Data Processing Agreement
Version 1.0 — effective 28 September 2026
This is the current version. Permanent link to this version: fandemiq.net/legal/dpa/v1
Between the client named in the applicable order form or agreement ("Controller") and FANDEMiQ Ltd, a company registered in England & Wales (company number 17177298), registered office Totnes, Devon, TQ9 5HR ("Processor", "FANDEMiQ", "we"). Contact: hello@fandemiq.net.
1. Roles
1.1 For all processing of Personal Data carried out under the Agreement in connection with the Services — fan-facing camera-app uploads, the derived AI outputs described in Annex A, and the delivery of personalised content back to fans — FANDEMiQ acts as Processor and Controller acts as Controller (or, where Controller itself processes on behalf of a further controller, as Processor, in which case FANDEMiQ is a Sub-processor and this Agreement applies with that meaning substituted throughout).
1.2 For three specific purposes, FANDEMiQ acts as an independent Controller and this Agreement does not apply to that processing (it is governed instead by FANDEMiQ's own privacy notice and the controller record in FANDEMiQ's record of processing activities):
(a) Anonymised cross-client benchmarking — aggregating de-identified metrics across FANDEMiQ's client base to produce benchmarking insight (e.g. engagement rates, upload volumes) shared back with clients and used in FANDEMiQ's own product and sales materials;
(b) Platform security — detection and prevention of fraud, abuse, and security incidents across the whole platform, which necessarily draws on signals from more than one Controller's data;
(c) Product improvement — understanding aggregate usage of the platform to prioritise engineering and product work.
1.3 FANDEMiQ's use of Personal Data for (a)–(c) is subject to the de-identification and flow-down commitments at §12. Controller acknowledges this dual role and that it does not require a separate instruction for each instance of (a)–(c) provided FANDEMiQ acts within the bounds of §12.
2. Subject matter, duration, nature and purpose
2.1 Subject matter: the collection, processing, and delivery of fan-generated photo and video content, and derived data about that content, at live events operated or sponsored by Controller.
2.2 Duration: for the term of the Agreement, and thereafter only as needed to comply with §9 (deletion/return) and any residual legal retention obligation.
2.3 Nature of processing: collection via a browser-based camera app; storage; automated content moderation and tagging; automated face analysis (age-range and, where permitted, mood estimation — never identification); scoring and selection for output products; compositing and AI-assisted image editing; delivery to fans by email/SMS; display on public and admin-facing fan walls; retention-driven deletion.
2.4 Purpose: to let fans at Controller's events capture and receive personalised content, and to let Controller run fan walls, films, and other branded outputs from that content.
2.5 Categories of Data Subjects: event attendees who use the camera app ("fans"); incidentally, bystanders who appear in fan-submitted photos/video without themselves using the app.
2.6 Categories of Personal Data: see Annex A.
3. Documented instructions
3.1 FANDEMiQ will process Personal Data only on Controller's documented instructions, including regarding international transfers, unless required to do otherwise by UK or EU law, in which case FANDEMiQ will inform Controller before processing (unless prohibited from doing so).
3.2 The Agreement, the order form, and Controller's configuration choices within the FANDEMiQ admin platform (event settings, consent module selection, retention period, AI feature tier, campaign scoping) together constitute Controller's documented instructions. Any instruction outside that scope must be agreed in writing (email is sufficient) before FANDEMiQ acts on it.
3.3 FANDEMiQ will promptly inform Controller if, in its opinion, an instruction infringes UK GDPR, the EU GDPR, or another applicable data protection law.
4. Confidentiality
4.1 FANDEMiQ ensures that any person it authorises to process Personal Data (including staff and contractors) is subject to a binding confidentiality obligation, whether contractual or statutory, and processes Personal Data only as necessary for the purposes of the Agreement.
5. Security (Article 32)
5.1 FANDEMiQ implements the technical and organisational measures set out in Annex B, having regard to the state of the art, cost of implementation, and the nature, scope, context and purposes of processing, and the risk to the rights and freedoms of Data Subjects.
5.2 Known gap — Controller acknowledges that, as at the date of this Agreement: two-factor authentication is available to admin users but not mandatory; there is no customer-managed encryption key option; there is no web application firewall in front of the public-facing services; and there is no staff access audit log. FANDEMiQ will notify Controller of material changes to this list.
6. Sub-processors
6.1 Controller gives FANDEMiQ a general authorisation to engage sub-processors, subject to the notice and objection rights in this clause. The current list is maintained in the sub-processor register at fandemiq.net/legal/sub-processors and incorporated by reference.
6.2 FANDEMiQ will give Controller at least 30 days' written notice (which may be by email or by update to the published sub-processor list with notification) before appointing or replacing a sub-processor whose processing is not purely incidental (e.g. general cloud hosting).
6.3 Controller may object to a new sub-processor on reasonable data-protection grounds within that 30-day window. If FANDEMiQ cannot address the objection by an alternative arrangement, either party may terminate the affected Service on written notice, without further liability for that termination, as Controller's sole remedy.
6.4 FANDEMiQ remains liable for each sub-processor's acts and omissions to the same extent FANDEMiQ would be liable if performing that processing itself, and imposes data protection terms on each sub-processor that are no less protective than this Agreement, to the extent relevant to the processing that sub-processor performs.
7. Assistance to Controller
7.1 Data subject requests. FANDEMiQ will, taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of Controller's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection).
Known gap. FANDEMiQ does not today offer Controller or fans a self-service export/erasure tool. Requests are handled manually: FANDEMiQ commits to beginning work on a documented Controller instruction to erase, export, or restrict a named fan's data within 5 working days of receiving that instruction, and to confirming completion in writing. Per-item (single clip/photo/event) erasure is available immediately through the admin platform for Controller's own staff to action directly.
7.2 Security and breach. FANDEMiQ will notify Controller without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Controller's data, providing the information reasonably available at the time and supplementing it as the investigation progresses. Controller remains solely responsible for any notification to the ICO (or other supervisory authority) or to Data Subjects, including compliance with the 72-hour timescale under Article 33; FANDEMiQ's 24-hour commitment is designed to leave Controller a practical margin inside that window.
7.3 DPIA and prior consultation. FANDEMiQ will provide reasonable information about the processing (drawing on FANDEMiQ's data protection impact assessment and record of processing activities) to assist Controller with any data protection impact assessment or prior consultation with a supervisory authority that Controller is required to carry out.
8. Records and audit
8.1 FANDEMiQ will make available to Controller the information reasonably necessary to demonstrate compliance with this Agreement, and will allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, on reasonable notice (not less than 20 working days, except where a regulator requires shorter notice) and no more than once per 12-month period absent a suspected breach.
8.2 FANDEMiQ may satisfy an audit request in the first instance by providing existing certifications, audit reports, or the documents in this set; a physical or system audit is a fallback where those are insufficient.
9. International transfers
9.1 FANDEMiQ's applications and media storage run in Azure UK South. FANDEMiQ's SQL databases run in Azure North Europe (Ireland) — there is currently no per-tenant regional choice. Certain processing (see Annex A and the sub-processor register at fandemiq.net/legal/sub-processors) is carried out by sub-processors located outside the UK, principally in the United States and the EU.
9.2 Where Personal Data is transferred outside the UK, FANDEMiQ relies on (as applicable to the receiving party, named per-vendor in the sub-processor register): the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; the EU Standard Contractual Clauses (for EU-originating transfers); and, where the receiving vendor is certified, the EU-US Data Privacy Framework or the UK Extension to the EU-US Data Privacy Framework (UK-US "Data Bridge").
9.3 Note for the EU-controller variant. Where Controller (or a Data Subject) is established in the EEA, the parties intend for the EU Standard Contractual Clauses (Module 2, Controller-to-Processor, or Module 3, Processor-to-Processor, as applicable) to apply as between them, incorporated by reference, with the UK Addendum applying in parallel for the UK leg of any onward transfer.
10. Deletion and return
10.1 On termination or expiry of the Agreement, or earlier on Controller's written request, FANDEMiQ will, at Controller's election, delete or return all Personal Data processed on Controller's behalf, and delete existing copies, within a reasonable period (not exceeding 90 days) unless UK or EU law requires FANDEMiQ to retain it. This is in addition to, and does not override, the ordinary retention-and-purge mechanism described in the retention schedule at fandemiq.net/legal/retention-schedule, which continues to operate on its own schedule for as long as the Agreement is in force.
11. Liability
11.1 Liability under this Agreement is governed by the liability clause of the main agreement.
12. Controller-for-benchmarking safeguards
12.1 Where FANDEMiQ acts as an independent Controller under §1.2, it commits to:
(a) de-identifying data to the standard described in California Civil Code §1798.140(m) — removing or transforming identifiers such that the data cannot reasonably identify, relate to, describe, or be linked, directly or indirectly, to a particular consumer — before using it for benchmarking, security correlation across clients, or product-improvement analytics;
(b) publicly committing (via FANDEMiQ's privacy notice) to maintain and use the information only in de-identified form and not to attempt re-identification, except solely to test the de-identification process itself;
(c) contractually requiring any recipient of such de-identified data (including a sub-processor or a client receiving benchmarking output) to comply with the same restriction, by contract flow-down.
12.2 This clause does not authorise FANDEMiQ to disclose Controller's identifiable client relationship (e.g. "Team X's fans...") in benchmarking output without Controller's separate agreement; benchmarking output is aggregated and anonymised at the metric level.
Annex A — Processing details
A.1 Categories of Data Subjects
- Fans who use the camera app at Controller's events.
- Bystanders incidentally captured in fan-submitted media, who have not themselves interacted with FANDEMiQ.
A.2 Categories of Personal Data
| Category | Detail | Collected when |
|---|---|---|
| Contact data | Email and/or phone number | Optional, per activation, fan-provided |
| Media | Photos and video captured on the camera app | Every upload |
| Location — GPS | Per-second GPS track (video) or a point (photo) | Only if the fan ticks the separate location consent AND the device grants permission; refusal at either step records no location |
| Location — coarse jurisdiction | Country and, for the US, state, resolved from request IP by a local GeoLite2 database inside the API (IP itself never leaves the platform for this) | Every upload, for consent-jurisdiction and legal-policy resolution only |
| Device/session | Random browser identifier, user agent, language | Every session |
| Consent record | Append-only ledger: one row per module answer, module key, jurisdiction and detection method, wording stored by hash in a separate wording table, keyed IP hash only if a salt is configured | Every consent interaction |
| AI-derived — face | Bounding box, estimated age range, estimated gender; emotion scores only where account/event configuration and the applicable legal policy both permit | Where face analysis runs (policy-gated — see §A.4) |
| AI-derived — image | Tags, captions, detected brands, adult/racy content scores | Every processed image |
| Retention metadata | Retention deadline per item | Every item, at ingest |
A.3 Purposes
Camera-app capture and upload; content moderation (adult/racy screening); tagging and captioning for search and curation; face analysis for demographic/mood insight (never identification); scoring and automated selection for fan walls, films, and FanMoments; AI-assisted compositing/generative image editing (opt-in, paid tier only); delivery of personalised outputs by email/SMS; retention-driven deletion.
A.4 Face analysis — policy gate
Face analysis uses AWS Rekognition DetectFaces (region eu-west-2, London). No face templates are created or stored; IndexFaces/SearchFaces are never used; FANDEMiQ never identifies who anyone is. FANDEMiQ's AWS account is opted out of AWS AI-services improvement by an AWS Organizations AI-services opt-out policy (in force from 11 September 2026), so AWS may not retain or use fan images to train or improve Rekognition or any other AWS service; inputs are used solely to return the DetectFaces result.
Emotion inference is on by default per Controller account but is forced off: for any fan or event connected to the EU/EEA; for Employee or Education audience types; when neither the event's nor the fan's country can be determined. The entire face pipeline is switched off for events in, or uploads originating from, China, Russia, and Vietnam. This policy exists because age/gender estimation is treated as "biometric categorisation" under the EU AI Act (Article 50(3) transparency duty, reflected in the consent screen) and emotion inference as an "emotion recognition system" (Annex III, high-risk from 2 December 2027; prohibited for workers/students under Article 5(1)(f)).
A.5 Locations of processing
| Function | Location |
|---|---|
| Application hosting, media storage | Azure UK South |
| SQL databases | Azure North Europe (Ireland) |
| Face analysis (AWS Rekognition) | AWS eu-west-2 (London) |
| Image tagging/captioning/brands/adult screening (Azure AI Vision) | Azure West Europe (Netherlands) |
| Video scenes/transcripts (Azure Video Indexer) | Azure UK South |
| Background removal (rembg, self-hosted) | Azure UK South |
| Generative image editing (OpenAI) | United States |
| Clip descriptions / analytics assistant (OpenAI, aggregate) | United States |
| Delivery email (Resend) | Sent from the US; account metadata stored in the US regardless of send region |
| Telemetry (Application Insights) | Azure UK South |
| Error reporting (Sentry) | EU (Germany); no personal data by configuration, see the sub-processor register |
| Admin-browser map rendering (Google Maps) | Rendered client-side in the admin's browser |
| Billing metering (Microsoft Marketplace) | Microsoft-managed |
Full detail, including transfer mechanism per vendor, is in the sub-processor register at fandemiq.net/legal/sub-processors.
Annex B — Security measures
- TLS 1.2 or higher for all data in transit.
- Encryption at rest for stored media and databases.
- Azure private endpoints for internal service-to-service traffic.
- Secrets management via Azure Key Vault; no secrets in source control.
- Role-based access control: 4 roles, 21 distinct permissions, on the admin platform.
- Correlation IDs propagated across all three backend services for traceability.
- Gated deployments: staging before production, migration checks and health checks before traffic cutover.
- Two-factor authentication available to admin users (not yet mandatory — see §5.2).
- Hourly automated retention purge (hard delete of media and derived AI data past the retention deadline).
- 7-day storage-level soft-delete recovery window as an operational safety net (not a retention extension).
Known gaps (also flagged at §5.2): no customer-managed encryption keys; no web application firewall; no staff access audit log; 2FA optional rather than mandatory.
Previous versions
None. Version 1.0 is the first version of this document.