Legal
Data Processing Agreement
Last updated: June 2026
Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between RealTime.Photos (operated by Nanjing Zhiyin Trading Co., Ltd.) and the photographer or organisation using the platform ("Controller"). It governs the processing of personal data that the Controller uploads to the platform in the course of using the service.
By accepting the Terms of Service, the Controller enters into this DPA. Where applicable law requires a separately signed agreement, the Controller may request a countersigned copy by emailing hello@realtime.photos with the subject line "DPA Request".
Definitions
Applicable Data Protection Law means the EU General Data Protection Regulation (GDPR 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and any other applicable national or state-level data protection or privacy legislation.
Controller means the photographer or organisation that determines the purposes and means of processing personal data uploaded to RealTime.Photos.
Processor means RealTime.Photos (Nanjing Zhiyin Trading Co., Ltd.), which processes personal data on behalf of the Controller.
Sub-Processor means any third-party processor engaged by RealTime.Photos to process personal data in the course of providing the service.
Data Subjects means the individuals whose personal data is contained in content uploaded by the Controller.
The terms Personal Data, Processing, Data Breach, and other capitalised data protection terms have the meanings given to them in the GDPR.
Roles & responsibilities
The Controller is the data controller for the personal data of event guests and other individuals whose images are uploaded to the platform. RealTime.Photos is the data processor, processing that data solely on the Controller's behalf and in accordance with this DPA and the Controller's documented instructions (as set out in the Terms of Service).
The Controller is responsible for:
- Ensuring it has complied with its transparency obligations to data subjects under GDPR Articles 13–14 (or equivalent under applicable law), including disclosing that face recognition is in use at the event. The platform's Print-ready QR card (Share tab) is designed for this.
- Ensuring that the chosen consent configuration satisfies its obligations under GDPR Article 9(2). Two configurations are available: (i) pre-event consent, in which the Controller collects consent from attendees before the event through a registration form or privacy notice — face recognition indexing then runs after consent already exists; and (ii) in-app consent, in which guests who choose to use face search are shown a consent screen by RealTime.Photos before any photos of them are surfaced. For Standard tier events (Small, Medium, Large), in-app consent is the platform default. For Custom tier events, including Agency Plan, pre-event consent is enabled by default at event creation and the in-app wizard is suppressed — the Controller is responsible for ensuring that attendees have given consent before the event. RealTime.Photos provides ready-to-use consent language from the dashboard to assist with this. The Controller, as data controller, is responsible for ensuring the chosen configuration satisfies Article 9(2)(a) or equivalent applicable law.
- Ensuring that any transfer of personal data to RealTime.Photos complies with applicable cross-border transfer rules.
Details of processing
The subject matter, duration, nature, and purpose of processing carried out by RealTime.Photos as Processor are as follows:
| Subject matter | Operation of the RealTime.Photos event gallery platform on behalf of the Controller |
| Duration | Raw per-face biometric attributes (age range, gender, emotion signals) are deleted within 48 hours of the last photo upload. Face embeddings stored in AWS Rekognition are purged 12 months after the first photo upload. All remaining event data is deleted according to the Controller's plan schedule (7–90 days after the event's first photo upload, or sooner on account deletion). For Custom-plan events, the retention period is agreed per contract. For Agency Plan events, data is retained for the contract duration plus a 30-day wind-down after expiry. |
| Nature | Storage, retrieval, display, format conversion, compression, face recognition analysis, demographic aggregation, and consent recording for photographic content |
| Purpose | Enabling event guests to view and filter photos via the guest gallery; selfie-based photo search; aggregate audience demographics and, for guests who opt in, personalised event sentiment summaries and networking connection counts; like and analytics features |
| Personal data types | Photographic images (which may depict identifiable individuals); biometric identifiers derived from face recognition (face vectors/embeddings); transient per-face demographic and emotion attributes (retained up to 48 hours); device identifiers (for like functionality); guest consent timestamps (for opted-in guests only) |
| Data subject categories | Event attendees and guests whose images appear in photos uploaded by the Controller |
| Special categories | Biometric data (facial images and derived biometric identifiers), processed under GDPR Article 9. Raw per-face age, gender, and emotion attributes are special-category data retained only transiently (up to 48 hours). Two consent configurations are available: (i) pre-event consent, in which the Controller collects consent from attendees before the event through a registration form or privacy notice — under this setup, face recognition indexing runs after consent already exists; or (ii) in-app consent, in which guests who choose to use face search are shown a consent screen before any photos of them are surfaced — under this setup, indexing runs upon photo upload. In-app consent is the platform default for Standard tier events (Small, Medium, Large). For Custom tier events, including Agency Plan, pre-event consent is enabled by default at event creation and the in-app wizard is suppressed. Under both configurations, guests who do not consent or who never interact with face search are never shown face-matched results. The Controller is responsible for ensuring its chosen configuration satisfies GDPR Article 9(2)(a) or equivalent applicable law, and for fulfilling its Articles 13–14 transparency obligations to attendees. The platform's Print-ready QR card (Share tab) is designed to support this. |
Processor obligations
(a) Instructions. RealTime.Photos processes personal data only on documented instructions from the Controller, as set out in the Terms of Service and this DPA. If RealTime.Photos is required by applicable law to process data for another purpose, it will inform the Controller before doing so, unless prohibited by law. RealTime.Photos will also promptly inform the Controller if, in its reasonable opinion, any instruction from the Controller would cause it to infringe Applicable Data Protection Law.
(b) Confidentiality. RealTime.Photos ensures that all personnel authorised to process the Controller's personal data are subject to appropriate confidentiality obligations.
(c) Security. RealTime.Photos implements appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. Current measures include:
- Encryption in transit: all data transmitted between clients, the application, and sub-processors is encrypted using TLS 1.2 or higher.
- Encryption at rest: personal data stored in databases and cloud storage is encrypted at rest using AES-256 or equivalent.
- Access controls: access to personal data is restricted to authorised personnel on a need-to-know basis, enforced through role-based access controls.
- Pseudonymisation: face recognition embeddings are stored separately from photo metadata, reducing the risk of re-identification in the event of a partial breach.
- Security assessments: key platform components undergo regular security reviews.
- Incident response: RealTime.Photos maintains documented incident detection and response procedures.
More detailed information about technical and organisational security measures is available on written request.
(d) Sub-processors. RealTime.Photos engages sub-processors as listed in the Sub-processors section below. By entering into this DPA, the Controller grants general written authorisation for the engagement of those sub-processors. RealTime.Photos will notify the Controller of any intended addition or replacement of a sub-processor by updating this DPA and notifying registered account holders by email or in-app notice at least 14 days in advance. The Controller may object in writing within 14 days of such notice. If the Controller objects and RealTime.Photos cannot reasonably accommodate the objection without engaging the new sub-processor, the Controller may terminate the affected service without penalty, effective 30 days after written notice of termination.
(e) Data subject rights. RealTime.Photos will assist the Controller in fulfilling its obligations to respond to data subject rights requests — including access, rectification, erasure, restriction, portability, and objection — by providing available data, deletion tools, and export functionality via the dashboard or, where not available via the dashboard, upon written request to hello@realtime.photos.
(f) Data breach notification. RealTime.Photos will notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of any confirmed personal data breach affecting the Controller's data. The notification will include: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and measures taken or proposed.
(g) Return and deletion. Upon termination of the service or upon request, RealTime.Photos will delete or return all personal data in accordance with the data retention schedule in the Terms of Service. Upon request, RealTime.Photos will provide written certification of deletion within 30 days of the request.
(h) Audit. RealTime.Photos will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits or inspections conducted by the Controller or a mandated auditor, subject to: reasonable written notice of at least 30 days; a frequency of no more than once per calendar year; and the auditor being bound by appropriate confidentiality obligations.
(i) DPIA and prior consultation support. Where the Controller is required to conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35 in relation to processing carried out by RealTime.Photos, we will provide reasonable assistance — including making available relevant information about our processing activities, security measures, and sub-processors. Where required, we will also assist with any prior consultation with the relevant supervisory authority under GDPR Article 36.
(j) Records of processing. RealTime.Photos maintains records of processing activities carried out on behalf of Controllers, as required by GDPR Article 30(2). These records include the categories of processing performed, the sub-processors engaged, and information about international data transfers. Records are maintained in written form and made available to supervisory authorities upon request.
Sub-processors
The following sub-processors are currently engaged by RealTime.Photos to process personal data of the Controller's event guests:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Photo storage (S3) and face recognition processing (Rekognition) | United States | SCCs (EU Decision 2021/914) + EU-US DPF |
| Convex, Inc. | Database storage — event metadata, face cluster data, analytics counters | United States | SCCs (EU Decision 2021/914) |
| Vercel, Inc. | Application hosting and content delivery | United States | SCCs (EU Decision 2021/914) + EU-US DPF |
Dodo Payments (payment processing), Clerk (photographer account authentication), and Resend (transactional email delivery to photographer accounts) process data of the Controller as an account holder, not data of the Controller's event guests, and are not sub-processors under this DPA.
International transfers
The sub-processors listed above are located in the United States. Personal data transferred from the European Economic Area (EEA) or the United Kingdom to these sub-processors is protected by one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs): EU Commission Decision 2021/914 (for EEA-origin transfers) and the UK ICO's International Data Transfer Addendum (for UK-origin transfers), incorporated into our agreements with each sub-processor.
- EU-US Data Privacy Framework or UK Extension: where a sub-processor holds a current certification under these frameworks, transfers to that entity may additionally rely on the applicable adequacy decision.
The Controller may request a summary of the transfer mechanisms in place for each sub-processor by contacting hello@realtime.photos.
US privacy law
Where the Controller or their data subjects are subject to the CCPA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), or any other applicable US state privacy law, RealTime.Photos agrees to act as a "service provider" or "processor" as defined under the applicable law, and will:
- Process personal data only for the business purposes specified in this DPA and the Terms of Service, and not sell or share it for cross-context behavioural advertising.
- Not retain, use, or disclose personal data for any purpose other than providing the service, except as permitted by applicable law.
- Assist the Controller in meeting its obligations to respond to consumer rights requests — including access, deletion, correction, and opt-out — in relation to personal data processed on the Controller's behalf.
- Notify the Controller promptly if RealTime.Photos determines it can no longer meet its obligations under applicable US privacy law.
Changes to this DPA
We may update this DPA from time to time to reflect changes in Applicable Data Protection Law, platform features, or sub-processor arrangements. We will provide at least 14 days' advance notice of material changes by email or in-app notice to registered account holders. Continued use of the platform after the effective date constitutes acceptance of the revised DPA.
Where applicable law requires a separately executed DPA, the Controller may request a countersigned copy of the current version at any time by contacting hello@realtime.photos with the subject line "DPA Request".
Governing law
This DPA is governed by the laws of Spain and the European Union. Where the Controller is established in the United Kingdom, this DPA shall be interpreted consistently with UK data protection law (UK GDPR and the Data Protection Act 2018). Where the Controller is subject to US state privacy law, the provisions of the US Privacy Law section above apply concurrently and are not limited by this governing law clause.
General provisions
Precedence. In the event of any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA shall take precedence. For all other matters, the Terms of Service shall govern. Where a Controller has entered into a separate written agreement with RealTime.Photos that expressly supersedes these Terms of Service, that agreement also takes precedence over this DPA to the extent it expressly addresses any matter covered herein — including the limitation of liability applicable to claims arising under this DPA.
Term. This DPA remains in force for the duration of the Terms of Service and terminates automatically when the Terms of Service terminate or expire, subject to the Survival clause below.
Survival. The obligations under sections (b) Confidentiality, (c) Security, (f) Data breach notification, (g) Return and deletion, and (j) Records of processing survive termination of this DPA for as long as RealTime.Photos retains any personal data of the Controller, or for any longer period required by applicable law.
Limitation of liability. Each party's liability arising out of or related to this DPA is subject to the limitation of liability provisions set out in the Terms of Service. Nothing in this DPA is intended to expand either party's aggregate liability beyond the cap established in the Terms of Service.
Contact
For data protection enquiries, to exercise data subject rights, or to request a countersigned copy of this DPA, contact us at hello@realtime.photos with the subject line "DPA Request".