Privacy Policy
How we protect your data.
-
- 1. In Brief
- 2. Data Controller
- 3. No Separate Data Processing Agreement
- 4. Who Do We Process Information About?
- 7. Consent and Acceptance Upon Upload
- 8. Events with Children and Minors
- 10. Admin Access to Accounts, Events, and Data
- 11. Purposes and Legal Bases
- 12. Sharing and Recipients
- 13. Transfer to Third Countries
- 14. Cookies and Statistics
- 15. Emails, SMS, and Messages from eazy.photo
- 17. Deletion Before Expiry
- 18. Your Rights
- 19. Security
- 20. Personal Data Breaches
- 21. Illegal or Offensive Content
- 22. The Host's Practical Responsibility
- 23. Shared Gallery, Live Wall, and Photo Kiosk
- 24. Changes to the Privacy Policy
- 25. Complaint to the Data Protection Authority
- 26. Contact
-
- A.1 General Information About the Data Controller
- A.2 Overall Overview of Processing Activities
- A.3 Processing Activity: Account and Access Management
- A.4 Processing Activity: Event Creation and Event Administration
- A.5 Processing Activity: Upload and Display of Photos and Videos
- A.6 Processing Activity: Admin Access, Operations, Support, and Legality Checks
- A.7 Processing Activity: Payment, Invoice, and Purchase History
- A.8 Processing Activity: eazyAI
- A.9 Processing Activity: Support and Service Communication
- A.10 Processing Activity: Security, Logs, and Abuse Protection
- A.11 Processing Activity: Website, Cookies, and Self-Hosted Statistics
- A.12 Processing Activity: Newsletter and Marketing
- A.13 Processing Activity: SMS Service Messages and Phone Verification
-
- B.1 Purposes of Processing
- B.2 Necessity and Proportionality
- B.3 Key Risks and Measures
-
- B.4.1 Unauthorised Access to Private Events
- B.4.2 Photos and Videos May Contain Sensitive Information
- B.4.3 Persons in Photos Have Not Themselves Used eazy.photo
- B.4.4 Live Wall and Photo Kiosk Can Display Content Widely
- B.4.5 AI and Transfer to Third Countries
- B.4.6 SMS Service Messages and Phone Number
- B.4.7 Internal Admin Access
- B.5 Overall Risk Assessment
- B.6 Conclusion of Impact Analysis
Privacy Policy for eazy.photo
Last updated: July 20, 2026
This privacy policy describes how eazy.photo processes personal data when you use our website, create an account, create or participate in events, upload photos or videos, use eazyAI, receive messages from us, or otherwise interact with eazy.photo.
The policy is written for event hosts, guests, persons appearing in photos or videos, and visitors to our website.
This privacy policy also contains eazy.photo's record of processing activities, deletion policy, and overall security assessment and impact analysis.
1. In Brief
| Topic | Short explanation |
|---|---|
| Who is responsible? | eazy.photo is the data controller for the processing of personal data in the eazy.photo platform. |
| What is eazy.photo used for? | eazy.photo is a platform for private and public events, where hosts can create events, invite guests, and collect photos and videos from the event. |
| What data is processed? | We process, among other things, name, email address, event information, payment information, technical information, guest names, photos, and videos. |
| Do photos and videos contain personal data? | Yes. Photos and videos of identifiable persons are personal data. |
| Can photos and videos contain sensitive data? | Yes. Photos and videos may in specific cases visually reveal, for example, religion, political beliefs, health conditions, sexual orientation, or similar. |
| Does eazy.photo include Article 9? | Yes. If photos or videos contain special categories of personal data, the processing is assessed under GDPR Article 9. |
| Does eazy.photo use photos or videos for marketing? | No. eazy.photo does not use photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent. |
| Does eazy.photo use facial recognition? | No. |
| Does eazy.photo use biometric identification? | No. |
| Can eazyAI see photos or videos? | No. eazyAI cannot see, analyse, recognise, or describe the content of photos or videos. |
| Are photos and videos sent to Google Gemini? | No. |
| How long are eazyAI conversations stored? | Conversations with eazyAI are stored for up to 90 days after the last activity and are then automatically deleted upon inactivity. |
| Are events public? | Events are by default private and accessed via an event link, QR code, token, or other access mechanism. |
| Can guests see each other's photos? | Only if the host enables features such as shared gallery, live wall, or photo kiosk. |
| Can guests download photos? | Guests do not have a direct download function. Only the host has a direct download function. |
| Can screenshots be prevented? | No. eazy.photo cannot prevent screenshots, screen recordings, or photographing of a screen. |
| Can eazy.photo admins access user accounts and event data? | Yes, authorised administrators may to the necessary extent access accounts, events, photos, videos, logs, and other data for the purpose of operations, support, security, troubleshooting, deletion, legality checks, and legal obligations. |
| How long are photos and videos stored? | A minimum of 6 months after the event start date, and longer if the host has chosen or previously agreed to longer storage. |
| How long is accounting material stored? | Bookkeeping-relevant information is generally retained for 5 years in accordance with accounting rules. |
| Does eazy.photo use SMS? | SMS service messages have not yet been implemented. When the function is implemented, SMS is expected to be used for, for example, phone verification, security messages, and messages about low storage on events. The expected SMS provider is InMobile. |
2. Data Controller
The data controller for the processing of personal data in the eazy.photo application and on the eazy.photo website is:
| Information | Content |
|---|---|
| Company | eazy.photo |
| Address | Svanemosevej 19B, 9490 Pandrup, Denmark |
| CVR no. | DK33551592 |
| Website | https://eazy.photo |
| hey@eazy.photo | |
| Phone | No public telephone contact |
| Data Protection Officer | Not appointed |
| EU Representative | Not relevant, as eazy.photo is established in Denmark |
We have not appointed a Data Protection Officer, as we assess that eazy.photo is not obligated to do so. Questions about data protection can be directed to hey@eazy.photo.
3. No Separate Data Processing Agreement
eazy.photo does not use a separate data processing agreement for ordinary use of the platform.
The chosen role model is that eazy.photo is the data controller for the processing of personal data that occurs in the eazy.photo application, including creation of events, guest access, upload, storage, display, sharing in private galleries, live wall, photo kiosk, technical operations, security, support, payment, and deletion.
The event host still has a practical responsibility for how the event is created and used. The host chooses, among other things, the event title, description, storage period by agreement, access sharing, and whether features such as shared gallery, live wall, or photo kiosk are activated.
When the host downloads, exports, publishes, forwards, or uses photos, videos, or guest information outside of eazy.photo, this subsequent use is not part of eazy.photo's platform processing. The host is responsible for their own use of the material outside of eazy.photo.
| Situation | Role distribution |
|---|---|
| Account creation, login, payment, and support | eazy.photo is the data controller. |
| Creation and operation of events in eazy.photo | eazy.photo is the data controller for the platform processing. |
| Guests' upload and viewing in eazy.photo | eazy.photo is the data controller for the platform processing. |
| The host's choice of settings, e.g. live wall or shared gallery | eazy.photo is the data controller for the platform processing, while the host has a practical responsibility for responsible use of the functions. |
| The host's download and use outside of eazy.photo | The host is responsible for the subsequent use outside the platform. |
| Guests' screenshots or screen recordings | eazy.photo cannot prevent this and is not responsible for guests' subsequent use outside the platform. |
4. Who Do We Process Information About?
We may process information about the following categories of persons:
| Category | Examples |
|---|---|
| Event hosts | Persons who create an account, purchase event packages, create events, administer galleries, or use eazyAI. |
| Guests | Persons who participate in an event, enter a name, open an event link, upload photos or videos, or view content in an event gallery. |
| Persons in photos or videos | Persons who appear in photos or videos, even if they have not themselves used eazy.photo. |
| Support contacts | Persons who contact us via email or support. |
| Marketing recipients | Persons who have given consent to newsletters or marketing. |
| Website visitors | Persons who visit the eazy.photo website. |
| Future SMS recipients | Event hosts who eventually add and verify a phone number for the purpose of receiving necessary service messages via SMS. The SMS function has not yet been implemented. |
5. What Information Do We Process?
5.1 Overview of Information
| Category | Information |
|---|---|
| Account information | Name, email address, login information, account status, phone number if you eventually add it, and relevant account settings. |
| Event information | Event title, event description, event date, event settings, storage period, live wall settings, photo kiosk settings, sharing settings, and information about storage usage. |
| Guest information | The name the guest enters themselves, access to the event, upload history, and event association. |
| Photos and videos | Uploaded or captured media files, visual information about persons, file type, file size, and technical metadata. |
| Payment and invoice information | Order number, invoice number, amount, VAT, payment status, purchase date, event package, and payment reference. |
| Technical information | IP address, user agent, timestamps, login logs, access logs, upload logs, error logs, and security logs. |
| Support information | Name, email address, the content of the enquiry, any technical context, and documentation of the enquiry. |
| eazyAI information | Text input from the host, AI conversations, conversation history, the host's name, event titles, event descriptions, basic event statistics, and potentially purchase history or order status. |
| Service message information | Email address, event status, storage usage, deletion deadlines, message history, and, when the SMS function is implemented, phone number, verification status, and technical SMS delivery information. |
| Marketing information | Email address, name if provided, consent status, time of consent, and unsubscription. |
| Admin and security information | Information about administrative actions, access logs, case notes, support context, and documentation for operations, support, security, legality checks, or legal obligations. |
5.2 Information About Event Hosts
When you create or use a host account, we may process:
| Type of information | Examples |
|---|---|
| Identification | Name and email address. Eventually also phone number, if you add it yourself. |
| Account | Login information, account status, and account settings. |
| Events | Event titles, event descriptions, event dates, event settings, storage usage, and selected functions. |
| Payment | Payment status, purchase history, order information, invoice information, and event packages. |
| Support | Communication with us and relevant information about your account or events. |
| Technical operations | IP address, log data, user agent, timestamps, and security-related information. |
| eazyAI | Messages you write to eazyAI, conversation history, and relevant text-based context. |
| SMS service messages | Not yet implemented. When the function is implemented, phone number, verification code, verification status, and SMS delivery data may be processed. |
| Admin access | Authorised administrators may to the necessary extent access the account and associated data for the purpose of operations, support, security, troubleshooting, deletion, legality checks, and legal obligations. |
5.3 Information About Guests
When you participate in an event, we may process:
| Type of information | Examples |
|---|---|
| Guest name | The name you choose to enter yourself. |
| Uploads | Photos and videos you upload. |
| Metadata | Upload time, file type, file size, and technical file information. |
| Access | Event link, token, QR code, or other access mechanism. |
| Technical operations | IP address, log data, user agent, timestamps, and security-related information. |
| Abuse protection | Information used for rate limiting, spam prevention, and protection against abuse. |
| Admin access | Authorised administrators may to the necessary extent access guest information, uploads, and technical information for the purpose of operations, support, security, troubleshooting, deletion, legality checks, and legal obligations. |
If the host has activated shared gallery, your chosen guest name and your uploaded media may be visible to other guests in the same event.
Your name is not shown on the live wall or photo kiosk. However, the live wall and photo kiosk may show photos and videos where persons may be visible.
5.4 Information About Persons in Photos and Videos
Photos and videos may contain personal data about persons who can be visually identified.
| Type of information | Examples |
|---|---|
| Ordinary visual information | Face, appearance, clothing, posture, and participation in a specific event. |
| Social information | Relationships, social contexts, and actions during the event. |
| Contextual information | Surroundings, signs, name tags, uniforms, place cards, or other visible elements. |
| Possible sensitive information | Circumstances that may be apparent visually, e.g. religion, political beliefs, health conditions, or sexual orientation. |
We do not analyse photo or video content to identify sensitive information. We do not categorise persons according to sensitive circumstances, and we do not use photo or video material for biometric identification.
Authorised administrators may to the necessary extent access photos and videos if it is necessary for operations, support, troubleshooting, deletion, security, handling of abuse, assessment of illegal or offensive content, or fulfilment of legal obligations.
5.5 Payment and Invoice Information
When you purchase an event package or other paid feature, we may process:
| Type of information | Examples |
|---|---|
| Customer information | Name and email address. |
| Order information | Order number, purchase date, event package, and payment status. |
| Invoice information | Invoice number, amount, VAT, and invoice document. |
| Payment information | Payment reference and information necessary to register payment. |
We use MobilePay for payments to start with. MobilePay processes payment information in connection with the actual payment. eazy.photo does not necessarily receive all payment card or account information, but receives the information necessary to register payment, issue a receipt, and deliver the purchased service.
5.6 Technical Information and Logs
In order to operate and protect eazy.photo, we process technical information.
| Type of information | Purpose |
|---|---|
| IP address | Security, abuse protection, troubleshooting, and rate limiting. |
| Timestamps | Documentation of events and technical operations. |
| Login and access logs | Protection against unauthorised access. |
| Upload and access events | Troubleshooting, security, and operations. |
| Error logs | Troubleshooting and regression detection. |
| Security logs | Protection against abuse, attacks, and unauthorised access. |
| User agent | Technical troubleshooting and compatibility. |
| Storage usage | Operations, capacity management, and service messages to the host if an event is running low on storage. |
| Admin logs | Documentation, security, and control of administrative actions where relevant. |
Technical information is used for security, troubleshooting, operations, prevention of abuse, documentation of events, and stable operation of the platform.
5.7 Support and Communication
When you contact us, we may process:
| Type of information | Examples |
|---|---|
| Contact information | Name and email address. |
| Enquiry | The content of your message and any attached information. |
| Technical context | Relevant information if the enquiry concerns errors, account access, payment, deletion, or security. |
| Documentation | Information necessary to document case proceedings, rights, or complaints. |
| Admin access | For support, authorised administrators may gain access to relevant accounts, events, logs, photos, or videos if it is necessary to assist with the specific case. |
We ask you to refrain from sending sensitive information to us unless it is necessary for the specific case.
5.8 Newsletter and Marketing
If you give consent to newsletter or marketing, we may process:
| Type of information | Examples |
|---|---|
| Contact information | Email address and name, if you have provided it. |
| Consent | Consent status, time of consent, and documentation of what you have consented to. |
| Unsubscription | Time of unsubscription and documentation of unsubscription. |
We only send marketing if you have given consent. You can always withdraw your consent.
Service messages, operational messages, security messages, SMS messages about phone verification or low storage, receipts, and necessary information about your account or events are not marketing.
eazy.photo does not use uploaded photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent.
6. Photos, Videos, and Sensitive Information
Photos and videos are central to eazy.photo.
Photos and videos of identifiable persons are personal data.
Photos and videos are not automatically sensitive personal data solely because they show persons. But they may in specific cases contain or reveal information that under the GDPR are special categories of personal data.
| Possible sensitive information | How it may appear |
|---|---|
| Religious or philosophical beliefs | E.g. religious clothing, religious ceremonies, or symbols. |
| Political beliefs | E.g. political symbols, banners, badges, or participation in a political event. |
| Sexual relations or sexual orientation | E.g. context, symbols, relationships, or participation in specific events. |
| Health conditions | E.g. visible aids, signs of illness, or treatment situations. |
| Race or ethnic origin | Visual information may in some cases give an impression of ethnicity. |
| Trade union membership | E.g. visible trade union symbols or participation in specific events. |
| Biometric data | Only if photos are processed technically for the purpose of unique identification. eazy.photo does not do this. |
eazy.photo does not process photos or videos with the aim of inferring, registering, or categorising sensitive circumstances.
eazy.photo does not use uploaded photos or videos for marketing, advertising, cases, social media, product promotion, training of AI models, or other commercial purposes without separate, voluntary, and explicit consent from the relevant persons.
This applies to both photos and videos uploaded by guests, material captured or displayed in connection with events, and material that may contain ordinary or sensitive personal data.
6.1 Legal Basis for Sensitive Information
Photos and videos may in specific cases contain or reveal special categories of personal data under GDPR Article 9.
eazy.photo does not process photos or videos with the aim of inferring, registering, or categorising sensitive information. We do not use facial recognition, biometric identification, profiling, or AI analysis of photo or video content.
If a guest themselves uploads photos or videos in which the guest appears, and the material contains special categories of personal data about the guest, the processing may take place on the basis of the guest's explicit consent, cf. GDPR Article 9(2)(a).
If photos or videos contain special categories of personal data about other persons, eazy.photo does not process this information with the aim of inferring or using the sensitive circumstances. The processing takes place solely as a necessary and limited part of the event-based photo and video sharing service.
If we are made aware that a photo or video contains sensitive information that should not be processed, we assess the case specifically and may delete, restrict access to, or otherwise handle the material.
If processing of sensitive information is necessary to establish, exercise, or defend a legal claim, the processing may take place under GDPR Article 9(2)(f).
6.2 What eazy.photo Does Not Use Photos and Videos For
| Processing | Does eazy.photo use it? |
|---|---|
| Facial recognition | No |
| Biometric identification | No |
| Biometric templates | No |
| AI analysis of photo or video content | No |
| Automatic categorisation of persons | No |
| Profiling based on photos or videos | No |
| Sending photos or videos to eazyAI | No |
| Sending photos or videos to Google Gemini | No |
| Use of photos or videos for marketing without separate consent | No |
| Use of photos or videos for AI training | No |
| Admin access when there is a legitimate need | Yes, but only to the necessary extent and for the purpose of operations, support, security, troubleshooting, deletion, legality checks, or legal obligations |
Since users can upload photos and videos from many types of events, we cannot guarantee in advance that an uploaded photo or video does not contain sensitive information.
Therefore, we have introduced special restrictions and security measures, including private access, access control, limited download, possibility of deletion, deletion deadlines, no AI image analysis, and no biometric processing.
If you believe that a photo or video on eazy.photo contains information about you that should not be processed, you can contact us at hey@eazy.photo. We may ask you for information that makes it possible to find the relevant event and the specific photo or video.
7. Consent and Acceptance Upon Upload
Guests must actively accept eazy.photo's relevant privacy information before they can upload photos or videos.
When you upload photos or videos, you confirm that you have the right to upload the material to the event, and that you are not uploading material that obviously violates other persons' privacy, rights, or security.
| Situation | What does it mean? |
|---|---|
| You upload photos or videos of yourself | You accept that eazy.photo processes the material to deliver the event function. |
| The material contains sensitive information about you | We may process this information on the basis of your explicit consent, to the extent such a basis is necessary. |
| You upload photos or videos of others | You should take into account privacy, children, vulnerable persons, and persons who do not wish to be photographed or shared. |
| You wish to withdraw consent | You can contact us at hey@eazy.photo. |
| eazy.photo wishes to use photos or videos for marketing | This does not happen without separate, voluntary, and explicit consent from the relevant persons. |
You can withdraw your consent by contacting us at hey@eazy.photo.
Withdrawal of consent does not affect the lawfulness of the processing that has already taken place before the withdrawal.
If you withdraw consent, we will assess whether the relevant information should be deleted, restricted, or can continue to be processed on another valid basis, for example if the processing is necessary to handle a legal claim, a security incident, or a statutory obligation.
8. Events with Children and Minors
eazy.photo can be used for events where children or minors participate or appear in photos or videos. It is up to the host to choose what types of events eazy.photo is used for.
You must be at least 18 years old to create a host account and purchase event packages.
If an event involves children, the host should ensure that participants and parents or guardians are clearly informed about the use of eazy.photo, including upload, display, live wall, photo kiosk, shared galleries, and deletion.
If a child under 15 years old is themselves to give consent to processing in connection with an information society service, the consent must be given or approved by the holder of parental responsibility, unless another valid legal basis applies.
For events with children, the host should at a minimum consider:
| Consideration | Why it is important |
|---|---|
| Information to parents or guardians | Children have special protection, and parents or guardians should know the framework for photo sharing. |
| Use of live wall or photo kiosk | Content may be displayed widely during the event. |
| Use of shared gallery | Other guests can see uploaded photos and videos. |
| Download and external sharing | When the host downloads or shares material outside of eazy.photo, it takes place outside the platform's controls. |
| Sharing of QR code or event link | The link should not be shared more widely than necessary. |
| Deletion and moderation | Content that should not be displayed should be deleted or restricted quickly. |
eazy.photo may delete or restrict access to content if we are made aware of content that may violate children's privacy, security, or rights.
9. eazyAI
eazyAI is an AI assistant that can only be used by event hosts.
eazyAI is powered by Google Gemini.
9.1 What eazyAI Can and Cannot Process
| Data type | Can eazyAI process it? | Note |
|---|---|---|
| Host's name | Yes | Used e.g. for personal greeting and relevant assistance. |
| Event titles | Yes | Can be used as text context. |
| Event descriptions | Yes | Can be used as text context. |
| Basic event statistics | Yes | Can be used to help the host. |
| Potential purchase history or order status | Yes | Only if relevant to the question or function. |
| Text messages the host writes themselves | Yes | Sent as user input to the AI function. |
| Conversation history with eazyAI | Yes | Stored for up to 90 days after last activity and then automatically deleted upon inactivity. |
| Photos | No | eazyAI cannot see or analyse photos. |
| Videos | No | eazyAI cannot see or analyse videos. |
| Faces | No | No facial recognition. |
| Photo content | No | No image understanding, image description, or image analysis. |
| Biometric identification | No | eazy.photo does not create biometric templates. |
| AI training on photos or videos | No | Photos and videos are not used for AI training. |
Photos and videos are not sent to eazyAI or Google Gemini.
eazyAI can only process text-based information that is necessary to provide relevant assistance to the host.
Conversations with eazyAI are stored for up to 90 days after the last activity in the conversation, so the host can continue the conversation and receive coherent assistance. If the conversation is inactive for 90 days, the conversation is automatically deleted.
eazyAI must not be used to enter sensitive information, confidential information, payment card details, social security numbers, passwords, or information about other persons, unless it is strictly necessary.
We use a paid Google Gemini/API configuration, where user data according to Google's current terms for paid services is not used to train Google's foundation models.
eazyAI does not make automated decisions with legal effect or similarly significant impact on you. eazyAI is an assistance function, and responses from AI may be imprecise or incomplete.
10. Admin Access to Accounts, Events, and Data
In order to deliver, operate, secure, and support eazy.photo, authorised administrators at eazy.photo may to the necessary extent gain access to user accounts, event information, guest information, photos, videos, technical logs, payment status, and other data stored in the platform.
Admin access is only used when it is necessary and substantively justified.
| Purpose | Examples | Legal basis |
|---|---|---|
| Deliver the service | Account, event creation, gallery, upload, display, download, payment, and access to purchased features | GDPR Article 6(1)(b) |
| Provide support | Help with errors, access issues, account issues, event setup, payment, or deletion | GDPR Article 6(1)(b) and/or (f) |
| Ensure operations | Troubleshooting, technical maintenance, capacity management, backups, log review, and stability | GDPR Article 6(1)(f) |
| Protect the platform | Prevent abuse, spam, unauthorised access, technical attacks, and security incidents | GDPR Article 6(1)(f) |
| Check legality and enforce terms | Investigate suspicion of illegal, offensive, harmful, or terms-violating content | GDPR Article 6(1)(f) |
| Comply with legal requirements | Bookkeeping, authority enquiries, legal obligations, or mandatory documentation | GDPR Article 6(1)(c) |
| Handle claims or disputes | Document events, handle complaints, legal claims, or abuse | GDPR Article 6(1)(f) and, where relevant, GDPR Article 9(2)(f) |
Admin access is limited according to the need-to-know principle. This means that administrators may only access personal data when it is necessary for a specific task.
Admin access must not be used for private purposes, curiosity, irrelevant review, marketing, or other purposes that are not substantively connected to operations, support, security, legality checks, documentation, or delivery of the service.
Where relevant, administrative actions are logged or documented to protect users, ensure responsible access, and be able to investigate security incidents or abuse.
Since photos and videos may contain ordinary personal data and in certain cases sensitive information, internal access to photos and videos is particularly limited. Administrators only access photos and videos when it is necessary for support, troubleshooting, security, deletion, handling of abuse, assessment of illegal or offensive content, or fulfilment of legal obligations.
11. Purposes and Legal Bases
We process personal data for the following purposes and on the following bases:
| Purpose | Information | Legal basis |
|---|---|---|
| Creation and administration of host account | Name, email, login information, and account status | GDPR Article 6(1)(b): performance of contract |
| Delivery of the eazy.photo platform to hosts | Event information, settings, galleries, media files, and guest access | GDPR Article 6(1)(b): performance of contract |
| Guests' use of event access and upload | Guest name, uploads, technical metadata, and access tokens | GDPR Article 6(1)(b): delivery of the guest function that the guest actively uses |
| Processing of photos and videos | Photos, videos, metadata, and persons in media | GDPR Article 6(1)(b) for delivery of the service to the user, and Article 6(1)(f) for our legitimate interest in delivering a private event-based photo sharing service, including for persons appearing in media without having uploaded themselves |
| Sensitive information that may appear in photos or videos | Information that visually may reveal e.g. religion, sexuality, political beliefs, health, ethnicity, or other special categories of personal data | GDPR Article 9(2)(a), where the data subject has given explicit consent. eazy.photo does not process photos or videos with the aim of inferring or using sensitive circumstances. If processing of sensitive information is necessary to establish, exercise, or defend a legal claim, GDPR Article 9(2)(f) may be applied. |
| Delimitation of marketing use | Photos and videos | eazy.photo does not use photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent |
| Admin access to user accounts, events, and stored data | Account information, event information, guest information, photos, videos, technical logs, payment status, and other relevant information | GDPR Article 6(1)(b), when access is necessary to deliver the agreed service. GDPR Article 6(1)(f), when access is necessary for operations, support, security, troubleshooting, abuse prevention, or legality checks. GDPR Article 6(1)(c), when access is necessary to comply with a legal obligation. For sensitive information, GDPR Article 9(2)(f) may be applied if processing is necessary for legal claims. |
| Payment and delivery of purchased event packages | Order, payment, receipt, invoice, and payment status | GDPR Article 6(1)(b): performance of contract |
| Accounting and mandatory documentation | Invoices, transaction information, and bookkeeping material | GDPR Article 6(1)(c): legal obligation |
| Access to order and invoice history | Invoices, purchase history, and order status | GDPR Article 6(1)(b) while the customer relationship exists, and Article 6(1)(f) for legitimate interest in giving the user access to their own history and documentation |
| Support and customer service | Email, enquiries, account information, and technical context | GDPR Article 6(1)(b) and (f) |
| Service messages via email | Email address, event status, deletion reminders, receipts, security messages, and relevant message data | GDPR Article 6(1)(b), (c), and (f) |
| SMS service messages and phone verification | Phone number, verification code, verification status, event status, storage usage, and SMS delivery data | Not yet implemented. When the function is implemented: GDPR Article 6(1)(b) for delivery of the service and Article 6(1)(f) for our legitimate interest in ensuring the host receives important operational, security, and capacity messages |
| Security, abuse protection, and troubleshooting | IP addresses, logs, tokens, access data, and error logs | GDPR Article 6(1)(f): legitimate interest in secure operations, prevention of abuse, and protection of users |
| eazyAI | Text input, conversation history, event titles, event descriptions, basic statistics, and relevant purchase history | GDPR Article 6(1)(b), when the function is used as part of the service, and Article 6(1)(f) for improved support and product functionality |
| Self-hosted statistics | Limited usage data and technical information | GDPR Article 6(1)(f): legitimate interest in understanding and improving the service |
| Newsletter and marketing | Email, name, and consent status | GDPR Article 6(1)(a): consent |
| Handling of rights and complaints | Identification information, enquiries, and relevant documentation | GDPR Article 6(1)(c) and (f) |
| Handling of illegal content, abuse, or legal claims | Account information, logs, media content, and technical documentation | GDPR Article 6(1)(f), and where relevant Article 6(1)(c). For sensitive information, GDPR Article 9(2)(f) may be applied if processing is necessary for legal claims |
12. Sharing and Recipients
We do not share personal data with third parties for their own marketing.
We may share or make information available to the following categories of recipients when necessary:
| Recipient | What information may be shared? | Why? |
|---|---|---|
| The event host | Guest names, photos, videos, event information, and upload information | For the host to administer the event. |
| Other guests in the same event | Photos, videos, and possibly guest names | Only if the host has activated shared gallery or similar functions. |
| Persons viewing the live wall or photo kiosk | Photos and videos | Only if the host has activated the function. Guest names are not shown on the live wall. |
| Hetzner | Platform data, database, and technical information | Hosting and infrastructure in Nuremberg, Germany. |
| OVHcloud | Platform data, database, storage, or technical information | Hosting and infrastructure in Frankfurt, Germany. |
| MobilePay | Payment-related information | Processing of payment. |
| Google Gemini | Text-based information from eazyAI | Only when the host uses eazyAI. Photos and videos are not sent. |
| InMobile | Phone number, verification code, SMS content, technical SMS delivery information, and relevant message data | Not yet implemented. Expected SMS provider for future SMS service messages, e.g. phone verification, security messages, and messages about low event storage. |
| Public authorities | Relevant information upon legal requirements, security incidents, or illegal content | If we are legally obligated to do so, or if it is necessary to handle abuse or legal claims. |
| Advisers | Relevant information | E.g. lawyer or accountant for documentation, accounting, complaints, or legal claims. |
We use self-hosted Umami for statistics and self-hosted Mosparo for spam and abuse protection. These services are hosted by us and do not entail data being sent to Google Analytics, Meta Pixel, or similar third-party tracking services.
We do not use an external email provider for ordinary system emails. Emails are sent via eazy.photo's own mail infrastructure.
13. Transfer to Third Countries
The core platform, including application, database, and media storage, is hosted on infrastructure located in the EU/EEA.
Photos and videos are not sent to eazyAI or Google Gemini.
When a host uses eazyAI, text-based information may be processed by Google Gemini. Google may in this connection process information outside the EU/EEA depending on the specific service configuration and Google's infrastructure.
SMS service messages have not yet been implemented. When the function is implemented, InMobile is expected to be used as SMS provider.
| Processing | Transfer to third countries? | Note |
|---|---|---|
| Hosting of core platform | No | Hosting takes place in the EU/EEA. |
| Database and media storage | No | Photos and videos are not sent outside the EU/EEA as part of normal platform operations. |
| eazyAI | Possible | Only text-based information may be processed via Google Gemini. |
| Photos and videos to eazyAI | No | Photos and videos are not sent to eazyAI or Google Gemini. |
| Payment via MobilePay | Depends on MobilePay's processing | Payment processing takes place according to MobilePay's own relevant terms and security measures. |
| SMS via InMobile | Not yet implemented | When the SMS function is implemented, InMobile's processing and any sub-processors will be assessed, including whether transfer outside the EU/EEA takes place. |
For transfers to third countries, we use relevant transfer bases and safeguards, including where relevant the EU Commission's standard contractual clauses, data protection terms, and relevant certification or transfer mechanisms.
14. Cookies and Statistics
eazy.photo uses only necessary functional cookies and similar technologies that are necessary for the website and application to function.
| Technology | Used? | Purpose |
|---|---|---|
| Necessary cookies | Yes | Login, sessions, security, and access to events. |
| Technical tokens | Yes | Access to events, validation of forms, and security. |
| Self-hosted statistics | Yes | Understand and improve the service without third-party tracking. |
| Google Analytics | No | Not used. |
| Meta Pixel | No | Not used. |
| Marketing cookies | No | Not used. |
| Third-party tracking cookies | No | Not used. |
Read more in our separate cookie policy.
15. Emails, SMS, and Messages from eazy.photo
We may send you necessary service messages when relevant to your account, your purchase, or your event.
Service messages are currently sent via email.
SMS service messages have not yet been implemented. When the function is implemented, service messages may also be sent via SMS if you have provided and verified a phone number. The expected SMS provider is InMobile.
| Message type | Channel | Purpose | Marketing? |
|---|---|---|---|
| Event creation | Confirm or inform about event creation | No | |
| Event start | Inform about the start of the event | No | |
| Event end | Inform about the end of the event | No | |
| Reminder about media deletion 30 days before | Give the host the opportunity to download or act before deletion | No | |
| Reminder about media deletion 7 days before | Give the host the opportunity to download or act before deletion | No | |
| Reminder about media deletion 1 day before | Give the host a final reminder before deletion | No | |
| Warning about low storage | Email and eventually SMS | Inform the host if an event is running low on storage | No |
| Phone number verification | Eventually SMS | Verify that the phone number belongs to the user | No |
| Changes to terms or privacy policy | Inform about material changes | No | |
| Receipts and invoices | Documentation for purchases and payment | No | |
| Password reset | Account security and access | No | |
| Email address verification | Account security and access | No | |
| Security messages | Email and eventually SMS | Protection of account and platform | No |
| Operational messages | Email and eventually SMS | Inform about relevant operations or technical matters | No |
| Newsletter or marketing | Marketing and news | Yes, only with consent |
Service messages are sent as part of the agreement with you, to deliver the service, to fulfil legal obligations, or to protect your account and the platform.
When the SMS function is implemented, SMS messages will only be used for necessary service messages, for example verification of phone number, security messages, or messages that an event is running low on storage.
SMS messages are not used for marketing without separate consent.
Newsletters and marketing are only sent if you have given consent.
16. Deletion Policy and Retention Periods
We only retain personal data for as long as it is necessary for the purposes for which it was collected, or for as long as we are obligated to do so by law.
16.1 Overall Overview
| Type of information | Normal retention period | Note |
|---|---|---|
| Photos and videos | Minimum 6 months after the event start date | May be retained longer if the host has chosen or previously agreed to longer storage. |
| Guest names | Normally together with the event | Deleted or anonymised when the event is deleted, unless there is a specific basis for longer retention. |
| Event information | As long as the event or account is active | May be deleted or anonymised upon account deletion. |
| Host account | As long as the account is active | Upon account deletion, the account is anonymised and media deleted when the deletion takes effect. |
| Invoices and accounting material | 5 years from the end of the financial year to which the material relates | Retained to comply with accounting rules. |
| Order and invoice history in account | As long as the account is active, if the user wishes access | Gives the user access to their own invoices and purchase history, even after 5 years, if the account remains active. |
| eazyAI conversations | Up to 90 days after last activity in the conversation | Automatically deleted upon inactivity in the conversation. |
| Phone number | Not yet implemented. When the SMS function is implemented: as long as the account is active, or as long as the information is necessary for service messages, security, and documentation | Phone number can be changed or removed by the user, unless continued retention is necessary for security, documentation, legal requirements, or legal claims. |
| SMS message data | Not yet implemented. When the SMS function is implemented: only as long as necessary | Used for documentation, troubleshooting, security, delivery status, and abuse prevention. |
| Ordinary technical logs | Rotated by default every 7 days | Used for operations, security, and troubleshooting. |
| Error logs | May be retained longer | Used for regression detection, security, stability, and troubleshooting. |
| Admin logs and documentation for administrative actions | As long as necessary for security, documentation, abuse prevention, or legal claims | May be retained longer than ordinary logs if necessary to document access, handle security incidents, or defend legal claims. |
| Database backups | 30 days | May contain information that has been deleted from active operations until the backup cycle expires. |
| Support enquiries | As long as necessary for the enquiry | May be retained longer for payment, security, abuse, rights, complaints, or legal claims. |
| Marketing consent | Until consent is withdrawn | Documentation of consent and unsubscription may be retained longer for documentation. |
16.2 Photos and Videos
Photos and videos are retained for a minimum of 6 months after the event start date.
Photos and videos may be retained longer if the host has chosen or previously agreed to a longer retention period.
When the agreed retention period expires, photos and videos are automatically deleted or according to the deletion process applicable to the event.
The host receives reminders about upcoming media deletion 30 days before, 7 days before, and 1 day before deletion.
Only the host has a direct download function. It is the host's responsibility to download event material before deletion if the host wishes to save it outside of eazy.photo.
When photos and videos have been deleted from active storage, they may for a limited period still appear in backups until the backup cycle expires.
16.3 Guest Names and Event Information
Guest names and event-related information are normally retained together with the event and deleted or anonymised when the event is deleted, unless there is a specific basis for longer retention.
16.4 Host Account
Information about a host account is retained as long as the account is active.
If you request account deletion, the account is anonymised and all associated media deleted when the deletion takes effect.
We may continue to retain information necessary for accounting, documentation, security, abuse prevention, or legal claims.
16.5 Invoices, Orders, and Purchase History
Accounting material, including invoices and bookkeeping-relevant information, is retained for 5 years from the end of the financial year to which the material relates.
Access to order and invoice history is a separate service purpose. This means we may make your invoices and purchase history available in your account as long as the account is active, even after the mandatory 5-year retention period, if you wish continued access to your invoices.
This is not a basis for retaining all other personal data. It only applies to information necessary to display order and invoice history, for example invoice number, date, amount, event package, payment status, and invoice document.
If you request account deletion, the account view that is no longer necessary is removed or anonymised. Mandatory accounting information continues to be retained to the extent required by law.
16.6 Logs
Ordinary technical logs are rotated by default every 7 days.
Error logs may be retained longer when necessary for troubleshooting, regression detection, security, stability, or documentation of technical events.
Admin logs and documentation for administrative actions may be retained longer than ordinary logs if necessary for security, documentation, abuse prevention, investigations, or legal claims.
Error logs, admin logs, and other documentation are deleted or anonymised when they are no longer necessary for the specific purpose.
16.7 Backups
Database backups are retained for 30 days.
Backups are used to be able to restore the system in the event of technical errors, security incidents, or data loss.
If information is deleted from active operations, it may still appear in backups for up to 30 days until the backup cycle expires.
We do not use backups to restore deleted personal data unless it is necessary in connection with a technical incident, security incident, or mandatory documentation.
16.8 Support Enquiries
Support enquiries are retained for as long as necessary to respond to the enquiry, document the proceedings, handle follow-up, improve the service, or handle any claims.
Enquiries relating to payment, security, abuse, rights, or complaints may be retained longer if necessary.
16.9 Marketing Consent
Information about newsletter and marketing is retained until you withdraw your consent.
Documentation of consent and unsubscription may be retained for a period after unsubscription if necessary to document that we have complied with the rules.
16.10 eazyAI Conversations
Conversations with eazyAI are stored for up to 90 days after last activity in the conversation.
The purpose is to make it possible for the host to continue a conversation and receive coherent assistance.
If the conversation is inactive for 90 days, the conversation is automatically deleted.
Photos and videos are not part of eazyAI conversations and are not sent to eazyAI or Google Gemini.
16.11 Phone Number and SMS Service Messages
SMS service messages have not yet been implemented.
When the SMS function is implemented, you can add and verify a phone number. We expect to use InMobile as SMS provider.
If you provide a phone number, we may use it for necessary service messages via SMS.
This may for example be verification of phone number, security messages, or messages that an event is running low on storage.
Phone number is retained as long as the account is active, or as long as it is necessary for service messages, security, documentation, or handling of abuse.
You can change or remove your phone number, unless we specifically have a need to retain the information longer for security, documentation, legal requirements, or legal claims.
SMS message data is only retained as long as necessary to document sending, troubleshoot delivery, handle security, or fulfil relevant obligations.
We do not use SMS for marketing without separate consent.
17. Deletion Before Expiry
You can contact us at hey@eazy.photo if you wish to have information about you deleted.
If you are a guest or person in a photo or video, we may ask you for information that makes it possible to find the relevant event and the specific material.
We assess deletion requests on a case-by-case basis.
We delete or restrict processing if the information is no longer necessary, if consent is withdrawn, if the processing is unlawful, or if your rights outweigh our basis for continued processing.
We may reject or limit deletion if continued retention is necessary to fulfil a legal obligation, document a legal claim, handle security incidents, prevent abuse, or protect other persons' rights.
18. Your Rights
Under data protection rules, you have a number of rights.
| Right | What does it mean? |
|---|---|
| Right of access | You can request access to the information we process about you. |
| Right to rectification | You can request that incorrect information be corrected. |
| Right to erasure | You may in certain cases request that information be deleted. |
| Right to restriction | You may in certain cases request that processing be restricted. |
| Right to object | You can object to processing based on legitimate interests. |
| Right to data portability | You may in certain cases receive information in a structured, commonly used, and machine-readable format. |
| Right to withdraw consent | If processing is based on consent, you can withdraw the consent. |
| Rights regarding automated decisions | You have the right not to be subject to automated decisions with legal effect or similarly significant impact. eazy.photo does not make such decisions. |
If you wish to exercise your rights, you can contact us at hey@eazy.photo.
We may ask for information necessary to verify your identity or find the relevant information.
19. Security
We apply appropriate technical and organisational security measures to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or deletion.
| Security measure | Description |
|---|---|
| Encryption in transit | Data is transferred via TLS/HTTPS. |
| Encryption at rest | Data is encrypted at rest where relevant. |
| Access control | Administrative systems are limited to authorised persons. |
| Limited admin access | Authorised administrators may access user accounts, event data, photos, videos, and other stored information when necessary for operations, support, security, legality checks, deletion, troubleshooting, or legal obligations. |
| Need-to-know | Admin access may only be used when there is a specific and substantive need. |
| Control of admin access | Administrative actions are logged or documented where relevant to protect users and investigate abuse or security incidents. |
| Token-based access | Events are accessed via event link, QR code, token, or other access mechanism. |
| EU/EEA hosting | Core platform and media storage are hosted in the EU/EEA. |
| Logging | Relevant technical events are logged for security and operations. |
| Rate limiting | Used to limit abuse and technical attacks. |
| Spam and bot protection | Self-hosted protection is used for relevant forms and functions. |
| Backups | Database backups are retained for 30 days. |
| Patching and maintenance | Systems are maintained and updated on an ongoing basis. |
| Deletion deadlines | Deletion deadlines and deletion processes are applied. |
| Automatic deletion of eazyAI conversations | eazyAI conversations are automatically deleted after up to 90 days of inactivity. |
| Phone verification | Not yet implemented. When the SMS function is implemented, phone verification is used to reduce the risk of an incorrect SMS recipient. |
| No AI image analysis | Photos and videos are not analysed by AI. |
| No facial recognition | eazy.photo does not use facial recognition. |
| No biometric identification | eazy.photo does not create biometric templates. |
| No marketing use of media without separate consent | eazy.photo does not use photos or videos for marketing, advertising, cases, social media, or product promotion without separate, voluntary, and explicit consent. |
| No third-party tracking | eazy.photo does not use Google Analytics, Meta Pixel, or marketing cookies. |
Security can never be fully guaranteed, but we work continuously to protect information as well as possible.
20. Personal Data Breaches
If we become aware of a personal data breach, we assess as quickly as possible the nature, scope, and risk of the incident for the affected persons.
We investigate, among other things, which information may be affected, which persons may be affected, whether the information has been accessed, altered, deleted, lost, or disclosed without authorisation, and what measures need to be taken.
If the breach is likely to result in a risk to persons' rights or freedoms, we report the breach to the Danish Data Protection Authority (Datatilsynet) without undue delay and as a rule no later than 72 hours after we have become aware of the breach.
If the breach is likely to result in a high risk to the affected persons, we also notify the affected persons without undue delay, unless the rules allow for individual notification to be omitted.
We document relevant security breaches, our assessment, the measures taken, and any reports or notifications.
21. Illegal or Offensive Content
It is not permitted to use eazy.photo for illegal, offensive, harassing, exploitative, or otherwise improper content.
If we are made aware of illegal or offensive content, we may remove or restrict access to the content, suspend functions, contact the host, retain necessary documentation, and in relevant cases report the matter to the authorities.
In such situations, we may process relevant personal data, including account information, logs, IP addresses, event information, and media content, to the extent necessary to investigate the matter, protect persons, enforce our terms, handle security, or comply with legislation.
Authorised administrators may in this connection review relevant content, including photos and videos, when necessary to assess legality, enforce terms, protect persons, or document incidents.
22. The Host's Practical Responsibility
Even though eazy.photo is the data controller for the processing in the platform, the host has a practical responsibility to use the platform responsibly.
| Host's responsibility | Why it is important |
|---|---|
| Inform participants about the use of eazy.photo | Participants should know that photos and videos may be uploaded and displayed. |
| Make it clear if guests can upload | Guests and participants should know the framework for the event. |
| Make it clear if shared gallery, live wall, or photo kiosk is active | These functions can display content more widely than just to the host. |
| Be particularly attentive to children and vulnerable persons | These groups require special protection. |
| Limit sharing of event link or QR code | Reduces the risk of unauthorised access. |
| Moderate and delete content | Content that should not be in the event should be removed. |
| Download event material before deletion | After deletion, the material cannot be expected to be recoverable. |
| Take responsibility for external use | When the host downloads, shares, or publishes the material outside of eazy.photo, the host is responsible for this use. |
| Keep contact information updated | If the SMS function is implemented, it is important that the host provides a correct phone number to receive relevant service messages. |
23. Shared Gallery, Live Wall, and Photo Kiosk
By default, events are private and accessible via event link, QR code, or other access mechanism.
The host may activate functions where photos and videos are displayed to persons other than the host.
| Function | What does the function do? | Who can see the content? |
|---|---|---|
| Shared gallery | Makes uploaded photos and videos visible in the event gallery. | Other guests in the same event, if the host has activated the function. |
| Live wall | Displays photos or videos on a screen, projector, or other live display. | Persons who can see the live wall screen. |
| Photo kiosk | Displays photos or videos in a kiosk view during the event. | Persons who use or can see the kiosk. |
| Host download | Gives the host the ability to download event material. | Only the host has a direct download function. |
If these functions are activated, photos and videos may be seen by persons present at the event or with access to the event.
Guest names are not shown on the live wall. Guest names may however be visible in shared gallery if the host has activated this function.
eazy.photo cannot prevent screenshots, screen recordings, or photographing of a live wall, photo kiosk, or the user's own screen.
24. Changes to the Privacy Policy
We may update this privacy policy if we change our processing of personal data, functions, providers, security measures, or legal obligations.
Material changes will be communicated to active hosts via email or in the application.
The current version will at all times be available at eazy.photo.
25. Complaint to the Data Protection Authority
If you believe that we are processing your personal data in violation of data protection rules, we would very much like you to contact us first at hey@eazy.photo, so that we can try to resolve the issue.
You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet).
| Authority | Contact |
|---|---|
| Datatilsynet | Carl Jacobsens Vej 35, 2500 Valby |
| Website | https://www.datatilsynet.dk |
26. Contact
If you have questions about this privacy policy, our processing of personal data, or your rights, you can contact us at:
| Information | Content |
|---|---|
| Company | eazy.photo |
| Address | Svanemosevej 19B, 9490 Pandrup, Denmark |
| CVR no. | DK33551592 |
| Website | https://eazy.photo |
| hey@eazy.photo |
Annex A: Record of Processing Activities
This annex describes eazy.photo's processing activities in a consolidated record.
The record can be used internally and can upon request be made available to the Danish Data Protection Authority (Datatilsynet).
A.1 General Information About the Data Controller
| Field | Information |
|---|---|
| Data controller | eazy.photo |
| CVR no. | DK33551592 |
| Address | Svanemosevej 19B, 9490 Pandrup, Denmark |
| Website | https://eazy.photo |
| hey@eazy.photo | |
| Phone | No public telephone contact |
| Data Protection Officer | Not appointed |
| Joint controllers | None for ordinary platform processing |
| EU representative | Not relevant, as eazy.photo is established in Denmark |
| Overall processing purpose | Operation of the eazy.photo platform, including event creation, photo and video sharing, payment, support, security, deletion, statistics, eazyAI, admin access, and legality checks. |
A.2 Overall Overview of Processing Activities
| No. | Processing activity | Primary purpose |
|---|---|---|
| A.3 | Account and access management | Create and administer host accounts and ensure access to the platform. |
| A.4 | Event creation and event administration | Create, administer, and operate events. |
| A.5 | Upload and display of photos and videos | Enable upload, storage, display, and download of event media. |
| A.6 | Admin access, operations, support, and legality checks | Ensure operations, support, security, troubleshooting, deletion, legality checks, and handling of legal obligations. |
| A.7 | Payment, invoice, and purchase history | Process payment, issue invoices, and fulfil bookkeeping obligations. |
| A.8 | eazyAI | Provide AI-based text assistance to event hosts. |
| A.9 | Support and service communication | Respond to enquiries and send necessary service messages. |
| A.10 | Security, logs, and abuse protection | Protect the platform, prevent abuse, and ensure stable operations. |
| A.11 | Website, cookies, and self-hosted statistics | Operate website and understand use of the service without third-party tracking. |
| A.12 | Newsletter and marketing | Send marketing on the basis of consent. |
| A.13 | SMS service messages and phone verification | Not yet implemented. When the function is implemented: send necessary SMS messages about phone verification, security, and low event storage. |
A.3 Processing Activity: Account and Access Management
| Field | Description |
|---|---|
| Purpose | Creation and administration of host accounts, login, access to the platform, secure identification of hosts, and administration of account settings. |
| Categories of data subjects | Event hosts. |
| Categories of personal data | Name, email address, login information, account status, technical access logs, IP address, and timestamps. When the SMS function is implemented, phone number may also be included if the host adds it themselves. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No, not as part of account and access management. |
| Legal basis | GDPR Article 6(1)(b) for performance of contract. GDPR Article 6(1)(f) for security and abuse prevention. |
| Recipients | Hosting and infrastructure providers, internally authorised personnel, and any authorities in the event of legal requirements or security incidents. |
| Third countries | No ordinary transfer outside the EU/EEA. |
| Deletion | Account information is retained as long as the account is active. Upon account deletion, the account is anonymised, unless information must be retained due to legal requirements, accounting, security, or legal claims. |
| Technical and organisational measures | Access control, TLS/HTTPS, logging, and need-to-know access. |
A.4 Processing Activity: Event Creation and Event Administration
| Field | Description |
|---|---|
| Purpose | Creation, operation, and administration of events, including event title, event description, access, storage, storage usage, and display functions. |
| Categories of data subjects | Event hosts, guests, and persons appearing in media. |
| Categories of personal data | Event title, event description, event date, event settings, storage usage, guest names, photos, videos, media metadata, access tokens, and technical logs. |
| Ordinary personal data | Yes. |
| Sensitive personal data | May occur if photos or videos visually reveal e.g. religion, political beliefs, health conditions, sexual orientation, or similar. |
| Legal basis | GDPR Article 6(1)(b) and (f). GDPR Article 9(2)(a), where special categories are processed on the basis of explicit consent. GDPR Article 9(2)(f), where processing is necessary for legal claims. |
| Recipients | Event host, guests if shared gallery is activated, persons viewing live wall or photo kiosk if the function is activated, and hosting and infrastructure providers. |
| Third countries | No transfer of photos or videos to third countries as part of normal platform operations. |
| Deletion | Photos and videos are retained for a minimum of 6 months after event start. Longer retention may occur upon prior agreement with the host. Media are deleted upon expiry of the retention period or upon account deletion when the deletion takes effect. |
| Technical and organisational measures | Private access via link, QR code, or token, TLS/HTTPS, access control, limited download function, possibility of deletion, no AI image analysis, no facial recognition, no biometric identification, and no marketing use of photos or videos without separate consent. |
A.5 Processing Activity: Upload and Display of Photos and Videos
| Field | Description |
|---|---|
| Purpose | To enable guests to upload photos and videos to an event, to enable the host to view, administer, and download event material, and to display media in shared gallery, live wall, or photo kiosk if the host activates these functions. |
| Categories of data subjects | Guests, event hosts, and persons appearing in photos or videos. |
| Categories of personal data | Guest name, photos, videos, file metadata, upload time, IP address, access logs, and event association. |
| Ordinary personal data | Yes. |
| Sensitive personal data | May occur as visual information in photos and videos. eazy.photo does not infer, categorise, or analyse such information. |
| Legal basis | GDPR Article 6(1)(b) and (f). GDPR Article 9(2)(a), where explicit consent has been given. GDPR Article 9(2)(f), where processing is necessary for legal claims. |
| Recipients | Event host, other guests in the same event if shared gallery is activated, persons viewing live wall or photo kiosk if the function is activated, and hosting and infrastructure providers. |
| Third countries | No transfer of photos or videos to eazyAI, Google Gemini, or third countries. |
| Deletion | Minimum 6 months after event start. Longer upon prior agreement with the host. Deletion upon account deletion when the deletion takes effect. Database backups are retained for 30 days. |
| Technical and organisational measures | Access control, private event access, limited download, deletion functions, encryption in transit, encryption at rest where relevant, no content analysis with AI, and no marketing use of media without separate consent. |
A.6 Processing Activity: Admin Access, Operations, Support, and Legality Checks
| Field | Description |
|---|---|
| Purpose | To ensure operations, support, security, troubleshooting, deletion, abuse prevention, legality checks, enforcement of terms, and fulfilment of legal obligations. |
| Categories of data subjects | Event hosts, guests, persons in photos or videos, support contacts, and website visitors. |
| Categories of personal data | Account information, event information, guest information, photos, videos, technical logs, payment status, support information, admin logs, case notes, and other information necessary for the specific task. |
| Ordinary personal data | Yes. |
| Sensitive personal data | May occur if photos or videos contain special categories of personal data, or if the user themselves submits sensitive information in a support or complaint case. |
| Legal basis | GDPR Article 6(1)(b), when access is necessary to deliver the agreed service. GDPR Article 6(1)(f), when access is necessary for operations, support, security, troubleshooting, abuse prevention, or legality checks. GDPR Article 6(1)(c), when access is necessary to comply with a legal obligation. GDPR Article 9(2)(f), where processing of sensitive information is necessary for legal claims. |
| Recipients | Internally authorised personnel, hosting and infrastructure providers, advisers, and authorities if necessary. |
| Third countries | No ordinary transfer outside the EU/EEA as part of admin access. |
| Deletion | Admin logs and documentation are retained as long as necessary for security, documentation, abuse prevention, investigations, or legal claims. |
| Technical and organisational measures | Need-to-know access, access control, limited administrative access, logging or documentation of relevant administrative actions, internal guidelines, and prohibition on access for private or irrelevant purposes. |
A.7 Processing Activity: Payment, Invoice, and Purchase History
| Field | Description |
|---|---|
| Purpose | Processing of payment, delivery of event packages, issuance of receipts and invoices, accounting, bookkeeping, and access to invoice and purchase history. |
| Categories of data subjects | Event hosts and customers. |
| Categories of personal data | Name, email address, order number, invoice number, amount, VAT, payment status, purchase date, event package, and payment reference. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No. |
| Legal basis | GDPR Article 6(1)(b) for purchase and delivery. GDPR Article 6(1)(c) for accounting and bookkeeping. GDPR Article 6(1)(f) for access to history and documentation. |
| Recipients | MobilePay, accountant or bookkeeping system if relevant, and public authorities if required by law. |
| Third countries | No ordinary transfer outside the EU/EEA. |
| Deletion | Accounting material is retained for 5 years from the end of the financial year to which the material relates. Invoice and purchase history may be available longer for the user, as long as the account is active, if the user wishes access. |
| Technical and organisational measures | Access control, limited access, and accounting documentation. |
A.8 Processing Activity: eazyAI
| Field | Description |
|---|---|
| Purpose | AI-based assistance to event hosts, answering questions about use of the platform, and assistance with event-related texts, descriptions, and functions. |
| Categories of data subjects | Event hosts. |
| Categories of personal data | Host's name, event titles, event descriptions, basic event statistics, potential purchase history or order status, text input from the host, conversation history, and technical information necessary for the AI function. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No, not intended. Users should not enter sensitive information in eazyAI. |
| Legal basis | GDPR Article 6(1)(b) and (f). |
| Recipients | Google Gemini. |
| Third countries | Possible processing outside the EU/EEA via Google Gemini. Relevant transfer safeguards are applied. |
| Deletion | Conversations with eazyAI are stored for up to 90 days after last activity and are then automatically deleted upon inactivity. Other relevant context is only retained as long as necessary for functionality, troubleshooting, security, and documentation. |
| Technical and organisational measures | No access to photos or videos, no image analysis, no facial recognition, no AI training on photos or videos, automatic deletion after inactivity, no automated decisions with legal effect, and paid Gemini/API configuration without training on user data according to Google's current terms. |
A.9 Processing Activity: Support and Service Communication
| Field | Description |
|---|---|
| Purpose | Responding to enquiries, technical support, account and event assistance, documentation of enquiries, and sending of necessary service messages. |
| Categories of data subjects | Event hosts, guests, persons in photos or videos, and other persons who contact eazy.photo. |
| Categories of personal data | Name, email address, enquiry content, event reference, technical information, and documentation of requests. When the SMS function is implemented, phone number may be included for relevant service messages. |
| Ordinary personal data | Yes. |
| Sensitive personal data | Only if the user themselves sends such information, or if necessary for a specific case. |
| Legal basis | GDPR Article 6(1)(b), (c), and (f). For sensitive information, GDPR Article 9(2)(f) may be applied if processing is necessary for legal claims. |
| Recipients | Internally authorised personnel and any advisers or authorities in case of specific need. When the SMS function is implemented, InMobile may receive necessary SMS data. |
| Third countries | No ordinary transfer outside the EU/EEA for email-based service communication. For SMS, InMobile's processing and any sub-processors will be assessed before the function is implemented. |
| Deletion | Deleted or anonymised when the enquiry is no longer necessary. May be retained longer for payment, complaints, security, abuse, or legal claims. |
| Technical and organisational measures | Access restriction, need-to-know, secure email handling via own infrastructure, and no SMS marketing without separate consent. |
A.10 Processing Activity: Security, Logs, and Abuse Protection
| Field | Description |
|---|---|
| Purpose | Protection of the platform, prevention of abuse, spam, and unauthorised access, troubleshooting, regression detection, and documentation of technical events. |
| Categories of data subjects | Event hosts, guests, visitors, and persons interacting with the platform. |
| Categories of personal data | IP address, timestamps, access logs, error logs, admin logs, user agent, technical events, rate limit data, and spam or bot protection data. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No, not intended. |
| Legal basis | GDPR Article 6(1)(f). GDPR Article 6(1)(c) for legal requirements. |
| Recipients | Hosting and infrastructure providers, internally authorised personnel, and authorities in the event of legal requirements or serious security incidents. |
| Third countries | No ordinary transfer outside the EU/EEA. |
| Deletion | Ordinary logs are rotated by default every 7 days. Error logs and admin logs are retained longer when necessary for regression detection, security, troubleshooting, documentation, or legal claims. Database backups are retained for 30 days. |
| Technical and organisational measures | Log rotation, access control, rate limiting, spam and bot protection, monitoring, backup, and control of admin access. |
A.11 Processing Activity: Website, Cookies, and Self-Hosted Statistics
| Field | Description |
|---|---|
| Purpose | Operation of website, necessary functions, sessions, security, and self-hosted statistics to improve the service. |
| Categories of data subjects | Website visitors, event hosts, and guests. |
| Categories of personal data | Technical cookies, session data, IP address, usage data, browser information, and timestamps. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No. |
| Legal basis | GDPR Article 6(1)(f). Consent, if non-necessary cookies are introduced at a later stage. |
| Recipients | No third-party tracking recipients. Self-hosted Umami and self-hosted Mosparo. |
| Third countries | No ordinary transfer outside the EU/EEA. |
| Deletion | According to cookie policy and technical deletion deadlines. |
| Technical and organisational measures | No Google Analytics, no Meta Pixel, no third-party tracking cookies, only necessary cookies, and self-hosted statistics. |
A.12 Processing Activity: Newsletter and Marketing
| Field | Description |
|---|---|
| Purpose | Sending of newsletter and marketing to persons who have given consent, and documentation of consent. |
| Categories of data subjects | Event hosts and other persons who give consent. |
| Categories of personal data | Name, email address, consent status, time of consent, time of unsubscription, and documentation of consent. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No. |
| Legal basis | GDPR Article 6(1)(a). |
| Recipients | No external email provider for ordinary sending, as emails are sent via own infrastructure. |
| Third countries | No ordinary transfer outside the EU/EEA. |
| Deletion | Until consent is withdrawn. Documentation may be retained after unsubscription as long as necessary to document compliance. |
| Technical and organisational measures | Consent registration, unsubscription option, limited access, and no use of uploaded photos or videos for marketing without separate consent. |
A.13 Processing Activity: SMS Service Messages and Phone Verification
This processing activity has not yet been implemented.
When the SMS function is implemented, InMobile is expected to be used as SMS provider.
| Field | Description |
|---|---|
| Status | Not yet implemented. |
| Expected provider | InMobile. |
| Purpose | To be able to send necessary service messages via SMS, including verification of phone number, security messages, and messages that an event is running low on storage. |
| Categories of data subjects | Event hosts. |
| Categories of personal data | Phone number, verification code, verification status, time of verification, event status, storage usage, SMS message data, and technical delivery information. |
| Ordinary personal data | Yes. |
| Sensitive personal data | No. |
| Legal basis | GDPR Article 6(1)(b) for delivery of the service and Article 6(1)(f) for our legitimate interest in ensuring the host receives important operational, security, and capacity messages. |
| Recipients | InMobile, when the SMS function is implemented. |
| Third countries | Assessed before implementation on the basis of InMobile's current data processing, sub-processors, and any transfers. If processing outside the EU/EEA is used, relevant transfer bases and safeguards are applied. |
| Deletion | Phone number is retained as long as the account is active, or as long as necessary for service messages, security, and documentation. SMS message data is only retained as long as necessary for documentation, troubleshooting, security, or abuse prevention. |
| Technical and organisational measures | Phone verification, access control, limited access, logging of relevant delivery events, and no use of SMS for marketing without separate consent. |
Annex B: Written Security Assessment and Impact Analysis
This annex describes eazy.photo's overall security assessment and data protection impact analysis.
The assessment covers the processing activities that take place in the eazy.photo platform, including processing of ordinary personal data, photos, videos, possible sensitive information, technical logs, payment, admin access, eazyAI, and deletion.
SMS service messages have not yet been implemented, but are included in the assessment as a planned future function.
B.1 Purposes of Processing
| Purpose | Description |
|---|---|
| Event-based photo and video sharing | To enable hosts to create events, invite guests, receive photos and videos, and administer event material. |
| Display of event material | To enable display via shared gallery, live wall, or photo kiosk if the host activates these functions. |
| Account and payment | To deliver account, purchase, payment, receipt, invoice, and access to purchase history. |
| Admin access and operations | To ensure operations, support, troubleshooting, deletion, security, legality checks, enforcement of terms, and fulfilment of legal obligations. |
| Security and operations | To ensure stable operations, troubleshooting, abuse protection, logging, and backups. |
| Support and service | To help users and send necessary messages. |
| eazyAI | To give hosts AI-based text assistance without access to photos or videos. |
| SMS service messages | Not yet implemented. When the function is implemented: to send necessary SMS messages about phone verification, security, and low event storage via InMobile. |
| Marketing | To send newsletter or marketing to persons who have given consent. Uploaded photos and videos are not used for marketing without separate, voluntary, and explicit consent. |
B.2 Necessity and Proportionality
| Processing | Assessment |
|---|---|
| Name, email, account, and login | Necessary to create account, provide access, and deliver the service. |
| Event information | Necessary to create and administer events. |
| Guest names | Necessary to identify uploads in the event and give the host an overview. |
| Photos and videos | Necessary for the platform's core function. |
| Admin access to accounts, events, photos, and videos | Necessary to a limited extent for operations, support, security, troubleshooting, deletion, legality checks, and legal obligations. Access is limited by need-to-know. |
| Photos and videos for marketing | Not necessary for the platform's core function and therefore does not take place without separate, voluntary, and explicit consent. |
| IP addresses and logs | Necessary for security, operations, troubleshooting, and abuse protection. |
| Invoice and payment information | Necessary for payment, accounting, and documentation. |
| eazyAI text data | Limited to text-based information and only when the host uses the function. |
| eazyAI conversation history | Necessary to be able to continue a conversation and provide coherent assistance, but retained for a maximum of 90 days after last activity. |
| Photos and videos to AI | Not necessary and therefore not part of the processing. |
| Phone number for SMS service messages | Not yet implemented. When the function is implemented, phone number is necessary to send phone verification and important SMS service messages. |
| SMS for low storage | Not yet implemented. Assessed as proportionate, because the message can help the host avoid interruption or loss of event functionality. |
| SMS for marketing | Not necessary for service purposes and not used without separate consent. |
Photos and videos are not sent to AI and are not used for biometric identification, profiling, or marketing without separate consent. This reduces the risk significantly.
Admin access to accounts, events, photos, videos, and other data is limited to situations where access is necessary and substantively justified. This reduces the risk of internal access.
B.3 Key Risks and Measures
| No. | Risk | Possible consequences | Measures |
|---|---|---|---|
| B.3.1 | Unauthorised access to private events | Unauthorised persons may see photos, videos, or event information. | Private access via event link, QR code, or token, access control, logs, abuse protection, and information to the host about limited sharing. |
| B.3.2 | Photos and videos may contain sensitive information | Violation of privacy or unwanted sharing of sensitive circumstances. | No AI image analysis, no facial recognition, no biometric identification, private galleries, deletion functions, consent/acceptance before upload, and special information about sensitive information. |
| B.3.3 | Persons in photos have not themselves used eazy.photo | The person does not know about the processing or does not wish to appear. | Guests accept privacy information before upload, the host should inform participants, and persons can contact eazy.photo for deletion or restriction. |
| B.3.4 | Live wall and photo kiosk can display content widely | Content may be displayed for persons who should not see it. | The function is activated by the host, guest names are not shown on the live wall, the host should inform participants and moderate content. |
| B.3.5 | Screenshots and external use | Photos can be copied and shared outside of eazy.photo. | Guests have no direct download function, only the host has a download function, and the policy clearly informs about screenshot risk. |
| B.3.6 | Children and minors | Children's privacy may be violated, and parents/guardians may be uninformed. | Host account requires 18 years, the policy recommends informing parents/guardians, and deletion or restriction is possible. |
| B.3.7 | AI and transfer to third countries | Text input may contain personal data, and data may be processed outside the EU/EEA. | eazyAI is only for hosts, photos and videos are not sent, users are encouraged not to enter sensitive information, and relevant transfer safeguards are applied. |
| B.3.8 | Deletion does not occur in time | Information may be retained longer than necessary. | Deletion policy, specific deadlines, deletion reminders, account deletion with anonymisation and deletion of media, 30-day database backup, log rotation, and automatic deletion of eazyAI conversations after 90 days of inactivity. |
| B.3.9 | Unauthorised internal access | Breach of confidentiality or misuse of information. | Need-to-know access, limited administrative access, access control, logs, and internal guidelines. |
| B.3.10 | Illegal or offensive content | Harm to persons, illegal sharing, or security risk. | Prohibition on illegal content, possibility of deletion/restriction, documentation, admin review when substantively necessary, and reporting to authorities where relevant. |
| B.3.11 | Use of photos or videos for marketing without sufficient basis | Violation of privacy, loss of control over one's own image, insufficient consent, or increased risk with sensitive information. | eazy.photo does not use photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent. |
| B.3.12 | SMS service messages and phone number | Phone number can become an additional identifier, and SMS can be sent to the wrong number if the number is entered incorrectly. | Not yet implemented. When the function is implemented: phone verification, limited use of SMS for service messages, possibility of changing or removing phone number, InMobile as expected provider, and no SMS marketing without separate consent. |
| B.3.13 | Storage of eazyAI conversations | AI conversations may contain personal data that the host enters themselves. | Conversations are automatically deleted after up to 90 days of inactivity, users are encouraged not to enter sensitive information, and photos/videos are not part of AI conversations. |
| B.3.14 | Internal admin access to user accounts, events, photos, and videos | Administrators may technically gain access to personal data, including photos and videos, which may contain sensitive information. Misuse or unauthorised access may violate privacy and confidentiality. | Admin access is limited to authorised persons, only used when there is a specific and substantive need, managed according to the need-to-know principle, used for operations, support, security, legality checks, and legal obligations, and administrative actions are logged or documented where relevant. |
| B.3.15 | Sensitive information under Article 9 | Photos and videos may contain or reveal special categories of personal data. | eazy.photo does not infer sensitive circumstances, does not use AI image analysis, does not use facial recognition, processes upload with explicit consent where relevant, and may delete or restrict content after specific assessment. |
B.4 Elaboration of Key Risks
B.4.1 Unauthorised Access to Private Events
If an event link, QR code, or token is shared more widely than intended, unauthorised persons may gain access to the event.
| Possible consequences | Measures |
|---|---|
| Unauthorised persons may see photos or videos. | Private access via event link, QR code, or token. |
| Unauthorised persons may see guest names in shared gallery, if the function is activated. | The host should only share access with relevant participants. |
| Unauthorised persons may misuse access to the event. | Logs, abuse protection, and possibility of deleting or restricting event content. |
B.4.2 Photos and Videos May Contain Sensitive Information
Photos and videos may show circumstances that may be sensitive, for example religion, political symbols, sexuality, health, or vulnerable situations.
| Possible consequences | Measures |
|---|---|
| Violation of privacy. | No AI analysis of photos or videos. |
| Unwanted sharing of sensitive circumstances. | No facial recognition, no biometric identification, and no categorisation according to sensitive circumstances. |
| Discomfort or harm to persons in photos or videos. | Private galleries by default, possibility of deletion, and information to users. |
| Unwanted use in marketing or cases. | No use of photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent. |
| Need for handling under Article 9. | Article 9 is included, including explicit consent where relevant and Article 9(2)(f) for legal claims. |
B.4.3 Persons in Photos Have Not Themselves Used eazy.photo
Guests may upload photos or videos of persons who have not themselves interacted with the platform.
| Possible consequences | Measures |
|---|---|
| The person does not know about the processing. | The host should inform participants about the use of eazy.photo. |
| The person does not wish to appear in event material. | Persons can contact eazy.photo for deletion or restriction. |
| The person may be a minor or vulnerable. | The host should be particularly attentive to children and vulnerable persons. |
| The person does not wish to appear in marketing. | eazy.photo does not use the material for marketing without separate, voluntary, and explicit consent. |
B.4.4 Live Wall and Photo Kiosk Can Display Content Widely
Live wall and photo kiosk can display photos and videos to persons present at the event.
| Possible consequences | Measures |
|---|---|
| Content is displayed for persons who should not see it. | The function must be activated by the host. |
| Unwanted photos may be displayed shortly after upload. | The host should use moderation and delete content that should not be displayed. |
| Photos can be photographed or recorded from the screen. | eazy.photo informs that screenshots and screen recordings cannot be prevented. |
B.4.5 AI and Transfer to Third Countries
eazyAI is powered by Google Gemini and may involve processing of text-based information at Google.
| Possible consequences | Measures |
|---|---|
| Text input may contain personal data. | eazyAI can only be used by hosts, and users are encouraged not to enter sensitive information. |
| Data may be processed outside the EU/EEA. | Relevant transfer safeguards are applied. |
| AI output may be imprecise. | eazyAI does not make automated decisions with legal effect. |
| Photos or videos could pose a special risk if sent to AI. | Photos and videos are not sent to eazyAI or Google Gemini. |
| Photos or videos could be used for AI training. | Photos and videos are not used for AI training. |
| Conversations may contain personal data entered by the host. | Conversations are automatically deleted after up to 90 days of inactivity. |
B.4.6 SMS Service Messages and Phone Number
SMS service messages have not yet been implemented.
When the SMS function is implemented, InMobile is expected to be used as SMS provider.
| Possible consequences | Measures |
|---|---|
| SMS is sent to wrong number if phone number is entered incorrectly. | Phone verification before use of SMS service messages. |
| Phone number becomes an additional identifier. | Phone number is only used for necessary service messages, security, and documentation. |
| SMS provider processes message data. | InMobile is expected to be used as provider, and data processing is assessed before implementation. |
| SMS may be perceived as marketing if the purpose is unclear. | SMS is not used for marketing without separate consent. |
| User does not wish to receive SMS. | Phone number can be changed or removed, unless continued retention is necessary for security, documentation, legal requirements, or legal claims. |
B.4.7 Internal Admin Access
Authorised administrators may technically gain access to user accounts, event data, photos, videos, logs, and other information.
| Possible consequences | Measures |
|---|---|
| Unauthorised internal access may violate privacy. | Admin access is limited to authorised persons and specific substantive needs. |
| Photos or videos may contain sensitive information. | Internal access to photos and videos is particularly limited and only used when necessary for operations, support, security, deletion, legality checks, or legal obligations. |
| Lack of documentation for access can make incidents difficult to investigate. | Administrative actions are logged or documented where relevant. |
| Administrators may see information that is not necessary for a task. | The need-to-know principle is applied. |
| Admin access may be misused for irrelevant purposes. | Admin access must not be used for private purposes, curiosity, marketing, or irrelevant review. |
B.5 Overall Risk Assessment
| Risk area | Assessment before measures | Assessment after measures |
|---|---|---|
| Ordinary account information | Low to moderate | Low |
| Payment and invoice | Moderate | Low to moderate |
| Photos and videos | Elevated | Moderate |
| Possible sensitive information in media | Elevated | Moderate |
| Children and minors | Elevated | Moderate |
| Live wall and photo kiosk | Elevated | Moderate |
| Screenshots and external sharing | Elevated | Moderate to elevated |
| Admin access to accounts, events, photos, and videos | Elevated | Moderate |
| Marketing use of photos or videos | Elevated | Low, because eazy.photo does not use media for marketing without separate, voluntary, and explicit consent |
| eazyAI text processing | Moderate | Low to moderate |
| eazyAI conversation history | Moderate | Low to moderate |
| SMS service messages and phone number | Moderate | Low to moderate, when phone verification, limited use, and provider assessment are implemented |
| Technical logs and security | Moderate | Low to moderate |
The overall risk is assessed as moderate to elevated, because the platform processes photos and videos of persons, and because such material may contain sensitive information, children, or third parties.
The risk is significantly reduced by eazy.photo:
| Reducing circumstances |
|---|
| Not using AI to analyse photos or videos. |
| Not using facial recognition. |
| Not creating biometric templates. |
| Not using photos for profiling. |
| Not sending photos or videos to Google Gemini. |
| Not using uploaded photos or videos for marketing, advertising, cases, social media, product promotion, or AI training without separate, voluntary, and explicit consent. |
| Including Article 9 bases for sensitive information, including explicit consent where relevant and legal claims where necessary. |
| Limiting admin access to specific substantive needs and need-to-know. |
| Logging or documenting administrative actions where relevant. |
| Automatically deleting eazyAI conversations after up to 90 days of inactivity. |
| By default using private event links, QR codes, and tokens. |
| Limiting download function to the host. |
| Having deletion deadlines and deletion reminders. |
| Using EU/EEA hosting for the core platform. |
| Using encryption, access control, logs, backups, and abuse protection. |
| Marking SMS service messages as not yet implemented and assessing InMobile and relevant security measures before implementation. |
The remaining risk cannot be completely eliminated, especially because users themselves upload photos and videos, because visible content can be copied via screenshots or displayed on live wall or photo kiosk, and because authorised administrators may to the necessary extent gain access to information for the purpose of operations, support, security, and legality checks.
B.6 Conclusion of Impact Analysis
eazy.photo assesses that the processing can be carried out with the described technical and organisational measures.
The processing requires ongoing attention, especially when:
| Situation | Why does it require attention? |
|---|---|
| Events with children | Children have special protection, and photos of children require extra care. |
| Public or commercial events | There may be a larger number of participants and greater risk of unexpected photo sharing. |
| Activation of shared gallery | More persons can see uploaded content. |
| Activation of live wall or photo kiosk | Content may be displayed widely in a physical space. |
| Handling of deletion requests | Requires specific assessment and the possibility of finding relevant material. |
| Admin access to user accounts, events, photos, and videos | Requires need-to-know, substantive justification, access control, and relevant documentation. |
| Use of eazyAI | Text input may contain personal data, and Google Gemini may involve transfer to third countries. |
| Storage of eazyAI conversations | Conversations may contain personal data but are automatically deleted after up to 90 days of inactivity. |
| Changes in providers or infrastructure | May change the risk picture and require updating of the assessment. |
| Implementation of SMS service messages via InMobile | The function has not yet been implemented and should be finally assessed before launch, including provider relationships, deletion deadlines, security, and any transfers to third countries. |
| New functions that affect photo or video processing | May require a new assessment before launch. |
| Any future use of photos or videos for marketing | May only take place after separate, voluntary, and explicit consent from the relevant persons and should be assessed separately before use. |
If eazy.photo later introduces facial recognition, automatic image analysis, biometric identification, public searchability, guest download, external marketing tracking, marketing use of event media without separate consent, or new AI functions, this assessment must be updated before the function is put into operation.
When SMS service messages are implemented via InMobile, the record, provider overview, cookie or communication information, and security assessment must be updated if the actual processing deviates from what is described here.