Legal

Data Processing Addendum

Last updated 28 July 2026. This addendum governs how Gallerite Ltd processes your Clients’ personal data on your behalf.

1. About this addendum

This Data Processing Addendum ("DPA") forms part of the Gallerite Terms of Service between Gallerite Ltd ("Gallerite") and you, the photographer ("you"). It reflects how we process personal data under the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation (NDPR) and, where your Clients are located elsewhere in Africa, any applicable local data protection law (together, "Data Protection Law"). You accept this DPA by accepting the Terms of Service or using the service.

2. Definitions

"Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the Data Protection Law. "Client Personal Data" means personal data about your Clients and their guests that you upload to, or collect through, Gallerite — such as names, email addresses, phone numbers and photographs. "Sub-processor" means a third party we engage to process Client Personal Data.

3. Roles of the parties

For Client Personal Data, you are the Controller and Gallerite is your Processor. (For your own account data, Gallerite is the Controller, as described in our Privacy Policy.) You confirm that you have a lawful basis and all consents and notices required to collect your Clients' data and to have Gallerite process it — including, where photographs feature children, the consent of a parent or guardian. On request, you will provide evidence of those consents.

4. Our processing

Gallerite processes Client Personal Data only to provide the service and on your documented instructions (including the actions you take in your account), for the duration of your account plus any retention required by law. If we are required by law to process it for another purpose, we will tell you first unless the law prevents us.

5. Sub-processors

You authorise us to engage the following Sub-processors to process Client Personal Data. We will give you notice before adding or replacing a Sub-processor so you can object.

  • Paystack — payments and payouts (Nigeria).
  • Cloudflare — photo and file storage (R2) and content delivery (Eastern Europe).
  • Google — sign-in and website analytics (outside Nigeria).
  • Zoho (ZeptoMail) — transactional email (United States).
  • Railway — application hosting and infrastructure (outside Nigeria).

Each Sub-processor is bound by a contract requiring it to process Client Personal Data only to deliver its service and to protect it to a standard consistent with this DPA.

6. International transfers

Some Sub-processors process Client Personal Data outside Nigeria (for example, Cloudflare R2 storage in Eastern Europe and ZeptoMail in the United States). Where this happens, we rely on a transfer mechanism permitted under Part IX of the NDPA — such as an adequate level of protection, your instruction or consent, or contractual safeguards.

7. Security

We implement and maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for sensitive data such as payment keys and two-factor secrets, hashed passwords and gallery PINs, role-based access controls, and private file storage reachable only through short-lived signed links. Our personnel who access Client Personal Data are bound by confidentiality obligations.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data, and will provide information to help you meet your obligations under the Data Protection Law — including notifying the Nigeria Data Protection Commission (NDPC) within any applicable timeline.

9. Data subject requests and assistance

If a Data Subject (for example, one of your Clients) contacts us directly about their data, we will refer them to you. Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests to access, correct, delete, restrict, object to or port their data. You are responsible for responding to those requests.

10. Return and deletion

On termination of your account, or on your written request, we will delete or return Client Personal Data, except where we are required by law to retain it. Data on backups is protected from further processing and is deleted on our normal backup cycle.

11. Audits

On reasonable written request, and no more than once a year unless required by a regulator, we will make available information necessary to demonstrate compliance with this DPA. The parties will agree the scope and timing in advance, and you will bear the reasonable costs of any audit.

12. Precedence and contact

If this DPA conflicts with the Terms of Service on data protection matters, this DPA prevails. Questions about this DPA or our data protection practices can be sent to privacy@gallerite.com.