Data Processing Agreement

Last updated 11 September 2026

When you run an event on Boothiva, the photographs belong to your guests' relationship with you, not with us. This agreement sets out what we will and will not do with them. It forms part of the Terms of Service and applies automatically — there is nothing to sign.

1. Roles

You are the controller. We are the processor. You decide what is captured at your events, who may see it, and how long it is kept. We hold and process it only to provide the service to you, and only as this agreement and your instructions allow.

This does not change who you are to your guests. Under the Privacy Act 1988 (Cth), and any equivalent law that applies where your event is held, the obligations owed to a guest are yours.

2. What is being processed

Subject matterProviding the Boothiva photobooth service to you
DurationFor as long as your account is open, plus the deletion window in clause 9
Nature and purposeStoring, transmitting, rendering, printing and deleting event content on your instructions
Types of personal dataPhotographic images of guests. Session metadata (device, event, timestamps, photo count, consent flag), which contains nothing identifying a guest. Contact details of anyone you enter as an event client contact.
Categories of data subjectGuests attending your events; the client who booked the event, where you record their details

The booth does not ask a guest for a name, email address or phone number, and there is nowhere in the system to store one. A guest's photograph is not linked to any identity we hold. This limits what can be exposed by any failure on our side.

3. Our instructions

We process your data only on your documented instructions. Your use of the product is the instruction: what you capture, publish, share and delete tells us what to do. We will not process it for any purpose of our own.

Specifically, we will not:

If the law requires us to disclose your data, we will tell you before we do, unless we are legally prohibited from telling you.

4. Confidentiality

Access to production systems is limited to the operator named in the Terms of Service, who is bound to keep your data confidential. If we ever engage anyone else with such access, they will be bound by equivalent obligations before they get it.

Support staff cannot browse your account at will. Entering an account for support requires an explicit, time-limited support session, and it is recorded in your audit history where you can see it.

5. Security

We maintain the measures described in section 8 of our Privacy Policy. In summary:

6. Sub-processors

You authorise us to engage the sub-processors listed on our sub-processors page, which names each one, what it receives and where it is located. Each is bound by terms protecting your data, and we remain responsible to you for what they do.

We will update that page and email account holders before a new sub-processor begins handling your data. If you object on reasonable grounds relating to data protection, tell us within 30 days and we will work with you to find a solution. If we cannot, you may terminate and receive a pro-rata refund of any prepaid fees for the remainder of your term.

7. Where the data goes

The primary copy of your data stays in Australia: the database in Sydney, the servers in Sydney, and photographs in object storage in the Oceania region. Only payment processing (Stripe) and transactional email (Resend) involve the United States, and neither receives photographs.

8. Guest requests and incidents

You can act on most guest requests yourself, immediately. Deleting a photograph, an event or a gallery in the portal takes effect at once and does not need us.

If a guest contacts us directly, we will not action their request ourselves — we will refer them to you and tell you. Where you need help responding, we will provide it at no charge.

If we become aware of a personal data breach affecting your data, we will notify you without undue delay and in any case within 72 hours of becoming aware of it, with what we know: what happened, what data was involved, what we are doing, and what we suggest you do. We will help you meet your own notification obligations, including under the Notifiable Data Breaches scheme.

9. Deletion and return

10. Demonstrating compliance

We will give you the information you reasonably need to satisfy yourself that we are meeting this agreement. Ask, and we will answer specifically rather than with a brochure. We do not currently hold ISO 27001, SOC 2 or any comparable certification, and we would rather say so than imply otherwise.

11. Changes

If we change this agreement in a way that materially affects your rights, we will email account holders at least 30 days before it takes effect. The date at the top always reflects the current version.

Questions, or a request under this agreement: help@boothiva.com