Data processing agreement
Version 2026-09-28. Part of the Terms of Service.
1. Parties and scope
This agreement is between the operator that holds a Patifot account ("Operator", the controller) and PATIFOT, société par actions simplifiée à associé unique (SASU), RCS Paris 983 410 473, 58 rue de Monceau, CS 48756, 75380 Paris Cedex 08, France ("Patifot", the processor). It is part of the Terms of Service and meets Article 28 of the GDPR. It covers the personal data of Guests that Patifot processes for the Operator through the Service, from the first real Guest photo, including during a free trial. Words defined in the Terms of Service have the same meaning here.
2. Subject matter and duration
Patifot processes Guest data to run booth sessions, compose and print the requested images, keep the closed event archive, deliver it to the Operator or an event host the Operator authorises, delete it on schedule, secure the Service and provide support. The processing lasts as long as the Operator uses the Service, plus the retention periods in the Privacy Policy.
3. Data and data subjects
The data subjects are Guests photographed at the Operator's booths. They can include children when a parent, a legal guardian or an adult authorised by one of them starts the session. The data are accepted and rejected takes, finished prints, event and session identifiers, choices made on screen, and a minimal record of the notice shown and of the Start action. Patifot does not run face recognition and does not create biometric templates. The Operator does not use the Service to process special categories of personal data on purpose.
4. Instructions
The Operator's documented instructions are this agreement, the Terms of Service and the event settings the Operator publishes in the Dashboard. The Operator instructs Patifot to keep the minimal notice record and the deletion journal for the periods stated in the Privacy Policy, so that the processing can be accounted for. Patifot processes Guest data only on these instructions, unless EU or Member State law requires otherwise; in that case Patifot informs the Operator first, unless that law forbids it. Patifot tells the Operator immediately if it considers that an instruction infringes data protection law.
5. Confidentiality
Only authorised Patifot staff access Guest data, only as far as the purposes above require, and each of them is bound by a duty of confidentiality.
6. Security
Patifot applies the following measures under Article 32 of the GDPR: encryption in transit (TLS), application servers in the EU, encrypted off-site backup copies, restricted and logged access to production systems, App Attest checks that requests come from a genuine copy of the app, signed deletion permits exchanged between the server and the iPads, and automatic deletion on the published schedule. Patifot reviews these measures when the Service changes. Guest photos are not exchanged by e-mail: the Operator does not send Guest data to Patifot by e-mail, and Patifot support looks at event data only through a short-lived support access to the Dashboard that the account owner approves and can revoke.
7. Subprocessors
The Operator gives Patifot a general authorisation to use subprocessors. For Guest data they are currently UpCloud Oy (application servers and storage in the EU), Backblaze, Inc. (off-site backup copies in its EU region), Cloudflare, Inc. (network delivery and protection) and Proton AG, Switzerland (the [email protected] mailbox, which can receive requests from Guests). Patifot gives at least 30 days' notice by e-mail before it adds or replaces a subprocessor. The Operator may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Operator may cancel the subscription before the change applies. Refunds follow the refund policy. Each subprocessor is bound by a written contract with data protection obligations at least as strict as these, and Patifot remains liable for it.
8. Transfers outside the EU
Patifot keeps Guest photos on servers in the EU. Any transfer of Guest data outside the EU relies on a safeguard under Chapter V of the GDPR. Cloudflare may process network data in the United States under the EU-US Data Privacy Framework and standard contractual clauses. Proton AG is based in Switzerland, which is covered by an EU adequacy decision, and stores the support mailbox on its servers in Switzerland, Germany or Norway.
9. Help with data subject requests
Patifot forwards to the Operator, without undue delay, any request it receives from a Guest about the Operator's events. It helps the Operator answer requests under Articles 12 to 23 of the GDPR, for example by finding, exporting or deleting a Guest's photos in the event archive.
10. Help with security and impact assessments
Taking into account the nature of the processing and the information available to it, Patifot helps the Operator meet its obligations under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation of a supervisory authority.
11. Personal data breaches
Patifot notifies the Operator of a personal data breach affecting Guest data without undue delay, and at the latest 48 hours after becoming aware of it. The notice gives the information listed in Article 33(3) of the GDPR as far as it is known, and Patifot completes it as more becomes available.
12. End of the processing
When the Operator stops using the Service, it chooses whether Patifot returns or deletes the Guest data it still holds. The Operator downloads the event archives (photos and prints) from the Dashboard while they are kept. On request to [email protected], made before the Operator asks for the deletion of its account, Patifot also returns the other Guest data it holds for the Operator, such as the notice and Start records, in a readable file within 30 days; it sends the file password-protected, with the password through a separate channel, and deletes its temporary export once it is delivered. Patifot does not extend the retention periods to wait for a return: data whose deadline has passed is deleted on schedule. After the return, or directly if the Operator chooses deletion, Patifot deletes all its copies of the Guest data when the retention periods end or when the Operator's account is deleted, whichever comes first, and backup copies lose them no later than 15 days after their deletion from the live database. Only two minimal records remain, as instructed in section 4: the record of the notice shown and of the Start action, without names or photos, until its deadline in the Privacy Policy and only for accountability and legal claims; and the deletion journal, which holds identifiers, hashes and signatures only and stops an older backup from restoring deleted data. Storage required by EU or Member State law also remains.
13. Audits
Patifot makes available to the Operator the information needed to show compliance with this agreement. The Operator, or an auditor bound by confidentiality that it appoints, may carry out an audit once a year with 30 days' written notice, at the Operator's cost and without access to other customers' data. The Operator may also audit sooner, with reasonable notice, after a personal data breach, when there are reasonable indications that this agreement is not respected, or when a supervisory authority requires it. Patifot cooperates with inspections by supervisory authorities.
14. Operator's obligations
The Operator determines the lawful basis for each purpose, gives Guests the information required by Articles 13 and 14 of the GDPR through its organizer block at the booth and any other means needed, obtains any consent or permission the law requires, and gives Patifot only lawful instructions.
15. Liability and precedence
Liability under this agreement follows section 11 of the Terms of Service, except where the law does not allow it to be limited. For the processing of Guest data, this agreement prevails over the Terms of Service.
16. Law and language
This agreement is governed by French law, and section 14 of the Terms of Service applies to disputes. It exists in English and in French, and both versions are equally authoritative. The German and Spanish versions are translations for convenience; if they differ, the English version prevails.