LEGAL · PHOTOSTRIP STUDIO
Data Processing Addendum
Controller–processor terms for business customers that use PhotoStrip Studio to handle client personal data.
1. Parties and application
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Oliver Perkins Robb, a sole trader operating PhotoStrip Studio (“Processor”), and the customer agreeing to those terms (“Customer” or “Controller”). It applies where PhotoStrip Studio processes personal data on the Customer’s behalf in connection with the service.
If the Customer is itself a processor, references to Controller include the relevant controller and PhotoStrip Studio acts as a subprocessor. The Customer confirms it is authorised to appoint PhotoStrip Studio on the terms of this DPA.
2. Definitions and priority
“Data Protection Law” means privacy and data-protection law applicable to the processing, including the UK GDPR and Australian Privacy Act where applicable. “Personal Data”, “Process”, “Controller”, “Processor” and “Data Subject” have the meanings given by applicable Data Protection Law. If this DPA conflicts with the Terms on processing personal data, this DPA controls.
3. Processing instructions
PhotoStrip Studio will process Customer Personal Data only on documented instructions from the Customer, including instructions expressed through normal use of the service, unless law requires otherwise. If legally permitted, we will tell the Customer before processing required by law. We will notify the Customer if an instruction appears to infringe applicable Data Protection Law, but the Customer remains responsible for its instructions and legal basis.
4. Customer obligations
- Provide lawful, fair and transparent instructions and all required notices to Data Subjects.
- Have a valid legal basis for collection, use, disclosure and transfer of Customer Personal Data.
- Use the service’s security, deletion, expiry and access controls appropriately.
- Avoid special-category, highly sensitive, criminal-offence, government-identifier, payment-card or health data unless expressly agreed in writing.
- Respond to Data Subjects and regulators as Controller and promptly give us information reasonably needed to assist.
5. Confidentiality
PhotoStrip Studio will ensure people authorised to process Customer Personal Data are subject to confidentiality duties and access it only as needed for their responsibilities.
6. Security
PhotoStrip Studio will maintain reasonable technical and organisational measures appropriate to the nature and risk of processing. Measures include, as applicable, encrypted network transport, authenticated operator access, database ownership controls, private asset storage, protected administrative credentials, tokenised client links, provider access controls, software maintenance, logging and incident-response procedures.
The Customer acknowledges that shareable client links intentionally permit access without client authentication and must be distributed, expired and revoked with care.
7. Subprocessors
The Customer gives general written authorisation for PhotoStrip Studio to use subprocessors needed to provide the service. Current subprocessors and supporting providers include Cloudflare for hosting, content delivery, serverless compute, database services and private object storage; Resend for transactional emails; Google for customer-selected authentication; and SplitForms for customer-initiated feedback. PhotoStrip Studio uses the Better Auth software framework within its Cloudflare-hosted application to manage authentication.
We will remain responsible for subprocessors to the extent required by Data Protection Law and impose appropriate data-protection obligations. We may add or replace a subprocessor for legitimate service reasons. Where required, we will provide advance notice and a reasonable opportunity to object on substantiated data-protection grounds. If no reasonable alternative is available, either party may end the affected service.
8. International transfers
The Customer authorises processing in Australia, North America and other regions where authorised providers operate. Each party remains responsible for any transfer rules that apply to transfers it initiates. Where a restricted transfer requires contractual safeguards, the parties will put the applicable UK International Data Transfer Agreement or UK Addendum, or European Commission standard contractual clauses, in place before relying on them. This paragraph does not by itself complete those instruments or any required transfer assessment.
9. Data Subject requests
Taking into account the nature of processing, PhotoStrip Studio will provide reasonable assistance through product functionality or support so the Customer can respond to requests to access, correct, delete, restrict, object or export. If we receive a request relating primarily to Customer Personal Data, we will direct it to the Customer where legally permitted and will not respond substantively except on instructions or as required by law.
10. Personal-data breaches
PhotoStrip Studio will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. We will provide information reasonably available about the nature of the breach, likely consequences, affected information and measures taken, and will provide reasonable cooperation. Notification is not an admission of fault. The Customer is responsible for determining and making Controller notifications unless law requires PhotoStrip Studio to notify directly.
11. Assessments and regulatory assistance
Taking into account the processing and information available to us, we will provide reasonable assistance with data-protection impact assessments, regulator consultations and compliance enquiries relating to the service. Material assistance beyond standard documentation and support may be charged at a reasonable agreed rate unless caused by our breach.
12. Information and audits
We will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer and allow for and contribute to audits and inspections required by applicable law. The Customer should first use current policies, security information and third-party reports we make available where these meet its needs. Other audits will be arranged on reasonable notice and subject to confidentiality, security and protection of other customers; an annual cadence does not prevent an audit reasonably required after a material incident or by a regulator. The Customer ordinarily bears its audit costs unless the audit identifies a material breach by PhotoStrip Studio.
13. Return and deletion
During the service, the Customer may delete projects and other content using available controls. At the end of the service, PhotoStrip Studio will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies within a reasonable period, unless applicable law requires storage. Residual backup or provider-system copies that cannot be removed immediately will be kept protected and beyond ordinary use until overwritten in the ordinary cycle.
14. Processing details
- Subject matter: hosted photo-booth project, design and client-collaboration services.
- Duration: the Customer’s use of the service plus the limited retention and deletion period described above.
- Nature and purpose: collection, organisation, storage, rendering, retrieval, transmission, review, export and deletion according to Customer instructions.
- Data Subjects: Customer personnel and contractors; clients, invitees, reviewers, brief respondents and Client Workspace contributors designated by the Customer.
- Data types: names, email addresses, business and brand details, event information, client briefs, comments, decisions, designs, images, logos, submissions, timestamps and related technical records.
- Sensitive data: not intended or authorised without a separate written agreement.
15. Liability, duration and contact
Liability under this DPA is subject to the Terms of Service to the maximum extent permitted by law. This DPA continues while PhotoStrip Studio processes Customer Personal Data. Data-protection enquiries and requests for transfer terms can be sent to hello@photostripstudio.com.