Data Protection & Backup Policy
Data Protection & Data Processing Policy and Data Backup & Recovery Policy
Data Processing Entity Details
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Website: www.studiomitra.in
Support Email: info.studiomitra@gmail.com
Compliance / DP Desk: compliance@safalpay.com
Helpline: +91 9918784000
Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Important Data-Backup Principle
StudioMitra provides software and storage functionality to support modern photography studios. However, StudioMitra storage must not be treated as your sole, permanent, or guaranteed archival backup of original photographs, raw camera reels, or critical records.
Every photographer and studio is required to maintain independent copies of original high-resolution assets on physical drives, local NAS, or personal cloud storage repositories.
1. Purpose
This combined Policy establishes the principles and controls followed by StudioMitra, a brand operated by SAFALPAY INDIA PRIVATE LIMITED (“StudioMitra”, “Company”, “we”, “us” or “our”), for protection, processing, storage, backup, recovery, retention and secure handling of information uploaded to or generated through the StudioMitra website and photography studio management software.
The Policy specifically addresses the nature of StudioMitra as a photography business management platform where photographers and photography studios upload and manage client photographs, videos, galleries, booking information, event details, invoices and other business information.
2. Important Data-Backup Principle
StudioMitra provides software and storage functionality to support the operation of photography businesses. However, StudioMitra storage must not be treated as the user's sole, permanent or guaranteed archival backup of photographs, videos, documents or other important data.
Every photographer, photography studio, business user and, where applicable, customer is responsible for maintaining an independent copy of important original photographs, videos, documents and other business-critical data outside the StudioMitra environment.
Users should maintain backups on their own computer, external storage, NAS, cloud storage or another secure backup location appropriate to the importance and volume of their data.
3. Company Details
Legal Name: SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
CIN: U72900UP2021PTC152896
GSTIN: 09ABGCS9381Q2Z6
Principal Place of Business: D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Email: info.studiomitra@gmail.com
Website Registered Email: info.safalpay@gmail.com
Compliance Email: compliance@safalpay.com
Phone: +91 9918784000
4. Scope
This Policy applies to customer information, photographer/studio information, booking and appointment records, event information, invoices, payment-status information, photographs, videos, galleries, documents, account information, support communications, technical information and other data processed through StudioMitra systems, databases, backup volumes, cloud infrastructure, and authorized service providers.
5. Data Categories Handled
6. Data Protection Principles
- Lawful and appropriate processing: Processing data with valid legal grounds.
- Purpose limitation: Only processing information necessary to provide studio tools.
- Data minimization: Limiting collection strictly to operational parameters.
- Accuracy: Maintaining correct and updated operational records.
- Confidentiality: Restricting data access to authorized personnel.
- Integrity and Security: Enforcing defenses against unauthorized alteration or loss.
- Retention & Disposal: Secure erasure once purpose is fulfilled.
- Accountability: Transparent and verifiable data processing practices.
7. Role of the Photographer / Studio User
The photographer or photography studio using StudioMitra acts as the Data Fiduciary/Controller responsible for the customer data and media that it uploads, manages or shares through the platform, including ensuring that it has appropriate rights, permissions, notices and lawful authority to process such information.
The user determines what client data is stored and is responsible for complying with applicable privacy legislation and StudioMitra's Terms & Conditions.
8. Rights and Permissions for Photographs and Videos
Before uploading photographs, videos or customer information, the photographer/studio must ensure it has the necessary intellectual property rights, model releases, and permissions.
StudioMitra does not become the owner of customer photographs merely because those photographs are uploaded to the platform. Ownership remains solely with the photographer or respective copyright holder.
9. Data Processing by StudioMitra
StudioMitra processes uploaded data as a Data Processor to deliver, maintain, secure and enhance platform functionalities, including gallery rendering, client proofing favorites, automated invoice delivery, payment reconciliation, and service backups.
10. Access Control
- Access to customer records is strictly segregated according to user permissions and studio ownership.
- StudioMitra personnel receive operational access only under explicit technical authorization or support requests.
- Administrative and database access is secured via multi-factor authentication and logged continuously.
- Users are responsible for protecting account passwords and client proofing access PINs.
11. Data Security
StudioMitra implements robust administrative, technical, and organizational measures aligned with ISO/IEC 27001 standards, including encrypted data transfers (TLS 1.3), AES-256 encrypted database volumes, rate limiting, and 24/7 infrastructure monitoring.
12. Data Storage
Data is hosted on hardened cloud environments located within Indian data centers. Users acknowledge that digital storage systems may experience infrastructure defects or external disruptions beyond the reasonable control of the Company.
13. User Independent Backup Obligation
Because wedding, portrait, and commercial photography collections hold immense personal and financial value, users are contractually obligated to maintain independent offline and remote backups:
- Photographers must retain original RAW files and high-res master exports on external hard drives or local NAS.
- Studios should maintain independent archive copies of all client delivery selections.
- Users should periodically perform test restores to confirm backup file integrity.
- For high-value commissions, the 3-2-1 backup rule (3 copies, 2 different media, 1 offsite) is strongly recommended.
14. StudioMitra Storage is Not a Guaranteed Archival Service
Unless explicitly agreed in a separate written service contract, StudioMitra is a SaaS studio workflow and delivery platform, not a permanent, indestructible cold-storage archive. The Company does not warrant that every file uploaded will remain accessible indefinitely.
15. Backup Objective
StudioMitra maintains internal automated database and volume backups solely for operational disaster recovery and platform continuity. These internal system snapshots are not designed to serve as an individual file-retrieval concierge for studio users.
16. Recovery from Backup
If platform data becomes unavailable due to an infrastructure outage, StudioMitra will attempt to restore affected environments from the most recent valid snapshot. Recovery is subject to backup integrity and technical feasibility.
17. No Guaranteed Data Recovery
While StudioMitra makes reasonable technical efforts to safeguard data, absolute data recovery cannot be guaranteed in every conceivable catastrophic scenario, including hardware destruction, catastrophic ransomware, zero-day defects, or third-party datacenter failures.
18. Data Loss Events
Potential data loss events include physical drive failure, database corruption, accidental user deletion, ransomware infection, cloud provider regional outages, fire, network severance, or force majeure events.
19. Limitation of Data-Loss Responsibility
To the maximum extent permitted by applicable Indian law, StudioMitra shall not be liable for the loss, corruption, or permanent deletion of user-uploaded photographs or records where such loss arises from circumstances beyond reasonable control, third-party provider failures, or the user's failure to maintain independent backups.
Nothing in this Policy excludes liabilities that cannot lawfully be disclaimed under applicable law.
20. Reasonable Efforts by StudioMitra
In the event of a storage incident, StudioMitra engineers will execute prompt forensic reviews, backup verification, and restoration efforts within technical and operational capabilities.
21. Data Export and Download Functionality
StudioMitra provides gallery zip download tools and invoice export facilities. Users are urged to exercise these download capabilities systematically to archive shoot selections locally.
22. Data Retention
Information is retained for as long as active studio subscriptions continue and as necessary to comply with tax, statutory, or dispute-mitigation requirements.
23. Deletion Requests
When a user requests account deletion, active database records and uploaded media are purged from active production volumes. Encrypted historical backup copies are overwritten according to the standard snapshot rotation cycle.
24. Account Closure
Users must download and export all critical photographs and customer invoices prior to submitting an account termination request.
25. Backup Retention
Operational snapshots are maintained across rolling retention schedules. Snapshot retention does not imply that every intermediate edit of every photograph is permanently archived.
26. Backup Security
Backup repositories are isolated with dedicated IAM credentials, encrypted at rest with rotating KMS keys, and protected against unauthorized modification or deletion.
27. Disaster Recovery
Disaster recovery protocols cover application redeployment, database replica promotion, DNS failover, and data integrity verification.
28. Recovery Time and Recovery Point Objectives
StudioMitra strives internally for a target Recovery Point Objective (RPO) of < 4 hours and Recovery Time Objective (RTO) of < 8 hours. Unless expressly agreed in an enterprise SLA, target metrics are operational benchmarks rather than absolute contractual guarantees.
29. Third-Party Cloud / Storage Providers
Infrastructure is hosted on enterprise cloud providers (e.g. AWS / Google Cloud / Cloudflare). StudioMitra coordinates directly with cloud providers to investigate and remediate service anomalies.
30. Data Breach Response
In the event of a security incident affecting customer data, StudioMitra initiates immediate containment, forensic preservation, and required regulatory notifications in compliance with the DPDP Act 2023 and CERT-In directions.
31. Cyber Attack / Ransomware Defense
Systems employ immutable backup storage configurations to mitigate the risk of ransomware-induced data corruption.
32. User Responsibility for Customer Data
Photographers must ensure they obtain valid consent from their photography subjects before uploading personal portraits, event photographs, or client contact details.
33. Customer Privacy
This Policy is supplemented by our Privacy Policy, which details how personal data is collected, processed, and safeguarded.
34. Data Minimization
Users should upload only information directly required for studio operations and client proofing.
35. Secure Data Transfer
All uploads and gallery downloads must be conducted over HTTPS with TLS 1.3 encryption.
36. Data Integrity
Checksum verification and write-integrity mechanisms are utilized to guard against bit-rot and transmission corruption.
37. User Verification of Independent Backups
Studios are strongly advised to perform periodic test restorations of their local backup disks to confirm readability and archive validity.
38. Shared Responsibility Matrix
39. Prohibited Use
Uploading malicious payloads, attempting unauthorized volume access, distributing unlawful media, or intentionally corrupting data is strictly prohibited.
40. Data Incident Reporting
To report suspected data loss, unauthorized access, or gallery exposure, contact our Data Protection Office:
Compliance / Data Protection:
compliance@safalpay.com
General Support:
info.studiomitra@gmail.com
Emergency Helpline:
+91 9918784000
Website:
www.studiomitra.in
41. Data Recovery Request
If a user requires investigation of unavailable gallery assets, submit the studio account ID, photoshoot title, approximate upload date, and affected gallery URL.
42. Service Availability
StudioMitra targets 99.9% uptime, excluding pre-announced routine maintenance periods.
43. Force Majeure
StudioMitra shall not be liable for disruptions or data loss resulting from acts of God, extreme natural calamities, widespread telecommunication blackouts, war, or catastrophic global internet disruptions.
44. No Absolute Data-Loss Waiver
This Policy is designed to balance reasonable shared responsibilities: StudioMitra maintains professional cloud safeguards and recovery mechanisms, while studio operators maintain independent offline copies of their creative assets.
45. Relationship With Terms & Conditions
This Policy is read in conjunction with the StudioMitra Terms & Conditions, Privacy Policy, and Information Security & Cyber Security Policy.
46. Policy Review
This Policy is reviewed annually and updated whenever material architectural or regulatory shifts occur.
47. Effective Date & Version
Effective Date: 19 September 2026
Version: 1.0
Policy Owner: SAFALPAY INDIA PRIVATE LIMITED / StudioMitra
48. Contact Details
SAFALPAY INDIA PRIVATE LIMITED
Brand: StudioMitra
D-30, Vibhuti Khand, Gomti Nagar, Lucknow, Uttar Pradesh – 226010, India
Website: www.studiomitra.in
General Email: info.studiomitra@gmail.com
Website Registered Email: info.safalpay@gmail.com
Compliance / Data Protection Email: compliance@safalpay.com
Phone: +91 9918784000