Data Processing Agreement

Effective: August 9, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Hey Photo Friend ("we", "us", "Processor") and the photographer or studio using the service ("you", "Controller"). It applies whenever we process personal data about your clients on your behalf.

1. Who is responsible for what

This distinction matters, so it is worth stating plainly:

If one of your clients contacts us directly with a request about their data, we will not act on it. We will tell them to contact you, and let you know it happened.

2. What we process

Subject matter Providing in-person sales, gallery delivery and studio management software.
Duration For as long as your account is active, plus the retention periods in section 6.
Data subjects Your photography clients and the people appearing in the photographs you upload, which may include children.
Personal data Names, email addresses, phone numbers, photographs, session notes, product selections, order and payment records, invoice details, order approvals (typed name, signature image, IP address), and any notes or tags you add.
Special categories We do not ask for special category data. Photographs can reveal it — racial or ethnic origin, religious belief, health — and photographs of children carry additional protections in most jurisdictions. Deciding whether you may lawfully take and store those images is yours to make.

3. Our obligations

4. Sub-processors

You authorise us to use sub-processors to run the service. Each is bound by data protection terms no less protective than these. The current list is in section 3 of our Privacy Policy and includes Supabase, Clerk, Cloudflare, Stripe, Square, Resend, Vercel, Sentry, Anthropic, Calendly, ActiveCampaign and HighLevel.

We will give you 30 days' notice before adding or replacing a sub-processor that handles your clients' personal data. If you object on reasonable data protection grounds, tell us within those 30 days and we will work with you on an alternative; if there isn't one, you may terminate the affected part of the service without penalty.

5. Security

No system is perfectly secure. We keep these measures under review and may change them, provided protection is not reduced.

6. Retention, deletion and return

You control retention. Specifically:

One exception, and it is deliberate. Where the law requires us or you to retain records — principally records of payments actually made — we keep those for the period required, even after an erasure request. In that case we destroy the personal information attached to them and retain only the financial record. Nothing in this DPA requires either of us to break a retention law in order to honour a deletion request.

7. International transfers

We and our sub-processors store and process data in the United States and potentially other countries. Where data protection law requires a transfer mechanism — such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum — those clauses are incorporated into this DPA by reference and apply to the relevant transfers, with us as data importer and you as data exporter.

8. Your obligations

9. General

This DPA takes effect when you accept the Terms of Service and continues while we process your clients' data. If it conflicts with the Terms of Service on data protection, this DPA governs. If a court finds any part unenforceable, the rest continues to apply. We may update this DPA as the product or the law changes; material changes will be announced by email or in the product before taking effect.

10. Contact

Data protection questions, breach notifications, audit requests, or a signed copy of this DPA for your records: privacy@heyphotofriend.com.

Privacy Policy · Terms of Service