Privacy Policy
Thank you for your interest in aftersnap. Protecting your personal data matters to us. Below we set out, in accordance with the General Data Protection Regulation (GDPR), how personal data is processed when you use our platform.
1. Controller
Danyel André Maus
Cami des Jardi d'en Ferrer 72
ES-07141 Marratxí, Spain
Email: [email protected]
The contact for questions about data protection is the controller named above; there is no legal requirement to appoint a data protection officer.
2. General points and legal bases
We process personal data only as far as required. Depending on the processing, the legal bases are chiefly Art. 6(1)(b) GDPR (contract and pre-contractual steps), (a) (consent), (c) (legal obligation) and (f) (legitimate interest), and, for special categories of data such as biometric data, Art. 9(2)(a) GDPR (explicit consent).
3. Hosting and technical provision
Our application and the data belonging to it run at service providers in the European Union: web hosting at ALL-INKL.COM (Neue Medien Münnich, EU), computing and processing capacity at Hetzner Online GmbH (EU), and object storage for uploaded original photos at Impossible Cloud GmbH (EU). The computation-heavy AI analysis (see section 9) runs there as well, on computing capacity we operate with these providers within the EU. For these analyses a reduced-size copy of the photos (the “analysis image”) is created and stored with the object storage provider named above (Impossible Cloud, EU). Data processing agreements under Art. 28 GDPR are in place with these providers.
For delivery through customers’ own domains and as a security and proxy layer (protection against overload and DDoS attacks, TLS encryption, content delivery, among other things) we use Cloudflare, Inc. (USA). Cloudflare processes IP addresses, connection and TLS handshake data, browser and device details and security logs in doing so. Personal data may also be transferred to the USA as part of this (see section 17).
We deliver the preview images of public galleries through the content delivery network of BunnyWay d.o.o. (bunny.net, Slovenia). This involves your IP address together with details of the request such as the time, the image requested and the browser type; the provider shortens the IP address in its logs. Delivery is limited to locations within the European Union, so no transfer to a third country takes place. Images from password-protected galleries, from drafts and from expired galleries stay on our own servers. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in delivering galleries with many photos quickly and reliably). A data processing agreement under Art. 28 GDPR is in place.
4. Server log files
When the platform is called up, technically necessary access data is processed (IP address, date and time, the resource requested, browser and system details). This serves secure and stable operation (Art. 6(1)(f) GDPR) and is stored only for a limited period, usually a few days, at most 30.
5. Cookies and local storage
We use technically necessary cookies and local storage, for the session (login), for protection against cross-site request forgery (CSRF) and for functional settings. The legal basis is Art. 6(1)(f) GDPR and, where information is stored on or read from your device, Art. 22.2 LSSI-CE (strict necessity). Third-party advertising and statistics cookies are used only on our information pages and only with your consent (see below, “Advertising tracking with consent”). There is no advertising tracking in photographers’ galleries or in the dashboard.
When you register, we record in your account which campaign brought you to us: the parameters utm_source, utm_medium, utm_campaign, utm_content and utm_term from the address you opened. Until you register they are held only in your session on our server; we set no cookie of our own for this. The purpose is measuring how well our own advertising works. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in assessing the effectiveness of our own advertising). We build no profile from this, and no third party receives it. After 24 months we delete it (section 18).
How often our public pages are opened is measured with Matomo on a server of our own at Hetzner Online GmbH (EU, see section 3). The measurement runs on our server, not in your browser: we only evaluate what reaches us with the request anyway: the address opened, the page visited before, browser and device type, and your IP address, which is shortened straight away. Nothing is stored on your device for this and nothing is read from it; there is no analytics cookie and no measurement JavaScript. We build no profile from this, and the data does not leave our server. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in knowing which content is found and read). If your browser sends “Do Not Track” or “Global Privacy Control”, we do not count the visit. We do not measure the photographers’ galleries. After 24 months we delete the measurement data (section 18).
Advertising tracking with consent. On our information pages (aftersnap.io without the dashboard and without galleries) a banner asks you on your first visit whether we may use services to measure whether our advertising works. Without your consent none of these services is loaded and no such cookie is set; “Decline” is as easy as “Accept”, and the site works the same either way. Category marketing: the Meta Pixel of Meta Platforms Ireland Ltd., Dublin (characteristics of the visit and of a sign-up, cookies _fbp and _fbc; for the collection we and Meta are joint controllers under Art. 26 GDPR, the essence of the arrangement is at facebook.com/legal/controller_addendum; Meta alone is responsible for the further processing) and Google Ads via Google Tag Manager of Google Ireland Ltd., Dublin (conversion measurement, cookies _gcl_*). Category statistics: Google Analytics 4 of Google Ireland Ltd. (usage statistics of our information pages, cookies _ga*, IP address shortened). After a sign-up we additionally transmit the event “registration completed” server-side to Meta or Google, only with the consent given for that category and only with a hashed email address, a shortened IP address and the click identifier from the cookie. Both providers may transfer data to the USA; the basis is the EU-U.S. Data Privacy Framework (section 17). The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you can withdraw or change it at any time with effect for the future via the “Cookie settings” link in the footer. We store your decision in a cookie (aftersnap_consent, twelve months) and record it without personal reference (time, version, decision, shortened IP address) for three years as evidence. If the services we use change, we ask again.
6. Photographer accounts
For use as a photographer we process account and contact data (name, email and the password, which is stored solely as a cryptographic hash) and, for billing, invoicing data (company, address, VAT ID). The legal basis is Art. 6(1)(b) GDPR; retention duties under tax and commercial law (point (c)) are unaffected. This data is needed to set up the account and to perform the contract; without it the account cannot be created and the contract cannot be performed.
7. Galleries and uploaded photos (processing on behalf of a controller)
Photographers upload photos and make them available to their clients as an online gallery. Where people are pictured in those photos, we process the photos on behalf of the photographer concerned; in data protection terms, the photographers are the controllers for that content. aftersnap processes the photos solely on documented instructions from the photographer concerned. We do not receive the personal data of the people pictured from them directly, but through the photographer who uploads it. This is governed by a data processing agreement (see the Data Processing Agreement).
8. Gallery guests and downloads
When a gallery is called up, we process the technical data needed to deliver it. For password-protected galleries the password entered is checked (Art. 6(1)(b) GDPR). If a guest requests a ZIP download, we process the email address given solely in order to notify them that the file is ready (Art. 6(1)(b)/(f) GDPR).
9. AI features: face search, content and person analysis (biometric data included)
Where the feature is switched on for a gallery, guests can upload a selfie to find the photos they appear in automatically. This processes biometric characteristics, a special category of data within the meaning of Art. 9 GDPR. The processing takes place only after explicit consent (Art. 9(2)(a) GDPR). The selfie is processed solely on our own servers in the EU, held only for as long as the analysis takes and deleted automatically once the search has finished; it is not stored permanently. It serves only to find the guest again in the photos within that gallery and is not used across galleries; unknown people are not identified. To make the search possible, the facial characteristics of the gallery photos are analysed in advance and held as biometric comparison patterns; these serve only for matching within the same gallery and are not used across galleries. This analysis, too, runs on our own servers in the EU (see section 3). Consent is voluntary and can be withdrawn at any time with effect for the future; without consent the gallery works as normal.
A photographer can also switch on AI-assisted content and person analysis for a gallery. An AI assigns the photos to picture contents automatically (subjects such as cake, flowers or dancing) and groups similar faces within the same gallery into people the photographer or their client can name; guests can then filter the gallery by content or by person. Grouping faces processes biometric characteristics (Art. 9 GDPR). It happens gallery by gallery only (no matching across galleries, no identification of unknown people) and, like the rest of the photo processing, on behalf of the photographer, who is responsible for the legal basis towards the people pictured. The analyses run on our own infrastructure in the EU (see section 3). No automated decision with legal effect is involved (see section 20).
10. Vendor portal
Where photographers invite vendors (to make a photo selection, for example), we process the contact details of those vendors and a record of their agreement to the applicable terms (for evidence, Art. 6(1)(b)/(f) GDPR).
11. Sending email
To provide the Service we send emails (gallery links, notifications, system messages). For evidence and operational purposes we log the sending to a reasonable extent (Art. 6(1)(b)/(f) GDPR).
12. Contact form
The form on our contact page lets you write to us without having an account. We process the details you enter yourself: name, email address, subject and the text of your message. These details go to our mailbox as an email and are handled there like any other enquiry; we do not store them in a database on top of that.
The sole purpose is to answer your enquiry. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering enquiries); where the enquiry concerns an existing or prospective contract, Art. 6(1)(b) GDPR applies in addition. We delete the message once it has been dealt with, unless statutory retention periods stand in the way.
To guard against automated submissions, the form contains a field that is invisible to you and measures how long it took to fill in. We also limit the number of submissions per IP address. No profiles are created in the process, and no data is passed to third parties.
13. Payment processing and invoicing
For paid plans we use Stripe Payments Europe, Ltd. (Ireland) as our payment service provider. When the payment page is called up, we pass Stripe your email address, your name or company and your billing address (street, postcode, town, country). Payment details such as card numbers are entered at Stripe only; they never reach our servers and we neither store nor process them. From Stripe we receive no more than the information whether a payment succeeded, together with the last four digits and the type of the payment method used. The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Stripe is a subsidiary of Stripe, Inc. (USA); on transfers to third countries see section 17.
For bookkeeping and to meet retention duties under tax law, we pass the invoicing data to sevDesk GmbH (Offenburg, Germany). That covers your name or company, your billing address, the invoice number, the services billed and the amounts. The legal basis is Art. 6(1)(c) GDPR (compliance with a legal obligation, in particular § 14b UStG, § 147 AO and § 257 HGB for supplies taxable in Germany). Data processing agreements under Art. 28 GDPR are in place with both providers.
14. Connecting a Google Business Profile
Photographers can connect their Google Business Profile through the Google Business Profile API by OAuth, if they wish. After explicit authorisation in the Google account, we access data from your own business listing only as far as required, in particular location and review data (including the Google location ID and the review link), in order to provide the review link and, where switched on, to show the overall rating on the profile page. The legal basis is your consent or the performance of the contract (Art. 6(1)(a)/(b) GDPR).
We use data received from Google APIs solely to provide or improve these user-facing features. We do not sell this data, do not use it for advertising and do not pass it on, except where this is necessary to provide the feature, required by law or expressly requested by you. Google data is used in line with the Google API Services User Data Policy, including the Limited Use requirements. The provider is Google Ireland Limited or Google LLC; personal data may be processed outside the EU as part of this, in particular in the USA (see section 17). The Google privacy notice applies in addition. The connection can be withdrawn at any time in the account (“Disconnect”) and in the security settings of your Google account.
15. Your own domain
If you connect your own (sub)domain, delivery is handled technically through Cloudflare (see section 3). This processes the connection data needed for delivery and TLS encryption, in particular the IP address; personal data may also be transferred to the USA (Art. 6(1)(b)/(f) GDPR, see section 17).
16. Recipients and processors
To provide the Service we use carefully chosen service providers as processors, amongst them: ALL-INKL.COM (web hosting and email, EU), Hetzner Online GmbH (processing, EU), Impossible Cloud GmbH (object storage, EU), BunnyWay d.o.o. (image delivery, Slovenia), Cloudflare, Inc. (CDN and proxy, USA), Stripe Payments Europe, Ltd. (payment processing, Ireland) and sevDesk GmbH (bookkeeping, EU). Where the Google connection is used, Google (Ireland/USA) in addition. For our own content (email templates, the music in our sound library and the contracts with our providers) we also use AI services from Anthropic, PBC, OpenAI, LLC and ElevenLabs, Inc. (each USA, EU standard contractual clauses); photos, galleries and customer data are never sent there. Advertising and analytics services (Meta Platforms Ireland Ltd. with the Meta Pixel; Google Ireland Ltd. with Google Tag Manager, Google Analytics 4 and Google Ads) are used only on our information pages and only with your consent (section 5).
17. Transfers to third countries
Where personal data is transferred to providers outside the EU or the EEA (Cloudflare, Google, Meta or, through the US parent company Stripe, Inc., Stripe as well), this takes place on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the current EU standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914) or, where applicable, an adequacy decision (EU-U.S. Data Privacy Framework).
18. Retention periods
We store personal data only for as long as the purpose in question requires or as long as statutory retention periods apply. As a rule:
- Photographer account (account and contact data): until the account is deleted;
- Invoicing and billing data: in line with the retention periods under tax and commercial law (at least the statutory period, 10 years in storage; for invoices carrying German VAT, § 14b UStG);
- Server and application log files: a few days, at most 30 days;
- Gallery content (original photos, previews, analysis image): according to the settings of the photographer, or until the gallery or the account is deleted; the analysis image is deleted together with the photo it belongs to;
- Selfie from the face search: immediately after the search has finished; the record of the consent given (timestamp, IP address) is kept until the gallery is deleted;
- Biometric comparison patterns of the gallery photos: for as long as the gallery exists; they are deleted with it;
- Registration origin (campaign parameters): 24 months from registration; deleted thereafter;
- Reach measurement (pages opened, shortened IP address): 24 months; they are deleted afterwards;
- Consent record of advertising tracking (time, version, decision, shortened IP address): 3 years; the cookie with your decision: 12 months;
- Passwords: until the account or the gallery is deleted.
19. Your rights
Under the GDPR you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You also have the right under Art. 21 GDPR to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you that is based on a legitimate interest (Art. 6(1)(f) GDPR); we will then stop processing the data, unless we can demonstrate compelling legitimate grounds. Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). A message to [email protected] is enough to exercise any of these rights.
20. Automated decisions
No automated decision-making, profiling included, with legal effect under Art. 22 GDPR takes place.
21. Technical and organisational measures
We take appropriate technical and organisational measures to protect personal data, in particular:
- Transport encryption (TLS/HTTPS) for every connection to the platform;
- Account passwords stored solely as a cryptographic hash; gallery passwords stored encrypted;
- A role-based access and permissions model (photographer, support, administration) following the principle of data minimisation;
- Processing and storage within the EU and the EEA (see section 3) on the basis of data processing agreements;
- Password-protected galleries, and share and download links that are access-restricted and cannot be found publicly;
- Logging of security-relevant events and regular backups at the level of the hosting infrastructure in use.
We review and improve these measures continuously in line with the state of the art.
22. Changes
We adapt this privacy policy when the law or our processing changes. The version published on this page at the time is the one that applies.
Last updated: July 2026 · Version 1.0
This page is a translation. Where the language versions differ, the German wording applies; which law governs is set out in the terms of use.