Who is responsible
PhotoMea is operated by VIONTA MANAGEMENT CONSULTING FZCO (“PhotoMea”, “we”), FZA Business Park Building A1, Dubai Silicon Oasis, Dubai, United Arab Emirates. This policy covers photomea.com, PhotoMea applications, and related services. Contact privacy@photomea.com about personal data. This is our global privacy policy. Turkey-specific texts address relationships with customers established in Turkey and processing governed by Turkish data protection law. Mandatory local law remains applicable.
Responsibility depends on the activity. PhotoMea is the controller for accounts, payments, security, face matching, and demographic estimation. The Event Owner is generally the controller for the event Content it chooses to upload and for event access settings; PhotoMea processes that Content on its instructions under the Data Processing Agreement.
The Event Owner is responsible for having authority to upload Content, informing people about the event photography and use of PhotoMea, and obtaining any permission required by applicable law.
Data we process
Account data includes name, contact details, user ID, password hash, preferences, and event roles. Event data includes event details and settings, photos and videos, previews, tags, logos, watermarks, permissions, and activity records.
Face data includes a registration selfie, face vectors derived from that selfie and event photos, match records, and estimated age range and gender produced from the selfie. The Biometric Data Policy provides the full details and Consent Statement.
Payment and communication data includes Package, amount, currency, transaction and invoice details, messages, support requests, and feedback. Payment providers process full payment-card details; PhotoMea does not store the full card number.
Technical data includes IP address, approximate location derived from IP, device and browser information, session identifiers, sign-in, upload and download activity, and security or administrator logs. We do not collect GPS or precise device location.
We collect data directly from you, from Event Owners, Photographers and other uploaders, from authentication and payment providers, and automatically when the service is used. Website measurement data is processed as described in the Cookie Policy.
Why we process data
We process data to create and secure accounts; provide event upload, storage, access, sharing, download, support, face matching, and event analytics; process business purchases; prevent fraud and abuse; diagnose faults; communicate about the service; comply with law; and establish, exercise, or defend legal claims.
Face matching, estimated age range, and gender are processed under the single approval described in the Biometric Data Policy. Age and gender results are used only for anonymous, aggregated event statistics, subject to a minimum group size, and are not displayed with Participant names.
Account and transaction information is needed to provide the services you request; without necessary information, we may be unable to open an account, complete a purchase, or provide a requested feature. Face matching and estimates are probabilistic. They are not used by PhotoMea for decisions producing legal or similarly significant effects and must not be used for official verification or high-impact decisions.
Legal bases
Where a legal basis is required, PhotoMea relies on contract to provide requested account and business services; legal obligation for accounting and lawful requests; legitimate interests for security, abuse prevention, diagnostics, legal claims, and cookieless, aggregated measurement of how the website and application are used (described in the Cookie Policy); and consent for measurement that uses cookies, marketing, face matching, and demographic estimation.
Where biometric data is treated as special-category or sensitive data, we rely on explicit consent and the additional conditions described in the Biometric Data Policy. You may withdraw consent at any time; withdrawal does not affect processing already carried out lawfully.
International processing
PhotoMea is established in the United Arab Emirates. Application hosting, photo storage, and face analysis are carried out in the European Union. Providers involved in payment, messaging, delivery, and app distribution may process data in the United States or through global networks. The current providers and locations are listed in the Data Processing Agreement.
International transfers are subject to the safeguards required by applicable law. You may request information about safeguards relevant to your data, including how to obtain a copy where applicable, from privacy@photomea.com.
Retention
We retain data for the periods below. Limited non-biometric records may be retained longer where required by law or necessary to establish, exercise, or defend legal claims. Biometric data remains subject to the earlier destruction requirements in the Biometric Data Policy. An Event Owner may delete Content earlier. Data removed from active systems is deleted or rendered inaccessible through the backup cycle.
| Data | Period |
|---|---|
| Registration selfie and account face vector | Deleted after six months without sign-in |
| Event-photo face vectors | Six months from the event date |
| Events, photos, videos, and match records | Two years from the event date |
| Estimated age range and gender | The related face-data period; earlier on withdrawal |
| Account data | While open and up to 30 days after closure |
| Payment and accounting records | The period required by applicable financial law |
| Consent records | The applicable limitation period |
| Security and access logs | Twelve months |
People in photos who have no account
Uploaded event photos are indexed for face comparison, including faces of people who have no PhotoMea account. The comparison area is isolated to the event; vectors are not linked to account contact details before a Participant is matched and are not used across events. Event-photo vectors are deleted within six months of the event date, subject to earlier destruction requirements in the Biometric Data Policy. A Participant’s consent covers their own data and does not authorize processing of another person’s biometric data.
The Event Owner is responsible for the Content it uploads and for informing people at the event as required by applicable law.
A person without an account may ask PhotoMea to remove a photo, delete the face data derived from it, or exclude it from matching by writing to support@photomea.com. We may request the minimum information reasonably needed to locate the Content and verify the request, and respond within the time required by applicable law.
Security and incidents
We use technical and organizational measures appropriate to the nature and risk of processing. These include encryption in transit and at rest, role-based access, event-level separation, logging, and confidentiality duties.
No system is completely secure. Where a personal data breach requires notice, PhotoMea notifies affected customers, individuals, or authorities within the time required by applicable law.
Your choices and requests
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, withdraw consent, appeal a refusal, and complain to a competent authority. You may manage cookies through cookie settings and withdraw face-matching consent through account settings.
Send a request to privacy@photomea.com. For a photo-removal request, use support@photomea.com and include the event name or code, enough information to locate the photo, the action requested, and a contact address. Do not send identity documents unless we specifically request them.
We may ask for information reasonably necessary to verify identity or authority, may refuse or charge for manifestly unfounded or excessive requests where law allows, and respond within the period required by applicable law. Authorized agents must provide evidence of authority.
Children
A person must be eighteen to open an account. A minor may use PhotoMea only under a parent or legal guardian’s supervision and approval, including that adult’s approval of face matching. Event Owners are responsible for required permissions concerning Content that includes children.
If we learn that a child’s account or face data was processed without valid permission, we delete it without undue delay.
European Economic Area and United Kingdom
If EU or UK data protection law applies, the legal bases described above apply under Article 6 GDPR, and explicit consent for biometric face data is relied on under Article 9(2)(a). You may exercise the rights provided by Articles 15 to 22 and lodge a complaint with the supervisory authority where you live or work. Judicial remedies remain available.
United States
Depending on your state, you may have rights to know, access, correct, delete, or obtain a copy of personal information; to opt out of sale, sharing, or targeted advertising; to limit certain uses of sensitive data; and to appeal a refusal without discrimination. Event Content and face data are not used for advertising or sold. Optional website advertising described in the Cookie Policy may constitute sharing for cross-context behavioral advertising or targeted advertising under applicable state law; the corresponding opt-out rights apply.
Submit requests to privacy@photomea.com. We respond within the period required by applicable law and may verify your identity or an agent’s authority. State-specific biometric notices are in the Biometric Data Policy.
Changes
We may update this policy. The current version and update date appear here. If a change materially expands consent-based processing, we request new consent where required.