Data Processing Agreement
Data Processing Agreement
This Data Processing Agreement governs how Railex Technology OÜ (operating Modacast) processes model personal data on behalf of agencies (the controllers) under Article 28 GDPR. It forms part of the Modacast Terms of Service.
1. Roles
For personal data relating to models that an agency enters and shares through Modacast (“Model Personal Data”), the Agency is the data controller and Railex Technology OÜ, operating Modacast, is the processor, processing only on the Agency’s documented instructions.
Railex is an independent controller only for account, authentication, billing and security-log data of the Agency’s users. Where two agencies (mother and booking) co-represent the same model, each is controller for its own representation.
2. Subject-matter, nature, duration and data
Modacast processes Model Personal Data to provide the platform (model management, per-agency representation, controlled sharing to clients, and billing), for the term of the agreement plus the retention/return-or-deletion period.
Categories of data subjects: models; model guardians or representatives where applicable; agency staff; end clients and booking recipients. Categories of personal data: identity and stage name, date of birth, body measurements, appearance attributes, nationality, photographs (including images flagged sensitive), contacts, social handles, and booking/placement records.
3. Processor obligations (Article 28(3))
- Process Model Personal Data only on the Agency’s documented instructions, including for transfers, unless required by EU/Member-State law (in which case Railex informs the Agency unless legally prohibited).
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Article 32): tenant isolation via row-level security, a private photo store with short-lived signed URLs, encryption in transit and at rest, an append-only audit log, least-privilege access and EU-only hosting (Frankfurt).
- Engage sub-processors only under the same data-protection obligations, with prior notice of changes and the Agency’s right to object; the current list is published at /legal/sub-processors.
- Assist the Agency, by appropriate technical measures, in responding to data-subject requests under Chapter III GDPR.
- Assist the Agency with security, breach notification, data-protection impact assessments and prior consultation (Articles 32–36).
- At the Agency’s choice, delete or return all Model Personal Data on termination, unless storage is required by law.
- Make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits.
4. Sub-processors and international transfers
The Agency gives general authorisation to the sub-processors listed at /legal/sub-processors. Railex notifies the Agency before adding or replacing a sub-processor and the Agency may object on reasonable data-protection grounds.
Where Model Personal Data is transferred outside the EEA, the transfer is governed by the Standard Contractual Clauses (Module 2, Commission Decision (EU) 2021/914) and/or the EU-US Data Privacy Framework where the sub-processor is certified. Core data is hosted in the EU (Frankfurt).
5. Personal-data breach
Railex notifies the Agency without undue delay after becoming aware of a personal-data breach affecting Model Personal Data (target: within 48 hours), with the information available under Article 33(3).
6. Liability, term and governing law
Liability under this Agreement is subject to the limitations in the Modacast Terms of Service. This Agreement remains in force while Railex processes Model Personal Data on the Agency’s behalf.
This Agreement is governed by Estonian law, without prejudice to the mandatory rights of data subjects and the competence of supervisory authorities.
7. Acceptance
This Agreement is accepted electronically by the Agency’s owner or admin during onboarding; the accepted version and timestamp are recorded. Questions: info@modacast.co.

