Data Processing Agreement
Last updated: 1 September 2026
This DPA applies where GuestDrops processes personal data on behalf of an event host or organisation (the controller). It forms part of our Terms.
Roles
The host/organisation is the controller of guest-contributed content and its event data; GuestDrops is the processor of that content. GuestDrops is the controller of host account and billing data.
Scope & purpose
GuestDrops processes personal data only to provide the platform features chosen by the controller (collecting, storing, displaying, moderating and exporting event content) and on the controller's documented instructions.
Sub-processors
GuestDrops uses vetted sub-processors for cloud database and object storage, payments (Stripe), transactional email (Resend), and — where enabled — analytics (Google) and error monitoring. A current list is available on request; we will give notice of material changes.
Security measures
Encryption in transit, hashed credentials, secure session cookies, server-side private-gallery access controls, short-lived signed media URLs, rate limiting, and least-privilege access.
Data subject requests
GuestDrops provides self-service data export and account/event deletion, and will assist controllers in responding to data-subject requests where the controller cannot do so via the platform.
Breach notification
GuestDrops will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller's data.
Return & deletion
On termination or on request, GuestDrops will delete or return the controller's personal data, subject to legal retention of anonymised financial records.
International transfers
Where processing occurs outside the UK/EEA, appropriate safeguards (e.g. adequacy or standard contractual clauses) are applied.
Contact
DPA enquiries and sub-processor lists: privacy@guestdrops.com.