Privacy Policy
Effective Date: 2025-01-01 | Version: 1.0.0
For Event Participants
Quick summary of how we handle your photos
✓What We Collect
- • Your selfie/photo
- • Phone number (for magic link only)
- • Basic device info
✓How We Use It
- • AI transforms your photo into fun styles
- • Display on event gallery/wall
- • Allow you to download
✓How Long We Keep It
- • 30 days after the event ends
- • Then automatically deleted
- • Never used to train AI
✓Your Rights
- • Request deletion anytime
- • Get a copy of your data
- • Contact: barakkadabra@gmail.com
The event organizer (company hosting the event) is responsible for informing you about photo collection. See full details below.
1. Data Controller Information
Golden Brown AI Technologies Ltd.
Email: barakkadabra@gmail.com
Data Protection Officer: barakkadabra@gmail.com
2. Data We Collect
Account Data
- Email address
- Full name
- Phone number (optional)
- Company name
- Timezone preference
Photo Data
- Original uploaded images
- AI-transformed images
- Thumbnails for gallery display
- Framed versions (Polaroid-style)
- Photo metadata (timestamp, style used)
Event Data
- Event name, date, duration
- Event settings and preferences
- Magic links and access codes
- Usage statistics (photo counts, approvals)
Usage Data
- IP address
- Device type and browser
- Pages visited and features used
- Session duration
Payment Data
Payment information is processed by our payment provider and is not stored on our servers. We only receive confirmation of successful payments.
3. Special Category Data (Biometric)
IMPORTANT: GDPR Article 9 / BIPA Disclosure
Photos containing human faces may constitute biometric data under GDPR (Article 9) and the Illinois Biometric Information Privacy Act (BIPA).
How we process facial images:
- We process photos using AI for artistic style transformation ONLY
- We do NOT perform facial recognition for identification purposes
- We do NOT create biometric templates or face prints
- We do NOT use your photos to train our AI models
- Photos are processed by Google Gemini AI for transformation only
Legal Basis: Explicit Consent
We process facial images based on your explicit consent, which you provide when agreeing to our Terms of Service and uploading photos to the platform.
4. Legal Basis for Processing
| Purpose | Legal Basis |
|---|---|
| Service delivery | Contract performance |
| Photo transformation | Contract + Explicit consent |
| Facial image processing | Explicit consent (GDPR Art. 9) |
| Security & fraud prevention | Legitimate interest |
| Marketing emails | Consent |
| Analytics & improvement | Legitimate interest |
5. Data Sharing
We share your data with the following third parties:
- Google Cloud / Firebase - Cloud storage, authentication, database hosting
- Google Gemini AI - Photo transformation processing
- Payment Provider - Payment processing (we do not store card details)
We DO NOT sell your personal data to third parties.
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Event photos | 30 days after event ends |
| Event data | 30 days after event ends |
| Account data | Until account deletion |
| Usage logs | 90 days |
| Backups | 30 days after main deletion |
After the retention period, data is automatically and permanently deleted from our systems.
7. Your Rights
Under GDPR, CCPA, and other privacy laws, you have the following rights:
- 1.Right to Access
Request a copy of all personal data we hold about you.
- 2.Right to Rectification
Request correction of inaccurate personal data.
- 3.Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data.
- 4.Right to Data Portability
Receive your data in a machine-readable format.
- 5.Right to Object
Object to processing based on legitimate interest.
- 6.Right to Withdraw Consent
Withdraw consent at any time for consent-based processing.
How to Exercise Your Rights:
Email us at barakkadabra@gmail.com. We will respond within 30 days.
8. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the CCPA:
- Right to know what personal information we collect
- Right to request deletion of your personal information
- Right to opt-out of the sale of personal information
- Right to non-discrimination for exercising your rights
We do not sell personal information. Therefore, we do not offer an opt-out for sale of data.
9. International Data Transfers
Your data may be processed in the United States through our cloud providers (Google Cloud). We ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Google Cloud compliance with EU-US Data Privacy Framework
- Adequacy decisions where applicable
10. Cookies
We use cookies for authentication and functionality. For detailed information, please see our Cookie Policy.
View Cookie Policy →11. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children.
Companies hosting events are responsible for ensuring that event participants meet minimum age requirements.
12. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.3)
- Encryption at rest for stored data
- Role-based access controls
- Firebase security rules for database access
- Security monitoring and logging
- Regular security audits
13. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours
- Inform affected users without undue delay if there is a high risk
- Document the breach and remediation steps
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through the Service at least 30 days before they take effect.
15. Contact & Complaints
Questions about this Privacy Policy?
Email: barakkadabra@gmail.com
Complaints:
You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have violated your privacy rights.