1. Parties
The customer is the controller. Shootbin is the processor. Contact: support@shootbin.com.
2. Subject and duration
Shootbin processes data for the duration of the service, including necessary temporary retention, deletion and backup cycles. Data may be retained longer where required by law.
3. Nature and purpose
Processing includes storage, access, transformation, web variants, collaboration, feedback, annotations, approvals, ratings, revisions, delivery, contracts, notifications, security, logging, account access and deletion, solely to provide the service or follow documented instructions.
4. Categories of data subjects
They can include the customer's clients, photographed people, models, employees, principals, approvers, guests, second shooters, downloaders and other project members.
5. Categories of personal data
They can include identity and contact data, account and role data, project membership, photos, files, metadata, messages, comments, annotations, ratings, approvals, revisions, delivery data, contract events, IP address, user agent, timestamps and audit data.
6. Special categories
Shootbin is not designed to analyse special categories of data. Photos can nevertheless reveal, directly or indirectly, health, religion, ethnic origin, biometric characteristics, political opinions or sexual orientation. The customer decides whether processing is lawful and must provide any required information or consent.
7. Instructions and confidentiality
Shootbin processes customer data only on documented instructions, to provide the service or where legally required. People authorised to process it are bound by confidentiality obligations.
8. Technical and organisational measures
Measures include HTTPS/TLS, password hashing, encrypted secrets and tokens where configured, private R2 objects, signed URLs, authorization, project and role access, two-factor authentication, API-token permissions, logging, queue isolation, backups, monitoring and deletion flows. Shootbin does not claim certifications that are not documented.
9. Subprocessors
The customer authorises the production subprocessors listed on the Subprocessors page. Shootbin remains responsible for the processor obligations applicable to its subprocessors and will communicate material additions or replacements by email, account notice, website or an updated legal page. The customer may raise a reasonable objection on data-protection grounds.
10. Assistance and incidents
Shootbin provides reasonable assistance with access, export, correction, deletion, restriction, portability, DPIAs and supervisory-authority consultations. Authenticated users can request a personal-data export. Shootbin will notify the customer without unreasonable delay after becoming aware of a personal-data breach and, where available, describe its nature, affected data, likely consequences and measures taken or proposed.
11. Audits and information
Shootbin will make information reasonably necessary to demonstrate compliance available and will support reasonable audits, subject to protecting other customers, confidential information, security and business continuity.
12. End of service
At the end of the service, Shootbin deletes or returns customer data where practically possible, subject to documented instructions, legal retention duties, temporary backup remnants and the normal purge processes described in the Privacy Policy.