Camwarden
FeaturesHow It WorksPricingFAQ
Get Started
Get Started

Data Processing Agreement

Camwarden — operated by CMP IT ApS Last updated: 23 July 2026

This Data Processing Agreement ("DPA") forms part of the Camwarden Terms of Service (the "Agreement") between CMP IT ApS, CVR no. 41254041, Hvedebakken 105, 8450 Hammel, Denmark ("Camwarden", "we") and the customer accepting the Agreement ("Customer", "you"). It applies whenever we process personal data contained in Customer Content on your behalf. It is incorporated into the Agreement by reference and requires no separate signature. On written request ([email protected]) we will provide a countersigned copy.

1. Roles

1.1 For Customer Content — photos and other media uploaded to or ingested by the Service, together with associated metadata (capture time, camera identifiers, GPS coordinates, detection results) — the Customer is the data controller (or a processor acting on behalf of another controller) and Camwarden is the data processor under Art. 28 GDPR.

1.2 For account, billing, authentication, support, and service-usage data, Camwarden is an independent data controller as described in our Privacy Policy. Such processing is outside the scope of this DPA.

2. Subject matter, duration, nature and purpose

Subject matterHosting, storage, display, organisation, sharing, and automated analysis (wildlife/object detection) of Customer Content
DurationThe term of the Agreement, plus the deletion period in Section 10
Nature of processingStorage, retrieval, structuring, image conversion, automated image analysis, transmission at the Customer's direction (e.g. share links, team access), erasure
PurposeProviding the Camwarden trail camera management service as described in the Agreement
Categories of data subjectsIndividuals incidentally captured by the Customer's trail cameras; members of the Customer's team; senders of ingestion emails
Categories of personal dataImages potentially depicting identifiable persons or vehicle registration plates; location data; email addresses and message metadata of ingestion senders; names/emails of team members within Customer Content context
Special categoriesNone intended. The Customer must not deliberately use the Service to process special-category data.

3. Customer instructions

3.1 We process Customer Content only on the Customer's documented instructions, which consist of: (a) the Agreement and this DPA; (b) the Customer's use of the Service's settings and features (uploading, sharing, team permissions, deletion); and (c) other written instructions agreed between the parties.

3.2 We will inform the Customer if, in our opinion, an instruction infringes the GDPR or other applicable data protection law, unless prohibited from doing so.

3.3 Customer responsibilities. The Customer warrants that it has a lawful basis for the capture and processing of Customer Content, and is responsible for compliance with laws applicable to camera surveillance in the relevant jurisdiction, including signage and notification obligations where required (in Denmark, tv-overvågningsloven where applicable).

4. Confidentiality

Persons authorised to process Customer Content are bound by confidentiality obligations. As of the date above, Camwarden's personnel consists of its founder; any future personnel will be bound by written confidentiality undertakings before receiving access.

5. Security (Art. 32)

We implement and maintain the technical and organisational measures described in Annex 1. We may update these measures provided the updates do not materially reduce the overall level of protection.

6. Sub-processors

6.1 The Customer grants general authorisation for the engagement of the sub-processors listed at camwarden.com/sub-processors.

6.2 We will give at least 30 days' notice of the addition or replacement of a sub-processor by updating that page and notifying account owners by email. The Customer may object on reasonable data-protection grounds within the notice period; if we cannot accommodate the objection, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees.

6.3 We impose data protection obligations on sub-processors materially equivalent to those in this DPA and remain liable for their performance.

7. International transfers

Customer Content is stored at rest within the EU (currently AWS eu-central-1, Frankfurt, via Supabase). Where a sub-processor's processing involves transfer to a third country, we ensure a valid transfer mechanism under Chapter V GDPR — the EU-U.S. Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), with supplementary measures where required. Transfer details per vendor are listed on the sub-processor page.

8. Assistance to the Customer

8.1 Taking into account the nature of the processing, we assist the Customer with appropriate technical and organisational measures to respond to data subject requests concerning Customer Content. In the first instance, the Service's built-in tools (search, deletion, export) enable the Customer to handle most requests directly. Where a data subject contacts us directly regarding Customer Content, we will forward the request to the Customer without undue delay and not respond substantively unless legally required.

8.2 We provide reasonable assistance with the Customer's obligations under Arts. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the information available to us. We respond to assistance requests within 5 business days.

9. Personal data breach

We will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Content, providing the information reasonably required for the Customer's obligations under Arts. 33–34, supplemented as it becomes available.

10. Deletion and return

10.1 During the term, the Customer can delete Customer Content and export it (JSON export with media via signed URLs) using the Service.

10.2 Upon termination of the Agreement or account deletion, we delete Customer Content within 30 days, except where retention is required by EU or Danish law. Backup copies are overwritten in the ordinary backup rotation within a further 35 days. Account deletion follows the anonymisation/tombstone pattern described in the Privacy Policy.

11. Audit

Upon written request, no more than once per 12-month period (absent a supervisory-authority requirement or a material breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party certifications and audit reports of our sub-processors (e.g. SOC 2 / ISO 27001 documentation of hosting providers). Where this is insufficient, the Customer may conduct or mandate an audit at its own cost, during business hours, with 30 days' notice, subject to confidentiality and without access to other customers' data.

12. Liability and order of precedence

Liability under this DPA is subject to the limitations of liability in the Agreement, except where prohibited by Art. 82 GDPR. In case of conflict between this DPA and the Agreement regarding the processing of Customer Content, this DPA prevails.

13. Governing law

This DPA is governed by Danish law. The competent supervisory authority is Datatilsynet (Danish Data Protection Agency).


Annex 1 — Technical and Organisational Measures

Hosting and data residency. Customer Content stored in AWS eu-central-1 (Frankfurt) via Supabase, in private storage buckets. AI image analysis performed on infrastructure operated by CMP IT ApS in Denmark; images are processed transiently for inference and not retained on inference infrastructure.

Encryption. TLS 1.2+ in transit; AES-256 encryption at rest (provider-managed). Media delivery via authenticated CDN using HMAC-signed, expiring URLs; no publicly enumerable media paths.

Access control. Row-level security enforced at the database layer; role-based team permissions (Owner / Admin / Member / View-only); administrative access protected by phishing-resistant authentication; principle of least privilege for service credentials.

Application security. Bot protection on authentication flows; audit logging of security-relevant account events; idempotent webhook processing; separation of production and development environments.

Availability and integrity. Automated database backups with point-in-time recovery; queued ingestion pipeline designed so that processing delays do not cause data loss; error monitoring (EU-hosted).

Organisational measures. Documented breach-response procedure; sub-processor due diligence and register; records of processing activities maintained per Art. 30; annual review of these measures.

Data minimisation. Images converted and stored as compressed WebP; no third-party advertising or analytics trackers in the Service.

Camwarden

Your trail camera photos, your control. No vendor lock-in.

Product

FeaturesPricingHow It WorksFAQ

Company

AboutContact

Legal

Terms of ServicePrivacy PolicyCookiesWithdraw from contractData Processing AgreementSub-processorsSecurityLegal NoticeAttribution
© 2023 - 2026 Camwarden. All rights reserved.EU-hosted · GDPR-native