mechanism covers transfers outside the EEA/UK?
Transfers are covered by approved Article 46 safeguards, incorporated into Section 6 of the DPA:
Do you perform transfer impact assessments?
Yes — the transfer safeguards are supported by the technical and organisational measures in Annex II of the DPA and our Security Policy, which together address the supplementary-measures expectation from the Schrems II ruling.
Do you use sub-processors, and is there a current list?
Yes. A current list of all sub-processors — including each entity's function, the data it can access, and its country — is published at /legal/sub-processors.
How are sub-processors authorised and contracted?
Customers grant general written authorisation for the sub-processors on the published list. Each sub-processor is bound by data-protection terms that are no less protective than those in our DPA.
Will you notify us of changes to sub-processors?
Yes. You can subscribe to change notifications in the admin dashboard, and you may object to a new sub-processor as set out in the DPA.
How do you assist with data-subject requests (access, erasure, etc.)?
As a processor, we assist the controller in responding to data-subject requests under Articles 12–22. Customers can export generated headshots at any time, and account deletion triggers full erasure of personal data within 14 days of confirmation.
Can individuals' data be deleted on request?
Yes. Input photos are automatically deleted 30 days after generation (earlier on request), and account deletion erases personal data within 14 days. See Data Management & Retention.
Is data encrypted in transit and at rest?
Yes. TLS 1.2+ (256-bit) in transit (HTTPS only) and AES-256 at rest across account data, uploaded photos, and generated headshots. Encryption keys are managed at the infrastructure-provider layer; staff cannot access raw keys.
What access controls are in place?
Role-based, least-privilege access with approval and logging; MFA enforced for production infrastructure and for organisation administrators; per-IP and per-account rate limiting. Developers work against staging data, not production customer data.
Do you hold security certifications?
Yes — SOC 2 Type II for the Security Trust Services Criteria, examined by an independent auditor. The report is available via our Trust Center. We also undergo regular independent penetration testing and continuous automated vulnerability scanning.
Where are your full technical and organisational measures documented?
In our Security Policy and Annex II of the DPA, maintained in line with our SOC 2 Type II programme.
Do you use customer photos or headshots to train AI models?
No. Uploaded photos and generated headshots are never used to train, fine-tune, or improve any AI model — ours or any third party's. This is an absolute commitment with no exceptions.
How long do you retain personal data?
Input photos are auto-deleted 30 days after generation. Generated headshots are retained for the term of the agreement and remain exportable for 30 days after termination. Backups are taken hourly with point-in-time recovery, retained up to one year, then securely deleted. Full schedule: Data Management & Retention.
What happens to data when the contract ends?
On termination, personal data is deleted or returned in accordance with Section 11 of the DPA, subject to the export window above.
Do you have an incident-response process and breach-notification commitment?
Yes. We maintain a documented incident-response and breach-notification process. We notify affected customers without undue delay and, in any event, within 48 hours of confirming a personal-data breach (and within 72 hours for other security incidents affecting customer personal data). Notice includes the nature of the incident, the categories of data affected, and remediation taken or planned.
Have you appointed a Data Protection Officer or privacy contact?
A formal DPO appointment under Article 37 is not mandatory given the nature and scale of our processing. We maintain a designated privacy and data-protection contact who handles all GDPR matters: legal@headshotpro.com. Security questionnaires and reviews are handled at support@headshotpro.com.
What other compliance frameworks do you align with?
We are compliant with GDPR, UK GDPR, CCPA, and Singapore PDPA, and certified under SOC 2 Type II (Security). We do not currently claim ISO 27001 certification.
What logging and audit-trail capabilities do you have?
Every API request is authenticated and scoped to the signed-in user. Production console access and security-relevant events are logged and reviewed for anomalous activity; application health and errors are monitored continuously via Sentry.
What are your availability and recovery commitments?
A 99.9% monthly uptime target with service credits, an RTO of 2 hours and RPO of 1 hour, supported by hourly backups with point-in-time recovery and at least quarterly restoration tests.
Need something this document doesn't cover, or have a questionnaire of your own to complete? Email support@headshotpro.com.