Privacy Policy
1. Data Controller
The data controller is Johann Flipo, sole trader (SIREN 107 376 071), 6 rue d'Armaillé, 75017 Paris, France. Contact: contact@fotelya.com. No data protection officer (DPO) has been appointed, as such an appointment is not required for the activity carried out; requests relating to personal data are handled directly by the publisher.
2. Our principle
Fotelya is built around minimization: guests share their photos and videos without an account or registration. We only collect what is strictly necessary for the Service to function. We do not resell any data and do not display any ads. No photo and no message is used to train an AI: neither by Fotelya, nor by our moderation provider (training option disabled).
3. Data processed
- Organizer: email address, event title, date and settings, language, and for the PRO plan the brand logo and colors. Payment data (card, billing identity) is processed by Paddle: we only receive the transaction reference, the plan and the amount.
- Guest: the photos and videos they choose to send and, if they leave one, a written or voice guestbook message with the name they enter. A random identifier, stored in a cookie and in the browser's local storage, lets them remove or edit their own uploads. EXIF geolocation data is removed on upload.
- Upload log: for each content upload, the IP address, the browser used and the timestamp (legal obligation, see section 4).
- Technical and security data: security logs (IP address, country, browser, timestamp), technical error reports in which access links are masked, and aggregated visit counters.
- Audience measurement: Cloudflare Web Analytics, without cookies, and a server-side tool (PostHog, servers located in Frankfurt). Neither tool places a cookie or tracker on your device. Your IP address is not sent to PostHog: it is replaced by an irreversible technical fingerprint, renewed every day, which rules out any tracking from one day to the next. Statistics are aggregated and are never used to build a profile.
- Post-event review (optional): rating, comment and, if you agree to its publication, your first name and city.
- Business prospecting: name, business email address and company of event professionals (venues, planners, suppliers), taken from their public websites.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the Service (album, live wall, download, guestbook, service emails) | Performance of the contract; for the Guest, their choice to send content |
| Security, prevention of abuse and fraud | Legitimate interest |
| Content moderation | Legitimate interest and legal obligation |
| Identification of content contributors (upload log: IP address, browser and timestamp of each upload) | Legal obligation (article 6 of the French LCEN and decree no. 2021-1362) |
| Billing and accounting | Legal obligation |
| Audience measurement and technical error detection | Legitimate interest |
| Fotelya news and offers sent to organizers (one-click unsubscribe in every message) | Consent or, for our customers, legitimate interest (article L34-5 of the French Postal and Electronic Communications Code) |
| Publication of a review | Consent |
| Prospecting event professionals | Legitimate interest; every message lets you object |
5. Recipients and processors
Your data is accessible to the publisher and, for an event's content, to its Organizer. We use the processors below, bound by a data processing agreement (article 28 GDPR). Several of them are US companies: we say so, together with the place of processing and the mechanism covering each transfer.
| Provider | Role and data | Place of processing | Safeguards |
|---|---|---|---|
| Cloudflare, Inc. (United States) | Application hosting; storage of photos, videos and voice messages; protection against attacks; cookieless audience measurement; routing of emails received at our addresses | Photos, videos and voice messages stored under European Union jurisdiction; pages and requests served by Cloudflare's global network, which also keeps technical copies of a gallery's content list for up to fifteen minutes | EU-US Data Privacy Framework; standard contractual clauses |
| Neon, LLC, part of Databricks, Inc. (United States) | Database: organizer emails, settings, written messages, logs | Frankfurt (Germany) | EU-US Data Privacy Framework; data processing agreement |
| Mistral AI (France) | Automatic moderation of photos and written messages | European Union | Data processing agreement; no transfer outside the Union |
| Plus Five Five, Inc., "Resend" service (United States) | Sending emails: recipient address and message content | United States | EU-US Data Privacy Framework; standard contractual clauses |
| PostHog, Inc. (United States) | Server-side audience measurement: daily fingerprint, page views, technical events | Frankfurt (Germany) | EU-US Data Privacy Framework; data processing agreement |
| Functional Software, Inc., "Sentry" service (United States) | Technical error detection: error message, browser, page address with access links masked | European Union (Germany) | EU-US Data Privacy Framework; data processing agreement |
| Google LLC (United States) | The publisher's email inbox (Gmail): internal email alerts (sale, refund, content report, withdrawal), which state the event code, never its title | United States and Google's global network | EU-US Data Privacy Framework |
| Discord, Inc. (United States) | Internal alerts to the publisher: amount, plan and order reference when a sale occurs; security alerts without personal data | United States | EU-US Data Privacy Framework |
| Hetzner Online GmbH (Germany) | Off-site backups, encrypted before they are sent | Helsinki (Finland) | European Union; encryption |
| Contabo GmbH (Germany) | Encrypted backup copies of the database | European Union | European Union; encryption |
Paddle.com Market Limited (United Kingdom), our official reseller (Merchant of Record), sells the paid plans in its own name: it processes your payment data as an independent controller, under its own privacy policy. The United Kingdom benefits from an adequacy decision of the European Commission.
The publisher also keeps backup copies on a server it operates in France. No data is sold or shared for advertising purposes. Any new processor is added to this table before it goes into service.
AI-powered automated moderation. When the organizer enables it (three-level setting, can be turned off), uploaded photos and written messages are automatically analyzed by Mistral AI (France, processing within the European Union) to detect clearly inappropriate content (explicit nudity, violence, etc.). Videos are not analyzed automatically. This analysis never makes a final decision on its own: the organizer keeps control and the final say (approval, restoration or manual removal). No photo and no message is used to train an AI: neither by Fotelya, nor by our moderation provider (training option disabled).
6. Transfers outside the European Union
Photos, videos and voice messages are stored under European Union jurisdiction, the database is hosted in Frankfurt (Germany) and automatic moderation takes place within the European Union. Some data is nevertheless processed outside the Union or by US companies, in the cases listed in section 5: pages and requests served by Cloudflare's global network, emails sent by Resend (United States), internal alerts by email (Google) and through Discord.
These transfers rely on the European Commission's adequacy decision of July 10, 2023 on the EU-US Data Privacy Framework, in which each of these companies participates (official list: dataprivacyframework.gov), supplemented where the provider offers them by the European Commission's standard contractual clauses. A US company may receive access requests from US authorities, including for data stored in the Union: encryption at rest and in transit, data minimization and automatic deletion limit their reach. The United Kingdom (Paddle) benefits from an adequacy decision. You can obtain a copy of the applicable safeguards by writing to contact@fotelya.com.
7. Retention periods
- Event media and data (photos, videos, guestbook, settings): deleted automatically when the plan expires, set at least 30 days after the event date for the free plan, 6 months for the Event plan, 12 months for the Premium plan and 3 months for an event created with the PRO plan. A gallery moved to the trash by its organizer can be restored for 7 days, then it is deleted.
- ZIP archives prepared for download: deleted 7 days after they are prepared.
- Billing data: kept for the legal period of ten (10) years (accounting obligations).
- Upload log (identification of contributors): the IP address, browser and timestamp of each content upload by a guest are kept for twelve (12) months (article 6 of the French LCEN and decree no. 2021-1362), including after the event and its media are deleted. This log contains no media; it is only consulted in response to a request from judicial authorities, then deleted automatically.
- Log of access link requests (email address): 90 days.
- Visit data (truncated IP address or daily fingerprint): 7 to 14 days; visit counters are only kept in aggregated form.
- Plan change log (IP address, country, browser): twelve (12) months.
- Commercial email sending history: three (3) years.
- Error reports and audience measurement: deleted according to the retention period of our subscription with Sentry and with PostHog.
- Unsubscribe preferences and addresses blocked for abuse: as long as needed to respect your choice or prevent repeat abuse.
- Published reviews: until you withdraw your consent.
- Business prospecting: three (3) years after the last contact, or until you object.
- Encrypted backups: for disaster recovery purposes, encrypted backups are stored separately; data deleted from the platform may remain there for up to twenty-four (24) months at most (automatic rotation: weekly, monthly and one yearly archive), before being permanently overwritten. These backups are never accessed except for an emergency restore.
8. Security
Photos, videos and the database are encrypted at rest (AES-256) by our hosting providers, and all connections are encrypted in transit (TLS). Access is through time-limited signed links and, if the organizer enables it, a code (PIN), on non-public galleries with non-enumerable identifiers. EXIF location metadata is removed. Administrative access is protected by Cloudflare Access authentication followed by a password, and access links are masked in error reports.
9. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, objection, restriction, portability, the right to withdraw your consent at any time, and to set directives regarding the fate of your data after your death. Any identifiable person in media has image rights and may request its removal. To exercise your rights: contact@fotelya.com. We respond within one month.
10. Complaint
You may lodge a complaint with the CNIL (French data protection authority, cnil.fr) or with the supervisory authority of your country of residence.
11. Minors
The Service is not intended for people under 15 without the consent of a parent or legal guardian. Event photos may show children: their image is personal data, and their parents' consent is required before any sharing (see the Terms and Conditions). A parent may at any time ask for a photo of their child to be removed, from the organizer or directly at contact@fotelya.com; we remove it as quickly as possible. We delete any data of a minor brought to our attention without such agreement.
12. Residents outside the European Union
We apply a GDPR-inspired standard of protection worldwide. Specific rights may apply depending on your place of residence:
- California (CCPA/CPRA): rights of access, deletion and objection to the “sale” of personal data. Fotelya does not sell any data.
- Brazil (LGPD): equivalent rights of access, correction and deletion.
- Other jurisdictions: contact us to exercise your local rights.
13. Cookies
The use of cookies is detailed in our Cookie Policy. No advertising trackers are used.
14. Online invitations
Fotelya also offers online invitations, which guests answer from a web page. The following rules apply to this service.
- Data controller: the same as for the rest of the Service, Johann Flipo, sole trader (see section 1).
- Data processed: for each reply, the name of the person replying, whether they will attend, the moments selected, the names and ages of the people in their household, any dietary requirement or allergy, and a message. A dietary requirement or allergy may be health data: entering it is optional. Guests' email addresses are not collected. For the organizers of the invitation: their email address.
- Legal basis: for attendance, the moments selected, the household and the message, replying to the invitation at the guest's request. For dietary requirements or allergies, the guest's explicit consent (Article 9(2)(a) GDPR), given by ticking a dedicated box, for themselves and for the members of their household they add. If the box is not ticked, no dietary requirement or allergy is recorded. The guest can withdraw their consent by writing to contact@fotelya.com.
- Recipients: replies are shared only with the organizers of the invitation. Dietary requirements and allergies are never sent by email: they are only visible in the organizer space.
- Hosting: in the European Union, with Cloudflare, the database and files being stored under European Union jurisdiction. Emails are sent through Resend.
- Retention: replies are automatically deleted 90 days after the date of the event.
- Emails to organizers: a summary of replies (at most one per day), a report after the reply deadline and an update the day before the event. They can be turned off in the organizer space.
15. Changes and contact
This policy may evolve. The applicable version is the one published on this page. For any questions regarding your data: contact@fotelya.com.