aftersnap

Privacy policy

Thank you for your interest in aftersnap. Protecting your personal data matters to us. Below we explain how personal data is processed when you use our platform, as required by the General Data Protection Regulation (GDPR).

1. Controller

Danyel André Maus
Cami des Jardi d'en Ferrer 72
ES-07141 Marratxí, Spain
Email: [email protected]

The contact for data protection questions is the controller named above; there is no legal requirement to appoint a data protection officer.

2. General information & legal bases

We process personal data only to the extent required. Depending on the processing, the legal bases are in particular Art. 6(1)(b) GDPR (contract and pre-contractual steps), (a) (consent), (c) (legal obligation) and (f) (legitimate interest). For special categories of data such as biometric data, the basis is Art. 9(2)(a) GDPR (explicit consent).

3. Hosting & technical operation

Our application and the data belonging to it run with service providers in the European Union: web hosting at ALL-INKL.COM (Neue Medien Münnich, EU), computing capacity at Hetzner Online GmbH (EU) and object storage for uploaded original photos at Impossible Cloud GmbH (EU). The compute-heavy AI analysis (see section 9) runs there too, on computing capacity we operate with these providers within the EU. For this analysis, a downscaled copy of the photos (the “analysis image”) is created and stored with the object storage provider named above (Impossible Cloud, EU). We have data processing agreements under Art. 28 GDPR with these providers.

For delivery through customers’ own domains and as a security and proxy layer (protection against overload and DDoS attacks, TLS encryption and content delivery, among other things) we use Cloudflare, Inc. (USA). Cloudflare processes IP addresses, connection and TLS handshake data, browser and device details, and security logs. Personal data may also be transferred to the USA in the process (see section 17).

We deliver the preview images of public galleries through the content delivery network of BunnyWay d.o.o. (bunny.net, Slovenia). This involves your IP address together with details of the request such as the time, the image requested and the browser type; the provider shortens the IP address in its logs. Delivery is limited to locations within the European Union, so no transfer to a third country takes place. Images from password-protected galleries, from drafts and from expired galleries stay on our own servers. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in delivering galleries with many photos quickly and reliably). A data processing agreement under Art. 28 GDPR is in place.

4. Server log files

When the platform is opened, technically necessary access data is processed (IP address, date and time, the resource requested, browser and system details, for example). This serves secure and stable operation (Art. 6(1)(f) GDPR) and is stored only for a limited period, as a rule a few days and at most 30 days.

5. Cookies & local storage

We use technically necessary cookies and local storage, for the session (login), for protection against cross-site request forgery (CSRF) and for functional settings. The legal basis is Art. 6(1)(f) GDPR and, where information is stored on or read from your device, Art. 22.2 LSSI-CE (strict necessity). Third-party advertising and statistics cookies are used only on our information pages and only with your consent (see below, “Advertising tracking with consent”). There is no advertising tracking in photographers’ galleries or in the dashboard.

When you register, we record in your account which campaign brought you to us: the parameters utm_source, utm_medium, utm_campaign, utm_content and utm_term from the address you opened. Until you register they are held only in your session on our server; we set no cookie of our own for this. The purpose is measuring how well our own advertising works. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in assessing the effectiveness of our own advertising). We build no profile from this, and no third party receives it. After 24 months we delete it (section 18).

How often our public pages are opened is measured with Matomo on a server of our own at Hetzner Online GmbH (EU, see section 3). The measurement runs on our server, not in your browser: we only evaluate what reaches us with the request anyway: the address opened, the page visited before, browser and device type, and your IP address, which is shortened straight away. Nothing is stored on your device for this and nothing is read from it; there is no analytics cookie and no measurement JavaScript. We build no profile from this, and the data does not leave our server. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in knowing which content is found and read). If your browser sends “Do Not Track” or “Global Privacy Control”, we do not count the visit. We do not measure the photographers’ galleries. After 24 months we delete the measurement data (section 18).

Advertising tracking with consent. On our information pages (aftersnap.io without the dashboard and without galleries) a banner asks you on your first visit whether we may use services to measure whether our advertising works. Without your consent none of these services is loaded and no such cookie is set; “Decline” is as easy as “Accept,” and the site works the same either way. Category marketing: the Meta Pixel of Meta Platforms Ireland Ltd., Dublin (characteristics of the visit and of a sign-up, cookies _fbp and _fbc; for the collection we and Meta are joint controllers under Art. 26 GDPR, the essence of the arrangement is at facebook.com/legal/controller_addendum; Meta alone is responsible for the further processing) and Google Ads via Google Tag Manager of Google Ireland Ltd., Dublin (conversion measurement, cookies _gcl_*). Category statistics: Google Analytics 4 of Google Ireland Ltd. (usage statistics of our information pages, cookies _ga*, IP address shortened). After a sign-up we additionally transmit the event “registration completed” server-side to Meta or Google, only with the consent given for that category and only with a hashed email address, a shortened IP address and the click identifier from the cookie. Both providers may transfer data to the USA; the basis is the EU-U.S. Data Privacy Framework (section 17). The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you can withdraw or change it at any time with effect for the future via the “Cookie settings” link in the footer. We store your decision in a cookie (aftersnap_consent, twelve months) and record it without personal reference (time, version, decision, shortened IP address) for three years as evidence. If the services we use change, we ask again.

6. Photographer accounts

For use as a photographer we process account and contact data (such as name, email and the password, which is stored only as a cryptographic hash) and, for billing, invoice data (such as company, address and VAT ID). The legal basis is Art. 6(1)(b) GDPR; retention duties under tax and commercial law (Art. 6(1)(c) GDPR) remain unaffected. This data is needed to set up the account and to perform the contract; without it the account cannot be created and the contract cannot be fulfilled.

7. Galleries & uploaded photos (processing on behalf of the photographer)

Photographers upload photos and make them available to their clients as an online gallery. Where these photos show people, we process the photos on behalf of the photographer concerned; under data protection law, the photographers are the controllers for this content. aftersnap processes the photos only on the documented instructions of the photographer concerned. We do not receive the personal data of the people shown from them directly, but through the photographer who uploads the photos. The basis is a data processing agreement (see Data Processing Agreement).

8. Gallery guests & downloads

When a gallery is opened, we process the technical data needed to deliver it. For password-protected galleries, the password entered is checked (Art. 6(1)(b) GDPR). If a guest requests a ZIP download, we use the email address given for that request only to send notice that the file is ready (Art. 6(1)(b) and (f) GDPR).

9. AI features: face search, content & people analysis (biometric data included)

If the feature is switched on for a gallery, guests can upload a selfie to find the photos they appear in automatically. This processes biometric characteristics, a special category of data under Art. 9 GDPR. The processing takes place only after explicit consent (Art. 9(2)(a) GDPR). The uploaded selfie is processed exclusively on our own servers in the EU, kept temporarily for the duration of the analysis only and deleted automatically as soon as the search is finished; it is not stored permanently. It serves only to find the guest again in the photos within this gallery and is not used across galleries; unknown people are not identified. To make the search possible, the facial characteristics of the gallery photos are analyzed beforehand and stored as biometric comparison patterns; these are used only for matching within the same gallery and not across galleries. This analysis also runs on our own servers in the EU (see section 3). Consent is voluntary and can be withdrawn at any time with effect for the future; without consent, the gallery works as usual.

A photographer can also switch on AI-assisted content and people analysis for a gallery. An AI assigns the photos to image content automatically (subjects such as cake, flowers or dancing) and groups similar faces within the same gallery into people that the photographer or their client can name; guests can then filter the gallery by content or by person. Grouping faces processes biometric characteristics (Art. 9 GDPR). It works per gallery only (no matching across galleries, no identification of unknown people) and, like the rest of the photo processing, on behalf of the photographer, who is responsible for the legal basis toward the people shown. The analyses run on our own infrastructure in the EU (see section 3). No automated decision with legal effect is involved (see section 20).

10. Vendor portal

If photographers invite vendors (to help with the image selection, for example), we process the vendors’ contact details and a record that they accepted the applicable terms (for proof, Art. 6(1)(b) and (f) GDPR).

11. Sending email

To provide the service we send emails (such as gallery links, notifications and system messages) through our host’s mail server. For proof and for operations, we log this to a reasonable extent (Art. 6(1)(b) and (f) GDPR).

12. Contact form

The form on our contact page lets you write to us without having an account. We process the details you enter yourself: name, email address, subject and the text of your message. These details go to our mailbox as an email and are handled there like any other inquiry; we do not store them in a database on top of that.

The only purpose is answering your inquiry. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in answering inquiries); if the inquiry concerns an existing or prospective contract, Art. 6(1)(b) GDPR applies as well. We delete the message once it is dealt with and no statutory retention periods stand in the way.

To guard against automated submissions, the form contains a field that is invisible to you and measures how long filling it in took. We also limit the number of submissions per IP address. No profiles are created, and no data is passed on to third parties.

13. Payment processing & invoicing

For paid plans we use Stripe Payments Europe, Ltd. (Ireland) as our payment service provider. When the payment page opens, we send Stripe your email address, your name or company and your billing address (street, postal code, city, country). You enter payment details such as card numbers at Stripe only; they never reach our servers, and we neither store nor process them. All we receive back from Stripe is whether a payment succeeded, plus the last four digits and the type of the payment method used. The legal basis is Art. 6(1)(b) GDPR (performance of the contract). Stripe is a subsidiary of Stripe, Inc. (USA); on transfers to third countries see section 17.

For bookkeeping and to meet retention duties under tax law, we pass the invoice data to sevDesk GmbH (Offenburg, Germany). This covers your name or company, your billing address, the invoice number, the services billed and the amounts. The legal basis is Art. 6(1)(c) GDPR (compliance with a legal obligation, in particular § 14b UStG, § 147 AO and § 257 HGB for transactions taxable in Germany). We have data processing agreements under Art. 28 GDPR with both providers.

14. Connecting the Google Business Profile

Photographers can connect their Google Business Profile through the Google Business Profile API using OAuth. This is optional. After explicit authorization in the Google account, we access data from the photographer’s own business listing only to the extent required, in particular location and review data (including the Google location ID and the review link). We use it to provide the review link and, where switched on, to show the overall rating on the profile page. The legal basis is your consent or performance of the contract (Art. 6(1)(a) and (b) GDPR).

We use data received from Google APIs only to provide and improve these user-facing features. We do not sell this data, do not use it for advertising and do not pass it on, except where that is needed to provide the feature, required by law or expressly requested by you. Our use of Google data follows the Google API Services User Data Policy, including the Limited Use requirements. The provider is Google Ireland Limited or Google LLC; personal data may also be processed outside the EU, in particular in the USA (see section 17). In addition, Google’s privacy notice applies. You can revoke the connection at any time in your account (“Disconnect”) and in the security settings of your Google account.

15. Your own domain

If you connect your own (sub)domain, delivery runs technically through Cloudflare (see section 3). The connection data needed for delivery and TLS encryption is processed, in particular the IP address; personal data may also be transferred to the USA (Art. 6(1)(b) and (f) GDPR, see section 17).

16. Recipients / processors

To provide the service we use carefully selected service providers as processors, among them: ALL-INKL.COM (web hosting/email, EU), Hetzner Online GmbH (processing, EU), Impossible Cloud GmbH (object storage, EU), BunnyWay d.o.o. (image delivery, Slovenia), Cloudflare, Inc. (CDN/proxy, USA), Stripe Payments Europe, Ltd. (payment processing, Ireland) and sevDesk GmbH (bookkeeping, EU). Where the Google connection is used, Google (Ireland/USA) is added to that list. For our own content (email templates, the music in our sound library and the contracts with our providers) we also use AI services from Anthropic, PBC, OpenAI, LLC and ElevenLabs, Inc. (each USA, EU standard contractual clauses); photos, galleries and customer data are never sent there. Advertising and analytics services (Meta Platforms Ireland Ltd. with the Meta Pixel; Google Ireland Ltd. with Google Tag Manager, Google Analytics 4 and Google Ads) are used only on our information pages and only with your consent (section 5).

17. Transfers to third countries

Where personal data is transferred to providers outside the EU/EEA (Cloudflare, Google and Meta, for example, or Stripe through its US parent company Stripe, Inc.), this rests on appropriate safeguards within the meaning of Art. 44 et seq. GDPR, in particular the current EU standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914) or, where applicable, an adequacy decision (EU-U.S. Data Privacy Framework).

18. Retention periods

We store personal data only as long as it is needed for the respective purposes or as long as statutory retention periods apply. In detail, the rule is usually:

  • Photographer account (account and contact data): until the account is deleted;
  • Invoice and billing data: in line with the retention periods under tax and commercial law (at least the statutory period, 10 years in storage; for invoices carrying German VAT, § 14b UStG);
  • Server and application log files: a few days, at most 30 days;
  • Gallery content (original photos, previews, analysis image): according to the photographer’s settings, or until the gallery or the account is deleted; the analysis image is deleted together with the photo it belongs to;
  • Selfie from the face search: as soon as the search is finished; the record of the consent given (timestamp, IP address) is kept until the gallery is deleted;
  • biometric comparison patterns from the gallery photos: as long as the gallery exists; they are deleted with the gallery;
  • Registration origin (campaign parameters): 24 months from registration; deleted thereafter;
  • Reach measurement (pages opened, shortened IP address): 24 months; they are deleted afterwards;
  • Consent record of advertising tracking (time, version, decision, shortened IP address): 3 years; the cookie with your decision: 12 months;
  • Passwords: until the account or the gallery is deleted.

19. Your rights

Under the GDPR you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). You also have the right under Art. 21 GDPR to object at any time, on grounds relating to your particular situation, to processing of personal data concerning you that rests on a legitimate interest (Art. 6(1)(f) GDPR); we then stop processing the data unless we can demonstrate compelling legitimate grounds. Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). A message to [email protected] is enough to exercise these rights.

20. Automated decisions

There is no automated decision-making, including profiling, with legal effect under Art. 22 GDPR.

21. Technical and organizational measures

We take appropriate technical and organizational measures to protect personal data, in particular:

  • transport encryption (TLS/HTTPS) for every connection to the platform;
  • account passwords stored only as a cryptographic hash; gallery passwords stored encrypted;
  • a role-based access and permission model (photographer, support, administration) following the principle of data minimization;
  • processing and storage within the EU/EEA (see section 3) on the basis of data processing agreements;
  • password-protected galleries and access-restricted share and download links that cannot be found publicly;
  • logging of security-relevant events and regular backups at the level of the hosting infrastructure in use.

We review and improve these measures continuously in line with the state of the art.

22. Changes

We adjust this privacy policy when the legal situation or our processing changes. The version published on this page is the one that applies.

Last updated: July 2026 · Version 1.0

This page is a translation. Where the language versions differ, the German wording applies; which law governs is set out in the terms of use.