Data processing agreement

Version of September 27, 2026

This agreement governs the processing of personal data Pictomatic carries out on behalf of a centre, as article 28.3 of Regulation (EU) 2016/679 (GDPR) requires. It is part of the terms of use and is accepted with them: whoever creates a centre on behalf of an organisation declares they have the authority to bind it to this agreement.

1. The parties

  • Controller: the centre — the school, the practice, the person — that creates a centre in Pictomatic and puts data into it ("the centre").
  • Processor: Josep Jaume Rey Peroy, tax number ⟨NIF⟩, ⟨adreça postal⟩, josepjaume@gmail.com ("Pictomatic").

2. Subject matter, duration, nature and purpose

Pictomatic processes the data the centre puts in for one purpose: giving it the service the terms of use describe — keeping the students and the projects, searching pictograms, asking a language model for words and sentences, printing and exporting. The processing consists of collecting, storing, consulting, showing to the centre's members, sending the model the text the centre chooses, exporting and deleting. It lasts as long as the centre exists in Pictomatic.

3. The data and the people

  • Students (minors, generally): name, language of their pictograms, vocabulary level and, if the centre uploads it, the photo. Having a student in Pictomatic may reveal a need for augmentative communication, which is data concerning health (art. 9 GDPR).
  • Members of the centre: email address, name.
  • People who appear in the centre's pictures: their image.
  • The content of the projects: texts, documents, web pages, sentences and pictures the centre puts in, which may contain personal data.

4. The centre's obligations

The centre, as controller:

  • Has a legal basis for processing this data (art. 6 and, for health data, art. 9.2 GDPR) and can show it; informs families of the processing; and, for each photo, holds the consent Pictomatic asks for when it is uploaded.
  • Puts into Pictomatic only the data the service needs.
  • Decides who is a member of the centre and removes them when needed.
  • Gives Pictomatic its instructions in writing (this agreement and any it sends to the processor's email) and answers for their lawfulness.
  • Carries out, where required, the impact assessment that falls to it.

5. Pictomatic's obligations

Pictomatic, as processor:

  1. Processes the data only on the centre's instructions, which are this agreement, and never for its own purposes. If Union or Member State law required it to process them otherwise, it would tell the centre first, unless the law forbade it.
  2. Keeps confidentiality. The only people who access the data are those who maintain the service, bound to confidentiality, and only when maintaining it requires.
  3. Applies the security measures of article 32 GDPR, described in the annex.
  4. Engages no other processor without authorisation. The centre authorises the sub-processors in the annex. If Pictomatic wants to change or add one, it will tell the centre at least thirty days ahead, and the centre may object and end the service without penalty. Each sub-processor is bound, by contract, to the same obligations as this agreement.
  5. Helps the centre answer people's requests to exercise their rights (access, rectification, erasure, restriction, portability, objection): if it receives one directly, it forwards it to the centre without delay and does not answer on its own.
  6. Helps the centre comply with articles 32 to 36 GDPR: security, breaches and impact assessments, with the information it holds.
  7. Notifies the centre of any personal data breach without undue delay and, in any case, within 48 hours of becoming aware of it, with everything it knows: what happened, which data and people are affected, what consequences it may have and what has been done.
  8. At the end of the service, deletes the centre's data — when the centre is deleted in Pictomatic, or when it asks — within thirty days, from sub-processors too, except what a law requires to be kept. Before that, the centre can export what it holds with the app's own tools.
  9. Makes available to the centre the information needed to show compliance with this agreement and allows the audits the centre, or an auditor on its behalf, wishes to carry out, at most once a year except after a breach or on an authority's request, with thirty days' notice and at the centre's expense.
  10. Tells the centre if it believes an instruction infringes the GDPR or another data protection rule.

6. International transfers

Some sub-processors are in the United States. Transfers are made with the safeguards of article 46 GDPR: the European Commission's standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework.

7. Liability

Each party is liable for the damage it causes by breaching this agreement or the GDPR, under article 82 GDPR.

Annex I. Sub-processors

Sub-processorServicePlace
Cloudflare, Inc.Hosting of the app, storage of photos and pictures, sending of emailsWorldwide network; based in the US
DigitalOcean, LLCDatabase⟨regió⟩
OpenRouter, Inc.Routing of requests to the language modelUS
Google LLC (through OpenRouter)Language modelUS
ARASAAC (Government of Aragon)Pictogram search: receives only the words searched forSpain

What the model receives: the text the words are to come from, the sentences typed, the list of words the student knows, and their level and language. Never a photo nor any other data of the student; the name, only if the professional writes it in a sentence.

Annex II. Security measures

  • All communication is encrypted (TLS).
  • Photos and pictures are kept in a space with no public access; only the app serves them, and only to the centre's members.
  • A centre's data is seen only by its members; access is checked on every request.
  • Sessions are kept in signed cookies and expire; sign-in is with a one-time code that expires in minutes, with attempt limits.
  • The service's keys are stored encrypted, and database backups are made by the provider with its own measures.
  • The record of access to the model holds no text sent, only who, when and how much.
  • Data is deleted when the centre deletes a student, a project or the centre.

Version of September 27, 2026.