Legal
Privacy Policy
Only the German version is legally binding. Switch the site language to Deutsch to read it.
1. Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Matthias Anderer GmbH
Abt-Kaspar-Str. 19, 83607 Holzkirchen, Germany
Managing Director: Matthias Anderer
Email: privacy@snapories.com · Phone: +49 151 22837719
Amtsgericht München HRB 224848 · VAT ID DE305934264
For any data-protection question and to exercise your rights: privacy@snapories.com.
A data protection officer has not been appointed; on our assessment the conditions of § 38 of the German Federal Data Protection Act (BDSG) are not met. Should that change, we will publish the contact details here.
2. What we are responsible for — and what the Organiser is
Snapories is always used within an event that someone has booked. Who is the controller depends on who books:
| Case | Who is controller for the event content? | Our role |
|---|---|---|
| Private event (wedding, birthday, family celebration) booked by a private individual | The booking individual is, for their own use, as a rule covered by the household exemption (Art. 2(2)(c) GDPR) and therefore not an addressee of the GDPR. | We are an independent controller (Art. 4(7) GDPR) for the processing we carry out. |
| Business event (company party, trade fair, festival, brand activation) booked by a business, authority or association | The booking organisation. | To that extent we are a processor under Art. 28 GDPR; the Data Processing Agreement applies. |
Irrespective of this, we are always an independent controller for: contract performance and billing, operational and IT security, abuse prevention, aggregated usage figures without personal reference, and compliance with legal obligations.
For the guest app we also have a direct relationship with you as a guest: you use the app on your own initiative; the legal basis in that respect is Art. 6(1)(b) GDPR (use relationship).
3. The six surfaces at a glance
Snapories consists of six separate websites/applications. They are on their own domains and share no browser storage:
| Surface | Domain | For whom |
|---|---|---|
| Marketing website | snapories.com | all visitors |
| Guest app | app.snapories.com | guests of an event |
| Organiser dashboard | host.snapories.com | the booking person |
| Partner page | partners.snapories.com | information about co-branding |
| Referral page | refer.snapories.com | information about the referral programme |
| Internal console | admin.snapories.com | our staff only |
4. Marketing website (snapories.com)
4.1 Server log data. When you access the site, technically necessary data is processed: IP address, date and time, requested resource, status code, volume transferred, referrer, user agent. Purpose: delivery, stability, IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning offering). Storage: short-term, within our hosting provider's operational logs.
4.2 No audience measurement, no advertising. We use no analytics, tracking or advertising services, no external fonts, no social-media plugins and no embedded third-party content. The pages load files exclusively from our own servers.
4.3 Booking form. For a booking we process name, email address, billing address and country, event name and period, the chosen guest count and quotas, and any discount code. Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for invoicing and tax data additionally Art. 6(1)(c) GDPR (§ 14 UStG, § 147 AO).
4.4 Contacting us. If you write to us, we process your details in order to reply. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete the correspondence once it is no longer needed and no retention obligation applies.
5. Guest app (app.snapories.com)
5.1 Identity without an account
You do not create an account. So that your images and your film roll stay attached to you, our server issues you a signed access pass. That pass lives in three places: in your browser's local storage, in a cookie we set (spr_id), and — for the current call — in a short-lived second entry.
We expressly do not use device fingerprinting. A method previously used to recognise your device by technical characteristics has been removed entirely: it could confuse two identical devices and was not justifiable under data protection law. A device without a valid pass is a new, unknown person to us.
Legal basis: Art. 6(1)(b) GDPR. Setting the pass is strictly necessary and therefore requires no consent under § 25(2) no. 2 TDDDG.
5.2 Your name
The name entered when joining is freely chosen. It is shown to other participants of that event where the Organiser has enabled it. Legal basis: Art. 6(1)(b) GDPR.
5.3 Photos and images
We process the images you take, technically derived versions (thumbnails) and metadata (time, dimensions, attribution to you and to the event). Purpose: providing the event gallery. Legal basis: Art. 6(1)(b) GDPR towards you; with respect to other persons depicted, Art. 6(1)(f) GDPR (legitimate interest of the participants in jointly documenting an occasion within a closed group).
Persons depicted who do not use the app have the rights under clause 13 — in particular the right to object under Art. 21 GDPR. In practice there are two routes: the Organiser can block an individual image immediately, and we delete images on request. There is no automatic face recognition, no automatic obscuring and no comparison against a reference image.
No biometric data. Snapories does not create face templates or face vectors and performs no biometric matching. We do not recognise anyone by their face, do not compare images against a reference image and cannot tell from an image who a person is. A feature once planned for blurring one's own face was cut before launch and is not present in the system.
What the AI analysis does describe. Where an image is analysed for the AI photobooth (clause 6), the analysis produces a short description of each person in the foreground — including their apparent skin tone and apparent ethnic origin — so that the generated image preserves each person's likeness instead of replacing it with someone else's. That is information of a special category within the meaning of Art. 9 GDPR, and we name it here rather than claim it does not arise. It is used for that one purpose only: we do not use it to classify, profile, segment, score or recognise anyone, and it influences nothing in the service beyond the image being generated. It is never written to our database. For a generation it is carried, encrypted, in the session token your app holds for the duration of that session; for the automatic check under clause 6.1a it is discarded as soon as the yes/no answer has been derived from it. Details of the transfer, the legal basis and the retention at the AI provider: clause 6.
5.4 Quotas and sharing
We count how many shots and credits you have used and whether an image has been shared. These counters are necessary for operation (quota management) and feed aggregated, non-personal statistics. Legal basis: Art. 6(1)(b) and (f) GDPR.
5.5 Access to the gallery
An event's gallery is reachable via the seven-character, random join code. The code is practically unguessable but is not a login: anyone who knows it can see the event's released images. We point this out so that you can judge who can see your images.
That access exists only during the event period. When the event ends the gallery can no longer be reached by guests; the Organiser can then make the images available through a time-limited share link (clause 14).
5.6 Personal recovery link
Via the "Save your photos" function you create a link that contains your identifier. Whoever holds the link gains access to your images and quotas. Treat it like a password. The link is valid for up to 400 days and can only be used to adopt the identity, not as a general access key.
6. AI photobooth and automatic image check — transfer to the AI provider
6.1 What happens in the photobooth. The photobooth has no camera of its own. You take your pictures with the one camera in the app; you then pick one of your own pictures that is already in the gallery and describe what you would like done with it. That picture, together with your text input, is transmitted to the AI provider Google (Gemini API, generativelanguage.googleapis.com). There, in several steps, the number of people depicted is determined, costume suggestions are generated and finally the result image is created. We store the result as an additional image of your event.
Your original picture is neither changed nor replaced — it stays in the gallery exactly as you took it. If you apply the AI to the same picture twice, you get two result images.
For the duration of a generation we make a working copy of the picture you picked, in the event's data region. Nothing displays it; it exists so that a picture we decline as unsuitable can be dropped without touching your photo in the gallery. If your picture is declined, that copy is deleted immediately. Otherwise it belongs to the event's data and is deleted with it; you can request its deletion at any time (clause 13).
6.1a Automatic check of every uploaded picture. So that the app knows on which pictures it can offer you the AI function at all, every picture you upload is checked automatically — not only the ones you later choose to use. This happens without any action on your part, immediately after upload, and for this the picture is transmitted to the same AI provider under the same conditions as clause 6.1 (Google, Gemini API) — scaled down to a maximum edge length of 1 280 pixels wherever our software can re-encode it, and otherwise transmitted as it is.
What we ask, and what we keep. We ask two things: is anyone in the picture, and is it framed widely enough for a costume to have somewhere to sit. From the answer we derive a single yes/no verdict, and that verdict — one value, nothing else — is all we store, with the picture. The provider's reply itself is not stored; it is discarded as soon as the verdict has been derived from it (see the box in clause 5.3, which describes what that reply contains).
When it does not happen. The check runs only for events for which the Organiser has booked AI images. For an event without them, nothing is transmitted and nothing is checked. If the check fails or takes too long, your picture simply remains unassessed — it is uploaded, stored and displayed exactly as before, and nothing about it changes.
Consequence for you. The verdict decides only whether the AI function is offered on that picture. It is not a judgement about the picture or about the people in it, it is not shown to anyone, it is not passed on, and it has no effect on anything else in the service.
6.2 Legal basis. For a generation you have asked for: Art. 6(1)(b) GDPR — the generation is the service you requested. For the automatic check under clause 6.1a: Art. 6(1)(f) GDPR — our legitimate interest, and the Organiser's, in offering the booked AI function only where it can actually work, instead of offering an action that would fail. You can object at any time under Art. 21 GDPR (clause 13); it is enough to write to us.
6.3 What the provider does with it. Under the terms applicable to paid use, Google does not use inputs and outputs to train its models. Google logs inputs and outputs for a limited period solely to detect abuse and to comply with legal obligations.
6.4 Place of processing and third-country transfer. The interface used processes outside the European Union, in particular in the United States, including for events with data region EU. The basis is the European Commission's adequacy decision for the EU-US Data Privacy Framework, to the extent the recipient is certified, supplemented by the European Commission's standard contractual clauses and additional safeguards. Despite these instruments, residual risks remain for transfers to the USA, in particular regarding access by state authorities.
6.5 Limits. What we transmit is images and, for a generation, your text input — nothing else: not your name, not your identifier, not your email address and not other guests' images. For a generation that is the one picture you picked. For the automatic check under clause 6.1a it is the picture currently being uploaded, one at a time as it arrives — never your gallery as a whole.
6.6 Labelling. Photobooth results are visibly labelled as AI-generated in the application (Art. 50(4) AI Act).
7. Protection against automated abuse (Cloudflare Turnstile)
7.1 On the forms that trigger a generation or send an email we use Cloudflare Turnstile — a privacy-friendly alternative to picture puzzles.
7.2 What is processed. The check module loads from challenges.cloudflare.com and evaluates signals from your browser. For server-side confirmation we transmit to Cloudflare the issued verification token and your IP address.
7.3 What does not happen. We have measured that Turnstile leaves neither a cookie nor any other entry in your browser's storage on our domain. No advertising identifier is set and no cross-site profile is built.
7.4 Legal basis. Art. 6(1)(f) GDPR (recital 49: network and information security, fraud prevention). Loading the check module is strictly necessary for the function you requested and therefore requires no consent under § 25(2) no. 2 TDDDG.
7.5 Recipient and third country. Cloudflare, Inc., USA, and Cloudflare Germany GmbH. Transfers to the USA take place on the basis of the EU-US Data Privacy Framework and additionally the standard contractual clauses.
8. Further processing in operations
8.1 Abuse limits for the free demo. So that the free try-it-out function is not exploited by automated means, we count generations per access pass and per network range. Your IP address is not stored: it is first truncated to a network range (IPv4 /24, IPv6 /64) and that value is then irreversibly reduced using a cryptographic hash function. Only this hash and a counter are stored. Retention: 2 days. Legal basis: Art. 6(1)(f) GDPR (protection against abuse and uncontrolled costs).
8.2 Payment processing. We process payments through Stripe (Stripe Payments Europe, Ltd., Ireland). Payment and invoicing data are transmitted directly to Stripe; full card details never reach our systems. If you pay with PayPal, that happens as a payment method inside Stripe. Legal basis: Art. 6(1)(b) GDPR, and for tax documentation Art. 6(1)(c) GDPR. Stripe also processes payment data in part as an independent controller for fraud prevention and to comply with its own regulatory obligations.
8.3 One-time-code sign-in. To sign in to the organiser dashboard and the internal console we send a six-digit one-time code to the address given. The code is valid for 10 minutes and is deleted afterwards. Legal basis: Art. 6(1)(b) GDPR.
8.3a Admin key recovery. Via the recovery function we send an event's admin keys exclusively to the address on file. Legal basis: Art. 6(1)(b) GDPR.
8.4 Organiser, partner and referral data. We process name, email address, region, booked events, invoicing and payment data and — for partners — company name, website, country, logo and brand colour, and — in the referral programme — the personal code, associated redemptions and points balance. Legal basis: Art. 6(1)(b) GDPR, and for tax-relevant data Art. 6(1)(c) GDPR.
8.5 Internal console. Our staff see business metrics, event and account master data, codes, redemptions and partner data in the internal console. Access is restricted to an explicitly configured list of addresses and all staff are bound to confidentiality.
8.6 After an event: the images, and one question, by email. About 35 hours after a booked event ends we write to the email address the event was booked with. The message carries a time-limited link that downloads all of the event's images as an archive, and a request that you reply briefly and tell us how it went. It goes to the booking person only — we hold no email address for guests (clause 5.1). For this we process the booking person's email address and name, the event's name and period, and the share link generated for it.
Two purposes, two legal bases. Providing the images is the service you bought: Art. 6(1)(b) GDPR. The question is direct advertising of our own similar services: Art. 6(1)(f) GDPR (legitimate interest in promoting and improving our own offering), with § 7 (3) UWG as the sector-specific rule. We meet its conditions: we obtained the address from you in connection with the sale, we use it only for our own similar services, we write to nobody who has objected, and we tell you about your right to object both when the address is collected and in every such email.
8.7 Objecting to that email, and what we store about the objection. You can object at any time to your address being used for the question — through the link in every such email or informally to support@snapories.com. No cost arises for you beyond the transmission costs at basic rates. After an objection you still receive the email with your images, because that is performance of the contract; the question is dropped. More on the right to object in clause 13.
About the objection itself we store your email address, the time, and the route by which it reached us. Legal basis: Art. 6(1)(c) GDPR together with § 7 (3) no. 3 UWG, and Art. 6(1)(f) GDPR (legitimate interest in being able to honour an objection permanently). That entry is not deleted; clause 14 says why.
9. Storage on your device
Snapories stores only what is strictly necessary for the service you requested. Concretely that is: one cookie set by our server (spr_id) in the guest app, and a few entries in your browser's local storage for the access pass, language choice, appearance, last-opened event and the offline version of the app.
There is no analytics, advertising or profiling storage. That is why no consent banner appears: § 25(2) no. 2 TDDDG requires information, not consent, for strictly necessary storage.
The complete, always-current list of every single entry — key, purpose, lifetime, provider — is available at snapories.com/en/cookies. That list is generated directly from the source code and enforced by an automated check: a new storage entry in the code makes the test fail until it is declared there. The disclosure therefore cannot go stale.
10. Recipients of your data
We pass on personal data only where necessary for operation or where we are legally obliged to do so. Categories of recipients:
- Hosting and storage: Amazon Web Services (data centres in Frankfurt or Northern Virginia, depending on the event's data region; account and commercial records always Frankfurt — clause 12), and the delivery of images over the same provider's content delivery network (clause 12)
- AI generation and the automatic image check: Google (clause 6)
- Abuse protection: Cloudflare (clause 7)
- Payment processing: Stripe (clause 8.2)
- Email delivery: our sending service provider
- Advisers and authorities: tax advisers, legal advisers, auditors, and authorities and courts where legally required
The named, always-current list with registered office, place of processing and transfer basis is in the Sub-processor list.
Your data is not passed to advertising networks, data brokers or analytics providers. No sale takes place.
11. Transfers to third countries
Transfers to countries outside the European Economic Area take place for AI generation and the automatic image check (Google, USA — clause 6), for abuse protection (Cloudflare, USA) and for the delivery of images (Amazon Web Services): while an event is running, the images are cached transiently at edge locations for delivery, outside the EU as well (clause 12). The basis is:
- the adequacy decision of the European Commission of 10 July 2023 on the EU-US Data Privacy Framework, to the extent the receiving company is certified, and
- additionally the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914) together with a transfer impact assessment and additional safeguards (encryption in transit and at rest, data minimisation, no transfer of names or identifiers to the AI provider).
A copy of the respective safeguards is available on request at privacy@snapories.com.
12. Data region (EU / US)
A data region is set for every event at booking. It determines in which region that event's data is stored and processed by us:
- EU → Frankfurt am Main (
eu-central-1) - US → Northern Virginia (
us-east-1)
An event's data is not mirrored between the regions. Each region has its own databases and its own storage areas for it.
Account and billing data. Your account with us — email address, sign-in codes, and which events it administers — is kept in the European Union (Frankfurt am Main), for every event and whichever data region that event uses. The same applies to partner and referrer accounts, to discount codes and their redemptions, to referral entitlements, and to the billing party and invoice belonging to a booking. Those records are held once and are read from both regions: one account administers events in both, and a voucher issued in one has to be redeemable in the other, so splitting them between the regions would mean a code being refused in the region it was not issued in. For an event with data region US this means: the event's images and its guests' data are in Northern Virginia, while the account that booked it and the invoice for it are in Frankfurt.
Delivery of images. So that images arrive quickly and reliably everywhere, we deliver them over a content delivery network (Amazon CloudFront). In the process they are cached transiently at edge locations — outside the EU as well; the footprint covers the United States, Canada, Europe and Israel. That caching exists only while the event is running; when the event ends we purge the cache and nothing can be retrieved by this route any more. The stored copy of an image does not leave the data region.
What the data region covers and what it does not: the data region governs the data of that event — its images, and what is recorded about the event and the people who took part in it — and it determines where those are stored, processed and deleted. Three things lie outside it. It does not describe every place a byte is briefly held for delivery (above). It does not reach the account and commercial records (above), which are held once in the EU and read from both regions. And it does not cover the calls to external providers described in clauses 6 and 7, which process independently of the chosen data region; clause 11 governs there.
13. Your rights
Under the GDPR you have the right to:
| Right | Reference | What it means |
|---|---|---|
| Access | Art. 15 | You learn whether and which data we process about you. |
| Rectification | Art. 16 | Inaccurate data is corrected. |
| Erasure | Art. 17 | Your data is deleted unless a retention obligation applies. |
| Restriction | Art. 18 | Processing is frozen instead of deleted. |
| Data portability | Art. 20 | You receive your data in a common format. |
| Objection | Art. 21 | You can object to processing based on legitimate interests. Against direct advertising the objection is absolute (para. 2). |
| Withdrawal of consent | Art. 7(3) | Effective for the future; prior processing remains lawful. |
How to exercise your rights: informally by email to privacy@snapories.com. We respond without undue delay and at the latest within one month. Where we cannot identify you without additional information — which is the normal case for account-free use of the guest app — we need details that make attribution possible (Art. 11(2) GDPR), such as the event's join code, the name you used and the approximate time.
Special case: persons depicted. If you appear in an image without using the app, contact privacy@snapories.com and describe the event and the image as precisely as possible. We will remove the image, or — for business events where we are a processor — forward the request to the responsible organisation without undue delay and support them in handling it.
Special case: direct advertising. You can object at any time under Art. 21(2) GDPR to your data being processed for direct advertising — which with us is only the question in the post-event email (clause 8.6). That objection is absolute: no balancing of interests takes place, and you do not have to give reasons. After it we no longer process your data for that purpose. The quickest route is the link in every such email; an informal message to support@snapories.com does just as well.
Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority, in particular the one competent for us:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de
14. Storage periods at a glance
| Data | Period |
|---|---|
| Images of a booked event and associated metadata | stored for at least 30 days after the end of the event. Guests' access ends when the event ends; during that period the images are available to the Organiser, who can make them available to guests through a time-limited share link. No entitlement to availability beyond that; deleted on request within 30 days |
| Working copy of a picture used for an AI generation (not displayed anywhere — clause 6.1) | deleted immediately if the picture is declined as unsuitable; otherwise with the event |
| Verdict of the automatic image check (one yes/no value per picture — clause 6.1a) | with the picture it belongs to |
| Images and data of a demo event | 7 days |
| Access pass in your browser · identity cookie | 90 days · up to 400 days |
| Personal recovery link | up to 400 days |
| One-time sign-in codes | 10 minutes |
| Abuse counters (hash of the network range) | 2 days |
| Organiser, partner and referral accounts | for the duration of the business relationship |
| Objection to the post-event email (address, time, route — clause 8.7) | indefinitely, and deliberately so: an objection that expires is an objection we would stop honouring at some point. § 7 (3) no. 3 UWG sets no time limit for it, and this entry is the only place a declared objection lives on |
| Invoices and accounting vouchers | 8 years (§ 147 (3) AO, § 257 (4) HGB, § 14b (1) UStG) |
| Aggregated counts without personal reference | indefinitely (no personal reference) |
15. No automated decision-making
There is no automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR. The AI photobooth creates an image; it makes no decision about a person and has no legal effect. The automatic image check (clause 6.1a) decides only whether the AI function is offered on a single picture; it assesses no one, has no legal effect and produces no comparable significant effect. Decisions about the removal of content are taken by humans.
16. Security
We implement technical and organisational measures under Art. 32 GDPR. These include transport encryption (TLS), encryption of data at rest, strict separation of the data regions for event data, access-restricted internal systems, signed short-lived access tokens for image files, server-side abuse protection and regular updating of the components used. Details are in Annex 2 of the Data Processing Agreement.
17. Changes to this policy
We adapt this policy when the service, the providers used or the legal situation change. The current version is available at snapories.com/privacy.html; the date at the top shows its status.
18. Binding language version
Only the German version of this privacy policy is legally binding. Versions in other languages are provided for information purposes only. In the event of any discrepancy, the German version prevails. Towards data subjects who relied on a non-German version provided by us, this applies only to the extent the German version is not less favourable to them.