Privacy Policy
Last updated: 30.06.2026
Summary of how we use your personal data
- PhotoAiD uses your personal data to provide a service or deliver a product.
- Personal data may be shared with payment providers to facilitate payment for the service, and with advertising partners for marketing purposes.
- Where we rely on your consent, e.g. for marketing purposes, you may withdraw that consent at any time.
What does this policy cover?
This policy describes how PhotoAiD S.A. and other companies within the PhotoAiD group (also referred to as "PhotoAiD", "we" or "us") will process your personal data when you use the services, at our websites and mobile applications (the aforementioned devices and services collectively referred to as the "Sites") and physical locations (such as Photo Booths and Photo Kiosks), where you can, among other things, take a photo yourself or print it ("Points").
It also describes your rights regarding the protection of personal data, including the right to object to certain types of data processing by PhotoAiD. Further information on your rights and how to exercise them can be found in the section "Your choices and rights".
Personal data we may collect about you
We collect and process your personal data when you interact with us and our Sites and Points.
- Contact details – email address, first name and surname, and delivery address.
- Service information – order details, including the image captured in the photo you have provided ("Photo"), and the details of your order (e.g. order number, order date, order value, service or product ordered), as well as communications regarding the provision of services, complaints or warranties.
- Financial information – information contained in a sales document, e.g. an invoice, and payment details.
- Marketing information – your marketing preferences, including any consents you have given us.
- Technical information – information about the browser or device you use to access the Sites or a Points, e.g. device type, model, language, operating system, unique identifier (e.g. advertising ID), location, your activity on the Site or at a Point, including tracking your movements on the Site, and the source of your visit to the Site or a Point.
The categories and details of the personal data collected via the Sites and Points may vary (we do not collect all the personal data listed above on every Sites or Points).
We sometimes receive information about you from third parties. In particular: from payment service providers who provide us with information relating to payments for services (such as your full name, card type and expiry date, part of your card number, and transaction number); or from the platforms from which you download our app (the "App"), from your friends in relation to a discount shared with you, or from publicly available websites (e.g. your reviews of our services).
If you upload Photos depicting third parties to the Sites or the Points, we receive the image of those individuals from you. By sending us such Photos, you declare that you hold all the necessary rights to make their image available to us, and to allow us to use the Photos for the purposes set out in this policy, in particular to fulfil the order, and that you have provided these individuals with a copy of this policy. You also declare that our fulfilment of the order using a third party's image complies with applicable law; in particular, you have obtained the consent or authorisation for us to use that person's image for the purposes set out in this policy, in particular to enable us to fulfil the order.
How do we use this information and what is the legal basis for this use?
We will use your personal data solely for the following purposes and on the following legal bases:
- Purpose: We will collect, use and store your personal data for the purpose of entering into and performing a contract to which you are a party, including providing you with services and delivering the products you have ordered, as well as to communicate with you regarding the Sites and Points, orders, complaints and warranties. When providing our services, we use modern technologies such as machine learning or generative artificial intelligence, which assist us in photo processing or in communicating with customers.
- Legal basis: The processing of personal data is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract with you (Article 6(1)(b) of the GDPR).
- Categories of personal data: Contact details, Service information, Financial information, Technical information.
- Purpose: We will collect, use and store your personal data for the purpose of managing our relationship with you, in particular to respond to any enquiries that do not relate to our services.
- Legal basis: We have a legitimate interest in managing our business, providing services to our customers and communicating with them (Article 6(1)(f) of the GDPR).
- Categories of personal data: Contact details, Service information, Technical information.
- Purpose: We will collect and use your personal data to send you personalised marketing communications regarding our relevant products and services or other products and services provided by us, our group entities and carefully selected partners.
- Legal basis: Your consent to marketing communications. Whenever we ask for your consent, we will explain why and how we will use your personal data so that you can give informed consent. Depending on your location, the related data processing may also take place on the basis of a legitimate interest (Article 6(1)(f) of the GDPR). We have a legitimate interest in promoting our services and products to our customers and to those who have consented to marketing communications.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect and use your personal data to send you personalised adverts for our relevant products and services or other products and services provided by us, our group entities and carefully selected partners. In particular, we may display adverts to you on third-party websites (known as remarketing) and analyse your interactions with these adverts.
- Legal basis: Your consent to cookies. Whenever we ask for your consent, we will explain why and how we will use your personal data so that you can give informed consent. Depending on your location, further processing of personal data relating to the use of cookies may also take place on the basis of a legitimate interest (Article 6(1)(f) of the GDPR). We have a legitimate interest in promoting our services and products to our customers and to those who have consented to the use of cookies.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect and analyse your personal data for the purpose of managing the Site, the Point and their operation, including updating them.
- Legal basis: We have a legitimate interest in operating our Sites and Points and in improving their performance (Article 6(1)(f) of the GDPR). If the analysis is based on cookies, the basis for the use of cookies is your consent to cookies. Whenever we ask for your consent, we will explain why and how we will use your personal data so that your consent is informed.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect and analyse your personal data for the purposes of statistical analysis, analytics and internal reporting.
- Legal basis: We have a legitimate interest in verifying the effectiveness of our activities for internal purposes (Article 6(1)(f) of the GDPR). If the analysis relies on cookies, the basis for using cookies is your consent to cookies. Whenever we ask for your consent, we will explain why and how we will use your personal data, so that your consent is informed.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect and analyse your personal data in order to tailor the Site and the Point to users' needs, develop our business and shape our marketing strategy.
- Legal basis: We have a legitimate interest in operating our Sites and improving their performance (Article 6(1)(f) of the GDPR). If the analysis is based on cookies, the basis for the use of cookies is your consent to cookies. Whenever we ask for your consent, we will explain why and how we will use your personal data, so that your consent is informed.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect, analyse and store your personal data for the purpose of developing new products and services and improving or modifying our existing services.
- Legal basis: We have a legitimate interest in managing our business, providing improved services to our customers and developing our products (Article 6(1)(f) of the GDPR). If the analysis is based on cookies, the legal basis for the use of cookies is your consent to cookies. Whenever we ask for your consent, we will explain why and how we will use your personal data, so that your consent is informed.
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect, analyse and store your personal data to facilitate payment for services.
- Legal basis: The processing of your personal data is necessary for the performance of the contract concluded with you (Article 6(1)(b) of the GDPR). We have a legal obligation arising from legislation, including tax and accounting regulations concerning the retention of tax and accounting documents (Article 6(1)(c) of the GDPR).
- Categories of personal data: Contact details, Service information, Financial information.
- Purpose: We will collect, use and store your personal data in order to fulfil our legal obligations and to respond to requests from the relevant authorities.
- Legal basis: We have a legal obligation under applicable legislation, including tax, accounting and consumer protection legislation (e.g. in relation to complaints and guarantees), and data protection legislation (e.g. in relation to responding to requests from data subjects) (Article 6(1)(c) of the GDPR).
- Categories of personal data: Contact details, Service information, Marketing information, Financial information, Technical information.
- Purpose: We will collect, use and store your personal data for the purpose of documenting compliance with applicable regulations and guidelines issued by the relevant authorities, as well as with our internal procedures and policies.
- Legal basis: We have a legitimate interest in complying with the guidelines of public authorities and our internal policies, as well as in demonstrating compliance with legal requirements (Article 6(1)(f) of the GDPR).
- Categories of personal data: Contact details, Service information, Marketing information, Financial information, Technical information.
- Purpose: We will collect, use and store your personal data for the purposes of detecting and preventing fraud, establishing and pursuing claims or defending against claims, and conducting proceedings before public authorities or bodies.
- Legal basis: We have a legitimate interest in preventing and detecting fraud or other breaches, protecting our legal rights and ensuring the security of our processes (Article 6(1)(f) of the GDPR).
- Categories of personal data: Contact details, Service information, Marketing information, Financial information, Technical information.
- Purpose: We will collect, use and store your personal data to ensure security, including cybersecurity, network management and service availability.
- Legal basis: We have a legitimate interest in ensuring the security and continuity of our services (Article 6(1)(f) of the GDPR).
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
- Purpose: We will collect, use and store your personal data to invite you to provide feedback on us and our services, to take part in satisfaction surveys and other market research activities conducted by us and other organisations on our behalf, and to manage these activities.
- Legal basis: Depending on your location and the requirements of local law, the legal basis for this will be your consent for this purpose or our legitimate interests in managing our business and providing services to our customers (Article 6(1)(f) of the GDPR).
- Categories of personal data: Contact details, Service information, Marketing information, Technical information.
There are instances where we have a legitimate interest to use your data. Our legitimate interest will vary depending on what we are using your data for, and we explain above what the interest is and how it relates to the processing operations that we are carrying out. Where we process personal data on the basis of a legitimate interest, then – as required by data protection law – we have carried out a balancing test to document our interests, to consider what the impact of the processing will be on individuals and to determine whether individuals' interests outweigh our interests in the processing taking place. You can obtain more information about this balancing test by using the contact details at the end of this policy.
How do we use cookies and similar technologies?
We may use tools to store information on your devices or to access information already stored on them, such as cookies and other similar technologies (collectively, "cookies").
1. What are cookies?
We use cookies on our Sites and at our Points (for example, when you connect to a Point remotely via a QR code – this gives you access to the Sites).
A cookie is a very small text file that often contains an anonymous, unique identifier. Cookies are created when a user's browser loads a specific web page. The web page sends information to the browser, which then creates a text file. Every time a user returns to the same website, the browser retrieves this file and sends it to the website's server. Further information on the use of cookies can be found here: https://allaboutcookies.org/
We also use other similar technologies (such as web beacons, pixels, tags, plug-ins or, in mobile applications, so-called Software Development Kits (SDKs)), which serve similar purposes to cookies and enable us to monitor and improve our Sites.
When we refer to cookies in this policy, the term also covers these similar technologies.
We use cookies in accordance with applicable legal requirements.
2. What cookies do we use and how long are they stored for?
With regard to the processing of your personal data via cookies, we will use your personal data solely for the following purposes and on the following legal bases:
- Necessary cookies
- Purpose: These cookies are necessary for the basic functionality of the Sites. They are used, for example, to send notifications, save language preferences and cookie choices, improve performance, report errors, update functionality remotely, determine loading times for pages/screens, and to measure aggregate audience figures, ensure the security of the Sites and prevent fraud, as well as to remember your shopping basket. Without these cookies, we cannot provide the services you have requested, including ensuring their security and continuous operation.
- Legal basis: The processing of personal data is necessary for the performance of a contract concluded with you or to take steps at your request prior to entering into a contract with you (Article 6(1)(b) of the GDPR). We have a legitimate interest in protecting our Site and its users from cyber threats, as well as in ensuring the continuity of the Site's operation (Article 6(1)(f) of the GDPR).
- Categories of personal data: Technical information.
- Functional cookies
- Purpose: We may use cookies that are not necessary but enable you to use various useful features on the Sites or at our Points. For example, these cookies collect information about your interaction with our services on the Sites and Points and may be used to remember your preferences (such as your preferred language), interests and how the website is displayed (e.g. font size). We will ask for your consent to use these cookies when you request a particular service.
- Legal basis: Your consent to cookies.
- Categories of personal data: Technical information.
- Analytics cookies
- Purpose: These cookies help us to improve and optimise the quality of the services we provide. They allow us to measure how users interact with the Sites and Points, and we use this information to improve the user experience and performance of the Sites and Points. These cookies are used to collect technical information, such as, the last page or screen visited, the number of pages/screens visited, whether emails have been opened, which elements of our Site or emails have been clicked on, and the time elapsed between clicks.
- Legal basis: Your consent to cookies.
- Categories of personal data: Technical information.
- Advertising cookies
- Purpose: We use these cookies to collect information about your behaviour whilst using the Site and the Points, so that content, adverts and offers are better tailored to you and your interests. They are also used to limit the number of times an advert is displayed, and help measure the effectiveness of advertising campaigns. They also help us display adverts to you on third-party websites (known as remarketing).
- Legal basis: Your consent to cookies.
- Categories of personal data: Technical information.
We store information collected from cookies for the period necessary to fulfil the purpose for which they are processed.
Further information on the specific cookies we use, the purposes for which we use them, and the period for which we store cookies can be found in the Privacy Centre in the Site (or in the App settings).
3. Third parties
Using the Site may result in certain cookies being stored over which we have no control. This may occur when a part of the Site you visit uses third-party analytics tools or tools for marketing automation/management. Please refer to the privacy policy and cookie policy of these services to find out how these third parties use cookies and whether personal data from cookies will be transferred to a third country.
A list of third parties that place cookies in the Site, along with links to their privacy policies and the retention periods for their cookies, can be found in the Privacy Centre in the Site (or in the App settings).
4. How do you manage these technologies?
You can adjust your cookie preferences at any time in the Privacy Centre in the Site (or in the App settings).
You can also opt-out of personalised adverts or adjust your advertising preferences on the Google advertising network by visiting the Google Ads settings page: https://adssettings.google.com. You can opt-out of Google Analytics at any time by adjusting your browser settings accordingly or by using the Google Analytics opt-out browser add-on, available here: https://tools.google.com/dlpage/gaoptout?hl=en
Most web browsers allow you to manage or delete your cookie settings. The methods vary, but you can find information on managing cookies via the following links:
- Google Chrome: https://support.google.com/chrome/answer/95647
- Mozilla Firefox: https://support.mozilla.org/en-US/kb/enhanced-tracking-protection-firefox-desktop
- Apple Safari: https://support.apple.com/en-gb/guide/safari/sfri11471/mac
- Microsoft Edge: https://support.microsoft.com/en-gb/windows/microsoft-edge-browsing-data-and-privacy-bb8174ba-9d73-dcf2-9b4a-c582b4e640dd
How do we share your personal data?
We may share your personal data with the following categories of recipients:
- Companies within our group
- Categories of personal data: All categories of personal data.
- Why: To provide, improve and develop our services.
- External service providers
- Categories of personal data: All categories of personal data.
- Why: We engage other companies and individuals to carry out tasks on our behalf, in particular hosting (including Amazon), the provision of other IT solutions (including Freshworks, Google Ireland Ltd), including process automation, photo processing (including Amazon Rekognition, Canva), applying graphic effects, transforming photos using artificial intelligence models from companies such as OpenAI and Google, delivering parcels, sending traditional post and email, and payment intermediation. Google Ireland Ltd. – a processor – provides services relating to error and fault reporting, the provision of push notifications, analytics and advertising services, performance analysis services and remote functionality updates. We recommend that you familiarise yourself with Google's Privacy Policy: https://policies.google.com/privacy?hl=en-US. We may also share personal data with independent controllers, such as advertising partners like Microsoft or Google, entities providing photo printing (Google and so-called "pick-up points"), electronic payment providers, banks, insurers, advisers (including legal advisers), and entities collecting user feedback about us and our services (e.g. Trustpilot), postal operators.
- The person to whom you are recommending our service
- Categories of personal data: Photo.
- Why: To send a discount to that person along with your Photo – where you have explicitly asked us to do so.
- Public authorities and law enforcement agencies, courts
- Categories of personal data: All categories of personal data.
- Why: To prevent, investigate or report fraud, security incidents or criminal offences, in accordance with applicable law. And also at the request of an authority or court, if we are legally obliged to do so or pursuant to a binding decision or ruling.
- Potential buyer/seller
- Categories of personal data: All categories of personal data.
- Why: In the event of the sale or merger of our business with another business, your personal data will be disclosed to our advisers and the advisers of the potential buyer, and transferred to the new owners of that business.
Where we transfer your personal data
Your personal data may be transferred (including stored) outside the European Economic Area or outside your country of residence, including to a country where different data protection and privacy laws apply. We assure you that this personal data is transferred in accordance with applicable law. Where the country to which we transfer personal data does not provide an adequate level of data protection, we implement appropriate safeguards to protect the transfer of your personal data to that country. These include standard contractual clauses approved by the European Commission (https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en) or other safeguards applicable in specific countries. We may also transfer personal data to countries with an adequate level of personal data protection based on decisions adopted by the competent authorities, such as adequacy decisions adopted by the European Commission.
A list of countries for which the European Commission has issued an adequacy decision can be found here: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/adequacy-decisions_en.
A copy of the relevant mechanism is available for inspection on request at the contact address provided below.
Your choices and rights
You have the following rights:
- Right of access – this allows you to obtain a copy of your personal data.
- Right to rectification – this allows you to correct any inaccurate or incomplete personal data we hold about you.
- Right to erasure – this allows you to ask us to erasure your personal data in certain circumstances.
- Right to restriction of processing – this allows you to ask us to restrict the processing of your personal data in certain circumstances.
- Right to object – this allows you to object to our processing of your personal data on the basis of our legitimate interests (or those of a third party), including processing for direct marketing purposes or profiling for direct marketing purposes – your objection will be taken into account, and we will cease processing your personal data, unless the processing has a legal basis or is necessary for the establishment, exercise or defence of legal claims that may be brought by us or against us.
- Right to data portability – this allows you to ask us to provide you with the personal data you have supplied to us, or to transfer it directly to a third party, provided this is technically feasible.
These rights may be restricted, for example if complying with your request would result in the disclosure of another person's personal data, or if you ask us to delete information that we are required by law to retain or that we have a legitimate interest in retaining.
If you wish to exercise any of these rights, please contact us using the contact details provided below.
In any instance where we rely on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal. However, we may have other legal grounds for processing your personal data for other purposes, such as those set out above.
In some cases, subject to applicable law, we may send you marketing communications without your consent, relying on our legitimate interests. You have an unconditional right to opt-out at any time of direct marketing or profiling carried out by us for direct marketing purposes. You can do this by following the instructions in the communication or by contacting us using the contact details provided below.
If you have any concerns, you may lodge a complaint with us and with the data protection authority in the country where you live, work or where the alleged infringement took place. A list of authorities within the EEA can be found here: https://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm.
For most services, uploading a Photo and providing your email address are mandatory in order to place an order; if you wish us to deliver the product physically, it is also mandatory to provide the recipient's details and the delivery address; if you wish to receive an invoice, it is mandatory to provide the invoicing details. If the relevant details are not provided, we will not be able to fulfil your order or issue an invoice. Providing all other information is optional.
How long we retain your personal data
We retain personal data for as long as we maintain a relationship with the data subjects, and for a certain period after that relationship has ended. We will retain your personal data for no longer than is necessary to fulfil our obligations or achieve the purposes for which the information was collected, or as required by applicable law. If we have entered into a contract with you, your personal data will be retained for the duration of the contract and for an appropriate period after its expiry to protect us against any legal claims.
Where we process personal data for marketing purposes or with your consent, we will process the personal data until you ask us to stop processing it and for a short period thereafter (so that we can comply with your request). We also retain a record of your request not to receive direct marketing or for your personal data not to be processed, so that we can respect this request in future.
We retain Photos for up to 14 days if you have not purchased our service, or for up to 6 months if you have purchased our service or product.
To determine the appropriate retention period, we take into account the amount, nature and sensitivity of the personal data; the potential risk of harm arising from unauthorised use or disclosure; the purposes for which we process the personal data and whether we can achieve those purposes by other means; and applicable legal requirements. Unless otherwise required by applicable law, once the retention period has expired, we will delete personal data from our systems or take appropriate steps to ensure it is properly anonymised.
Changes to this policy
We reserve the right to amend this policy at any time. We will provide you with the new privacy policy when we make significant changes. From time to time, we may also notify you in other ways regarding the processing of your personal data.
Contact us
The controller for your personal data is PhotoAiD.
If you have any questions about this policy or wish to contact us regarding any matter relating to the processing of personal data or privacy, please contact us at privacy@photoaid.com.