Data Processing Addendum
Last updated: 2026-09-18
This Data Processing Addendum ("DPA") supplements the papershot Terms of Service between you (the "Customer" or "Controller") and Wellbayt LLC-FZ, a free zone limited liability company registered in Dubai, United Arab Emirates ("papershot" or "Processor"). It applies when the Customer uses papershot and the processing of personal data is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR"), the UK General Data Protection Regulation ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), or other applicable data protection law ("Data Protection Laws").
1. Roles and Scope
The Customer is the controller of Customer Personal Data (the one who decides why and how it is processed) and papershot is the processor (the one who processes it on the Customer's instructions). Subprocessors engaged by papershot act as sub-processors of the Customer through papershot.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: processing of Customer Personal Data to deliver papershot as described in the Terms of Service.
- Duration: the term of the Terms of Service, plus any retention the law requires.
- Nature and purpose: storing, screening and serving the photos, videos and memos added to a moment, together with moment details and prompts; revealing them to the moment's participants on the schedule the host sets; sending push notifications, Live Activities and transactional email; receiving and validating payments; handling reports and blocks; operating, securing and improving the service; and deleting media when a moment expires.
3. Types of Personal Data and Data Subjects
- Types: Apple or Google sign-in identifiers, names and email addresses; display names and profile photos; signed install identifiers for guests without an account; photos, videos and memos with the film look applied, their dimensions and taken-at time (EXIF reduced to an allow-list on upload); moment details, video and memo prompts, and Guest Lens prompts; favourites; reports and blocks; purchase receipts and product identifiers; push notification and Live Activity tokens; device platform and last-seen time; consent records (kind, granted or revoked, time, IP address); IP addresses; and pseudonymous identifiers in crash and analytics data.
- Data subjects: hosts (people who make moments), guests (people who join moments, with or without an account), people who appear in the media, and where applicable employees and contractors of the Customer.
4. Processor Obligations
- Process Customer Personal Data only on documented instructions from the Customer, including about transfers, unless the law requires otherwise.
- Make sure the people authorised to process Customer Personal Data are bound by confidentiality.
- Put in place appropriate technical and organisational measures, as described in Annex II below.
- Help the Customer respond to data subject requests, carry out data protection impact assessments and prior consultations, and notify supervisory authorities and data subjects.
- At the Customer's option, delete or return Customer Personal Data at the end of the services, except where the law requires retention.
- Make available the information needed to show compliance with this DPA, and allow and contribute to audits, on reasonable notice and at reasonable cost, no more than once a year unless a regulator requires more.
5. Subprocessors
The Customer authorises papershot to engage the subprocessors listed in Annex III below and at /subprocessors. papershot notifies the Customer at least 30 days before adding or replacing a subprocessor that processes Customer Personal Data. The Customer may object on reasonable data-protection grounds. If the parties cannot agree, the Customer may end the affected services with a pro-rata refund of prepaid fees.
6. International Transfers
Where Customer Personal Data of EEA data subjects is transferred outside the EEA, the EU Commission Standard Contractual Clauses (Module Two, controller to processor; or Module Three, processor to processor; June 2021) are incorporated by reference. The clauses are completed as follows: Clause 7 (docking) applies; Clause 9(a) Option 2 (general written authorisation) applies; Clause 11 opt-in does not apply; Clause 17 Option 1 (laws of an EU Member State, Ireland) applies; Clause 18(b) (courts of Ireland) applies. The Annexes are populated by the Customer's and papershot's identification details, the descriptions in sections 2 and 3 of this DPA, and Annexes II and III below.
For UK transfers, the UK International Data Transfer Addendum (Version A1.0) is incorporated, with Tables 1, 2 and 3 populated accordingly and Table 4 unchecked.
For Swiss transfers, the SCCs are read with references to EU law replaced or supplemented by Swiss law where the FADP requires it.
For transfers from the United Arab Emirates, papershot follows Articles 22 and 23 of the UAE PDPL and the UAE Data Office's guidance on cross-border transfer.
7. Security (Annex II)
- TLS in transit, including forced TLS to the database; AES-256 with KMS-managed keys at rest.
- Media uploaded straight from the device to storage over short-lived signed URLs and delivered through CloudFront.
- Role-based access control with MFA on all administrative access.
- Network segmentation, least-privilege IAM, and audit logging of every tester and administrator action.
- Intrusion detection, automated vulnerability scanning, and patch management.
- Annual third-party penetration testing; quarterly internal review.
- Vulnerability disclosure via security.txt.
- Mobile auth tokens stored in Apple Keychain and Android EncryptedSharedPreferences.
- Backups encrypted; backup retention 35 days; tested restore procedures.
8. Incident Response
papershot notifies the Customer of any Personal Data Breach (within the meaning of Article 4(12) GDPR) affecting Customer Personal Data without undue delay, and in any case within 72 hours of becoming aware. The notice includes the information listed in Article 33(3) GDPR as far as it is known at the time.
9. Data Subject Requests
papershot forwards to the Customer any request it receives from a data subject about Customer Personal Data, without responding directly unless the Customer has authorised it. papershot helps the Customer respond within the timeframes the Data Protection Laws require.
10. Records
papershot keeps the records required by Article 30(2) GDPR.
11. Term and Termination
This DPA takes effect on the effective date of the Terms of Service and stays in effect for as long as papershot processes Customer Personal Data for the Customer. Sections 6 (transfers), 7 (security), 8 (incident response) and 12 (governing law) survive termination as needed to give effect to their purpose.
12. Governing Law
This DPA is governed by the federal laws of the United Arab Emirates as applied in the Emirate of Dubai, except that the EU SCCs and the UK Addendum are governed by their own stated laws. Mandatory provisions of local law apply where required.
13. Acceptance
If you need a signed copy of this DPA, email papershot@wellbayt.com with "Legal: DPA" in the subject line. We counter-sign within 10 business days. Using the service after being notified of this DPA counts as acceptance.
Annex III: Subprocessors
The current list, with regions and data categories, is kept at /subprocessors. As of 2026-09-18:
- Amazon Web Services (S3, CloudFront, RDS, KMS, Rekognition, SES): storage, delivery, database, key management, automated screening of thumbnails and poster frames, and transactional email. Ireland (eu-west-1).
- Apple: in-app purchases and App Store Server Notifications, Apple Push Notification service, Sign in with Apple.
- Google: Firebase Cloud Messaging, Google Play Billing, Google Sign-In, Firebase Analytics (Google Analytics 4). United States and European Union.
- Sentry: crash and performance monitoring, with a pseudonymous user id only. United States or European Union.
- Stripe: web payments. United States and European Union.