Data Processing Agreement
Effective: August 9, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Hey Photo Friend ("we", "us", "Processor") and the photographer or studio using the service ("you", "Controller"). It applies whenever we process personal data about your clients on your behalf.
1. Who is responsible for what
This distinction matters, so it is worth stating plainly:
- You are the controller of your clients' personal data. You decide whose photographs you take, what you record about them, how long you keep it, and what you do with it. You are responsible for having a lawful basis to collect it, for any consent required (including from parents or guardians when you photograph a child), and for responding to your clients' requests.
- We are your processor. We store and process that data only to provide the service to you, and only on your instructions.
- We are a controller for your own account data — your email, billing details and how you use the product. That is covered by our Privacy Policy, not this DPA.
If one of your clients contacts us directly with a request about their data, we will not act on it. We will tell them to contact you, and let you know it happened.
2. What we process
| Subject matter | Providing in-person sales, gallery delivery and studio management software. |
| Duration | For as long as your account is active, plus the retention periods in section 6. |
| Data subjects | Your photography clients and the people appearing in the photographs you upload, which may include children. |
| Personal data | Names, email addresses, phone numbers, photographs, session notes, product selections, order and payment records, invoice details, order approvals (typed name, signature image, IP address), and any notes or tags you add. |
| Special categories | We do not ask for special category data. Photographs can reveal it — racial or ethnic origin, religious belief, health — and photographs of children carry additional protections in most jurisdictions. Deciding whether you may lawfully take and store those images is yours to make. |
3. Our obligations
- We process your clients' data only to provide the service, and only on your documented instructions. Your use of the product is the instruction.
- We do not sell your clients' data, share it with advertisers, or use it to train AI models.
- Everyone with access is bound by confidentiality obligations.
- We apply the security measures in section 5.
- We help you respond to your clients' access, correction and deletion requests — mostly by giving you tools that do it directly, so you are not waiting on us.
- We tell you about a personal data breach affecting your clients without undue delay and within 72 hours of becoming aware, with what we know and what we are doing.
- On request we give you the information needed to demonstrate compliance, and will accept an audit no more than once a year, on reasonable notice, at your cost.
4. Sub-processors
You authorise us to use sub-processors to run the service. Each is bound by data protection terms no less protective than these. The current list is in section 3 of our Privacy Policy and includes Supabase, Clerk, Cloudflare, Stripe, Square, Resend, Vercel, Sentry, Anthropic, Calendly, ActiveCampaign and HighLevel.
We will give you 30 days' notice before adding or replacing a sub-processor that handles your clients' personal data. If you object on reasonable data protection grounds, tell us within those 30 days and we will work with you on an alternative; if there isn't one, you may terminate the affected part of the service without penalty.
5. Security
- In transit: TLS on every connection. Plain HTTP is not accepted.
- At rest: encrypted storage. Payment credentials are held in a dedicated secrets vault, never in plain text.
- Separation: row-level security in the database scopes every record to the account that owns it, enforced by the database itself rather than by application code.
- Photographs: stored in private buckets. Client galleries are reachable only through the link you share, and password-protected galleries are verified server-side against a hashed password.
- Payment cards: handled entirely by Stripe or Square. Card numbers never reach our servers.
- Access control: multi-factor authentication for administrators, and an audit log of privileged actions.
- Abuse: rate limiting and bot challenges on public endpoints.
No system is perfectly secure. We keep these measures under review and may change them, provided protection is not reduced.
6. Retention, deletion and return
You control retention. Specifically:
- Full-resolution originals are permanently deleted 90 days after you archive a session. Previews remain so the session stays viewable.
- You can erase an individual client from the Clients page at any time, which permanently deletes their photographs and the underlying files. See section 6 of the Privacy Policy.
- On termination, we delete or return your clients' data within 30 days of your request. Without a request we delete it within 90 days of account closure.
- Copies can persist in encrypted backups for up to 30 days after deletion, and are deleted when the backup expires.
One exception, and it is deliberate. Where the law requires us or you to retain records — principally records of payments actually made — we keep those for the period required, even after an erasure request. In that case we destroy the personal information attached to them and retain only the financial record. Nothing in this DPA requires either of us to break a retention law in order to honour a deletion request.
7. International transfers
We and our sub-processors store and process data in the United States and potentially other countries. Where data protection law requires a transfer mechanism — such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum — those clauses are incorporated into this DPA by reference and apply to the relevant transfers, with us as data importer and you as data exporter.
8. Your obligations
- Have a lawful basis for the personal data you collect, and give your clients the privacy notice they are entitled to.
- Obtain any consent or release needed to photograph and store images of a person, and from a parent or guardian where the subject is a child.
- Only upload data you are entitled to process.
- Keep your account credentials secure, and remove access for people who no longer need it.
- Respond to your own clients' data protection requests. We give you the tools; the obligation is yours.
9. General
This DPA takes effect when you accept the Terms of Service and continues while we process your clients' data. If it conflicts with the Terms of Service on data protection, this DPA governs. If a court finds any part unenforceable, the rest continues to apply. We may update this DPA as the product or the law changes; material changes will be announced by email or in the product before taking effect.
10. Contact
Data protection questions, breach notifications, audit requests, or a signed copy of this DPA for your records: privacy@heyphotofriend.com.