You are reading an archived version of our legal texts (version 2.0.0, in force from 2026-07-31). It is not the text currently in force.

Privacy and data protection

Corpus compliant

What we do with personal data, on what legal basis, for how long, and what you can require of us. This page covers three regimes at once: Côte d'Ivoire, the European Union, and the United States.

Who is responsible

For photographs and facial search, {legalName} and the photographer who created the event are joint controllers. The photographer decides the purpose — which event, which photographs, which guests. We decide the means — which recognition provider, what matching threshold, what retention, and the fact that facial search is switched on by default when an event is created. Because we make those decisions, we do not present ourselves as a mere technical processor. You may exercise your rights against either of us; we will not send you away.

Legal basis, regime by regime

Facial templates and comparison selfies are sensitive data everywhere they are processed. In the European Union we rely on your explicit consent under Article 9(2)(a) of the GDPR. In Côte d'Ivoire we rely on your consent under law no. 2013-450. In United States states with a dedicated biometric statute, we rely on your prior written consent. Account, billing and security data rest on the performance of our contract with the photographer, or on our legal obligations.

International transfers

Facial templates are processed and stored by Amazon Web Services in Ireland, inside the European Union. Our other providers host in regions we are in the process of confirming contractually; until each is confirmed, we state it as unconfirmed on the sub-processors page rather than assert a guarantee we have not verified. Where a transfer leaves the European Union, we rely on the European Commission's standard contractual clauses.

Your rights

You may ask for access to your data, correction, erasure, restriction, portability, and you may object to a processing operation. Where we rely on consent, you may withdraw it at any time, and withdrawing it is as easy as giving it. Write to {privacyEmail}. We answer within one month; if a request is complex we will tell you why and how much longer we need. You do not have to go through the photographer — that route exists, but it is never the only one.

Complaining to an authority

If our answer does not satisfy you, you can complain to a supervisory authority without going through us. In Côte d'Ivoire, the data protection authority (ARTCI). In the European Union, the supervisory authority of the country where you live, work, or where the problem occurred. In the United States, the attorney general of your state.

How long we keep things

Your comparison selfie is deleted the moment the search has run, whether or not it found anything; a sweeper removes orphaned selfies every fifteen minutes, so at worst one lives about half an hour. Facial templates are kept alongside the event's photographs and are deleted with them. Photographs follow the retention of the plan the photographer bought, plus a seven-day grace period. Invoices and payment records are kept because accounting law requires it, and survive the deletion of an account under a neutral identity. Web performance metrics are deleted after thirty days. Where we have not yet set an automatic deletion for a category, the table above says so plainly.

Children and young people

Today, uploading a selfie requires ticking a single box that states you are over 18 or have a parent's or guardian's permission. That statement is not verified, and we do not operate a separate parental consent process — we would rather say so than describe a safeguard that does not exist. The age at which a person can consent on their own differs by regime: between 13 and 16 in the European Union depending on the member state. If you believe a child's image is being processed and should not be, write to {privacyEmail} and we will act on it.

Automated matching

Comparing a selfie against an event's photographs is entirely automated. No person looks at your selfie to decide. The result is binary — either photographs are returned to you, or none are. The matching threshold is deliberately strict, and no biometric measurement is ever shown to the photographer or to you.

Security

Access to data is restricted by role and enforced by the database itself, not only by the interface. Files are served through short-lived signed links rather than public addresses. Administrative actions are logged. We deliberately do not describe our measures in more detail here: a security page precise enough to be useful to an attacker is a weakness in itself.

If something goes wrong

We have a procedure for handling a personal data breach. Where a breach is likely to result in a risk to people, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we inform the people concerned directly when the risk to them is high.

Changes to this policy

This policy carries a version number and a date, shown at the foot of the page. Previous versions stay available at a permanent address so you can see what was published when. When a change materially affects a processing operation that relies on your consent, we ask for it again rather than assume the old one still covers it.

Read the version currently in force