In plain language
- The customer decides the purpose and data; FotoFit processes it to provide the configured service.
- The customer must have lawful authority and give required notices to recipients and form respondents.
- FotoFit uses documented instructions, confidentiality, security controls, and providers needed to operate the service.
Scope and roles
These Data Processing Terms form part of the Terms of Service when a customer uses FotoFit to process personal data for its own purposes. The customer is the controller or data fiduciary and FotoFit is its processor or data processor, except where FotoFit independently determines a purpose required for account administration, billing, security, fraud prevention, or legal compliance.
The subject matter is the provision of FotoFit's template, campaign, bulk generation, managed credential, Smart Form, workspace, integration, delivery, verification, and API features. Processing continues for the subscription or account term and any retention period described in the Privacy Policy or required by law.
Customer instructions
FotoFit will process customer personal data only to provide, secure, maintain, and support the service; follow product settings and support requests; and comply with law. The Terms, the customer's use of the product, and documented support instructions constitute the customer's instructions.
If FotoFit believes an instruction violates applicable data-protection law, we may pause the affected processing and notify the customer unless law prohibits notice.
People and data involved
- People may include customer users, workspace members, credential recipients, students, employees, event participants, Smart Form respondents, and people represented in uploaded content.
- Data may include names, email addresses, identifiers, organization or course details, form responses, images, dynamic image URLs, spreadsheet values, credentials, verification status, delivery events, and technical metadata.
- The customer must not submit special-category, highly sensitive, or regulated data unless the service is expressly configured and contractually approved for it.
Customer responsibilities
- Have a lawful basis and authority for the data and instructions, including data about children or students.
- Give required privacy notices, obtain consent where required, and configure public visibility, lookup keys, roles, and delivery responsibly.
- Keep data accurate, limit it to what is necessary, secure account credentials, and respond to requests from individuals.
- Ensure its use of Google Sheets, email, URLs, webhooks, and public pages complies with provider terms and applicable law.
Confidentiality and security
FotoFit restricts personal-data access to personnel and providers who need it for authorized work and who are bound by confidentiality obligations. Controls include encrypted transport, hashed passwords and API keys, encrypted integration secrets, private object storage with time-limited access, role checks, rate limiting, logging, and backup and recovery measures appropriate to the service.
FotoFit will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information reasonably needed for the customer's legal obligations. Notification is not an admission of fault or liability.
Subprocessors
The customer authorizes FotoFit to use the providers listed on the Subprocessors page. FotoFit remains responsible for each subprocessor's processing to the extent required by applicable law and imposes data-protection obligations appropriate to the service performed.
We may update the list as the service changes. We will post material additions before or when they begin processing customer personal data. A customer with a legally supportable objection should contact us promptly; we will work in good faith on a reasonable solution, which may include disabling the affected integration or ending the affected service.
Rights requests and compliance assistance
Taking into account the nature of processing, FotoFit will provide reasonable assistance for verified individual-rights requests, security obligations, breach notifications, and required impact or regulator inquiries. The customer remains responsible for determining whether and how to respond.
FotoFit will provide information reasonably necessary to demonstrate compliance with these terms. Any audit must protect other customers, security, and confidential information, use existing reports first, and be reasonably scoped, scheduled, and paid for by the customer unless law requires otherwise.
Deletion and international transfers
During the account term, customers can delete many records and files in the dashboard. On a verified account-deletion request, FotoFit will delete or return customer personal data as described in the Privacy Policy, except for information required for security, backups, disputes, accounting, or law. Managed credentials are not deleted merely because a subscription ends; the customer must delete them or request account deletion.
Processing may occur outside the customer's country. Where applicable law requires a transfer mechanism, the parties will cooperate to put appropriate contractual safeguards in place. Contact hello@fotofit.in if an executed addendum or specific transfer terms are required for procurement.