Data Processing Addendum

Last material changes: July 2026

Welcome to NowCandid’s Data Processing Addendum!

This Data Processing Addendum forms part of and is incorporated into the NowCandid Terms of Service.

This Data Processing Addendum (the “DPA”) forms part of and is incorporated into the Terms of Service and any order form, service agreement, or other written or electronic agreement governing a Customer’s use of the NowCandid Services (collectively, the “Agreement”) between Candid Color Systems, Inc. (“CCS”, “NowCandid”, “we”, “us”, or “our”) and the Customer. This DPA applies to the extent CCS Processes Customer Personal Data on behalf of the Customer. Capitalized terms not defined in this DPA have the meanings given in the Agreement or the NowCandid Privacy Policy.

This DPA becomes effective for a Customer on the date it is incorporated into or accepted with the Agreement. Electronic acceptance of the Agreement constitutes acceptance of this DPA. If a conflict concerns the Processing of Customer Personal Data, this DPA controls over the Agreement. The EU SCCs or UK Addendum control over this DPA to the extent required for a covered Restricted Transfer.

Contents:

  • 1. Definitions
  • 2. Scope and Roles of the Parties
  • 3. Customer Obligations and Instructions
  • 4. CCS Processing Obligations and Use Restrictions
  • 5. Security of Processing
  • 6. Subprocessors
  • 7. Data Subject Requests
  • 8. Compliance Assistance and Regulatory Cooperation
  • 9. Personal Data Breaches
  • 10. Retention, Return, and Deletion
  • 11. Information and Audits
  • 12. International Transfers
  • 13. Government and Public-Authority Requests
  • 14. Liability, Term, and Order of Precedence
  • 15. Notices and Miscellaneous
  • 16. Appendix 1 - Details of Processing
  • 17. Appendix 2 - Technical and Organisational Measures
  • 18. Appendix 3 - EU Standard Contractual Clauses Information
  • 19. Appendix 4 - UK International Data Transfer Addendum Information

1. Definitions

1. Definitions

1.1 “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party, where “control” means ownership of more than fifty percent of the voting interests or the power to direct management and policies.

1.2 “Applicable Data Protection Laws” means the privacy, data protection, data security, and breach-notification laws that apply to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, the UK GDPR, the UK Data Protection Act 2018, laws of EEA Member States implementing or supplementing the GDPR, and applicable United States and Canadian privacy laws.

1.3 “CCS Controller Data” means Personal Data that CCS Processes as an independent Controller for its own purposes as described in the Privacy Policy, including, to the extent applicable, Customer account administration, billing and payment reconciliation, direct service communications, legal compliance, prevention of fraud or abuse, and deidentified or aggregated service analytics. CCS Controller Data does not include Personal Data merely because CCS uses it to provide security or support while acting on the Customer’s behalf.

1.4 “Customer” has the meaning used in the Privacy Policy and includes a professional photographer, studio, school photography company, organization, or other business that uses the NowCandid Services under the Agreement.

1.5 “Customer Content” means User Content, End User Content, Your Images, data associated with Your Events, and other content or information that the Customer or an End User submits to, uploads to, transmits through, or causes CCS to collect through the NowCandid Services on the Customer’s behalf.

1.6 “Customer Personal Data” means Personal Data contained in Customer Content that CCS Processes on behalf of the Customer. Customer Personal Data excludes CCS Controller Data and information that has been rendered anonymous so that no individual is identified or reasonably identifiable.

1.7 “Data Subject”, “Controller”, “Processor”, “Personal Data”, “Processing”, and “Special Categories of Personal Data” have the meanings given in the GDPR or, where another Applicable Data Protection Law applies, the corresponding meanings under that law.

1.8 “EEA” means the European Economic Area. “GDPR” means Regulation (EU) 2016/679. “UK GDPR” has the meaning given in the UK Data Protection Act 2018.

1.9 “End User” has the meaning used in the Privacy Policy and includes an individual who is photographed, registers for or participates in a Customer’s Event, submits contact information or a selfie, browses or purchases from an Event gallery, or otherwise interacts with the NowCandid Services in connection with a Customer’s Event.

1.10 “EU SCCs” means the standard contractual clauses for transfers of Personal Data to third countries adopted by the European Commission in Commission Implementing Decision (EU) 2021/914, as lawfully amended, replaced, or superseded.

1.11 “Face Matching Tool” means the optional NowCandid feature that analyzes facial features to identify relationships between images that appear to depict the same person, as further described in the Privacy Policy and Face Matching Tool Data Statement.

1.12 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed.

1.13 “NowCandid Services” or “Services” has the meaning used in the Privacy Policy and includes the websites, applications, software, dashboards, tools, features, and related services made available by CCS, including event creation, capture and upload, registration and check-in, online retail, communications, image hosting, automated or AI-assisted image editing, the optional Face Matching Tool, account management, fulfillment, and related support.

1.14 “Subprocessor” means a third party, including a CCS Affiliate, engaged by CCS to Process Customer Personal Data on behalf of the Customer in connection with the Services.

1.15 “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0 in force March 21, 2022, as revised in accordance with its terms.

1.16 “Your Events” and “Your Images” have the meanings given in the Terms of Service.

2. Scope and Roles of the Parties

2.1 This DPA applies only when and to the extent CCS Processes Customer Personal Data on behalf of the Customer in connection with the Services.

2.2 For Customer Personal Data, the Customer is the Controller and CCS is the Processor. If the Customer Processes Customer Personal Data on behalf of another Controller, the Customer is a Processor and CCS is the Customer’s Subprocessor. At CCS’s reasonable request, the Customer will identify the relevant Controller and confirm that the Customer is authorized to appoint CCS.

2.3 Each party will comply with the obligations applicable to it under Applicable Data Protection Laws. The Customer determines the purposes and essential means of Processing Customer Personal Data. CCS Processes Customer Personal Data only on documented instructions from the Customer and as necessary to provide the Services.

2.4 This DPA does not apply to CCS Controller Data. CCS’s Processing of CCS Controller Data is governed by the Privacy Policy and Applicable Data Protection Laws. Nothing in this DPA makes the parties joint controllers unless they separately and expressly agree in writing to a joint-controller arrangement required by law.

2.5 The Customer retains all rights and responsibilities concerning Customer Personal Data that are not expressly assigned to CCS by this DPA. The Customer’s use of the Services, account settings, feature selections, API requests, support requests, and other written directions constitute documented instructions to CCS.

3. Customer Obligations and Instructions

3.1 The Customer is responsible for ensuring that its instructions and use of the Services comply with Applicable Data Protection Laws, including establishing a lawful basis for Processing, providing required notices, honoring Data Subject rights, and obtaining consent or other authorization where required.

3.2 The Customer represents and warrants that it has all rights, permissions, and authority necessary to collect, upload, disclose, and instruct CCS to Process Customer Personal Data, including photographs and contact information submitted by or concerning End Users.

3.3 The Customer will use reasonable efforts to limit Customer Personal Data to information necessary for the Services. Unless separately agreed in writing, the Customer will not submit protected health information, full payment-card data, financial-account information, Social Security numbers, government-issued identification numbers, or other highly sensitive information that is not necessary to provide the Services.

3.4 Photographs may incidentally reveal information treated as sensitive under Applicable Data Protection Laws. The Customer is responsible for evaluating the legal basis for such Processing and for applying any restrictions required by law, contract, school policy, or Event terms. Where Events involve minors, the Customer will obtain parent or guardian authorization when required.

3.5 The optional Face Matching Tool is separate from ordinary image editing. Where the Face Matching Tool is enabled, the Customer is responsible for providing any legally required biometric notice, obtaining any legally required consent or written release, and complying with applicable retention and destruction requirements. This DPA does not itself constitute consent from any Data Subject.

3.6 The Customer will notify CCS before using the Services if the Customer is subject to a binding data-residency, localization, school, government, or contractual restriction that is not satisfied by the Processing locations and controls disclosed by CCS. The Customer will not enable an affected feature unless CCS confirms that the restriction can be supported.

3.7 The Customer is responsible for maintaining accurate account contact information, safeguarding credentials, limiting authorized users, and configuring the Services in a manner appropriate to the sensitivity of Customer Personal Data.

4. CCS Processing Obligations and Use Restrictions

4.1 CCS will Process Customer Personal Data only on documented instructions from the Customer, including instructions concerning transfers to a third country or international organization, unless CCS is required to Process the data by applicable law. If legally permitted, CCS will inform the Customer of that legal requirement before the required Processing.

4.2 The Customer instructs CCS to Process Customer Personal Data as described in the Agreement, this DPA, and Appendix 1, including to host, organize, display, transmit, deliver, edit, enhance, match or group where an optional feature is enabled, support, secure, fulfill, and otherwise provide the NowCandid Services.

4.3 If CCS reasonably believes an instruction infringes Applicable Data Protection Laws, CCS will immediately inform the Customer and may suspend the affected Processing until the parties resolve the issue. CCS is not required to perform an instruction that is unlawful, technically infeasible, or inconsistent with the Agreement.

4.4 CCS will not sell Customer Personal Data, use it for cross-context behavioral advertising or targeted advertising, use it to market independently to End Users, or use source images, editing instructions, temporary processing artifacts, or edited outputs to train or improve generalized artificial-intelligence or machine-learning models. CCS will contractually restrict its image-processing Subprocessors from using such content for independent model training, advertising, or unrelated product development.

4.5 CCS may generate and use aggregated, deidentified, or anonymized information for security, support, analytics, benchmarking, and improvement of the Services, provided CCS does not attempt to reidentify the information and the information cannot reasonably be associated with a Customer, End User, household, or individual.

4.6 Ordinary image-editing features may temporarily detect or locate faces, people, glasses, hair, clothing, objects, or backgrounds solely to perform a requested or enabled visual edit. Except for the separately governed Face Matching Tool, those ordinary editing features are not intended or used to identify or authenticate a person, compare a person across photographs or against a database, or create or retain a biometric template or scan of face geometry.

4.7 CCS will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary for their duties.

5. Security of Processing

5.1 CCS will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Those measures will take into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the likelihood and severity of risks to individuals.

5.2 The measures maintained by CCS are described in Appendix 2 and are intended to support ongoing confidentiality, integrity, availability, and resilience; restoration of availability following an incident; and regular assessment of security effectiveness.

5.3 CCS may update its technical and organizational measures to reflect changes in technology, threats, law, and the Services, provided the updates do not materially decrease the overall protection of Customer Personal Data during the applicable Services term.

5.4 The Customer is responsible for security risks arising from its own systems, devices, personnel, credentials, downloads, exports, account permissions, and configurations. The Customer’s responsibilities do not reduce CCS’s obligations under this DPA.

5.5 Detailed security information supplied by CCS is CCS Confidential Information and may be used only to evaluate CCS’s compliance, unless disclosure is required by law or a competent Supervisory Authority.

6. Subprocessors

6.1 The Customer provides CCS with general written authorization to engage the Subprocessors included on CCS’s current Subprocessor List as of the effective date of this DPA.

6.2 CCS will maintain a current Subprocessor List identifying each material Subprocessor’s name, processing function, and relevant Processing locations. The list need not be publicly available, but CCS will make it available to Customers upon request to ccssupport@candid.com.

6.3 CCS will provide at least thirty days’ prior notice of an intended addition or replacement of a material Subprocessor that will Process Customer Personal Data. Notice may be delivered to the Customer’s account administrator email address, through the Services, or through another agreed channel. For Processing governed by the EU SCCs or UK Addendum, the new or replacement Subprocessor will not Process Customer Personal Data until the thirty-day notice period has expired. For other Processing, if advance notice is not reasonably possible because of an urgent security, availability, or legal need, CCS will provide notice as soon as reasonably practicable.

6.4 The Customer may object to a new Subprocessor within fifteen days after notice, but only on reasonable and documented data-protection grounds. The parties will work in good faith to resolve the objection. CCS may address the objection by declining to use the Subprocessor for the Customer, providing a commercially reasonable alternative, or allowing the Customer to terminate the affected Service without penalty. If the Customer does not object within the stated period, the Customer is deemed to have authorized the Subprocessor.

6.5 Before a Subprocessor Processes Customer Personal Data, CCS will enter into a written agreement imposing data-protection obligations that are no less protective in substance than the obligations applicable to CCS under this DPA, including confidentiality, security, purpose limitation, deletion or return, assistance, and restrictions on further Subprocessors.

6.6 CCS remains responsible to the Customer for each Subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Laws. Where the GDPR applies, CCS remains fully liable to the Customer for the Subprocessor’s performance of those obligations as required by Article 28(4). CCS Affiliates that Process Customer Personal Data on CCS’s behalf are treated as Subprocessors under this Section.

7. Data Subject Requests

7.1 If CCS receives a request from a Data Subject concerning Customer Personal Data and can reasonably associate the request with the Customer, CCS will notify the Customer and direct the requester to the Customer, unless law prohibits CCS from doing so.

7.2 CCS will not independently respond to a Data Subject request concerning Customer Personal Data except on the Customer’s documented instructions or as required by law. If CCS is legally required to respond, CCS will inform the Customer before responding where legally permitted.

7.3 Taking into account the nature of the Processing, CCS will provide reasonable assistance through appropriate technical and organizational measures to help the Customer respond to requests for access, correction, deletion, restriction, portability, objection, consent withdrawal, and rights concerning automated decision-making, where applicable.

7.4 The Customer remains responsible for verifying the requester’s identity, determining whether a request is valid, communicating with the requester, and meeting applicable deadlines. If assistance materially exceeds the functionality and support ordinarily included in the Services, the parties may agree on reasonable fees, except to the extent the assistance is required because of CCS’s breach of this DPA.

8. Compliance Assistance and Regulatory Cooperation

8.1 Taking into account the nature of the Processing and information available to CCS, CCS will provide reasonable assistance to the Customer with compliance obligations concerning security of Processing, Personal Data Breaches, data protection impact assessments, and prior consultation with a Supervisory Authority.

8.2 CCS will make available information reasonably necessary for the Customer to maintain records of Processing activities, assess international transfers, document safeguards, and demonstrate compliance with Article 28 of the GDPR or corresponding requirements under Applicable Data Protection Laws.

8.3 CCS will cooperate with a competent Supervisory Authority concerning Customer Personal Data as required by Applicable Data Protection Laws. Unless prohibited by law, CCS will notify the Customer of a regulatory inquiry that specifically concerns the Customer Personal Data and will coordinate the response with the Customer.

8.4 The Customer is responsible for deciding whether a data protection impact assessment or prior consultation is required and for preparing and submitting it. CCS’s assistance does not constitute legal advice or transfer the Customer’s Controller responsibilities to CCS.

8.5 CCS will notify the Customer without undue delay if CCS determines that it can no longer comply with material obligations under this DPA or an applicable transfer mechanism, and CCS will take reasonable steps to remediate the issue or suspend the affected Processing.

9. Personal Data Breaches

9.1 CCS will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will be sent to the Customer’s account administrator, designated security contact, or another contact identified in the Agreement. CCS will not delay the initial notice solely because its investigation is incomplete.

9.2 To the extent information is reasonably available, CCS’s notice will describe the nature of the Personal Data Breach; the categories and approximate number of affected Data Subjects and records; the likely consequences; the measures taken or proposed to address and mitigate the breach; and a contact point for additional information. CCS may provide information in phases without undue further delay.

9.3 CCS will investigate the Personal Data Breach, take reasonable measures to contain and mitigate it, preserve relevant records, and provide reasonable cooperation requested by the Customer for legally required notifications and remediation.

9.4 The Customer is responsible for determining whether to notify a Supervisory Authority, Data Subjects, Event organizers, schools, or other parties. CCS will not make a notification on the Customer’s behalf unless the Customer instructs CCS to do so or CCS is independently required by law.

9.5 A notification or response under this Section is not an admission of fault or liability by CCS. Unsuccessful attempts that do not compromise Customer Personal Data do not constitute a Personal Data Breach.

10. Retention, Return, and Deletion

10.1 During the Services term, CCS will retain source photographs, edited outputs, Event data, and other Customer Personal Data in accordance with the Customer’s account, Event, gallery, and storage settings, the Agreement, and CCS’s documented retention schedule.

10.2 Temporary copies and intermediate technical artifacts created solely to perform an image-editing request will be deleted or rendered non-identifiable promptly after the request is completed and, in all cases, within ninety days, except where a longer period is required by law or reasonably necessary to investigate a documented security or technological incident. Provider-specific material exceptions will be included in or made available with the Subprocessor List.

10.3 Following termination of the affected Services or the Customer’s valid written deletion request, the Customer may request return of Customer Personal Data in a reasonably available format. If the Customer does not request return within thirty days after termination, the Customer instructs CCS to delete the Customer Personal Data. CCS will complete deletion from active systems without undue delay and ordinarily within ninety days, unless law requires continued storage or a shorter period applies under the Services.

10.4 Customer Personal Data in secure backups may remain until the backups expire under CCS’s documented backup-rotation schedule. During that period, backup data will remain protected, will not be used for ordinary business purposes, and will be restored only as necessary for disaster recovery, security, or legal requirements, after which the applicable deletion instruction will be reapplied.

10.5 Data associated with the optional Face Matching Tool will be retained and deleted as described in the Privacy Policy and Face Matching Tool Data Statement. Any conflict concerning Face Matching Tool retention is resolved in favor of the Face Matching Tool Data Statement.

10.6 If law requires CCS to retain Customer Personal Data after the Services end, CCS will isolate and protect the retained data, Process it only for the legally required purpose, and delete it when the legal requirement ends. Upon reasonable written request, CCS will confirm completion of deletion, subject to the backup and legal-retention limitations in this Section.

10.7 This Section does not require deletion of information that has been irreversibly anonymized or aggregated so that it is no longer Personal Data, provided CCS does not attempt to reidentify it.

11. Information and Audits

11.1 CCS will make available information reasonably necessary to demonstrate compliance with this DPA. Where available and appropriate, CCS may satisfy this obligation by providing current security summaries, independent assessment reports, certifications, policies, or responses to reasonable questionnaires.

11.2 If the information provided is insufficient for the Customer to meet a legal obligation, the Customer may conduct, or appoint an independent auditor to conduct, an audit, including a reasonable inspection, of CCS’s relevant Processing. Audits are limited to once in any twelve-month period unless required by a Supervisory Authority, following a Personal Data Breach, or based on reasonable evidence of material noncompliance.

11.3 The Customer will provide at least thirty days’ advance written notice, conduct the audit during normal business hours, minimize disruption, comply with CCS’s reasonable security requirements, and ensure the auditor is not a CCS competitor and is bound by confidentiality. Audits may not access other customers’ data, compromise security, or require disclosure of privileged information, source code, or trade secrets beyond what Applicable Data Protection Laws require.

11.4 The Customer bears its audit costs and reimburses CCS for reasonable costs of extraordinary audit assistance, unless the audit identifies a material breach of this DPA by CCS, in which case CCS will bear its reasonable internal costs and will remediate the identified noncompliance without undue delay.

11.5 Nothing in this Section limits the audit or inspection rights of a competent Supervisory Authority or rights that cannot lawfully be restricted under the EU SCCs, UK Addendum, or Applicable Data Protection Laws.

12. International Transfers

12.1 CCS is based in the United States. Depending on the feature used and the Subprocessors engaged, Customer Personal Data may be Processed in the United States, Canada, the EEA, the United Kingdom, and other locations identified in the Subprocessor List. The Customer authorizes such Processing locations subject to this DPA and Applicable Data Protection Laws.

12.2 Where a transfer is covered by an applicable adequacy decision or another lawful transfer basis, the parties may rely on that basis to the extent the recipient and Processing fall within its scope. A server’s physical location alone does not establish that an adequacy decision applies to the recipient.

12.3 Where Customer Personal Data is transferred from the EEA to CCS in a country not recognized as providing adequate protection and the EU SCCs are legally available for the transfer, the EU SCCs are incorporated into this DPA and completed as set out in Appendix 3. Module Two applies when the Customer is a Controller and CCS is a Processor. Module Three applies when the Customer is a Processor and CCS is a Subprocessor.

12.4 For the EU SCCs: Clause 7 (Docking Clause) is included; Clause 9(a), Option 2 (General Written Authorization) applies with a thirty-day notice period; the optional language in Clause 11 is not included; Clause 17, Option 1 is governed by the law of Ireland; and the courts of Ireland are selected under Clause 18. The competent Supervisory Authority is determined under Clause 13 based on the Data Exporter’s establishment, representative, or relevant Data Subjects.

12.5 Appendix 1 of this DPA supplies the description of Processing and transfer information required by Annex I.B of the EU SCCs. Appendix 2 supplies Annex II. The parties and competent Supervisory Authority are identified in Appendix 3. Because the Customer gives general written authorization, Annex III is not required; the current Subprocessor List is available as described in Section 6.

12.6 If the EU SCCs are not legally available because the recipient’s relevant Processing is directly subject to the GDPR, or if a transfer mechanism is invalidated or replaced, the parties will cooperate in good faith to implement another lawful mechanism, including successor clauses or an approved adequacy framework, without materially reducing protection for Customer Personal Data.

12.7 Where a transfer from the United Kingdom to CCS is a Restricted Transfer and no adequacy regulation applies, the UK Addendum is incorporated and completed as described in Appendix 4. The unmodified mandatory clauses of the Approved UK Addendum apply, and the EU SCC selections in this DPA apply as adapted by the UK Addendum.

12.8 Each party will provide information reasonably necessary for a transfer impact assessment or transfer risk assessment. CCS will implement supplementary safeguards reasonably required for the transfer, taking into account the nature of the data, the Processing, the destination, and information available to CCS. The Customer remains responsible for completing assessments required of it as Data Exporter.

12.9 Onward transfers by CCS or a Subprocessor will occur only as permitted by this DPA, the applicable transfer mechanism, and Applicable Data Protection Laws. If a transfer mechanism conflicts with this DPA or the Agreement, the transfer mechanism controls for the covered transfer.

13. Government and Public-Authority Requests

13.1 CCS will not voluntarily disclose Customer Personal Data to a public authority except as authorized by the Customer or required by law.

13.2 If CCS receives a legally binding request for Customer Personal Data from a public authority, CCS will, where legally permitted, notify the Customer before disclosure and, where required by an applicable transfer mechanism and reasonably possible, notify the affected Data Subject. CCS will provide information reasonably necessary for the Customer to seek protection, review the request for legal validity, disclose only the minimum data legally required, and challenge an unlawful or disproportionate request where there are reasonable grounds to do so.

13.3 If CCS is prohibited from notifying the Customer, CCS will use reasonable efforts to obtain a waiver of the prohibition. CCS will document requests and responses to the extent required by the EU SCCs or other Applicable Data Protection Laws and will provide aggregated transparency information where legally permitted and reasonably available.

14. Liability, Term, and Order of Precedence

14.1 This DPA remains in effect for as long as CCS Processes Customer Personal Data on the Customer’s behalf. Provisions concerning confidentiality, security, audits, liability, transfers, and deletion survive termination to the extent necessary to fulfill their purpose.

14.2 The limitations and exclusions of liability in the Agreement apply to this DPA to the maximum extent permitted by law. They do not limit rights or liability that cannot lawfully be limited, including enforceable Data Subject rights under the EU SCCs or UK Addendum.

14.3 For matters concerning Customer Personal Data, the order of precedence is: first, the EU SCCs or UK Addendum for a covered transfer; second, this DPA; third, the Agreement; and fourth, other policies incorporated into the Agreement. The Privacy Policy continues to govern CCS Controller Data and public transparency obligations.

14.4 For Customer Personal Data, this DPA limits any broader content license in the Agreement to the Processing necessary to provide, secure, maintain, support, and comply with law concerning the Services. No provision of the Agreement authorizes CCS or a Subprocessor to use Customer Personal Data or edited outputs for generalized model training, advertising, or independent promotion without separate written authorization from the Customer and any legally required authorization from the affected Data Subject.

15. Notices and Miscellaneous

15.1 Notices to CCS under this DPA must be sent to ccssupport@candid.com and, if requested by CCS, to the address listed in the Agreement. Notices to the Customer may be sent to the Customer’s account administrator email address, through the Services, or by another method permitted under the Agreement. The Customer is responsible for keeping its contact information current.

15.2 CCS may update this DPA to reflect changes in law, transfer mechanisms, or the Services, provided CCS gives notice of a material change and does not materially reduce the protection of Customer Personal Data during an existing paid Services term unless required by law. Changes to the EU SCCs or UK Addendum occur only as permitted by those instruments.

15.3 If a provision of this DPA is invalid or unenforceable, it will be interpreted or replaced to preserve its lawful purpose as closely as possible, and the remaining provisions remain in effect. This DPA may be entered into electronically and in counterparts.

15.4 Except for rights granted to Data Subjects under the EU SCCs, UK Addendum, or non-waivable law, this DPA creates no third-party beneficiary rights.

16. APPENDIX 1

16.1 Details of Processing

This Appendix describes the subject matter, duration, nature, purposes, categories of Personal Data, categories of Data Subjects, processing locations, and retention criteria associated with CCS’s Processing of Customer Personal Data.

16.2 Subject Matter

CCS Processes Customer Personal Data to provide the NowCandid Services selected, configured, enabled, or requested by the Customer.

16.3 Duration

Processing continues:

  • For the term of the Agreement.
  • For any limited period necessary to return or delete Customer Personal Data.
  • For any period necessary to secure the Services or investigate a security incident.
  • For any additional period during which CCS is legally required or permitted to retain particular records, as described in Section 10 of the DPA.

16.4 Nature of the Processing

Depending on the Customer’s use of the Services, CCS may perform the following Processing activities:

  • Collection and receipt.
  • Recording and organization.
  • Structuring and classification.
  • Hosting and storage.
  • Retrieval and consultation.
  • Transmission and delivery.
  • Display and publication within Customer-controlled Events or galleries.
  • Association of information with Events, participants, images, orders, or Customer accounts.
  • Image editing and enhancement.
  • Image segmentation and generation of temporary processing information.
  • Generation of edited images and other outputs.
  • Customer-directed communications.
  • Order processing and fulfillment.
  • Customer and End User support.
  • Security monitoring and fraud prevention.
  • Deletion and disposal.
  • Where enabled, matching or grouping images through the optional Face Matching Tool.

16.5 Purposes of Processing

CCS Processes Customer Personal Data for purposes including:

  • Creating and managing Customer Events.
  • Capturing, uploading, hosting, organizing, displaying, delivering, and selling photographs.
  • Registering and checking in End Users.
  • Managing rosters, participants, and Event information.
  • Sending Customer-directed Event communications.
  • Performing requested or enabled image-editing functions.
  • Performing retouching, glare reduction, background removal, object removal, background replacement, and similar image enhancements.
  • Operating the optional Face Matching Tool.
  • Processing orders, payments, delivery, and fulfillment.
  • Providing technical, retail, and Customer support.
  • Maintaining the security and reliability of the Services.
  • Preventing fraud, misuse, abuse, or unauthorized access.
  • Complying with documented Customer instructions.
  • Complying with applicable legal obligations.

16.6 Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer owners.
  • Customer employees and contractors.
  • Photographers and other authorized Customer users.
  • End Users.
  • Individuals appearing in photographs or videos.
  • Event participants.
  • Gallery visitors.
  • Buyers and order recipients.
  • Parents and legal guardians.
  • School, team, organization, and Event personnel.
  • Recipients of Customer-directed communications.
  • Minors where a Customer’s Event involves children.

16.7 Categories of Personal Data

Customer Personal Data may include:

  • Names.
  • Email addresses.
  • Telephone numbers.
  • Postal, billing, and shipping addresses.
  • Customer account identifiers.
  • Event identifiers.
  • Roster and participant identifiers.
  • Order and fulfillment identifiers.
  • Photographs and selfies.
  • Videos, where supported by the Services.
  • Image thumbnails and crops.
  • File metadata remaining in uploaded files.
  • Editing instructions.
  • Edited images and outputs.
  • Temporary masks and segmentation information.
  • Temporary bounding regions or image-area detections.
  • Communication and messaging records.
  • Consent, authorization, and opt-out records.
  • Customer-support records.
  • Order and fulfillment information.
  • Limited payment and transaction-reconciliation information.
  • IP addresses.
  • Device and browser information.
  • Event, gallery, and Service interaction information.
  • Other Customer Content submitted through the Services.

16.8 Sensitive or Special-Category Data

Photographs and related Customer Content may incidentally reveal information considered sensitive or Special Categories of Personal Data under Applicable Data Protection Laws, including:

  • Racial or ethnic origin.
  • Religious or philosophical beliefs.
  • Health or disability information.
  • Sexual orientation.
  • Other sensitive personal characteristics.

The optional Face Matching Tool may involve transient Processing of face geometry or other biometric information for the purpose of identifying relationships between images that appear to depict the same person.

Customer Events may also involve minors.

CCS applies purpose limitations, access restrictions, retention controls, and any additional safeguards required under the DPA and Applicable Data Protection Laws.

16.9 Ordinary Image-Processing Information

For ordinary image-editing functions, CCS may Process:

  • Source photographs.
  • File metadata remaining in the photograph.
  • Customer editing instructions.
  • Edited outputs.
  • Temporary masks.
  • Segmentation information.
  • Bounding regions.
  • Temporary detections indicating the location of:
    • A person.
    • A face.
    • Glasses.
    • Hair.
    • Clothing.
    • An object.
    • A foreground.
    • A background.

These ordinary editing functions are intended solely to perform the requested visual edit. They are not intended or used to identify or authenticate individuals or to compare an individual against other photographs or a database.

16.10 Frequency of Processing

Processing may occur:

  • Continuously.
  • Recurringly.
  • Automatically.
  • On demand.
  • In response to Customer or End User actions.

The frequency depends on the Customer’s use of the Services and the features the Customer enables.

16.11 Processing Locations

Subject to Section 12 of the DPA, Customer Personal Data may be Processed in:

  • The United States.
  • Canada.
  • The European Economic Area.
  • The United Kingdom.
  • Other locations identified in the current Subprocessor List.
  • Other locations separately agreed to in writing by the parties.

16.12 Retention Criteria

Source images, edited outputs, Event data, and related Customer Personal Data are retained according to:

  • Customer account and Event settings.
  • The Agreement.
  • CCS’s documented retention schedule.
  • Applicable legal requirements.

Temporary image-processing artifacts are deleted or rendered non-identifiable promptly after they are no longer required and, in all cases, within ninety days.

Following termination of the Agreement or a valid deletion request, CCS will delete Customer Personal Data from active systems without undue delay and ordinarily within ninety days, subject to:

  • Secure backup-rotation schedules.
  • Legal-retention requirements.
  • Security and fraud-prevention records.
  • Records necessary to establish, exercise, or defend legal claims.

Information used by the Face Matching Tool is retained and deleted in accordance with the Privacy Policy, the Face Matching Tool Data Statement, and Applicable Data Protection Laws.

16.13 Subprocessors

CCS may use Subprocessors that provide:

  • Cloud infrastructure.
  • Hosting and storage.
  • Image processing and model inference.
  • Communications.
  • Payment services.
  • Information security.
  • Product production and fulfillment.
  • Customer support.
  • Other services necessary to operate NowCandid.

A current Subprocessor List is available to Customers upon request to ccssupport@candid.com.

16.14 Customer Rights and Responsibilities

Under the DPA, the Customer may:

  • Issue documented Processing instructions.
  • Configure the Services.
  • Select or disable available features.
  • Request the return or deletion of Customer Personal Data.
  • Exercise the audit and information rights described in the DPA.
  • Object to a new Subprocessor on reasonable data-protection grounds.
  • Receive reasonable assistance with Data Subject requests and compliance obligations.

The Customer remains responsible for:

  • Lawfully collecting Customer Personal Data.
  • Establishing an appropriate legal basis for Processing.
  • Providing required privacy notices.
  • Obtaining consent or authorization where required.
  • Communicating with Data Subjects.
  • Complying with restrictions imposed by law, contract, school policy, or Event terms.

17. APPENDIX 2

17.1 Technical and Organisational Measures

CCS maintains a risk-based information-security program designed to protect Customer Personal Data.

The measures described below apply as appropriate to the relevant system, feature, Processing activity, and level of risk. CCS may update these measures in accordance with Section 5.3 of the DPA, provided that the overall level of protection is not materially reduced.

17.2 Security Governance

CCS maintains measures including:

  • Defined security and privacy responsibilities.
  • Policies and procedures appropriate to the nature of the Services.
  • Periodic review of security and privacy controls.
  • Management oversight of material security risks.
  • Risk-based assessment of systems, vendors, and Processing activities.

17.3 Personnel and Confidentiality

CCS maintains personnel protections including:

  • Confidentiality obligations for personnel with access to Customer Personal Data.
  • Access limited according to job responsibilities.
  • Security and privacy awareness appropriate to personnel roles.
  • Procedures for changes in responsibilities.
  • Procedures for terminating or modifying access when personnel leave CCS or no longer require access.

17.4 Identity and Access Management

CCS uses access controls including:

  • Authentication controls for production and administrative systems.
  • Role-based or need-to-know authorization.
  • Restrictions on privileged and administrative access.
  • Periodic review of user access.
  • Multi-factor authentication where supported and appropriate to the risk.
  • Procedures for issuing, modifying, and revoking access.

17.5 Network and Infrastructure Security

CCS maintains network and infrastructure protections including:

  • Firewalls and other network-security controls.
  • Logical separation of environments and Customer data where appropriate.
  • Secure configuration practices.
  • Restrictions on administrative interfaces.
  • Controls designed to prevent unauthorized network access.
  • Protections appropriate to CCS-operated and third-party hosted infrastructure.

17.6 Protection During Transmission and Storage

CCS uses data-protection measures including:

  • Encryption using industry-standard protocols when Customer Personal Data is transmitted over public networks.
  • Storage protections appropriate to the sensitivity and risk of the data.
  • Encryption at rest where supported by the relevant platform.
  • Access controls or compensating safeguards where encryption at rest is not available.
  • Secure handling of passwords, API credentials, encryption keys, and other secrets.

17.7 Application and Change Security

CCS maintains application and change-management practices including:

  • Development practices designed to reduce security defects.
  • Review and testing of material system changes.
  • Dependency and configuration management.
  • Controls concerning deployment to production systems.
  • Separation of development, testing, and production activities where appropriate.
  • Review of material changes to image-processing and other high-risk features.

17.8 Logging and Monitoring

CCS uses logging and monitoring measures appropriate to:

  • Detect unauthorized access.
  • Detect anomalous or suspicious activity.
  • Identify service failures.
  • Identify potential security incidents.
  • Support investigation and response.
  • Restrict access to logs.
  • Retain logs for periods appropriate to security and operational requirements.

17.9 Vulnerability Management and Testing

CCS maintains processes to:

  • Identify vulnerabilities.
  • Assess and prioritize security weaknesses.
  • Remediate vulnerabilities according to risk.
  • Test networks and applications for weaknesses.
  • Apply security updates and patches.
  • Review the effectiveness of security measures periodically.

17.10 Availability, Resilience, and Recovery

CCS maintains availability and recovery measures including:

  • System redundancy appropriate to service requirements.
  • Backups appropriate to the relevant systems and information.
  • Procedures designed to restore availability after a physical or technical incident.
  • Procedures designed to restore access to Customer Personal Data.
  • Periodic review or testing of recovery capabilities.

17.11 Incident Response

CCS maintains documented procedures for:

  • Identifying potential security incidents.
  • Escalating incidents.
  • Investigating incidents.
  • Containing affected systems or data.
  • Remediating vulnerabilities or other causes.
  • Documenting material incidents.
  • Communicating with affected Customers where required.
  • Conducting post-incident review where appropriate.

17.12 Data Minimization and Retention

CCS maintains measures designed to:

  • Limit collection and Processing to information reasonably necessary for the Services.
  • Apply documented retention and deletion controls.
  • Securely dispose of Customer Personal Data.
  • Avoid retaining temporary processing information longer than necessary.
  • Use pseudonymous, randomized, or non-descriptive technical identifiers where practicable.

17.13 Image-Processing Controls

CCS applies image-processing protections including:

  • Configuring image-processing providers to limit storage where supported.
  • Configuring providers to limit payload logging where supported.
  • Restricting human access to Customer images where supported.
  • Restricting provider use to delivering, supporting, and securing the contracted service.
  • Prohibiting independent use for generalized model training.
  • Prohibiting independent use for advertising or unrelated product development.
  • Minimizing unnecessary contact information, Event names, school names, and similar identifiers sent with image-processing jobs where technically practicable.
  • Deleting or rendering temporary image-processing artifacts non-identifiable within the period described in the DPA.
  • Applying appropriate access controls to source images and edited outputs.

17.14 Subprocessor Management

CCS maintains a Subprocessor-management process that includes:

  • Reasonable diligence before engagement.
  • Written confidentiality and data-protection obligations.
  • Security and privacy requirements appropriate to the services provided.
  • Restrictions on Processing outside CCS’s documented instructions.
  • Review of material changes.
  • Procedures for addressing Subprocessor security incidents.
  • Procedures for ending access and Processing when a Subprocessor relationship terminates.

17.15 Physical Security

For facilities operated by CCS, CCS maintains physical and environmental protections appropriate to the relevant risks.

For hosted infrastructure, CCS relies on data-center and infrastructure providers that maintain controls appropriate to their services, which may include:

  • Restricted facility access.
  • Physical monitoring.
  • Environmental protections.
  • Power and network resilience.
  • Fire detection and suppression.
  • Business-continuity measures.

17.16 Data Subject Rights and Deletion Support

CCS maintains technical and operational procedures designed to assist with:

  • Locating Customer Personal Data.
  • Exporting Customer Personal Data.
  • Correcting Customer Personal Data where supported.
  • Restricting Processing where supported.
  • Deleting Customer Personal Data.
  • Responding to Customer instructions relating to Data Subject rights.

Such assistance is subject to:

  • Appropriate identity verification.
  • The capabilities of the Services.
  • Applicable legal-retention obligations.
  • Security requirements.
  • Backup and archive limitations.

18. APPENDIX 3

18.1 EU Standard Contractual Clauses Information

The EU Standard Contractual Clauses adopted through European Commission Implementing Decision (EU) 2021/914 are incorporated into the DPA when Section 12.3 applies.

The official EU SCC text is available through EUR-Lex.

The EU SCCs are not modified by this DPA except to:

  • Select modules and options expressly permitted by the EU SCCs.
  • Complete the information required in the EU SCC annexes.
  • Incorporate the processing and security information contained in the DPA.

18.2 Parties to the EU SCCs

(a) Data Exporter

The Data Exporter is the Customer identified in:

  • The Agreement.
  • The applicable order form.
  • The Customer’s NowCandid account records.

The Data Exporter’s address and contact details are the information maintained in the Agreement, order form, or Customer account.

Unless another contact is designated, the Customer’s account administrator is the primary transfer and privacy contact.

The Data Exporter’s role is:

  • Controller when Module Two applies.
  • Processor when Module Three applies.

(b) Data Importer

The Data Importer is:

Candid Color Systems, Inc.
NowCandid
1300 Metropolitan Ave
Oklahoma City, Oklahoma 73108
United States

Privacy contact: ccssupport@candid.com

The Data Importer’s role is:

  • Processor when Module Two applies.
  • Subprocessor when Module Three applies.

(c) Relevant Activities

The relevant activities are those described in Appendix 1, including:

  • Provision of the NowCandid Services.
  • Hosting and Processing Customer Personal Data.
  • Image processing.
  • Customer-directed communications.
  • Event and gallery management.
  • Any international transfer necessary to provide the Services.

(d) Signature and Effective Date

The parties’ electronic acceptance of the Agreement and the DPA constitutes their signature of the applicable EU SCCs to the extent permitted by law.

The effective date is the date on which the DPA becomes effective for the applicable Customer.

18.3 Description of the Transfer

Appendix 1 provides the information required by Annex I.B of the EU SCCs, including:

  • Categories of Data Subjects.
  • Categories of Personal Data.
  • Sensitive or Special-Category Data.
  • Safeguards applicable to sensitive information.
  • Frequency of the transfer.
  • Nature of the Processing.
  • Purposes of the Processing.
  • Processing locations.
  • Retention periods and criteria.
  • Subject matter and duration of Processing.

18.4 Competent Supervisory Authority

The competent Supervisory Authority is determined under Clause 13 of the EU SCCs.

Depending on the circumstances, this will be:

  • The Supervisory Authority responsible for the Data Exporter’s GDPR compliance.
  • The Supervisory Authority where the Data Exporter’s representative under GDPR Article 27 is established.
  • Where applicable, a Supervisory Authority in an EEA Member State where affected Data Subjects are located.

The Customer will identify the specific Supervisory Authority upon reasonable request if it is not apparent from the Customer’s establishment or representative.

18.5 Modules and Options Selected

(a) Module Two

Module Two applies when:

  • The Customer is a Controller.
  • CCS is a Processor.

(b) Module Three

Module Three applies when:

  • The Customer is a Processor acting on behalf of another Controller.
  • CCS is the Customer’s Subprocessor.

(c) Clause 7: Docking Clause

Clause 7 is included.

(d) Clause 9(a): Use of Subprocessors

Option 2, General Written Authorization, applies.

CCS will provide at least thirty days’ prior notice of a material new or replacement Subprocessor as described in Section 6 of the DPA.

(e) Clause 11: Redress

The optional language in Clause 11 is not included.

(f) Clause 17: Governing Law

Option 1 applies.

The EU SCCs are governed by the law of Ireland.

(g) Clause 18: Choice of Forum and Jurisdiction

The courts of Ireland are selected.

(h) Annex II: Technical and Organisational Measures

Appendix 2 of the DPA supplies the information required for Annex II of the EU SCCs.

(i) Annex III: Subprocessor List

A separate Annex III is not included because general written authorization applies.

The current Subprocessor List is available as described in Section 6 of the DPA.

18. APPENDIX 4

19.1 UK International Data Transfer Addendum Information

When Section 12.7 of the DPA applies, the parties enter into the United Kingdom Information Commissioner’s International Data Transfer Addendum to the EU Commission Standard Contractual Clauses.

The Approved Addendum is version B1.0, which came into force on March 21, 2022, together with any lawful successor or replacement.

The official Approved Addendum is available from the United Kingdom Information Commissioner’s Office.

The information below completes Part 1 of the Approved Addendum. The unmodified Part 2 Mandatory Clauses of the Approved Addendum are incorporated into the DPA.

19.2 Parties

(a) Start Date

The Start Date is the effective date of the DPA for the applicable Customer.

(b) Data Exporter

The Data Exporter is the Customer identified in:

  • The Agreement.
  • The applicable order form.
  • The Customer’s NowCandid account records.

The Data Exporter’s main address and official registration information, where applicable, are those maintained in the Agreement, order form, or Customer account.

The Data Exporter’s primary contact is:

  • The Customer’s account administrator; or
  • Another privacy or legal contact designated by the Customer.

(c) Data Importer

The Data Importer is:

Candid Color Systems, Inc.
NowCandid
1300 Metropolitan Ave
Oklahoma City, Oklahoma 73108
United States

Primary privacy contact:
Privacy Support
ccssupport@candid.com

(d) Signature

Electronic acceptance of the Agreement and the DPA binds both parties and has the same effect as a signature to the extent permitted under the Approved Addendum and applicable law.

19.3 Selected EU SCCs, Modules, and Clauses

The Approved EU SCCs are the clauses adopted through European Commission Implementing Decision (EU) 2021/914 and incorporated through Appendix 3 of the DPA.

(a) Module Two

Module Two is in operation where:

  • The Customer is a Controller.
  • CCS is a Processor.

The following selections apply:

  • Clause 7 is included.
  • Clause 11 optional language is not included.
  • General written authorization applies under Clause 9.
  • CCS will provide thirty days’ notice of a material new or replacement Subprocessor.

(b) Module Three

Module Three is in operation where:

  • The Customer is a Processor.
  • CCS is a Subprocessor.

The following selections apply:

  • Clause 7 is included.
  • Clause 11 optional language is not included.
  • General written authorization applies under Clause 9.
  • CCS will provide thirty days’ notice of a material new or replacement Subprocessor.

(c) Modules One and Four

Modules One and Four are not in operation under this DPA.

(d) Combination of Modules

The combination question in the Approved Addendum is not applicable to the Module Two and Module Three transfers covered by the DPA.

19.4 Appendix Information

(a) Annex I.A: List of Parties

The parties are identified in:

  • Appendix 3, Part A.
  • Section 19.2 of this Appendix.
  • The Agreement and applicable Customer account records.

(b) Annex I.B: Description of Transfer

The description of the transfer is contained in Appendix 1.

(c) Annex II: Technical and Organisational Measures

The applicable technical and organisational measures are contained in Appendix 2.

(d) Annex III: Subprocessors

General written authorization applies.

The current Subprocessor List is available as described in Section 6 of the DPA.

19.5 Ending the Approved Addendum Following Changes

Both the Data Exporter and Data Importer may exercise any termination right provided by the Approved Addendum if the requirements for that right are satisfied.

Unless a permitted termination right is exercised, revisions to the Approved Addendum that are lawfully issued in accordance with its terms will apply automatically as provided by that instrument.