Data Processing Agreement
1. Who this is between, and when it applies
This agreement is between you — the studio, photographer or business with a lemon.gallery account (the "Controller") — and lemon.gallery (the "Processor", "we", "us").
It applies automatically from the moment you create an account and put another person's personal data into the platform. It forms part of, and is subject to, our Terms of Service. Where this agreement and the Terms disagree about the processing of personal data, this agreement wins. You do not need to sign anything separately; if your own compliance process needs a countersigned copy, email privacy@lemon.gallery.
This page is our written contract with you in electronic form, which is what Article 28(9) asks for. Accepting it in the sign-up flow, or simply carrying on using the account, is how it is entered into.
It does not cover your own account data (your name, email, billing, settings). For that we are the controller in our own right, and our Privacy Policy applies.
2. Subject matter and duration
The subject matter is our provision of studio-management and client-gallery software to you. The processing lasts for as long as your account is open, plus the wind-down period described in section 13 while you export the data and we delete it.
Some of this has to outlive the account, and does: confidentiality (section 7), the deletion and return obligations (section 13), and audit and information rights (section 14) all survive closure until they have been worked through.
3. Nature and purpose of the processing
We process your clients' personal data only to operate the features you use, which may include: storing and displaying galleries and files; sending gallery, booking, invoice and marketing emails you compose or trigger; taking payments and issuing refunds; handling bookings, contracts, questionnaires and enquiries; fulfilling print orders you sell; carrying messages between you and clients who message you on Instagram; working out travel time from a booking address; and — where you switch them on — the AI features described in section 3a. We do not process the data for our own purposes, and we never sell it or make it available for anyone else's marketing.
3a. What the AI features actually send, and where
This is the part people most often assume, so here it is plainly. Photographs do leave the platform for some of these features. Nothing below happens unless you use the feature.
- Text drafting — emails, captions, descriptions, replies, blog and marketing copy. We send the words and the workflow context needed for the draft (for example a client's first name, a booking date, the notes on a shoot) to our AI provider, which routes the request to a model run by Google, Anthropic or OpenAI. No photograph is sent for this.
- Alt text and photo descriptions — this one does send the picture. We generate a downsized copy of the photograph, at most 768 pixels on its long edge and with any watermark switched off, and send that copy to a vision model so it can describe what it sees. The original never leaves storage. If the photograph shows identifiable people, their image goes to the model along with it.
- Image-theft monitoring — off unless you turn it on. A copy of the photograph goes to Google Cloud Vision, which searches the public web for visually matching pages. We request web detection only. We do not request face detection, and there is no face recognition, face grouping or face search anywhere in this product.
- AI photo editing — off unless you turn it on, and paid per operation. Your original file is never overwritten and every edited image waits for a human to approve it before any client can see it.
- Editing by our team (lemonHelp) — where you send a job to our editors, the files are worked on in industry-standard Adobe software, so they pass through Adobe applications and Adobe's cloud services for the duration of the work, subject to Adobe's terms. Adobe is a sub-processor for that feature.
- Voice dictation — if you dictate instead of typing, the audio is sent to a transcription model and comes back as text. Whoever is speaking is on that recording.
- Outreach and research — where a feature needs facts from the live web, the search query goes to our search provider. See section 9.
On training: we do not train AI models on your clients' data or images, and we do not knowingly permit anyone else to. Requests are sent with training refused at the API level, and by default images are marked not to be used for AI training. Where the controller asks for a task that requires AI, that request is the agreement for that task and the no-AI marker is not applied to those files.
If you connect your own on-device AI instead, that processing happens on your machine and no AI provider is involved.
4. Types of personal data
- Contact details — names, email addresses, phone numbers, and postal addresses where you or your clients enter them (for example for a print delivery, or as the location of a booking).
- Booking and commercial data — enquiries, bookings, dates, locations, services, invoices, payment status, contracts and questionnaire answers.
- Content — photographs, videos and files you upload, which may show identifiable people, and any notes or captions attached to them.
- Signing evidence — when a client signs a contract or a model release, we record the IP address they signed from, the browser and device they used, the timestamp, and the signature they drew, stored as an image. That is deliberate: it is what makes the signature stand up later.
- Prospect data — if you use the outreach and research features, the platform will find and store details about businesses and people who have never contacted you: names, roles, public contact details, and notes drawn from public sources. These people are data subjects too, and they did not come to you.
- Instagram message contacts — where you connect an Instagram account, the profile and message content of anyone who messages that account.
- Activity data — gallery access emails, favourites, downloads, message and email history within the platform.
You decide what goes in, and you should keep it to what you actually need. Two honest notes on the edges of that:
- Special-category data. Questionnaires routinely end up collecting health-adjacent answers — dietary requirements, accessibility needs, pregnancy, a medical reason a shoot moved. That is normal in this industry and the platform will store it, but it is special-category data and the lawful basis for it has to be yours, not ours. Decide it before you ask the question.
- Biometric data. A photograph of a person is not biometric data on its own. It becomes biometric data when it is processed specifically to identify that person — face templates, face matching, face search. This product never does that, so photographs here stay ordinary personal data rather than Article 9 data.
Criminal-offence data should not go into the platform unless you have your own lawful basis for it and have told us, because the service is not designed around it.
5. Categories of data subject
Your clients and prospective clients; the people who appear in the photographs and files you upload; the people your clients share a gallery with; people who message your connected Instagram account; businesses and individuals the outreach features research who have never contacted you; and, where relevant, your own staff or team members who use your account.
6. Our instructions from you
We process the data only on your documented instructions. Your use of the platform's featuresis your instruction — pressing send on an email, publishing a gallery, running an AI draft, deleting a contact. We also act on instructions you give us in writing.
If we think an instruction breaches UK data protection law, we'll tell you immediately, and we may pause that particular processing until it's sorted out. Pausing one instruction doesn't suspend your account or the rest of the service. If we are ever required by law to process the data for something else, we'll tell you first unless the law forbids it.
7. Confidentiality
Everyone with access to your data is bound by a duty of confidentiality that continues after they stop working with us, and access is limited to the people who need it to run, support and secure the service. We don't browse your galleries or your client list, and we don't use your clients' data to train AI models — ours or anyone else's. See the note on training in section 3a for exactly how far that promise reaches.
8. Security
We take appropriate technical and organisational measures, taking account of the risk. Annex A at the bottom of this page is the schedule your compliance team can attach to a supplier file: it lists what is actually in place, and is deliberately written without the usual padding. No system is perfectly secure, and we won't pretend otherwise — but we review these measures as the service changes, and Annex A changes with them.
9. Sub-processors
You give us general authorisation to use sub-processors. We use them strictly to deliver the service, we impose data-protection obligations on them no weaker than the ones in this agreement, and we stay responsible to you for what they do.
This is the full list, not a sample. If it changes, this page changes — it is the canonical version, and we don't keep a longer one somewhere else.
- Vercel — the hosting platform the application itself runs on. Everything the platform processes passes through it, which makes it the broadest recipient on this list, not the smallest.
- Neon — managed Postgres, holding your account and business records. The database itself sits in the UK (AWS London). Neon is a US company, and its control plane, support staff and backup tooling can reach UK-region data, so "UK region" is a true statement about where the bytes live and not a claim that no one outside the UK can ever touch them.
- Cloudflare R2 — object storage for the photos, videos and files you upload. We configure R2 with no jurisdictional restriction, which means Cloudflare places and replicates objects automatically across its network rather than pinning them to one country. This is the largest and most sensitive dataset on the platform, so we'd rather say that plainly than leave it undefined; section 10 covers the transfer safeguards that apply.
- Stripe — taking payments from you and from your clients. Stripe is an independent controller for its own payment and fraud-prevention purposes, not only our processor.
- Resend — sending the emails you send from the platform, and receiving client replies back into your inbox.
- SendGrid and Mailjet — supported mail rails. If you connect one, the credentials are stored on your account and we hand your outbound mail, and its recipients, to that provider. Postmark, Mailgun and your own mailbox are supported the same way. These are your choice rather than our default, but they receive your clients' data through us, so they belong on this list.
- Prodigi — print fulfilment. Used only when a client actually buys a print, and receives only the name and delivery address needed to ship it.
- Adobe — professional editing software used by our own editing team where you send a job to us (lemonHelp). Files pass through Adobe applications and Adobe's cloud services while the work is being done. Not involved in anything you edit yourself.
- OpenRouter — the routing layer in front of the AI models. Requests, and for the vision features the downsized image, pass through it on the way to the model that answers.
- Anthropic and OpenAI — model providers. They receive AI requests routed through OpenRouter, and we also call them directly for some features and for the chat assistant.
- Google (platform features, on our keys) — Cloud Vision receives a copy of the whole photograph for image-theft monitoring; the Distance Matrix API receives a booking's address to work out travel time; Gemini models answer some AI requests routed through OpenRouter; and Gmail carries mail where that rail is in use.
- Google (your own account, if you connect it) — calendar sync. Booking times and titles are written to the calendar you choose. This is separate from the line above, and switching it off doesn't switch that one off.
- Meta / Instagram — where you connect an Instagram account, messages between you and the people who contact you there travel through Meta's messaging API, and the message content and profile details pass through it in both directions.
- FreeAgent — accounting sync, if you connect it. Receives client names, addresses, invoice line items and amounts so your books match your bookings.
- Parallel — the search provider behind the outreach and research features. Receives the search queries those features run, which will include the names of businesses and people being researched.
- Twilio — SMS delivery. Only if you switch on text reminders; SMS is off by default and no phone numbers are sent anywhere until you do.
We'll give you at least 30 days' notice before adding or replacing a sub-processor, so you have time to object. If you object on reasonable data-protection grounds and we can't resolve it, you may cancel your subscription.
10. International transfers
Most of that list is outside the UK. Concretely: Vercel, Stripe, Resend, SendGrid, OpenRouter, Anthropic, OpenAI, Google, Meta, Parallel and Twilio are US-headquartered and process outside the UK; Cloudflare distributes storage across its global network; and Neon runs the database in the UK but supports and administers it from the US. Prodigi and FreeAgent are UK companies, though Prodigi prints through partners in several countries so a delivery address can travel with the order.
Where data goes outside the UK we rely on an approved transfer mechanism — the UK International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses — together with a transfer risk assessment and any additional safeguards the law requires. If your own compliance process needs the paperwork rather than the summary, email privacy@lemon.gallery and we'll send the relevant clauses and assessments for the providers you actually use.
11. Helping you with data-subject rights
Your clients should bring access, correction, deletion, portability and objection requests to you: you are their controller. The platform gives you the tools to answer most of them yourself — you can search, edit, export and delete contacts, galleries and files from inside the app. Where a request needs something the app doesn't expose, we'll help you, taking account of the nature of the processing and the information available to us. If a request comes to us directly, we'll pass it to you rather than answer it, unless you tell us otherwise.
We'll acknowledge a request for help within five working days and tell you then what we can do and how long it will take — which leaves you room inside the one-month deadline you're working to. If it's urgent, say so in the subject line.
We'll also give you reasonable assistance with data protection impact assessments and prior consultation with the ICO, to the extent it concerns processing we carry out for you.
12. Personal data breaches
If we become aware of a personal data breach affecting your clients' data, we'll notify you without undue delay, with what we know: what happened, roughly who and what is affected, the likely consequences, and what we're doing about it. In practice we aim to make first contact within 24 hours of confirming a breach, by email to the account's registered address and in-app, with a named person to reply to. If we don't have the full picture yet we'll send what we have and follow up rather than wait. Reporting to the ICO and to affected individuals is your decision as controller; we'll give you what you need to make it.
13. Deletion or return at the end
Article 28 makes this your call, not ours, so it is: when the account closes you choose whether we delete your clients' personal data or return it to you first. Tell us at privacy@lemon.gallery, or just use the export tools. If you don't tell us either way, the default is deletion.
The window is concrete. You can export at any time while the account is open. When it closes:
- Days 0–30: your data stays available to export. Client-facing links go dead immediately, so nobody is browsing a gallery belonging to a studio that has left, but the data is still there for you.
- After day 30: we delete your clients' personal data and your uploaded files — from the database and from object storage. If you asked for return instead, we send an export first and then delete.
Two honest exceptions. Routine backups age out on their own cycle rather than being surgically edited, and anything sitting in a backup stays protected by this agreement until that backup expires. And we keep the records the law requires us to keep — payment, invoice, refund and tax records — for as long as it requires, attached to an account that no longer names anybody.
If you need the deletion certified in writing for your own records, ask and we'll confirm it.
14. Audit and information
On reasonable written request, we'll give you the information you need to demonstrate that we're meeting our obligations under this agreement, and we'll allow and contribute toaudits and inspections carried out by you or by an auditor you mandate. Contributing means we answer the questions, produce the documents and make the right person available, rather than opening a door and leaving you to it.
We ask for reasonable notice, no more than once a year unless something has actually gone wrong or a regulator requires it, confidentiality over what you see, and that it doesn't compromise other customers' data or the security of the service. Where a written response, Annex A or existing documentation answers the question, we'll start there.
15. Your side of it
Article 28 assumes both of us have obligations, and a DPA that only lists ours is half a contract. Yours, in plain terms:
- You need a lawful basis for everything you put into the platform, and for everything you ask it to do — including marketing sends, outreach to people who never contacted you, and any special-category answers a questionnaire collects.
- Your own privacy notice has to cover this processing and tell your clients that a provider like us holds their data. We can't write that for you and your clients will look for it.
- Where consent is the basis — marketing emails and texts especially — getting it, recording it and honouring a withdrawal is yours. The platform records unsubscribes and honours them; it can't know whether the original consent was valid.
- Your instructions to us have to be lawful. You confirm you're entitled to give them and that our carrying them out won't put us in breach.
- Keep the data accurate and don't upload more of it than the job needs, and look after your own account: your logins, your team's access, and who you invite in.
If we end up on the wrong side of a regulator because of something in this list, that's yours to carry — just as our breaches are ours to carry under section 16.
16. Liability and changes
The liability limits in our Terms of Service apply to this agreement too, except where the law says they can't and except as follows, because a data protection cap set at a few hundred pounds isn't a real allocation of this risk:
- Our liability to you for breaching this agreement is capped at the greater of £25,000 or the fees you paid us in the 12 months before the claim — not the Terms' general cap.
- The indemnity you give us in the Terms does not apply to any claim, fine or regulator enquiry caused by our own breach of this agreement. You are not indemnifying us against us.
We may update this agreement to keep it accurate or to meet a change in law; material changes will be notified in-app or by email.
17. Contact
Data protection questions, DPA requests, transfer paperwork and sub-processor queries: privacy@lemon.gallery.
Annex A — Technical and organisational measures
This is the schedule referred to in section 8. It describes what is in place today, so it is shorter and blunter than the ones you may be used to receiving. Where something isn't done yet, it isn't listed as if it were.
- Encryption in transit — HTTPS/TLS across the application, the API, file uploads and downloads, and every sub-processor connection.
- Passwords — hashed with bcrypt and never stored or logged in plain text, including for accounts created through Google sign-in, which hold an unusable hash rather than a real password.
- File access — object storage is not public. Files are served through presigned URLs that expire shortly after they are issued, so a leaked link stops working rather than staying open.
- Stored credentials — the AI provider keys and the Instagram access tokens you connect are encrypted at rest with AES-256-GCM under a key held outside the database. Some other integration credentials — certain mail-provider secrets, SMS tokens, and the Google and FreeAgent OAuth tokens — are currently held in the database without that additional layer, protected by the database's own access controls and encryption rather than per-field encryption. We are working through those, and this line will change when they are done. We would rather you read it here than find it in an audit.
- Access control — least-privilege access to production systems, limited to the people who run and support the service; role-based permissions inside the product so your own team only reaches what you give them; and immediate revocation when someone leaves.
- Tokens and integrations — API, calendar and integration tokens are scoped and individually revocable, and are destroyed when an account closes.
- Audit logging — key actions across orders, signatures, bookings, account changes and closures are written to an append-only audit log.
- Segregation — every record is scoped to the owning account at the query layer, so one studio's data is not reachable from another's session.
- Backups — the database is backed up on a rolling schedule; backups inherit the same access restrictions and are covered by this agreement until they expire.
- AI requests — sent with model training refused at the API level, and with the smallest payload the feature needs; images sent to vision models are downsized copies with watermarks removed rather than originals.
- Sub-processor governance — the list in section 9 is maintained as the canonical record, with data-protection terms in place with each provider and 30 days' notice to you before it changes.
- Change review — these measures are reviewed when the service changes materially, and at least annually.