TriPrism, Inc. / PhotoTouch, Inc.
Effective: February 28, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Use between TriPrism, Inc. doing business as PhotoTouch, Inc. (“Processor”) and the photographer or entity using the PhotoTouch platform (“Controller”).
This DPA applies where the Processor processes personal data on behalf of the Controller in connection with the PhotoTouch platform services, as required by the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.
This public DPA describes our standard processor terms. Enterprise customers may execute a separate signed DPA addendum. Where a signed DPA addendum conflicts with this public DPA, the signed addendum governs with respect to data processing matters.
The Processor shall:
The Controller shall:
Photographer-configured integrations (services connected by the Controller via the API Integration Builder) are not sub-processors of TriPrism. The Controller is solely responsible for data shared with services they configure.
The Processor implements and maintains appropriate technical and organizational security measures, including but not limited to:
For full details, see our Security Overview.
The Platform provides the Controller with built-in tools to fulfill Data Subject rights requests:
| Right | Platform Tool |
|---|---|
| Right of Access (Art. 15) | Customer 360° profile + GDPR data export (CSV ZIP) |
| Right to Rectification (Art. 16) | CRM profile editing (inline email, phone, name updates) |
| Right to Erasure (Art. 17) | GDPR erasure tools with cascade-safe deletion across all channels |
| Right to Restriction (Art. 18) | Gallery disable toggle, email/SMS suppression lists |
| Right to Portability (Art. 20) | GDPR data export in standard CSV format |
| Right to Object (Art. 21) | Email unsubscribe + SMS opt-out mechanisms |
| Right to Withdraw Consent | Model release revocation links |
The Controller is the primary point of contact for Data Subject requests. If a Data Subject contacts the Processor directly, the Processor will redirect the request to the Controller and notify the Controller promptly.
Each party’s liability under this DPA is subject to the limitations of liability set forth in the Terms of Use. Nothing in this DPA limits either party’s liability for breaches of data protection law to the extent such limitation is not permitted by applicable law.
For data processing inquiries or to exercise rights under this DPA:
© 2026 TriPrism, Inc. All rights reserved.
Terms of Use • Privacy Policy • Sub-Processors • Security • Back to Login