← lemon.gallery

Data Processing Agreement

1. Who this is between, and when it applies

This agreement is between you — the studio, photographer or business with a lemon.gallery account (the "Controller") — and lemon.gallery (the "Processor", "we", "us").

It applies automatically from the moment you create an account and put another person's personal data into the platform. It forms part of, and is subject to, our Terms of Service. Where this agreement and the Terms disagree about the processing of personal data, this agreement wins. You do not need to sign anything separately; if your own compliance process needs a countersigned copy, email privacy@lemon.gallery.

This page is our written contract with you in electronic form, which is what Article 28(9) asks for. Accepting it in the sign-up flow, or simply carrying on using the account, is how it is entered into.

It does not cover your own account data (your name, email, billing, settings). For that we are the controller in our own right, and our Privacy Policy applies.

2. Subject matter and duration

The subject matter is our provision of studio-management and client-gallery software to you. The processing lasts for as long as your account is open, plus the wind-down period described in section 13 while you export the data and we delete it.

Some of this has to outlive the account, and does: confidentiality (section 7), the deletion and return obligations (section 13), and audit and information rights (section 14) all survive closure until they have been worked through.

3. Nature and purpose of the processing

We process your clients' personal data only to operate the features you use, which may include: storing and displaying galleries and files; sending gallery, booking, invoice and marketing emails you compose or trigger; taking payments and issuing refunds; handling bookings, contracts, questionnaires and enquiries; fulfilling print orders you sell; carrying messages between you and clients who message you on Instagram; working out travel time from a booking address; and — where you switch them on — the AI features described in section 3a. We do not process the data for our own purposes, and we never sell it or make it available for anyone else's marketing.

3a. What the AI features actually send, and where

This is the part people most often assume, so here it is plainly. Photographs do leave the platform for some of these features. Nothing below happens unless you use the feature.

On training: we do not train AI models on your clients' data or images, and we do not knowingly permit anyone else to. Requests are sent with training refused at the API level, and by default images are marked not to be used for AI training. Where the controller asks for a task that requires AI, that request is the agreement for that task and the no-AI marker is not applied to those files.

If you connect your own on-device AI instead, that processing happens on your machine and no AI provider is involved.

4. Types of personal data

You decide what goes in, and you should keep it to what you actually need. Two honest notes on the edges of that:

Criminal-offence data should not go into the platform unless you have your own lawful basis for it and have told us, because the service is not designed around it.

5. Categories of data subject

Your clients and prospective clients; the people who appear in the photographs and files you upload; the people your clients share a gallery with; people who message your connected Instagram account; businesses and individuals the outreach features research who have never contacted you; and, where relevant, your own staff or team members who use your account.

6. Our instructions from you

We process the data only on your documented instructions. Your use of the platform's featuresis your instruction — pressing send on an email, publishing a gallery, running an AI draft, deleting a contact. We also act on instructions you give us in writing.

If we think an instruction breaches UK data protection law, we'll tell you immediately, and we may pause that particular processing until it's sorted out. Pausing one instruction doesn't suspend your account or the rest of the service. If we are ever required by law to process the data for something else, we'll tell you first unless the law forbids it.

7. Confidentiality

Everyone with access to your data is bound by a duty of confidentiality that continues after they stop working with us, and access is limited to the people who need it to run, support and secure the service. We don't browse your galleries or your client list, and we don't use your clients' data to train AI models — ours or anyone else's. See the note on training in section 3a for exactly how far that promise reaches.

8. Security

We take appropriate technical and organisational measures, taking account of the risk. Annex A at the bottom of this page is the schedule your compliance team can attach to a supplier file: it lists what is actually in place, and is deliberately written without the usual padding. No system is perfectly secure, and we won't pretend otherwise — but we review these measures as the service changes, and Annex A changes with them.

9. Sub-processors

You give us general authorisation to use sub-processors. We use them strictly to deliver the service, we impose data-protection obligations on them no weaker than the ones in this agreement, and we stay responsible to you for what they do.

This is the full list, not a sample. If it changes, this page changes — it is the canonical version, and we don't keep a longer one somewhere else.

We'll give you at least 30 days' notice before adding or replacing a sub-processor, so you have time to object. If you object on reasonable data-protection grounds and we can't resolve it, you may cancel your subscription.

10. International transfers

Most of that list is outside the UK. Concretely: Vercel, Stripe, Resend, SendGrid, OpenRouter, Anthropic, OpenAI, Google, Meta, Parallel and Twilio are US-headquartered and process outside the UK; Cloudflare distributes storage across its global network; and Neon runs the database in the UK but supports and administers it from the US. Prodigi and FreeAgent are UK companies, though Prodigi prints through partners in several countries so a delivery address can travel with the order.

Where data goes outside the UK we rely on an approved transfer mechanism — the UK International Data Transfer Agreement, or the UK Addendum to the EU standard contractual clauses — together with a transfer risk assessment and any additional safeguards the law requires. If your own compliance process needs the paperwork rather than the summary, email privacy@lemon.gallery and we'll send the relevant clauses and assessments for the providers you actually use.

11. Helping you with data-subject rights

Your clients should bring access, correction, deletion, portability and objection requests to you: you are their controller. The platform gives you the tools to answer most of them yourself — you can search, edit, export and delete contacts, galleries and files from inside the app. Where a request needs something the app doesn't expose, we'll help you, taking account of the nature of the processing and the information available to us. If a request comes to us directly, we'll pass it to you rather than answer it, unless you tell us otherwise.

We'll acknowledge a request for help within five working days and tell you then what we can do and how long it will take — which leaves you room inside the one-month deadline you're working to. If it's urgent, say so in the subject line.

We'll also give you reasonable assistance with data protection impact assessments and prior consultation with the ICO, to the extent it concerns processing we carry out for you.

12. Personal data breaches

If we become aware of a personal data breach affecting your clients' data, we'll notify you without undue delay, with what we know: what happened, roughly who and what is affected, the likely consequences, and what we're doing about it. In practice we aim to make first contact within 24 hours of confirming a breach, by email to the account's registered address and in-app, with a named person to reply to. If we don't have the full picture yet we'll send what we have and follow up rather than wait. Reporting to the ICO and to affected individuals is your decision as controller; we'll give you what you need to make it.

13. Deletion or return at the end

Article 28 makes this your call, not ours, so it is: when the account closes you choose whether we delete your clients' personal data or return it to you first. Tell us at privacy@lemon.gallery, or just use the export tools. If you don't tell us either way, the default is deletion.

The window is concrete. You can export at any time while the account is open. When it closes:

Two honest exceptions. Routine backups age out on their own cycle rather than being surgically edited, and anything sitting in a backup stays protected by this agreement until that backup expires. And we keep the records the law requires us to keep — payment, invoice, refund and tax records — for as long as it requires, attached to an account that no longer names anybody.

If you need the deletion certified in writing for your own records, ask and we'll confirm it.

14. Audit and information

On reasonable written request, we'll give you the information you need to demonstrate that we're meeting our obligations under this agreement, and we'll allow and contribute toaudits and inspections carried out by you or by an auditor you mandate. Contributing means we answer the questions, produce the documents and make the right person available, rather than opening a door and leaving you to it.

We ask for reasonable notice, no more than once a year unless something has actually gone wrong or a regulator requires it, confidentiality over what you see, and that it doesn't compromise other customers' data or the security of the service. Where a written response, Annex A or existing documentation answers the question, we'll start there.

15. Your side of it

Article 28 assumes both of us have obligations, and a DPA that only lists ours is half a contract. Yours, in plain terms:

If we end up on the wrong side of a regulator because of something in this list, that's yours to carry — just as our breaches are ours to carry under section 16.

16. Liability and changes

The liability limits in our Terms of Service apply to this agreement too, except where the law says they can't and except as follows, because a data protection cap set at a few hundred pounds isn't a real allocation of this risk:

We may update this agreement to keep it accurate or to meet a change in law; material changes will be notified in-app or by email.

17. Contact

Data protection questions, DPA requests, transfer paperwork and sub-processor queries: privacy@lemon.gallery.

Annex A — Technical and organisational measures

This is the schedule referred to in section 8. It describes what is in place today, so it is shorter and blunter than the ones you may be used to receiving. Where something isn't done yet, it isn't listed as if it were.