Data processing agreement
1. Parties and roles
You as the customer are the data controller for the personal data processed in your event — above all the pictures of your guests and the names they chose to give. We are the data processor and process them only on your documented instructions.
If you are a partner reselling the service, you are the processor towards your end customer and we are a sub-processor in that chain. Who the contracting party is, who the controller is and where a support question goes is stated on each event's package page, for that particular event.
2. Subject matter of the processing
The processing takes place in order to deliver the photo sharing service: receiving pictures and video from guests, deriving the variants the gallery and the live wall need, storing the material for the agreed period, making it available to you and those you have given access, and handing it over as an archive. No other processing occurs.
Categories of data subjects: your guests and the people appearing in the material, and the users you have given access to the event. Categories of data: pictures, video, voluntarily given names and greetings, technical data about the upload, and timestamps.
3. Our instructions and our limits
We process the data only according to your instructions and this agreement. We never use the material for our own purposes: not for marketing, not for product development and not to train machine learning models. Nor do we hand it to anyone who does.
Should we be required by law to process the data in some other way, we inform you before the processing unless the law forbids us from doing so.
4. Security
The data is encrypted in transit and at rest. Access to customer material requires a named action with a stated reason and is written to an append-only audit log; nobody in our organisation has standing read access to your pictures. Staff with access are bound by confidentiality.
5. Sub-processors
You give us general prior authorisation to engage sub-processors. Who they are, what they do and in which region is stated in the list of sub-processors, an annex to this agreement. We give you reasonable notice before a sub-processor is added or replaced, and you have the right to object.
We impose on every sub-processor the same obligations we have under this agreement, and we remain liable to you for their processing as for our own.
6. Where processing takes place
All processing and storage takes place within the EU and the EEA, in the storage region the event is set to. We transfer no personal data to third countries.
7. Assistance to you
We assist you in responding to data subjects' requests for access, rectification and erasure, and in meeting your obligations regarding security, breaches and impact assessments. A guest wanting a picture removed can report it directly in the gallery; the decision is yours, with us as the last instance.
8. Personal data breaches
If we discover a personal data breach we notify you without undue delay and within 72 hours at the latest, with what we know about what happened, which data is affected and what measures we have taken.
9. Deletion and return
When the viewing period has expired you have at least 30 days to export all the material before it is deleted. When the agreement ends we delete the personal data, except for the accounting data we are required by law to keep — which is limited to invoicing data and described in the privacy information.
10. Audit
You have the right to the information needed to demonstrate that our obligations are met, and to audit the processing. An audit is announced with reasonable notice and carried out so that it does not disturb the operation of other customers' events.
11. Term
This agreement applies for as long as we process personal data on your behalf. A new version is published with its own version number; earlier versions remain readable.