PRIVACY
Privacy Notice
Information on the processing of personal data under Article 13 GDPR
Effective: 31 August 2026
2.1 Controller
The controller for the processing of personal data is: ARTR Einzelunternehmen Uferstr. 3 48529 Nordhorn Germany Email: [email protected] No data protection officer has been appointed.
2.2 Purposes and legal bases
We process data to provide private wedding albums (guest upload via link/QR, host administration, optional paid packages). - Art. 6(1)(b) GDPR — contract or pre-contractual steps: creating an album, storing uploads, host account, ordering and providing Free / Keepsake / Heirloom / Extra-year packages. - Art. 6(1)(c) GDPR — legal obligations (in particular tax and commercial retention of order data where applicable). - Art. 6(1)(f) GDPR — legitimate interests: operational security, abuse and fraud prevention, session binding, language choice, enforcing storage and retention limits. There is no automated decision-making including profiling within the meaning of Art. 22 GDPR. There is no first-party reach measurement, advertising, or tracking pixels.
2.3 Categories of personal data
- Host / couple: partners’ first names, wedding date, optional album title and welcome note, email and password hash (host account only), Stripe customer identifier where a payment account is created, orders and voucher codes. - Guests: uploaded photos and videos, optional first name at upload, technical file metadata, SHA-256 checksum for duplicate detection, timestamps. Guests do not create an account. - Sessions: account session, host album session, language preference (see cookie table). - Payment data: cards and payment instruments are processed by Stripe on stripe.com and are not stored on our servers.
2.4 Recipients / processors
Personal data is disclosed only as needed to operate the service: - Cloudflare — hosting, content delivery and securing the service (processor). - Stripe — payment processing for paid packages (payment provider; payment data remains with Stripe). There is no disclosure to other third parties (advertising, data trading). Original files in this product version sit on operator-run storage behind Cloudflare, not a further cloud object store.
2.5 Third country / USA
Cloudflare and Stripe have establishments or processing in the USA. Both rely, according to their own statements, on the EU-US Data Privacy Framework and provide Standard Contractual Clauses (SCCs) as a fallback. Details follow from each provider’s current processing and transfer terms.
2.6 Storage period
- Free: album and media 28 days after the wedding date, then automatic deletion; the host may delete earlier. - Keepsake: 12 months; an extra year extends by 12 months. - Heirloom: until the host deletes the album. - Host account: until the host deletes the account. - Orders: as long as required for tax or commercial law, including after the album ends. - Session cookies: see table.
2.8 Rights of data subjects
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). An email to [email protected] is sufficient to exercise these rights. Hosts and guests can also delete uploads and albums through product features where they have access.
2.9 Complaint to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority competent for the controller in Nordhorn (Lower Saxony) is: Der Landesbeauftragte für den Datenschutz Niedersachsen Prinzenstraße 5 30159 Hannover Email: [email protected] https://www.lfd.niedersachsen.de/
2.10 Obligation to provide data
At least partner names and the wedding date are required for an album. Without these details the contract cannot be performed. A host account with email and password is required for paid packages. Guests need not provide a name.
