This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Customer", the gallery) and Joe Designs LLC, a New Mexico limited liability company doing business as GalleryCamp ("GalleryCamp"). It applies whenever GalleryCamp processes Customer Personal Data on the Customer's behalf, and takes effect automatically when the Customer accepts the Terms.
Need a signed copy? Email hello@gallerycamp.com with your organization's legal name and address, and we will send a countersigned copy. The signed copy and this page have the same terms.
1. Definitions
- Data Protection Laws means all laws on the processing of personal data that apply to a party's processing under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act.
- Customer Personal Data means personal data within Customer Data that GalleryCamp processes on the Customer's behalf.
- Subprocessor means a third party GalleryCamp engages to process Customer Personal Data.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- "Controller", "processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR.
2. Roles
The Customer is the controller of Customer Personal Data, and GalleryCamp is its processor. For US state privacy laws, GalleryCamp is a "service provider" or "processor".
GalleryCamp is a separate controller of the account, billing and usage data of the Customer's own users, which its Privacy Policy covers.
3. Instructions
GalleryCamp processes Customer Personal Data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's use and configuration of the Service — including switching engagement recording on or off for a viewing room — are those instructions.
GalleryCamp will tell the Customer if it believes an instruction breaks Data Protection Laws, unless the law prohibits telling it. GalleryCamp will not:
- sell or share Customer Personal Data, or use it for targeted advertising;
- use it for any purpose other than providing the Service; or
- combine it with personal data it receives from other customers.
4. Customer obligations
The Customer is responsible for having a lawful basis for the processing it instructs, for giving data subjects the notices the law requires — including notice that viewing rooms record engagement — and for the accuracy of the data it provides.
5. Confidentiality
GalleryCamp ensures everyone it authorises to process Customer Personal Data is bound by confidentiality, and limits access to those who need it to provide or support the Service.
6. Security
GalleryCamp implements the technical and organizational measures in Annex 2 and maintains them for as long as it processes Customer Personal Data. It may update them, but not in a way that reduces the overall level of protection.
7. Subprocessors
The Customer authorises GalleryCamp to engage the Subprocessors listed in Annex 3.
- GalleryCamp will give at least 30 days' notice of a new Subprocessor by updating Annex 3 and emailing the Customer's owner.
- The Customer may object on reasonable data-protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.
- GalleryCamp imposes data-protection obligations on each Subprocessor no less protective than this DPA, and remains liable for its Subprocessors.
8. Data subject requests
Taking into account the nature of the processing, GalleryCamp will help the Customer respond to requests from data subjects exercising their rights. The Service lets the Customer find, correct, export and delete a collector's records itself. If GalleryCamp receives a request directly, it will pass it to the Customer without responding on its own, except to say it has done so.
9. Security Incidents
GalleryCamp will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a Security Incident affecting the Customer's data. It will provide the information it reasonably can to help the Customer meet its own notification obligations, take reasonable steps to contain the incident, and keep the Customer updated. Notifying the Customer is not an admission of fault.
10. Assistance
GalleryCamp will provide reasonable help with the Customer's data protection impact assessments and prior consultations with supervisory authorities, where they concern the Service.
11. Return and deletion
The Customer can export all Customer Data, and delete its organization, at any time from within the Service. When the Terms end, GalleryCamp keeps the export available for at least 30 days and then deletes Customer Personal Data, unless the law requires it to keep it. Copies in encrypted backups are deleted as those backups expire on their normal schedule, and are protected under this DPA until then.
12. Audits
GalleryCamp will make available the information reasonably necessary to show it complies with this DPA, and will answer the Customer's reasonable written security questionnaires, once a year. Where that information is not enough, or a supervisory authority requires it, the Customer may carry out an audit on 30 days' notice, during business hours, at its own cost, and under confidentiality.
13. International transfers
GalleryCamp processes Customer Personal Data in the United States. To the extent a transfer from the EEA, UK or Switzerland is not covered by an adequacy decision:
- EEA: the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs") apply and are incorporated by reference — Module Two (controller to processor), or Module Three (processor to processor) where the Customer is itself a processor. Clause 7 (docking) applies; under Clause 9, option 2 (general authorisation) applies with the notice period in section 7 above; the option in Clause 11 does not apply; Clauses 17 and 18 are governed by, and disputes resolved in the courts of, Ireland. Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA.
- UK: the International Data Transfer Addendum issued by the UK Information Commissioner applies, with the SCCs as completed above, and either party may end it as permitted by its Section 19.
- Switzerland: the SCCs apply as amended so that references to the GDPR include the Swiss FADP, the competent authority is the Swiss FDPIC, and "Member State" includes Switzerland.
If the SCCs conflict with this DPA, the SCCs prevail.
14. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws do not allow it. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.
Annex 1 — Details of processing
| Data exporter | The Customer, identified by its account details, as controller |
| Data importer | Joe Designs LLC (GalleryCamp), 110 2nd St SW Suite 501, Albuquerque, NM 87102, United States, as processor — hello@gallerycamp.com |
| Data subjects | The Customer's collectors, prospects, consignors, artists and other contacts; recipients of viewing rooms; visitors to the Customer's websites; people who send the Customer inquiries |
| Categories of data | Names and contact details; relationship notes and interests; purchase, invoice, consignment and payment records (not full card numbers); inquiry content; viewing-room engagement — works opened, time spent, zooms, plays, downloads, favourites, inquiries, visit times; IP address, browser and referring page for room visits and website artwork views |
| Sensitive data | None intended. The Customer should not enter special categories of data. |
| Frequency | Continuous, for as long as the Customer uses the Service |
| Nature and purpose | Hosting, storing, displaying and organising Customer Data; sending emails the Customer initiates; recording viewing-room engagement and website views when the Customer enables them; processing payments on the Customer's own Stripe account — all to provide the Service |
| Duration and retention | For the term of the Terms, then as in section 11 |
| Competent supervisory authority | The authority of the EU Member State where the Customer is established, or as determined under Clause 13 of the SCCs |
Annex 2 — Technical and organizational measures
- Encryption. All connections use TLS. Databases, storage and backups are encrypted at rest by our providers.
- Tenant separation. Every record belongs to one organization, and every query is scoped to the organization of the signed-in user or API key.
- Access control. Roles within each organization (owner, admin, member). Passwords are stored as salted hashes. API keys are scoped to one organization, stored as hashes, and revocable at once. Viewing-room links and passcodes are stored as hashes.
- Least privilege. Production access is limited to the people who operate the Service.
- Backups and resilience. Managed database backups; infrastructure on managed providers with their own redundancy.
- Logging and monitoring. Server traces, logs and errors are monitored; changes to a gallery's records are written to an audit log the gallery can see.
- Minimisation. Viewing rooms record engagement only when the Customer enables it, skip automated agents and previews, and count time only while the page is visible. No email tracking pixels are used.
- Vendor management. Subprocessors are bound by written data-protection terms.
- Deletion. Organization deletion removes records and stored files immediately; see section 11.
Annex 3 — Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Fly.io, Inc. | Application hosting | United States |
| PlanetScale, Inc. | Database | United States |
| Tigris Data, Inc. | Image and document storage | United States, with cached copies in other regions |
| Stripe, Inc. | Payments on the Customer's own Stripe account | United States |
| Bird (bird.com) | Sending email the Customer initiates | United States |
| Anthropic, PBC | AI generation for the website builder | United States |
| OpenAI, L.L.C. | AI generation for the website builder | United States |
| Maple (maple.dev) | Error tracking and server logs | United States |
| Sizy (sizy.io) | Image resizing | United States |
| Automattic Inc. (Gravatar) | Contact avatars from a hash of an email address | United States |