Snapories
How it works
WeddingsEvery guest's angle on the dayBirthdaysTurn the party into a photoboothCorporate eventsTeam fun, zero logistics
PricingFAQ
Create your event

Legal

Sub-processors and external recipients

Status: 15 September 2026 · All legal documents

Only the German version is legally binding. Switch the site language to Deutsch to read it.

This list is Annex 3 to the Data Processing Agreement and at the same time the named list referenced in clause 10 of the Privacy Policy. Changes are notified at least 30 days in advance under § 5.2 DPA.


1. In use

ProviderLegal entityServiceData processedLocationTransfer basisStatus
Amazon Web ServicesAmazon Web Services EMEA SARL, Luxembourg (EU region) · Amazon Web Services, Inc., USA (US region)hosting, object storage, database; delivery of images over a content delivery network (section 1.1)event data and image files; account, partner and commercial records (section 1.2)Event data: EU: Frankfurt (eu-central-1) · US: Northern Virginia (us-east-1), following the event's data region. Account and commercial records: Frankfurt (eu-central-1), for every event (section 1.2). Delivery: additionally edge locations in the United States, Canada, Europe and IsraelAn event's data is stored, processed and deleted exclusively in the data region chosen for that event; account and commercial records are held once, in the EU, and are read from both regions (section 1.2). For delivery, images are cached transiently outside the EU as well (section 1.1); the basis is the AWS DPA with SCC and, where the USA is involved, the EU-US DPF adequacy decision.✅
GoogleGoogle Ireland Limited / Google LLC, USA(a) AI photobooth: analysis of the picture the guest picked, costume suggestions, image generation; (b) automatic check of every uploaded image for whether the AI function can be offered on it (section 1.3) — both via the Gemini APIthe image concerned and, for a generation, the guest's text inputmostly USA — including for data region EUEU-US DPF adequacy decision (where certified) + SCC✅
CloudflareCloudflare, Inc., USA · Cloudflare Germany GmbHbot protection (Turnstile) on the photobooth and the email-sending formsverification token, IP address, browser signalsUSA / globalEU-US DPF adequacy decision + SCC✅

1.1 Delivery of images (content delivery network)

We deliver an event's images over Amazon's content delivery network (CloudFront). So that they arrive quickly and reliably everywhere, they are cached transiently at edge locations in the process — outside the EU as well. For the delivery of images the footprint is limited to the United States, Canada, Europe and Israel.

That caching exists only while the event is running. When the event ends we purge the cache; after that, nothing can be retrieved by this route.

The stored copy of an image does not leave the data region chosen at booking. The data region determines where an image is stored, processed and deleted — not every place a byte is briefly held for delivery.

For the marketing website and the applications' program files (JavaScript, stylesheets, website imagery) we use the same network with a larger footprint. Those files contain no personal data.

1.2 Account and commercial records (European Union)

The data region chosen at booking governs the data of that event: the images, and what is recorded about the event and the people who took part in it. Those are stored, processed and deleted in that region, and are not mirrored into the other.

Account and commercial records are kept in the European Union — Frankfurt (eu-central-1) — for every event, whichever data region the event uses. They are:

  • the organiser's account: email address, sign-in codes, and which events it administers
  • partner and referrer records, including a partner's brand settings
  • discount and voucher codes, their redemptions, and referral entitlements
  • the billing party of a booking and the invoicing record belonging to it
  • a withdrawal declaration made under § 356a BGB

Those records are held once, in the European Union, and are read from both regions. That is a deliberate arrangement rather than a by-product. One account administers events in both regions, a partner is one business with one brand record, and a voucher issued while one event was booked has to be redeemable against a booking in the other region — a record that must be readable from both regions cannot be split between them, and splitting it would mean a code issued in one region being refused in the other. Our payment service provider and our email sending service are each a single service established in the EU for the same reason.

For an event with data region US this means: the event's images and its guests' data are in Northern Virginia, while the account that booked it and the invoice for it are in Frankfurt.

1.3 Automatic check of uploaded images (Google)

Beyond a generation the guest asks for, there is a second, automatic transfer to Google, and it is named here separately because it reaches images whose owner never uses the AI at all.

The AI photobooth has no camera of its own: a guest applies it to an image they took themselves and that is already in the gallery. So that the application knows on which images it can offer the function, every uploaded image is transmitted to the Gemini API once, immediately after upload — scaled down to a maximum edge length of 1 280 pixels wherever our software can re-encode it, otherwise as it is — and assessed for two things: whether anyone is in the image, and whether it is framed widely enough for a costume. Only the resulting yes/no verdict is stored, with the image; the provider's reply is discarded once the verdict has been derived from it.

The check runs only for events for which the Organiser has booked AI images — for an event without them nothing is transmitted. A failure or a timeout leaves the image unassessed and changes nothing else about it.

Conditions, transfer basis and the provider's retention are the same as for a generation and are those given in the table above. What is transmitted, what is kept, and how a guest can object is set out in clause 6.1a of the Privacy Policy.


2. Planned

ProviderLegal entityServiceData processedLocationTransfer basisStatus
StripeStripe Payments Europe, Ltd., Ireland (Stripe, Inc., USA as group company)payment processing, tax determination, invoicing data; PayPal as a payment method inside Stripename, email, billing address, country, amount, payment methodEU / USAStripe DPA with SCC; EU-US DPF⏳
Email delivery servicenot yet selecteddelivery of one-time codes, key recovery, booking confirmations, deletion noticesemail address, message contentpreferably EUDPA with SCC where a third country is involved⏳

3. Removed

ProviderLegal entityServiceLocationStatus
fal.aiFeatures and Labels, Inc., USAautomatic image enhancement (denoise, sharpen, upscale)USA❌ — removed on 30 July 2026 and no longer part of the system. This provider was never activated; no data was ever transmitted to it.

4. Non-recipients

We use no:

  • analytics, statistics or audience-measurement services
  • advertising networks, retargeting, conversion pixels
  • external font, icon or script services, third-party content delivery networks
  • social-media plugins, embedded videos or maps
  • customer data platforms, CRM tracking, session recording
  • data brokers

The marketing website and all applications load files exclusively from our own servers and over our own delivery network (section 1.1). The sole exception is the bot-protection module in section 1; it is declared as such in the central storage registry.


5. Internal recipients

RecipientAccessBasis
Management and staffinternal console: business metrics, event and account master data, codes, redemptions, partner dataaccess only via an explicitly configured address list; confidentiality undertaking
Tax advisersinvoicing and booking datalegal obligation, professional secrecy
Legal advisersas requiredlegitimate interest, professional secrecy

Binding language version

Only the German version of this document is legally binding. Versions in other languages are provided for information purposes only. In the event of any discrepancy, the German version prevails.

Snapories

A digital disposable camera for every guest — and an AI photobooth in every pocket. One QR code, no app, no account.

EU & US data residency

Product

How it worksPricingTry the live demo

Best for

WeddingsBirthdaysCorporate events

Support

FAQHost dashboardData privacyCookies & storageReport content

Legal

ImprintTermsRight of withdrawalWithdraw from contractAll legal documents

Programmes

Refer a friendVenue co-branding

Company

CompanyCreate your event
© 2026 Snapories · snapories.com
Appearance
PrivacyCookiesTermsImprintLegal