Privacy Policy
1. Who we are (data controller)
Photo Community (legal entity, KvK number, registered address — to be completed) is the controller for personal data processed through this platform. Contact: privacy@… (to be completed).
2. What data we process
Account data (name, email, role), photographer profile data, uploaded photographs (which may show identifiable people), album and order metadata, and technical data (IP, device, log data). Payment data is handled by our payment processor (Stripe) and not stored by us.
3. Purposes & legal bases (GDPR/AVG art. 6)
Providing the service and account (performance of a contract); processing payments and unlocks (contract); securing the platform and preventing abuse (legitimate interest); sending service emails (contract/legitimate interest); marketing only with consent. Publishing photos of identifiable people relies on the photographer/organiser obtaining the appropriate consent (portrait rights) — managed via the platform's consent flow.
4. Photographs & portrait rights
Photographers and organisers are responsible for having the right to upload and publish images of the people depicted. The platform provides a consent mechanism; final responsibility rests with the uploader. To be expanded by lawyer.
5. Face search & biometric data (AVG art. 9)
Albums include a “Find my photos” feature that is enabled by default; the photographer can disable it per album (which immediately erases that album’s face data). When enabled, a face-recognition model running in the browser computes a mathematical face descriptor for each face in the uploaded photos. These descriptors are special-category biometric data and are stored, album-scoped and in irreversible vector form (no extra image), in our own EU database (Supabase). They are deleted automatically when the album is deleted or purged, and immediately when the photographer turns the feature off. The lawful basis is explicit consent / a documented legitimate basis obtained by the photographer for the people depicted (art. 9(2)(a)). When a guest uses the feature, their selfie is processed only in their own browser; the resulting descriptor is sent once to find matches and is never stored or shared. You can object or request erasure of your face data via the contact above; we run a Data Protection Impact Assessment (DPIA) for this processing.
6. Sharing & processors
We use processors including Supabase (hosting/database/storage) and Stripe (payments). Data may be processed within the EU/EEA; transfer safeguards to be completed.
7. Retention
Albums and their files are retained per the platform's retention policy (currently up to one year after unlock, then purged) and account data for as long as the account exists. Face descriptors follow the album and are erased on album deletion/purge or when face search is disabled. Exact periods to be confirmed.
8. Your rights
You have the right to access, rectify, erase, restrict, object, and to data portability, and to lodge a complaint with the Autoriteit Persoonsgegevens. Requests via the contact above.
9. Cookies
We use strictly necessary cookies for authentication. Any analytics/marketing cookies require consent. Cookie banner and list to be added.
Last updated: draft — not published.