Skip to content

Legal

Data Processing Agreement

Last updated September 29, 2026

Draft — requires review by a lawyer
This document is a working draft published for transparency. It has not yet been reviewed by a lawyer and may change before it becomes final.

1. Parties and scope

This Data Processing Agreement ("DPA") is between the venue that uses a Snapia venue subscription (the "Venue") and Snapia Technologies FZ-LLC, [Registered address, United Arab Emirates] ("Snapia"). It forms part of the Terms of Service and applies automatically when the Venue accepts them.

Where the Venue creates an event, the Venue is the controller of the guest content and related personal data of that event, and Snapia is its processor. Snapia remains a controller for its own account and billing data, as described in the Privacy Policy.

2. Details of the processing

  • Subject matter: hosting and processing event content and related data to provide the Snapia service.
  • Duration: the term of the venue subscription plus the retention period of each event (12 months after the event, unless extended), followed by deletion.
  • Nature: collection through upload pages, storage, creating previews, converting videos, removing location metadata, optional automated moderation, display through signed links, download and deletion.
  • Purpose: solely to provide the service to the Venue and its hosts.
  • Data subjects: guests, hosts and Venue staff.
  • Categories of data: names (optional for guests), contact details of hosts and staff, photos, videos, voice recordings, written guestbook messages, guest device tokens and technical logs.

Snapia does not perform face recognition or face search. The service is not designed for special categories of data, and the Venue should not instruct Snapia to process such data beyond what may incidentally appear in event content.

3. Access to album content

By default, Venue staff cannot view the content of a host's album, even for events the Venue created, unless the host grants access in the album settings. The Venue instructs Snapia to apply this default and accepts that its staff see only event settings and non-content information until the host grants access.

4. Venue obligations

The Venue is responsible for having a lawful basis for the processing, for informing guests and hosts (for example with a notice next to the QR code), and for ensuring its instructions comply with applicable data protection law.

5. Snapia's obligations

Instructions

Snapia processes personal data only on the Venue's documented instructions, which consist of this DPA, the Terms of Service and the Venue's use of the service settings. Snapia will inform the Venue if it believes an instruction breaks data protection law, unless the law prohibits this.

Confidentiality

Snapia ensures that everyone authorised to process the data is bound by confidentiality obligations.

Security measures

Snapia maintains appropriate technical and organisational measures, including:

  • storage in a private Cloudflare R2 bucket under EU jurisdiction, with no public access;
  • access to files only through short-lived signed links;
  • encryption in transit and encryption at rest by the storage provider;
  • automatic removal of GPS metadata from stored photos;
  • role-based access, including the default restriction on Venue staff described above;
  • bot protection and rate limiting on upload pages;
  • least-privilege internal access, strong authentication for administrative accounts and logging;
  • regular updates and security patching.

Sub-processors

The Venue authorises Snapia to use the following sub-processors:

  • Cloudflare: storage, content delivery and bot protection;
  • E-mail delivery provider [name to be confirmed]: service e-mails to hosts and staff;
  • Sentry (optional): error monitoring;
  • AI moderation provider [name to be confirmed] (optional): only for albums where moderation is enabled.

Our payment provider, Stripe, processes billing data for which Snapia is the controller; it does not process event content. Snapia will give at least 30 days' notice of any new or replacement sub-processor. The Venue may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Venue may terminate the affected part of the service. Snapia imposes data protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for their performance.

Data subject requests

Snapia will, taking into account the nature of the processing, help the Venue respond to requests from data subjects. Guests can delete their own uploads directly. If Snapia receives a request that concerns the Venue's events, it will forward it to the Venue without undue delay.

Personal data breaches

Snapia will notify the Venue without undue delay after becoming aware of a personal data breach affecting the Venue's data, and will provide the information reasonably available to help the Venue meet its own notification duties.

Deletion or return

At the end of each event's retention period, or earlier on the Venue's written instruction, Snapia deletes the event content. Before deletion, the Venue or host can download content through the service. Snapia may keep data only where the law requires it.

Audits and assistance

Snapia will make available the information reasonably needed to demonstrate compliance with this DPA and will assist with data protection impact assessments where relevant. The Venue may carry out an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days' reasonable notice, during business hours, no more than once a year unless required by a regulator or following a breach. Each party bears its own costs, and Snapia may first provide existing certifications or reports of its sub-processors.

6. International transfers

Event content is stored in the EU. Snapia is based in the United Arab Emirates, and some sub-processors may process data in other countries, including the United States. Where required, Snapia ensures transfers are protected by appropriate safeguards, such as standard contractual clauses, and for Türkiye the mechanisms under Article 9 of Law No. 6698.

7. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. On data protection matters, this DPA prevails over the Terms of Service.

8. Contact

Data protection questions: privacy@snapia.co. Legal notices: legal@snapia.co.

Questions about this document? Write to privacy@snapia.co.