Data Processing Addendum
Last updated: 2026-05-30
This Data Processing Addendum ("DPA") supplements the Papershot Terms of Service between you (the "Customer" or "Controller") and Quantum Byte Technologies, a company registered in the Republic of Kenya ("Papershot" or "Processor"). It applies when Customer uses Papershot and the processing of personal data is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the Kenya Data Protection Act 2019, or other applicable data protection law ("Data Protection Laws").
1. Roles and scope
Customer is the controller of Customer Personal Data and Papershot is the processor. Subprocessors engaged by Papershot act as sub-processors of Customer through Papershot.
2. Subject matter, duration, nature, and purpose
- Subject matter: processing of Customer Personal Data to deliver Papershot as described in the Terms of Service.
- Duration: the term of the Terms of Service, plus any retention required by law.
- Nature and purpose: hosting and serving photos and moment metadata; sending push notifications and transactional email; receiving and validating payments; operating, securing, and improving the service.
3. Types of personal data and data subjects
- Types: account identifiers, display names, photos and their metadata, device identifiers, IP addresses, push tokens, payment receipt identifiers, consents log.
- Data subjects: hosts (people who create moments), guests (people who join moments), and where applicable employees and contractors of the Customer.
4. Processor obligations
- Process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers, unless required by law.
- Ensure personnel authorised to process Customer Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures, as described in Annex II below.
- Assist Customer with responses to data subject requests, data protection impact assessments, prior consultations, and notices to supervisory authorities and data subjects.
- At Customer's option, delete or return Customer Personal Data at the end of the provision of services, except where retention is required by law.
- Make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, on reasonable notice and at reasonable cost, no more than once per year unless a regulator requires more.
5. Subprocessors
Customer authorises Papershot to engage the subprocessors listed at /subprocessors. Papershot will notify Customer at least 30 days before adding or replacing a subprocessor that processes Customer Personal Data. Customer may object on reasonable data-protection grounds. If the parties cannot agree on a resolution, Customer may terminate the affected services with pro-rata refund of prepaid fees.
6. International transfers
Where Customer Personal Data of EEA data subjects is transferred outside the EEA, the EU Commission Standard Contractual Clauses (Module Two, controller to processor; or Module Three, processor to processor; June 2021) are incorporated by reference. The clauses are completed as follows: Clause 7 (docking) applies; Clause 9(a) Option 2 (general written authorisation) applies; Clause 11 opt-in does not apply; Clause 17 Option 1 (laws of an EU Member State, Ireland) applies; Clause 18(b) (courts of Ireland) applies. Annexes are populated by the Customer's and Papershot's identification details, the descriptions in sections 2 and 3 of this DPA, and Annex II below.
For UK transfers, the UK International Data Transfer Addendum (Version A1.0) is incorporated, with Tables 1, 2, and 3 populated accordingly and Table 4 unchecked.
For Swiss transfers, the SCCs are read with references to EU law replaced or supplemented by Swiss law where required by the FADP.
For transfers from Kenya, Papershot complies with section 48 of the Kenya Data Protection Act 2019 and Office of the Data Protection Commissioner guidance on cross-border processing.
7. Security (Annex II)
- TLS 1.3 in transit; AES-256 with KMS-managed keys at rest.
- Role-based access control with MFA on all administrative access.
- Network segmentation, least-privilege IAM, and audit logging.
- Intrusion detection, automated vulnerability scanning, and patch management.
- Annual third-party penetration testing; quarterly internal review.
- Vulnerability disclosure via security.txt.
- Mobile auth tokens stored in Apple Keychain and Android EncryptedSharedPreferences.
- Backups encrypted; backup retention 35 days; tested restore procedures.
8. Incident response
Papershot will notify Customer of any Personal Data Breach (within the meaning of Article 4(12) GDPR) affecting Customer Personal Data without undue delay, and in any case within 72 hours of becoming aware. The notice will include the information listed in Article 33(3) GDPR to the extent then known.
9. Data subject requests
Papershot will forward to Customer any request received from a data subject relating to Customer Personal Data, without responding directly unless Customer has authorised it. Papershot will assist Customer in responding within the timeframes required by Data Protection Laws.
10. Records
Papershot maintains the records required by Article 30(2) GDPR.
11. Term and termination
This DPA takes effect on the effective date of the Terms of Service and remains in effect for as long as Papershot processes Customer Personal Data on Customer's behalf. Sections 6 (transfers), 7 (security), 8 (incident response), and 12 (governing law) survive termination as needed to give effect to their purpose.
12. Governing law
This DPA is governed by the laws of the Republic of Kenya, except that the EU SCCs and the UK Addendum are governed by their respective stated laws. Mandatory provisions of local law apply where required.
13. Acceptance
If you need a signed copy of this DPA, email legal@papershot.com with "Legal: DPA" in the subject line. We will counter-sign within 10 business days. Use of the service after notification of this DPA constitutes acceptance.