SendShoot

Legal

Data Processing Addendum

Effective and last updated 23 September 2026 · Asika Emmanuel Digital Enterprise, trading as SendShoot

For photographers who need it for GDPR, UK GDPR or the Nigeria Data Protection Act. It’s already part of your agreement with SendShoot, so there’s nothing to sign.

The short version
  • You control your clients’ data. We process it only to run your galleries.
  • We never sell it, use it for ourselves or train AI on it.
  • Subprocessors are listed publicly, with 14 days’ notice before changes.
  • We tell you about a breach without undue delay, within 48 hours where we can.
  • Delete photos or your whole account whenever you like.

This summary helps you find your way around. The full text below is what applies.

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the SendShoot Terms of Service between you, the photographer, and Asika Emmanuel Digital Enterprise, trading as SendShoot. It applies whenever we process personal data on your behalf through the Service.

For that data, you are the controller and we are your processor. It applies under the EU General Data Protection Regulation, the UK GDPR and the Nigeria Data Protection Act 2023, and similar laws, where they apply to you. You accept this DPA by accepting the Terms. You don’t need to sign anything separately.

2. Details of the processing

  • Subject matter and purpose: hosting, displaying and delivering your photos to your clients, recording their favourites, notes, messages and downloads, and sending the related emails.
  • People concerned: your clients and gallery visitors, and the people who appear in your photos.
  • Types of personal data: names, email addresses, photographs of people, notes and messages, and gallery activity such as opens, downloads, device type and approximate location.
  • Special categories: we don’t ask for any. Photos can sometimes reveal sensitive information. You decide what to upload, and you’re responsible for having a lawful basis for it.
  • Duration: for as long as you use the Service, then until deletion as described in section 7.

3. Your instructions

We process your clients’ personal data only to provide the Service and on your documented instructions. Your use of the Service’s settings and features counts as those instructions. If we believe an instruction breaks data protection law, we’ll tell you. We won’t use this data for our own purposes, sell it, or use it to train artificial intelligence models.

4. Confidentiality and security

Anyone who can access the data is bound by confidentiality. We keep appropriate technical and organisational measures in place, including:

  • encryption in transit;
  • encryption at rest by our infrastructure providers;
  • private storage with no public access;
  • passcode-protected galleries with rate-limited guessing;
  • access to production systems limited to people who need it; and
  • sign-in security provided by Clerk.

5. Subprocessors

You authorise us to use the subprocessors listed in our Privacy Policy. We have contracts with them that require data protection at least as strong as this DPA. We’ll give account holders at least 14 days’ notice by email before adding or replacing a subprocessor that handles your clients’ personal data. If you object on reasonable data protection grounds and we can’t address the objection, you may cancel and receive a pro-rata refund of any prepaid fees.

6. Helping you meet your obligations

The Service lets you view, correct and delete the personal data in your galleries yourself. If a client contacts us directly, we’ll send them to you, unless we’re legally required to respond ourselves.

We’ll give you reasonable help with data protection impact assessments and consultations with regulators, where they relate to the Service.

7. Deletion and return

You can download your photos and delete shoots or your whole account at any time. Deleted photos are removed from storage shortly afterwards, and expired shoots are deleted 90 days after they expire. When you ask us, we’ll also erase the remaining database records about your clients, unless the law requires us to keep them.

8. Personal data breaches

If we become aware of a personal data breach affecting your clients’ data, we’ll notify you without undue delay, and within 48 hours where we can. We’ll include what we know about the breach and the steps we’re taking, and keep you updated.

9. International transfers

Personal data may be processed outside the country where you or your clients are, including in Nigeria, Europe and the United States. Where the law requires it, transfers are covered by the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and these are incorporated into this DPA where needed.

10. Information and audits

We’ll give you the information reasonably needed to show that we meet this DPA, including our subprocessors’ security documentation where available. If that isn’t enough and a regulator requires it, we’ll cooperate with a reasonable audit, on reasonable notice and at your cost.

11. Liability and precedence

The limits of liability in the Terms apply to this DPA, except where the law doesn’t allow them to. If this DPA and the Terms conflict on data protection, this DPA wins.

Contact

Questions about this policy go to support@sendshoot.com. SendShoot is operated by Asika Emmanuel Digital Enterprise, Nigeria.