Back to Home

Data Protection & Backup Policy

Data Protection & Data Processing Policy and Data Backup & Recovery Policy

Brand: StudioMitraOperated by: SAFALPAY INDIA PRIVATE LIMITEDEffective Date: 19 September 2026Version: 1.0

Data Processing Entity Details

Legal Name: SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

CIN: U72900UP2021PTC152896

GSTIN: 09ABGCS9381Q2Z6

Website: www.studiomitra.in

Support Email: info.studiomitra@gmail.com

Compliance / DP Desk: compliance@safalpay.com

Helpline: +91 9918784000

Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Important Data-Backup Principle

StudioMitra provides software and storage functionality to support modern photography studios. However, StudioMitra storage must not be treated as your sole, permanent, or guaranteed archival backup of original photographs, raw camera reels, or critical records.

Every photographer and studio is required to maintain independent copies of original high-resolution assets on physical drives, local NAS, or personal cloud storage repositories.

1. Purpose

This combined Policy establishes the principles and controls followed by StudioMitra, a brand operated by SAFALPAY INDIA PRIVATE LIMITED (“StudioMitra”, “Company”, “we”, “us” or “our”), for protection, processing, storage, backup, recovery, retention and secure handling of information uploaded to or generated through the StudioMitra website and photography studio management software.

The Policy specifically addresses the nature of StudioMitra as a photography business management platform where photographers and photography studios upload and manage client photographs, videos, galleries, booking information, event details, invoices and other business information.

2. Important Data-Backup Principle

StudioMitra provides software and storage functionality to support the operation of photography businesses. However, StudioMitra storage must not be treated as the user's sole, permanent or guaranteed archival backup of photographs, videos, documents or other important data.

Every photographer, photography studio, business user and, where applicable, customer is responsible for maintaining an independent copy of important original photographs, videos, documents and other business-critical data outside the StudioMitra environment.

Users should maintain backups on their own computer, external storage, NAS, cloud storage or another secure backup location appropriate to the importance and volume of their data.

3. Company Details

Legal Name: SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

CIN: U72900UP2021PTC152896

GSTIN: 09ABGCS9381Q2Z6

Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Website: www.studiomitra.in

General Email: info.studiomitra@gmail.com

Website Registered Email: info.safalpay@gmail.com

Compliance Email: compliance@safalpay.com

Phone: +91 9918784000

4. Scope

This Policy applies to customer information, photographer/studio information, booking and appointment records, event information, invoices, payment-status information, photographs, videos, galleries, documents, account information, support communications, technical information and other data processed through StudioMitra systems, databases, backup volumes, cloud infrastructure, and authorized service providers.

5. Data Categories Handled

Account and profile information
Photography studio business profiles
Customer names, contact details and bookings
Event dates, venue details and shoot calendars
Invoices, billing records and payment status
Photographs, videos, galleries and related media
Signed agreements and client documents
Technical logs, device and access analytics
Support requests and service communications
Security and incident investigation records

6. Data Protection Principles

  • Lawful and appropriate processing: Processing data with valid legal grounds.
  • Purpose limitation: Only processing information necessary to provide studio tools.
  • Data minimization: Limiting collection strictly to operational parameters.
  • Accuracy: Maintaining correct and updated operational records.
  • Confidentiality: Restricting data access to authorized personnel.
  • Integrity and Security: Enforcing defenses against unauthorized alteration or loss.
  • Retention & Disposal: Secure erasure once purpose is fulfilled.
  • Accountability: Transparent and verifiable data processing practices.

7. Role of the Photographer / Studio User

The photographer or photography studio using StudioMitra acts as the Data Fiduciary/Controller responsible for the customer data and media that it uploads, manages or shares through the platform, including ensuring that it has appropriate rights, permissions, notices and lawful authority to process such information.

The user determines what client data is stored and is responsible for complying with applicable privacy legislation and StudioMitra's Terms & Conditions.

8. Rights and Permissions for Photographs and Videos

Before uploading photographs, videos or customer information, the photographer/studio must ensure it has the necessary intellectual property rights, model releases, and permissions.

StudioMitra does not become the owner of customer photographs merely because those photographs are uploaded to the platform. Ownership remains solely with the photographer or respective copyright holder.

9. Data Processing by StudioMitra

StudioMitra processes uploaded data as a Data Processor to deliver, maintain, secure and enhance platform functionalities, including gallery rendering, client proofing favorites, automated invoice delivery, payment reconciliation, and service backups.

10. Access Control

  • Access to customer records is strictly segregated according to user permissions and studio ownership.
  • StudioMitra personnel receive operational access only under explicit technical authorization or support requests.
  • Administrative and database access is secured via multi-factor authentication and logged continuously.
  • Users are responsible for protecting account passwords and client proofing access PINs.

11. Data Security

StudioMitra implements robust administrative, technical, and organizational measures aligned with ISO/IEC 27001 standards, including encrypted data transfers (TLS 1.3), AES-256 encrypted database volumes, rate limiting, and 24/7 infrastructure monitoring.

12. Data Storage

Data is hosted on hardened cloud environments located within Indian data centers. Users acknowledge that digital storage systems may experience infrastructure defects or external disruptions beyond the reasonable control of the Company.

13. User Independent Backup Obligation

Because wedding, portrait, and commercial photography collections hold immense personal and financial value, users are contractually obligated to maintain independent offline and remote backups:

  • Photographers must retain original RAW files and high-res master exports on external hard drives or local NAS.
  • Studios should maintain independent archive copies of all client delivery selections.
  • Users should periodically perform test restores to confirm backup file integrity.
  • For high-value commissions, the 3-2-1 backup rule (3 copies, 2 different media, 1 offsite) is strongly recommended.

14. StudioMitra Storage is Not a Guaranteed Archival Service

Unless explicitly agreed in a separate written service contract, StudioMitra is a SaaS studio workflow and delivery platform, not a permanent, indestructible cold-storage archive. The Company does not warrant that every file uploaded will remain accessible indefinitely.

15. Backup Objective

StudioMitra maintains internal automated database and volume backups solely for operational disaster recovery and platform continuity. These internal system snapshots are not designed to serve as an individual file-retrieval concierge for studio users.

16. Recovery from Backup

If platform data becomes unavailable due to an infrastructure outage, StudioMitra will attempt to restore affected environments from the most recent valid snapshot. Recovery is subject to backup integrity and technical feasibility.

17. No Guaranteed Data Recovery

While StudioMitra makes reasonable technical efforts to safeguard data, absolute data recovery cannot be guaranteed in every conceivable catastrophic scenario, including hardware destruction, catastrophic ransomware, zero-day defects, or third-party datacenter failures.

18. Data Loss Events

Potential data loss events include physical drive failure, database corruption, accidental user deletion, ransomware infection, cloud provider regional outages, fire, network severance, or force majeure events.

19. Limitation of Data-Loss Responsibility

To the maximum extent permitted by applicable Indian law, StudioMitra shall not be liable for the loss, corruption, or permanent deletion of user-uploaded photographs or records where such loss arises from circumstances beyond reasonable control, third-party provider failures, or the user's failure to maintain independent backups.

Nothing in this Policy excludes liabilities that cannot lawfully be disclaimed under applicable law.

20. Reasonable Efforts by StudioMitra

In the event of a storage incident, StudioMitra engineers will execute prompt forensic reviews, backup verification, and restoration efforts within technical and operational capabilities.

21. Data Export and Download Functionality

StudioMitra provides gallery zip download tools and invoice export facilities. Users are urged to exercise these download capabilities systematically to archive shoot selections locally.

22. Data Retention

Information is retained for as long as active studio subscriptions continue and as necessary to comply with tax, statutory, or dispute-mitigation requirements.

23. Deletion Requests

When a user requests account deletion, active database records and uploaded media are purged from active production volumes. Encrypted historical backup copies are overwritten according to the standard snapshot rotation cycle.

24. Account Closure

Users must download and export all critical photographs and customer invoices prior to submitting an account termination request.

25. Backup Retention

Operational snapshots are maintained across rolling retention schedules. Snapshot retention does not imply that every intermediate edit of every photograph is permanently archived.

26. Backup Security

Backup repositories are isolated with dedicated IAM credentials, encrypted at rest with rotating KMS keys, and protected against unauthorized modification or deletion.

27. Disaster Recovery

Disaster recovery protocols cover application redeployment, database replica promotion, DNS failover, and data integrity verification.

28. Recovery Time and Recovery Point Objectives

StudioMitra strives internally for a target Recovery Point Objective (RPO) of < 4 hours and Recovery Time Objective (RTO) of < 8 hours. Unless expressly agreed in an enterprise SLA, target metrics are operational benchmarks rather than absolute contractual guarantees.

29. Third-Party Cloud / Storage Providers

Infrastructure is hosted on enterprise cloud providers (e.g. AWS / Google Cloud / Cloudflare). StudioMitra coordinates directly with cloud providers to investigate and remediate service anomalies.

30. Data Breach Response

In the event of a security incident affecting customer data, StudioMitra initiates immediate containment, forensic preservation, and required regulatory notifications in compliance with the DPDP Act 2023 and CERT-In directions.

31. Cyber Attack / Ransomware Defense

Systems employ immutable backup storage configurations to mitigate the risk of ransomware-induced data corruption.

32. User Responsibility for Customer Data

Photographers must ensure they obtain valid consent from their photography subjects before uploading personal portraits, event photographs, or client contact details.

33. Customer Privacy

This Policy is supplemented by our Privacy Policy, which details how personal data is collected, processed, and safeguarded.

34. Data Minimization

Users should upload only information directly required for studio operations and client proofing.

35. Secure Data Transfer

All uploads and gallery downloads must be conducted over HTTPS with TLS 1.3 encryption.

36. Data Integrity

Checksum verification and write-integrity mechanisms are utilized to guard against bit-rot and transmission corruption.

37. User Verification of Independent Backups

Studios are strongly advised to perform periodic test restorations of their local backup disks to confirm readability and archive validity.

38. Shared Responsibility Matrix

StudioMitra Responsibilities:Secure platform hosting, TLS data transmission, database replication, server security, and infrastructure disaster recovery.
Photographer / Studio Responsibilities:Maintaining independent copies of original high-res photos, obtaining client consents, configuring gallery access PINs, and securing login passwords.
Third-Party Cloud Providers:Physical datacenter security, power redundancy, and underlying hypervisor durability.

39. Prohibited Use

Uploading malicious payloads, attempting unauthorized volume access, distributing unlawful media, or intentionally corrupting data is strictly prohibited.

40. Data Incident Reporting

To report suspected data loss, unauthorized access, or gallery exposure, contact our Data Protection Office:

Compliance / Data Protection:
compliance@safalpay.com

General Support:
info.studiomitra@gmail.com

Emergency Helpline:
+91 9918784000

Website:
www.studiomitra.in

41. Data Recovery Request

If a user requires investigation of unavailable gallery assets, submit the studio account ID, photoshoot title, approximate upload date, and affected gallery URL.

42. Service Availability

StudioMitra targets 99.9% uptime, excluding pre-announced routine maintenance periods.

43. Force Majeure

StudioMitra shall not be liable for disruptions or data loss resulting from acts of God, extreme natural calamities, widespread telecommunication blackouts, war, or catastrophic global internet disruptions.

44. No Absolute Data-Loss Waiver

This Policy is designed to balance reasonable shared responsibilities: StudioMitra maintains professional cloud safeguards and recovery mechanisms, while studio operators maintain independent offline copies of their creative assets.

45. Relationship With Terms & Conditions

This Policy is read in conjunction with the StudioMitra Terms & Conditions, Privacy Policy, and Information Security & Cyber Security Policy.

46. Policy Review

This Policy is reviewed annually and updated whenever material architectural or regulatory shifts occur.

47. Effective Date & Version

Effective Date: 19 September 2026

Version: 1.0

Policy Owner: SAFALPAY INDIA PRIVATE LIMITED / StudioMitra

48. Contact Details

SAFALPAY INDIA PRIVATE LIMITED

Brand: StudioMitra

D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India

Website: www.studiomitra.in

General Email: info.studiomitra@gmail.com

Website Registered Email: info.safalpay@gmail.com

Compliance / Data Protection Email: compliance@safalpay.com

Phone: +91 9918784000

© 2026 SAFALPAY INDIA PRIVATE LIMITED. All Rights Reserved.Brand: StudioMitra