← Back

Privacy Policy

Compliant with GDPR (EU 2016/679) and the French "Informatique et Libertés" law. Version of September 21, 2026.
The essentials in plain terms: no account for guests, no ads, no data resale, photos and videos stored in the European Union, database in Frankfurt, automatic deletion after the event. Our processors are named in section 5, with their country and the safeguards covering each transfer. A privacy-by-design approach and data minimization.

1. Data Controller

The data controller is Johann Flipo, sole trader (SIREN 107 376 071), 6 rue d'Armaillé, 75017 Paris, France. Contact: contact@fotelya.com. No data protection officer (DPO) has been appointed, as such an appointment is not required for the activity carried out; requests relating to personal data are handled directly by the publisher.

2. Our principle

Fotelya is built around minimization: guests share their photos and videos without an account or registration. We only collect what is strictly necessary for the Service to function. We do not resell any data and do not display any ads. No photo and no message is used to train an AI: neither by Fotelya, nor by our moderation provider (training option disabled).

3. Data processed

4. Purposes and legal bases

PurposeLegal basis
Providing the Service (album, live wall, download, guestbook, service emails)Performance of the contract; for the Guest, their choice to send content
Security, prevention of abuse and fraudLegitimate interest
Content moderationLegitimate interest and legal obligation
Identification of content contributors (upload log: IP address, browser and timestamp of each upload)Legal obligation (article 6 of the French LCEN and decree no. 2021-1362)
Billing and accountingLegal obligation
Audience measurement and technical error detectionLegitimate interest
Fotelya news and offers sent to organizers (one-click unsubscribe in every message)Consent or, for our customers, legitimate interest (article L34-5 of the French Postal and Electronic Communications Code)
Publication of a reviewConsent
Prospecting event professionalsLegitimate interest; every message lets you object

5. Recipients and processors

Your data is accessible to the publisher and, for an event's content, to its Organizer. We use the processors below, bound by a data processing agreement (article 28 GDPR). Several of them are US companies: we say so, together with the place of processing and the mechanism covering each transfer.

ProviderRole and dataPlace of processingSafeguards
Cloudflare, Inc. (United States)Application hosting; storage of photos, videos and voice messages; protection against attacks; cookieless audience measurement; routing of emails received at our addressesPhotos, videos and voice messages stored under European Union jurisdiction; pages and requests served by Cloudflare's global network, which also keeps technical copies of a gallery's content list for up to fifteen minutesEU-US Data Privacy Framework; standard contractual clauses
Neon, LLC, part of Databricks, Inc. (United States)Database: organizer emails, settings, written messages, logsFrankfurt (Germany)EU-US Data Privacy Framework; data processing agreement
Mistral AI (France)Automatic moderation of photos and written messagesEuropean UnionData processing agreement; no transfer outside the Union
Plus Five Five, Inc., "Resend" service (United States)Sending emails: recipient address and message contentUnited StatesEU-US Data Privacy Framework; standard contractual clauses
PostHog, Inc. (United States)Server-side audience measurement: daily fingerprint, page views, technical eventsFrankfurt (Germany)EU-US Data Privacy Framework; data processing agreement
Functional Software, Inc., "Sentry" service (United States)Technical error detection: error message, browser, page address with access links maskedEuropean Union (Germany)EU-US Data Privacy Framework; data processing agreement
Google LLC (United States)The publisher's email inbox (Gmail): internal email alerts (sale, refund, content report, withdrawal), which state the event code, never its titleUnited States and Google's global networkEU-US Data Privacy Framework
Discord, Inc. (United States)Internal alerts to the publisher: amount, plan and order reference when a sale occurs; security alerts without personal dataUnited StatesEU-US Data Privacy Framework
Hetzner Online GmbH (Germany)Off-site backups, encrypted before they are sentHelsinki (Finland)European Union; encryption
Contabo GmbH (Germany)Encrypted backup copies of the databaseEuropean UnionEuropean Union; encryption

Paddle.com Market Limited (United Kingdom), our official reseller (Merchant of Record), sells the paid plans in its own name: it processes your payment data as an independent controller, under its own privacy policy. The United Kingdom benefits from an adequacy decision of the European Commission.

The publisher also keeps backup copies on a server it operates in France. No data is sold or shared for advertising purposes. Any new processor is added to this table before it goes into service.

AI-powered automated moderation. When the organizer enables it (three-level setting, can be turned off), uploaded photos and written messages are automatically analyzed by Mistral AI (France, processing within the European Union) to detect clearly inappropriate content (explicit nudity, violence, etc.). Videos are not analyzed automatically. This analysis never makes a final decision on its own: the organizer keeps control and the final say (approval, restoration or manual removal). No photo and no message is used to train an AI: neither by Fotelya, nor by our moderation provider (training option disabled).

6. Transfers outside the European Union

Photos, videos and voice messages are stored under European Union jurisdiction, the database is hosted in Frankfurt (Germany) and automatic moderation takes place within the European Union. Some data is nevertheless processed outside the Union or by US companies, in the cases listed in section 5: pages and requests served by Cloudflare's global network, emails sent by Resend (United States), internal alerts by email (Google) and through Discord.

These transfers rely on the European Commission's adequacy decision of July 10, 2023 on the EU-US Data Privacy Framework, in which each of these companies participates (official list: dataprivacyframework.gov), supplemented where the provider offers them by the European Commission's standard contractual clauses. A US company may receive access requests from US authorities, including for data stored in the Union: encryption at rest and in transit, data minimization and automatic deletion limit their reach. The United Kingdom (Paddle) benefits from an adequacy decision. You can obtain a copy of the applicable safeguards by writing to contact@fotelya.com.

7. Retention periods

8. Security

Photos, videos and the database are encrypted at rest (AES-256) by our hosting providers, and all connections are encrypted in transit (TLS). Access is through time-limited signed links and, if the organizer enables it, a code (PIN), on non-public galleries with non-enumerable identifiers. EXIF location metadata is removed. Administrative access is protected by Cloudflare Access authentication followed by a password, and access links are masked in error reports.

9. Your rights

In accordance with the GDPR, you have the rights of access, rectification, erasure, objection, restriction, portability, the right to withdraw your consent at any time, and to set directives regarding the fate of your data after your death. Any identifiable person in media has image rights and may request its removal. To exercise your rights: contact@fotelya.com. We respond within one month.

10. Complaint

You may lodge a complaint with the CNIL (French data protection authority, cnil.fr) or with the supervisory authority of your country of residence.

11. Minors

The Service is not intended for people under 15 without the consent of a parent or legal guardian. Event photos may show children: their image is personal data, and their parents' consent is required before any sharing (see the Terms and Conditions). A parent may at any time ask for a photo of their child to be removed, from the organizer or directly at contact@fotelya.com; we remove it as quickly as possible. We delete any data of a minor brought to our attention without such agreement.

12. Residents outside the European Union

We apply a GDPR-inspired standard of protection worldwide. Specific rights may apply depending on your place of residence:

13. Cookies

The use of cookies is detailed in our Cookie Policy. No advertising trackers are used.

14. Online invitations

Fotelya also offers online invitations, which guests answer from a web page. The following rules apply to this service.

15. Changes and contact

This policy may evolve. The applicable version is the one published on this page. For any questions regarding your data: contact@fotelya.com.