1. Roles and scope
The customer is the controller and THE PRINT COMPANY BAGSHOT LTD, company number 16904402, trading as Afterbooth, is the processor for personal data contained in event uploads and galleries. These terms form part of the AfterBooth Terms of Service and apply for as long as we process that data. Account, billing, security and support data that AfterBooth determines how to use is covered separately by our Privacy Policy.
2. Processing details
- Subject: short-term photobooth event processing and delivery.
- Duration: from upload until scheduled deletion, normally seven days, plus limited backup or log rotation.
- Nature and purpose: storage, cropping, watermarking, review, gallery display, download, ZIP creation, requested Google Drive export, security and deletion.
- Data: photographs, booth strips, audio, names or messages included by the customer, technical identifiers and gallery activity.
- People: customers, their staff, event clients, guests and other people appearing in or contributing to event content, including children where lawfully included.
3. Customer instructions
We process event data only on the customer's documented instructions, consisting of the Terms, product settings and lawful support requests, unless UK law requires otherwise. The customer is responsible for lawful instructions, transparency to guests, responding to data-subject requests and deciding whether the service is suitable for its event.
4. Confidentiality and security
People authorised to process event data are bound by confidentiality. We maintain measures appropriate to the risk, including encrypted transport, private storage, signed access, least-privilege credentials, isolated processing, access controls and scheduled deletion. Customers must secure their accounts, gallery links, PINs and exported copies.
5. Subprocessors
The customer authorises the infrastructure providers identified in our Privacy Policy, currently including Supabase, Railway, Resend and, for the relevant function, Google and Stripe. We remain responsible for imposing appropriate data-protection obligations on subprocessors. We will give reasonable notice of a material new subprocessor where practical so a customer can raise a genuine data-protection objection.
6. Assistance
Taking account of the nature of processing and information available to us, we will provide reasonable assistance with data-subject requests, security obligations, impact assessments and regulator consultations. Customers should contact us promptly and must not instruct us to respond directly unless agreed or legally required.
7. Incidents
We will notify the affected customer without undue delay after becoming aware of a personal-data breach involving its event data and provide information reasonably available to help it meet legal duties. Notification is not an admission of fault.
8. Deletion and return
The product allows customers to export event files. Event data is scheduled for deletion after seven days. On termination or a lawful written request, we will delete remaining processor data unless retention is required by law, subject to limited backup rotation and evidence needed to protect legal rights.
9. International transfers and audit
Restricted transfers use a lawful transfer mechanism as described in the Privacy Policy. We will make information reasonably necessary to demonstrate compliance available to the customer and allow a proportionate audit where legally required, subject to confidentiality, security, reasonable notice and avoidance of disruption. Independent reports or documentation may be used first.
10. Contact
Data-processing questions and requests should be sent to info@afterbooth.co.uk.