Privacy and data protection
Last updated: July 31, 2026
What we do with personal data, on what legal basis, for how long, and what you can require of us. This page covers two regimes at once: the European Union and the United States.
What we process
One row per processing operation we actually carry out. Nothing here is aspirational: each row was checked against the code before being published.
| Purpose | Legal basis | Data | People concerned | Retention | Recipients |
|---|---|---|---|---|---|
| Index facial templates so a guest can find their own photos | Explicit consent (GDPR art. 9(2)(a)) | Facial templates | Photographed guests | Same lifetime as the event photographs | Amazon Web Services (Rekognition) |
| Compare a selfie against the event to return the guest's photos | Explicit consent (GDPR art. 9(2)(a)) | Comparison selfie · Email given for a search | Photographed guests | Deleted immediately after the search; orphans within 1 hour | Amazon Web Services (Rekognition) · Cloudflare (R2, CDN, Workers) |
| Host and deliver the photographs of an event | Performance of the contract, and consent for the guest | Event photographs | Photographed guests | Plan retention period, plus a grace period before purge | Cloudflare (R2, CDN, Workers) · Supabase |
| Run the photographer's account and subscription | Performance of the contract | Account details · Contact details | Photographers | Until the account is deleted | Supabase · Railway |
| Collect payments and issue invoices | Legal obligation | Billing and payment data · Contact details | Photographers | Kept for the statutory accounting period | Stripe · Paystack · CinetPay · Supabase |
| Tell a guest when the photos of their event are ready | Consent | Contact details · Name given by the guest | Photographed guests | 12 months | Supabase · Resend · Meta (WhatsApp Business) |
| Record downloads so the photographer can measure delivery | Legitimate interest | Technical and security logs | Photographed guests | 12 months | Supabase |
| Measure site audience, only after the visitor accepts | Consent | Usage data | Site visitors | Google Analytics retention period | Google Analytics 4 |
| Measure page performance to fix what is slow | Legitimate interest | Usage data | Site visitors | 30 days | Supabase |
| Send in-app and email notices to the photographer | Performance of the contract | Contact details | Photographers | 12 months | Supabase · Resend |
| Trace sensitive administrative actions | Legal obligation | Technical and security logs | Photographers · Administrators | 12 months | Supabase |
| Collect an anonymous rating of an event | Legitimate interest | Anonymous rating and comment | Photographed guests | 12 months | Supabase |
Marked durations are commitments we have published and are implementing; where a duration is not yet applied automatically, we say so rather than imply otherwise.
Who is responsible
For photographs and facial search, BLACKNIDEAS LLC and the photographer who created the event are joint controllers. The photographer decides the purpose — which event, which photographs, which guests. We decide the means — which recognition provider, what matching threshold, what retention, and the fact that facial search is switched on by default when an event is created. Because we make those decisions, we do not present ourselves as a mere technical processor. You may exercise your rights against either of us; we will not send you away.
Legal basis, regime by regime
Facial templates and comparison selfies are sensitive data everywhere they are processed. In the European Union we rely on your explicit consent under Article 9(2)(a) of the GDPR. In United States states with a dedicated biometric statute, we rely on your prior written consent. Account, billing and security data rest on the performance of our contract with the photographer, or on our legal obligations.
International transfers
Facial templates are processed and stored by Amazon Web Services in Ireland, inside the European Union. Our other providers host in regions we are in the process of confirming contractually; until each is confirmed, we state it as unconfirmed on the sub-processors page rather than assert a guarantee we have not verified. Where a transfer leaves the European Union, we rely on the European Commission's standard contractual clauses.
How long we keep things
Your comparison selfie is deleted the moment the search has run, whether or not it found anything; a sweeper removes orphaned selfies every fifteen minutes, so at worst one lives about half an hour. Facial templates are kept alongside the event's photographs and are deleted with them, and also as soon as the photographer archives the event. Photographs follow the retention of the plan the photographer bought, plus a seven-day grace period. Download records, administrative audit logs, waiting-list sign-ups and in-app notifications are deleted after twelve months. An account with no sign-in for three years is anonymised: its content is destroyed and its invoices survive under a neutral identity, because accounting law requires them to. Invoices and payment records are kept for the same reason and outlive the deletion of an account. Web performance metrics are deleted after thirty days. Satisfaction feedback has no automatic deletion yet.
Your rights
You may ask for access to your data, correction, erasure, restriction, portability, and you may object to a processing operation. Where we rely on consent, you may withdraw it at any time, and withdrawing it is as easy as giving it. Write to [email protected]. We answer within one month; if a request is complex we will tell you why and how much longer we need. You do not have to go through the photographer — that route exists, but it is never the only one.
Complaining to an authority
If our answer does not satisfy you, you can complain to a supervisory authority without going through us. In the European Union, the supervisory authority of the country where you live, work, or where the problem occurred. In the United States, the attorney general of your state.
Children and young people
Today, uploading a selfie requires ticking a single box that states you are over 18 or have a parent's or guardian's permission. That statement is not verified, and we do not operate a separate parental consent process — we would rather say so than describe a safeguard that does not exist. The age at which a person can consent on their own differs by regime: between 13 and 16 in the European Union depending on the member state. If you believe a child's image is being processed and should not be, write to [email protected] and we will act on it.
Automated matching
Comparing a selfie against an event's photographs is entirely automated. No person looks at your selfie to decide. The result is binary — either photographs are returned to you, or none are. The matching threshold is deliberately strict, and no biometric measurement is ever shown to the photographer or to you.
Security
Access to data is restricted by role and enforced by the database itself, not only by the interface. Files are served through short-lived signed links rather than public addresses. Administrative actions are logged. We deliberately do not describe our measures in more detail here: a security page precise enough to be useful to an attacker is a weakness in itself.
If something goes wrong
We have a procedure for handling a personal data breach. Where a breach is likely to result in a risk to people, we notify the competent supervisory authority within 72 hours of becoming aware of it, and we inform the people concerned directly when the risk to them is high.
Changes to this policy
This policy carries a version number and a date, shown at the foot of the page. Previous versions stay available at a permanent address so you can see what was published when. When a change materially affects a processing operation that relies on your consent, we ask for it again rather than assume the old one still covers it.