RelyveHome

Legal

Relyve Data Processing Addendum

Last updated: 27 August 2026

This Data Processing Addendum (“DPA”) forms part of the Relyve Terms of Service between the Customer and Vyredo Ltd, trading as Relyve (“Relyve”, “we”, “us” or “our”).

It applies whenever Relyve processes Customer Personal Data on behalf of a Customer in connection with the Relyve Service.

1. Parties and scope

This DPA is entered into between:

Vyredo Ltd trading as Relyve
Company No. 16939602
Registered in England and Wales
67 Ravencarr Road
Sheffield
England
S2 1SR

and the Customer that has accepted the Relyve Terms of Service.

For the processing covered by this DPA:

  • the Customer generally acts as the Controller; and
  • Relyve generally acts as the Processor.

If the Customer acts as a Processor on behalf of another Controller, Relyve will act as the Customer’s Subprocessor for the relevant Customer Personal Data.

This DPA applies only to personal data that Relyve processes on behalf of the Customer. It does not apply to personal data for which Relyve independently determines the purposes and means of processing, such as Relyve account administration, billing, security, Service analytics and our own business operations. Those activities are described in our Privacy Policy.

2. Definitions

In this DPA:

Applicable Data Protection Law means any privacy or data-protection law that applies to the processing covered by this DPA, including, where applicable, the UK GDPR, the Data Protection Act 2018, the EU GDPR and applicable United States state privacy laws.

Controller, Processor, Data Subject, Personal Data, Personal Data Breach and Processing means have the meanings given to them under Applicable Data Protection Law.

Customer Content means has the meaning given in the Relyve Terms of Service.

Customer Personal Data means means Personal Data contained in Customer Content or otherwise processed by Relyve on behalf of the Customer in connection with the Service.

Subprocessor means means a third party appointed by Relyve to process Customer Personal Data on behalf of the Customer.

Service means means the Relyve services described in the Terms of Service.

Terms means means the Relyve Terms of Service.

3. Details of the processing

The subject matter, nature, purpose and duration of the Processing, together with the categories of Personal Data and Data Subjects involved, are set out in Schedule 1 to this DPA.

The Customer’s use of the Service and the instructions contained in the Terms, this DPA, the Customer’s account settings and other documented instructions given through the Service constitute the Customer’s documented instructions to Relyve.

4. Customer responsibilities

The Customer is responsible for determining the purposes and means of its Processing of Customer Personal Data and for ensuring that its use of Relyve complies with Applicable Data Protection Law.

The Customer is responsible for ensuring that it:

  • has an appropriate lawful basis for processing Customer Personal Data;
  • provides any privacy information required by law;
  • has all rights, permissions and other authority required to provide Customer Personal Data to Relyve;
  • complies with any additional requirements applying to sensitive or special-category Personal Data;
  • gives Relyve lawful instructions;
  • responds appropriately to requests made by Data Subjects; and
  • uses appropriate Gallery access and security settings for its particular circumstances.

The Customer must not instruct Relyve to process Customer Personal Data in a way that would violate Applicable Data Protection Law.

Where the Customer acts as a Processor rather than a Controller, the Customer confirms that its instructions to Relyve are authorised by the relevant Controller.

5. Relyve’s processing obligations

Relyve will process Customer Personal Data only:

  • on the Customer’s documented instructions;
  • as necessary to provide, secure, maintain and support the Service; or
  • where required by applicable law.

If applicable law requires Relyve to process Customer Personal Data other than on the Customer’s documented instructions, we will inform the Customer before carrying out that Processing unless the law prohibits us from doing so.

If we reasonably believe that an instruction infringes Applicable Data Protection Law, we will inform the Customer and may suspend the affected Processing until the issue has been resolved.

Relyve will not independently determine new purposes for Customer Personal Data while acting as Processor.

6. Confidentiality

Relyve will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Personal Data will be limited to personnel and contractors who require access for purposes connected with providing, securing, maintaining or supporting the Service.

7. Security

Relyve will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

The measures we currently use are described generally in Schedule 2.

When assessing appropriate security measures, Relyve will take into account, as applicable:

  • the state of the art;
  • implementation costs;
  • the nature, scope, context and purposes of the Processing; and
  • the risks to the rights and freedoms of individuals.

Relyve may update its security measures as the Service develops, provided that any update does not materially reduce the overall level of protection afforded to Customer Personal Data.

8. Personal Data Breaches

If Relyve becomes aware of a Personal Data Breach affecting Customer Personal Data, we will notify the Customer without undue delay.

Where available and relevant, the notification will include information reasonably necessary to assist the Customer with its obligations, such as:

  • the nature of the breach;
  • the categories of affected Personal Data;
  • the categories or approximate number of affected Data Subjects where known;
  • likely consequences of the breach;
  • measures taken or proposed to address the breach; and
  • contact information for further enquiries.

Where all information is not available at the same time, it may be provided in stages as it becomes available.

Relyve’s notification of a Personal Data Breach does not constitute an admission of fault or liability.

The Customer remains responsible for determining whether notification to a regulator, Data Subject or other person is legally required.

9. Subprocessors

The Customer gives Relyve general written authorisation to appoint Subprocessors to process Customer Personal Data.

Relyve will maintain information about the Subprocessors used in connection with Customer Personal Data in its Subprocessor List.

Before appointing a new Subprocessor that will materially process Customer Personal Data, we will provide reasonable advance notice to affected Customers where required by Applicable Data Protection Law.

Notice may be provided by email, through the Service or by another reasonable method.

The Customer may object to a new Subprocessor on reasonable and documented data-protection grounds.

Any objection must be submitted promptly after receiving notice and must explain the specific data-protection concern.

We will work with the Customer in good faith to consider a reasonable solution. Where no reasonable solution is available, either party may terminate the affected part of the Service in accordance with the Terms.

Relyve will enter into a written agreement with each Subprocessor that imposes data-protection obligations appropriate to the Processing and providing a level of protection for Customer Personal Data that is materially equivalent to the obligations imposed on Relyve under this DPA where required by law.

Relyve remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.

In urgent circumstances, including where a Subprocessor change is necessary to address a security incident, legal requirement or material service failure, advance notice may not be reasonably possible. Where appropriate, we will provide notice as soon as reasonably practicable.

10. Data Subject requests

Taking into account the nature of the Processing, Relyve will provide reasonable assistance to the Customer with responding to requests by Data Subjects exercising rights available under Applicable Data Protection Law.

Where a Data Subject contacts Relyve directly about Customer Personal Data and Relyve can reasonably identify the relevant Customer, we will normally direct the individual to the Customer.

We will not independently respond to a request concerning Customer Personal Data except:

  • on the Customer’s documented instructions;
  • where necessary to confirm that the request has been referred to the Customer; or
  • where required by law.

The Customer remains responsible for determining how to respond to Data Subject requests.

11. Assistance with compliance

Taking into account the nature of the Processing and information available to us, Relyve will provide reasonable assistance to the Customer with applicable obligations relating to:

  • security of Processing;
  • Personal Data Breach assessment and notification;
  • data-protection impact assessments;
  • prior consultation with a supervisory authority; and
  • other obligations for which processor assistance is required by Applicable Data Protection Law.

The Customer remains responsible for its own compliance decisions and regulatory obligations.

If a request for assistance requires material work beyond what is reasonably included in the Service, the parties may agree reasonable additional charges before that work is undertaken, except where the assistance is required because of Relyve’s breach of this DPA.

12. Government and legal requests

If Relyve receives a legally binding request from a public authority for Customer Personal Data, we will, where legally permitted:

  • notify the Customer;
  • inform the Customer about the request; and
  • limit disclosure to the information legally required.

Where reasonably appropriate and legally permitted, we may challenge requests that we reasonably consider unlawful or disproportionate.

Nothing in this section requires Relyve to breach applicable law.

13. International transfers

Relyve is established in the United Kingdom and may use Subprocessors located in the United Kingdom, European Economic Area, United States or other countries.

Where Customer Personal Data is transferred internationally, the parties will comply with applicable international-transfer requirements.

Where an adequacy regulation or adequacy decision applies to the relevant transfer, the parties may rely on that adequacy mechanism.

At the date of this DPA, the European Commission recognises the United Kingdom as providing an adequate level of protection under the EU GDPR.

Where a transfer requires additional safeguards, Relyve will use an appropriate lawful transfer mechanism as required, which may include:

  • the European Commission Standard Contractual Clauses;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the European Commission Standard Contractual Clauses;
  • another recognised contractual safeguard; or
  • another lawful transfer mechanism permitted under Applicable Data Protection Law.

Where required, relevant transfer risk assessments or data-protection tests will also be carried out.

Relyve will require relevant Subprocessors to implement appropriate transfer safeguards where required by Applicable Data Protection Law.

If a transfer mechanism relied upon by the parties becomes invalid or unavailable, the parties will cooperate in good faith to implement an alternative lawful mechanism where reasonably necessary.

14. United States privacy requirements

To the extent Customer Personal Data is subject to a United States state privacy law under which Relyve is treated as a processor, service provider, contractor or similarly defined recipient acting on behalf of the Customer, Relyve will process that Customer Personal Data only for the purposes described in the Terms, this DPA and the Customer’s documented instructions.

Relyve will not use Customer Personal Data for its own unrelated advertising or profiling purposes while acting in that capacity.

Relyve will not sell Customer Personal Data for monetary consideration.

Where required by applicable U.S. privacy law, Relyve will:

  • provide the level of privacy protection required of a processor, service provider or contractor;
  • cooperate with reasonable Customer requests relating to applicable consumer rights;
  • notify the Customer if we determine that we can no longer meet an applicable legal obligation; and
  • allow the Customer to take reasonable and appropriate steps to help ensure Customer Personal Data is processed consistently with the applicable contractual requirements.

Nothing in this section changes the parties’ roles for Processing for which Relyve independently acts as a Controller.

15. Return and deletion of Customer Personal Data

  • the Customer may access and download Customer Content using the functionality made available through the Service while the relevant functionality remains available.
  • when the Services involving Customer Personal Data end, the Customer may choose to retrieve Customer Personal Data using the available export or download functionality before deletion.
  • unless the Customer gives Relyve a different lawful documented instruction that we can reasonably implement, the Customer instructs Relyve to delete remaining Customer Personal Data in accordance with the standard retention and deletion process described in the Terms and Privacy Policy.
  • this generally includes the limited 30-day retention period that may apply after a Subscription or trial ends.
  • Customer Content moved to Trash may be deleted according to the Customer’s selected 15- or 30-day deletion setting.

After permanent deletion, Customer Personal Data may remain for a limited period in backups, logs or disaster-recovery systems where immediate deletion is not technically practicable.

Any Personal Data remaining in those systems will continue to be protected under this DPA and will not be restored for ordinary business purposes except where reasonably necessary for disaster recovery, security or legal compliance.

Relyve may retain Customer Personal Data for longer where required by applicable law. Where legally permitted, we will inform the Customer of that requirement.

16. Audit and compliance information

Relyve will make available information reasonably necessary to demonstrate compliance with its obligations as Processor under Applicable Data Protection Law and this DPA.

Where appropriate, this may include:

  • security information;
  • relevant policies or documentation;
  • compliance questionnaires;
  • independent audit or certification information where available; and
  • other reasonable evidence of compliance.

The Customer may request an audit where reasonably necessary to verify Relyve’s compliance with this DPA.

Except where a regulator requires otherwise or there has been a material security incident or reasonable evidence of material non-compliance:

  • audits should normally occur no more than once in any 12-month period;
  • the Customer must provide reasonable advance written notice;
  • document-based or remote review should be used first where it can reasonably satisfy the Customer’s requirements;
  • any auditor must be independent, appropriately qualified and subject to confidentiality obligations;
  • audits must take place during normal business hours and must not unreasonably disrupt Relyve or compromise the security, confidentiality or rights of other Customers; and
  • the Customer will bear its own audit costs and Relyve’s reasonable costs associated with an unusually burdensome audit.

If an audit identifies a material breach of this DPA by Relyve, Relyve will take reasonable steps to address the breach and will not charge the Customer for reasonable audit costs directly attributable to confirming that material breach.

Nothing in this section requires Relyve to disclose:

  • another Customer’s information;
  • information that would compromise security;
  • legally privileged information; or
  • confidential information unrelated to the Customer’s compliance assessment.

17. Records and regulatory cooperation

Relyve will maintain records of Processing activities where required by Applicable Data Protection Law.

Relyve will cooperate with competent supervisory authorities to the extent required by applicable law.

Nothing in this DPA limits either party’s direct statutory obligations under Applicable Data Protection Law.

18. Liability

The liability of each party arising from this DPA is subject to the limitations and exclusions of liability contained in the Terms, except to the extent that Applicable Data Protection Law does not permit the relevant liability to be limited or excluded.

Nothing in this DPA limits any liability or obligation that cannot lawfully be limited.

19. Order of precedence

If there is a conflict between this DPA and the Terms regarding the Processing of Customer Personal Data, this DPA will take priority.

If there is a conflict between this DPA and a mandatory international transfer mechanism that applies to a particular transfer, the mandatory transfer mechanism will take priority for that transfer.

The Terms continue to apply to all matters not specifically addressed by this DPA.

20. Duration

This DPA begins when the Customer accepts the Terms or otherwise enters into an agreement with Relyve under which Relyve processes Customer Personal Data.

It remains in effect for as long as Relyve processes Customer Personal Data on behalf of the Customer.

Provisions that by their nature need to continue after termination, including confidentiality, deletion, audit, liability and international-transfer obligations, will continue for as long as necessary.

21. Changes to this DPA

We may update this DPA where reasonably necessary to reflect:

  • changes in Applicable Data Protection Law;
  • changes to recognised international-transfer mechanisms;
  • changes to the Service;
  • changes to our Processing arrangements; or
  • regulatory guidance.

We will provide reasonable notice of material changes where required.

An update will not materially reduce the level of protection afforded to Customer Personal Data in a manner that would cause the Processing to cease complying with Applicable Data Protection Law.

If a mandatory legal change requires an amendment to this DPA, that amendment may take effect when legally necessary.

22. Governing law

Unless Applicable Data Protection Law or a mandatory transfer mechanism requires otherwise, this DPA is governed by the governing-law and jurisdiction provisions in the Relyve Terms of Service.

23. Contact

Questions relating to this DPA or Relyve’s Processing of Customer Personal Data may be sent to:

Vyredo Ltd trading as Relyve
Company No. 16939602
Registered in England and Wales
Registered Office
67 Ravencarr Road
Sheffield
England
S2 1SR
Email: hello@relyve.co

Schedule 1 — Details of Processing

Subject matter

Processing of Customer Personal Data as necessary to provide the Relyve Service to the Customer, including media storage, processing, transcoding, gallery creation, presentation, delivery, download functionality, security, maintenance and technical support.

Duration

For the duration of the Customer’s use of the relevant Service and any applicable retention period following cancellation, expiry or termination, subject to the deletion provisions in the Terms and this DPA.

Nature and purpose of Processing

Depending on the Customer’s use of Relyve, Processing may include:

  • receiving and uploading Customer Content;
  • storing media;
  • organising Customer Content;
  • transcoding and processing video;
  • resizing or creating technical versions of media;
  • generating thumbnails or previews;
  • presenting Customer Content in galleries;
  • transmitting Customer Content to Gallery Visitors;
  • enabling downloads selected by the Customer;
  • applying Customer-selected access controls;
  • backing up and restoring systems where applicable;
  • securing the Service;
  • troubleshooting technical problems; and
  • deleting Customer Content in accordance with Customer instructions and applicable retention settings.

Relyve does not process Customer photographs or videos on behalf of the Customer for advertising profiling, unrelated behavioural analysis or AI model training.

Categories of Data Subjects

Customer Personal Data may relate to:

  • the Customer’s clients;
  • photography or video subjects;
  • wedding couples;
  • wedding or event guests;
  • family members;
  • children appearing in Customer Content;
  • employees or contractors of the Customer;
  • individuals appearing in photographs or videos;
  • other individuals whose Personal Data the Customer chooses to upload; and
  • Gallery Visitors, to the extent technical information is processed on the Customer’s behalf rather than for Relyve’s independent purposes.

Types of Personal Data

Depending on the Customer Content uploaded, Customer Personal Data may include:

  • photographs;
  • video recordings;
  • audio contained within video;
  • names contained within files or metadata;
  • filenames;
  • metadata;
  • images and likenesses;
  • voices;
  • event information;
  • information contained visibly or audibly within Customer Content;
  • gallery information;
  • access-related information; and
  • other Personal Data selected and uploaded by the Customer.

Sensitive and special-category data

Customer Content may contain information that qualifies as sensitive or special-category Personal Data depending on the Content and how it is processed.

This may include information relating to:

  • racial or ethnic origin;
  • religious or philosophical beliefs;
  • health;
  • sexual orientation;
  • biometric information where legally classified as such; and
  • other information afforded additional protection under Applicable Data Protection Law.

Relyve does not intentionally infer, categorise or profile individuals based on these characteristics when providing the Service.

The Customer is responsible for determining whether its Customer Content contains such information and for satisfying any additional requirements applicable to that Processing.

Processing frequency

Processing occurs on a continuous or recurring basis as initiated by the Customer through its use of the Service.

Schedule 2 — Technical and Organisational Measures

Relyve uses technical and organisational measures designed to protect Customer Personal Data appropriate to the nature of the Service and the risks associated with the Processing.

These measures may include the following.

Access control

Access to production systems and Customer Personal Data is restricted to authorised persons who require access for legitimate operational, support, security or technical purposes.

Account authentication and access controls are used to reduce unauthorised access.

Transmission security

Relyve uses encrypted network connections for transmission of data where supported and appropriate, including encryption in transit for connections to the Service.

Account security

Customer Accounts are protected by authentication controls.

Customers are responsible for protecting their own login credentials and Gallery passwords and for choosing appropriate Gallery access settings.

Infrastructure and network security

Relyve uses cloud, network and infrastructure providers that provide security controls appropriate to their respective services.

Security measures may include network protections, access restrictions, monitoring, logging and measures designed to mitigate unauthorised access or malicious traffic.

Logging and monitoring

Relevant technical and security events may be logged and monitored to support security, troubleshooting, abuse prevention and incident investigation.

Development and change management

Relyve uses development and deployment processes intended to reduce the risk of unauthorised or accidental changes to production systems.

Security incident response

Relyve maintains procedures intended to identify, investigate, contain and respond to security incidents affecting the Service.

Availability and resilience

Relyve uses commercially reasonable measures designed to support the availability and resilience of the Service.

Customers must maintain independent copies of Customer Content and must not rely on Relyve as their sole archive or backup.

Data minimisation and purpose limitation

Relyve processes Customer Personal Data only to the extent reasonably necessary to provide the Service and carry out the Processing described in this DPA.

Personnel confidentiality

Personnel authorised to access Customer Personal Data are subject to appropriate confidentiality obligations.

Subprocessor management

Relyve assesses and contracts with Subprocessors in accordance with the requirements of this DPA and Applicable Data Protection Law.

Review and improvement

Security measures may be reviewed and updated as Relyve, its technology and the relevant risks develop, provided the overall level of protection is not materially reduced.

Last updated: 27 August 2026

Company: Vyredo Ltd trading as Relyve

Company No. 16939602

Contact: hello@relyve.co

© Vyredo Ltd trading as Relyve. All rights reserved.