1time studios, LLC Data Processing Agreement
Last Updated: September 3, 2026
This Data Processing Agreement ("DPA") is between 1time studios, LLC ("Provider") and the Customer under the Check1 Terms of Service (the "Agreement"), which names this page as its DPA. It applies whenever Provider processes personal data on Customer's behalf in providing the Service, and it forms part of the Agreement.
This DPA consists of: (1) the Cover Page below and (2) the Common Paper Data Processing Agreement Standard Terms Version 1.1, which are incorporated by reference. Any modifications to the Standard Terms made in the Cover Page control over conflicts with the Standard Terms. Capitalized words have the meanings given in the Cover Page, the Standard Terms, or the Agreement.
Customers who need a countersigned copy of this DPA, or who want to propose changes to it, can write to notices@1timestudios.com.
Cover Page
Key Terms
Approved Subprocessors: Subprocessors are posted online at https://check1.app/subprocessors.
Provider Security Contact: privacy@1timestudios.com
Security Policy: Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.
Changes to the Agreement
Service Provider Relationship: To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq ("CCPA") applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
Restricted Transfers
Governing Member State:
EEA Transfers: Ireland
UK Transfers: England and Wales
Annex I(A) List of Parties
Data Exporter
Name: the Customer under the Agreement
Activities relevant to transfer: See Annex I(B)
Role: Controller
Data Importer
Name: 1time studios, LLC (the Provider)
Contact person: Brian J. McGuirk, Founder
Address: 229 Washington Avenue, Providence, Rhode Island 02905, USA
Activities relevant to transfer: See Annex I(B)
Role: Processor
Annex I(B) Description of Transfer and Processing Activities
The Service is: Check1, an equipment inventory, valuation, and insurance-documentation service for iOS, Android, and web, provided under the Agreement.
Categories of Data Subjects:
- Customer's end users or customers
- Customer and Customer's authorized users; individuals Customer records in the Service, namely borrowers of Customer's equipment, repair shops, insurance agents, and police officers named in reports; other individuals who appear in photos or receipts Customer uploads
Categories of Personal Data:
- Name
- Contact information such as email, phone number, or address
- Transactional information such as account information or purchases
- User activity and analysis such as device information or IP address
- Location information
- Photos and images of equipment, receipts, damage, handoffs, and incident scenes; equipment serial numbers and values; insurance policy, claim, and police-report details; incidental partial payment-card details printed on receipts; subscription status and store transaction identifiers
Special Category Data: Is special category data (as defined in Article 9 of the GDPR) Processed? No.
Frequency of Transfer: Continuous
Nature and Purpose of Processing: Provider will Process Customer Personal Data as instructed in Section 2.3 of the DPA Standard Terms. The nature of processing includes:
- Receiving data, including collection, accessing, retrieval, recording, and data entry
- Holding data, including storage, organization, and structuring
- Using data, including analysis, consultation, testing, automated decision making, and profiling
- Updating data, including correcting, adaption, alteration, alignment, and combination
- Protecting data, including restricting, encrypting, and security testing
- Sharing data, including disclosure, dissemination, allowing access, or otherwise making available
- Returning data to the data exporter or data subject
- Erasing data, including destruction and deletion
- Improving Provider's equipment-recognition models using redacted copies of scan data, subject to Customer's in-app opt-out, as described in Section 1.6 of the Agreement's Cover Page and the Privacy Policy
Duration of Processing: Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.
Annex I(C)
Competent Supervisory Authority: The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
Annex II
Technical and Organizational Security Measures:
Pseudonymization and encryption of personal data: Data is encrypted at rest on Google Cloud managed storage and databases. Scan records are de-identified on account deletion, and receipt images used for recognition training are first redacted of card numbers, email addresses, and phone numbers.
Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services: The Service runs on Google Cloud managed services (Cloud Run, Cloud SQL, Cloud Storage) with automatic scaling and health monitoring. Uploaded files are validated by content signature before storage.
Ability to restore the availability of and access to the Customer Personal Data in a timely manner following a physical or technical incident: Automated database backups with point-in-time recovery, and a weekly export of the sign-in directory to a separate backup bucket.
User identification and authorization process and protection: Sign-in is handled by Firebase Authentication; Provider does not hold passwords. Every API request carries a signed token that is verified server-side, and every read and write is checked against the requesting account's ownership. Access to production systems is limited to named personnel.
Protecting Customer Personal Data during transmission (in transit): All connections use TLS, including between the app, the API, and each subprocessor.
Protecting Customer Personal Data during storage (at rest): Google Cloud encrypts all stored data at rest by default, including the database, file storage, and backups.
Physical security where Customer Personal Data is processed: Customer Personal Data is processed in Google Cloud data centres (us-central1), covered by Google's physical security controls and certifications.
Events logging: Server request logs are kept in Cloud Logging for a limited period. Attempts to access data belonging to another account are recorded as security events. Error reports are scrubbed of personal fields before being sent to Sentry.
Ensuring limited data retention: Forwarded receipt emails are deleted once parsed. Gigs are deleted two years after they end. Server logs are retained for a limited period. Backups and the sign-in export expire on a rolling schedule of up to 180 days.
Allowing data portability and erasure: Customers can export their data as documents from the app and request a machine-readable copy under Section 3.3 of the Agreement's Cover Page. In-app account deletion removes the Customer's records and files, scrubs the account record, deletes the sign-in identity, and de-identifies scan records.
Standard Terms
The Common Paper Data Processing Agreement Standard Terms Version 1.1 are posted publicly at commonpaper.com/standards/data-processing-agreement/1.1 and are incorporated into this DPA by reference. Those terms are hosted by Common Paper and do not change.