Privacy Policy

11 October 2026

This policy explains what personal data we process when you use the Fotomenti service, for what purposes, for how long, with whom we share it and what rights you have. We process it in accordance with Regulation (EU) 2016/679 (GDPR), Slovak Act No. 18/2018 Coll. on personal data protection and, where applicable, US state laws.

1. Controller

The controller of personal data is INTELLOPE, s.r.o., Kutuzovova 17, 831 03 Bratislava – mestská časť Nové Mesto, Slovak Republic, company ID (IČO): 51047021, registered in the Commercial Register of the Municipal Court Bratislava III.

For data protection matters, you can contact us at [email protected].

2. Our role: controller and processor

As controller, we process the data of customers and organisers (accounts, orders, payments, invoicing), guest account data, marketing consents and data relating to visits to our website.

For photos, videos and guest names uploaded to an event, the event organiser is the controller. The organiser decides why the content is collected, who has access to it and what happens to it. For this data, INTELLOPE acts as a processor under Article 28 GDPR, processing the content only on the organiser’s instructions and solely to provide the service.

If you are a guest and have questions about your photos and videos in an event, or wish to exercise your rights, please contact the organiser first. If you contact us directly, we will pass your request on to the organiser without undue delay or help them respond to it.

3. What data we process

Customer account and billing data: name, email, phone, company name, address, company ID, VAT ID, country.

Order and payment records: order details, amounts, payment status and invoices. Card payments are handled by Stripe; we do not store card numbers.

Event content: photos, videos and their metadata (e.g. date and time of capture, device type and, if stored in the file, location), as well as the name a guest enters when uploading.

Guest account data: first name, last name, email and a hashed password; any marketing consent.

Technical data: IP address, browser and device information, sign-in and security logs, statistics on visits via QR code or link, which we store with an anonymised (hashed) visitor identifier, and strictly necessary cookies.

4. Purposes and legal bases

Performance of a contract and pre-contractual steps (Art. 6(1)(b) GDPR): creating and managing accounts, signing in, creating events, uploading and making content available, processing orders, communicating with customers and handling complaints.

Legal obligation (Art. 6(1)(c) GDPR): keeping accounting and tax records, responding to requests from public authorities and handling notices of illegal content.

Legitimate interest (Art. 6(1)(f) GDPR): securing the service and protecting it from abuse, troubleshooting, aggregate usage statistics, and establishing, exercising or defending legal claims.

Consent (Art. 6(1)(a) GDPR): sending marketing emails. Consent is voluntary and can be withdrawn at any time via the link in the email or by writing to [email protected], without affecting the lawfulness of processing before withdrawal.

5. Event content and guest names

We process photos, videos and guest names only as needed to run the event: storing them, generating previews, sorting them into the guest’s folder and making them available to the organiser and, depending on the organiser’s settings, to other guests.

We do not use the content for our own marketing, we do not sell it, and we do not use it to train artificial intelligence models or for biometric identification.

The organiser is responsible for having an appropriate legal basis for collecting and further using the content and for informing guests appropriately.

6. Guest accounts and marketing consent

A guest account is optional and lets guests see their own uploads. Passwords are stored only in hashed form, and a sign-in session lasts no more than 48 hours.

If a guest gives optional marketing consent when registering, we may send them information about Fotomenti. Declining consent does not affect use of the service.

7. Retention periods

Event content: for the period chosen in the package (7 days to 12 months after the end of the event; with credit, 1 month, extendable), after which it is deleted automatically and irreversibly. The event record and aggregate statistics may be retained.

Organiser and guest accounts: until the account is closed or you request deletion.

Invoices and accounting records: 10 years under Slovak accounting law.

Marketing data: until consent is withdrawn. Technical and security logs: for as long as necessary to protect the service, usually a few months.

8. Recipients and processors

Hetzner Online GmbH (Germany) – servers and object storage in data centres in Germany and the EU, where service data, including event content, is stored.

Cloudflare, Inc. – content delivery network (CDN), DNS and security protection; this may involve data transfers to the USA.

Stripe (Stripe Payments Europe, Ltd., Ireland) – payment processing. For payments, Stripe also acts as an independent controller under its own privacy policy.

Email delivery provider (SMTP) – sending verification codes, confirmations, invoices and notifications.

Unsplash – illustrative images on the website are loaded from images.unsplash.com, which receives the visitor’s IP address in the process.

We may also disclose data to public authorities where required by law and to our advisers (e.g. our accountant) to the extent strictly necessary. Event content is accessible to the organiser, co-organisers and, depending on the settings, other guests of the event.

9. Transfers outside the EU

We primarily store data in the EU. Using Cloudflare’s services may involve transferring data to the USA. Such transfers are safeguarded by the EU-U.S. Data Privacy Framework or by standard contractual clauses approved by the European Commission.

10. Data security

We use appropriate technical and organisational measures, in particular encrypted connections (HTTPS), access restricted to authorised persons, password hashing and anonymised identifiers in statistics.

No system is completely secure, however. In the event of a personal data breach, we will give notifications as required by law.

11. Your rights

You have the right to access your data and to have it rectified or erased, to restrict its processing and to data portability, as well as the right to object to processing based on legitimate interest.

Where processing is based on consent, you may withdraw it at any time.

You can exercise your rights by emailing [email protected]. We respond within one month; in justified cases this period may be extended. We may ask you to verify your identity before acting on your request.

12. Complaints to the supervisory authority

If you believe that the processing of your data breaches the law, you may lodge a complaint with the supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava, www.dataprotection.gov.sk. You may also contact the supervisory authority in your country of residence.

13. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.

14. Children

The service is not directed to children under 16, and we do not knowingly collect their personal data. If we learn that we have collected such data, we will delete it.

15. Information for US residents

This section supplements this policy for residents of California (CCPA as amended by the CPRA) and other US states with similar privacy laws.

Categories of personal information collected: identifiers (name, email, IP address), commercial information (orders and payments), internet activity information (technical data and statistics), audio-visual information (photos and videos) and professional information (company). Sources, purposes and recipients are described in the sections above.

We do not sell personal information and do not share it for cross-context behavioural advertising.

Depending on your state of residence, you have the right to know what personal information we collect about you, to request its deletion and correction, and the right not to be discriminated against for exercising your rights.

You can exercise your rights by emailing [email protected]. We will verify your identity before acting on a request; an authorised agent may also submit a request on your behalf.

16. Cookies

We use only strictly necessary cookies required for the service to work, and no advertising or analytics trackers. For details, see our Cookie Policy.

17. Changes and contact

We may update this policy. The current version is always published at fotomenti.com with the date of the last update, and we will inform you of material changes.

If you have any questions, contact us at [email protected].

Privacy Policy · Fotomenti