Legal

Privacy Policy

Status: 11 August 2026 · All legal documents

Only the German version is legally binding. Switch the site language to Deutsch to read it.

Translation for information purposes. Only the German version is legally binding.


1. Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Matthias Anderer GmbH
Abt-Kaspar-Str. 19, 83607 Holzkirchen, Germany
Managing Director: Matthias Anderer
Email: privacy@snapories.com · Phone: +49 151 22837719
Amtsgericht München HRB 224848 · VAT ID DE305934264

For any data-protection question and to exercise your rights: privacy@snapories.com.

A data protection officer has not been appointed; on our assessment the conditions of § 38 of the German Federal Data Protection Act (BDSG) are not met. Should that change, we will publish the contact details here.


2. What we are responsible for — and what the Organiser is

Snapories is always used within an event that someone has booked. Who is the controller depends on who books:

CaseWho is controller for the event content?Our role
Private event (wedding, birthday, family celebration) booked by a private individualThe booking individual is, for their own use, as a rule covered by the household exemption (Art. 2(2)(c) GDPR) and therefore not an addressee of the GDPR.We are an independent controller (Art. 4(7) GDPR) for the processing we carry out.
Business event (company party, trade fair, festival, brand activation) booked by a business, authority or associationThe booking organisation.To that extent we are a processor under Art. 28 GDPR; the Data Processing Agreement applies.

Irrespective of this, we are always an independent controller for: contract performance and billing, operational and IT security, abuse prevention, aggregated usage figures without personal reference, and compliance with legal obligations.

For the guest app we also have a direct relationship with you as a guest: you use the app on your own initiative; the legal basis in that respect is Art. 6(1)(b) GDPR (use relationship).


3. The six surfaces at a glance

Snapories consists of six separate websites/applications. They are on their own domains and share no browser storage:

SurfaceDomainFor whom
Marketing websitesnapories.comall visitors
Guest appapp.snapories.comguests of an event
Organiser dashboardhost.snapories.comthe booking person
Partner portalpartners.snapories.comco-branding partners
Referral portalrefer.snapories.comreferral programme participants
Internal consoleadmin.snapories.comour staff only

4. Marketing website (snapories.com)

4.1 Server log data. When you access the site, technically necessary data is processed: IP address, date and time, requested resource, status code, volume transferred, referrer, user agent. Purpose: delivery, stability, IT security. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning offering). Storage: short-term, within our hosting provider's operational logs.

4.2 No audience measurement, no advertising. We use no analytics, tracking or advertising services, no external fonts, no social-media plugins and no embedded third-party content. The pages load files exclusively from our own servers.

4.3 Booking form. For a booking we process name, email address, billing address and country, event name and period, the chosen guest count and quotas, and any discount code. Legal basis: Art. 6(1)(b) GDPR (performance of a contract); for invoicing and tax data additionally Art. 6(1)(c) GDPR (§ 14 UStG, § 147 AO).

4.4 Contacting us. If you write to us, we process your details in order to reply. Legal basis: Art. 6(1)(b) or (f) GDPR. We delete the correspondence once it is no longer needed and no retention obligation applies.


5. Guest app (app.snapories.com)

5.1 Identity without an account

You do not create an account. So that your images, film roll and booth credits stay attached to you, our server issues you a signed access pass. That pass lives in three places: in your browser's local storage, in a cookie we set (snap_id), and — for the current call — in a short-lived second entry.

We expressly do not use device fingerprinting. A method previously used to recognise your device by technical characteristics has been removed entirely: it could confuse two identical devices and was not justifiable under data protection law. A device without a valid pass is a new, unknown person to us.

Legal basis: Art. 6(1)(b) GDPR. Setting the pass is strictly necessary and therefore requires no consent under § 25(2) no. 2 TDDDG.

5.2 Your name

The name entered when joining is freely chosen. It is shown to other participants of that event where the Organiser has enabled it. Legal basis: Art. 6(1)(b) GDPR.

5.3 Photos and images

We process the images you take, technically derived versions (thumbnails) and metadata (time, dimensions, attribution to you and to the event). Purpose: providing the event gallery. Legal basis: Art. 6(1)(b) GDPR towards you; with respect to other persons depicted, Art. 6(1)(f) GDPR (legitimate interest of the participants in jointly documenting an occasion within a closed group).

Persons depicted who do not use the app have the rights under clause 13 — in particular the right to object under Art. 21 GDPR. In practice there are two routes: the Organiser can block an individual image immediately, and we delete images on request. There is no automatic face recognition, no automatic obscuring and no comparison against a reference image.

No biometric data. Snapories does not create face templates or face vectors, performs no biometric matching and processes no special categories of personal data within the meaning of Art. 9 GDPR. A feature once planned for blurring one's own face was cut before launch and is not present in the system.

5.4 Quotas and sharing

We count how many shots and credits you have used and whether an image has been shared. These counters are necessary for operation (quota management) and feed aggregated, non-personal statistics. Legal basis: Art. 6(1)(b) and (f) GDPR.

5.5 Access to the gallery

An event's gallery is reachable via the seven-character, random join code. The code is practically unguessable but is not a login: anyone who knows it can see the event's released images. We point this out so that you can judge who can see your images.

That access exists only during the event period. When the event ends the gallery can no longer be reached by guests; the Organiser can then make the images available through a time-limited share link (clause 14).

5.6 Personal recovery link

Via the "Save your photos" function you create a link that contains your identifier. Whoever holds the link gains access to your images and quotas. Treat it like a password. The link is valid for up to 400 days and can only be used to adopt the identity, not as a general access key.


6. AI photobooth — transfer to the AI provider

6.1 What happens. In the booth you take a picture. That picture, together with your text input, is transmitted to the AI provider Google (Gemini API, generativelanguage.googleapis.com). There, in several steps, the number of people depicted is determined, costume suggestions are generated and finally the result image is created. We store the result as an image of your event.

The booth shot itself is also stored — in the event's data region, separately from the gallery and not visible there. It belongs to the event's data and is deleted with it; you can request its deletion at any time (clause 13).

6.2 Legal basis. Art. 6(1)(b) GDPR — the generation is the service you requested.

6.3 What the provider does with it. Under the terms applicable to paid use, Google does not use inputs and outputs to train its models. Google logs inputs and outputs for a limited period solely to detect abuse and to comply with legal obligations.

6.4 Place of processing and third-country transfer. The interface used processes outside the European Union, in particular in the United States, including for events with data region EU. The basis is the European Commission's adequacy decision for the EU-US Data Privacy Framework, to the extent the recipient is certified, supplemented by the European Commission's standard contractual clauses and additional safeguards. Despite these instruments, residual risks remain for transfers to the USA, in particular regarding access by state authorities.

6.5 Limits. For a booth generation we transmit only the booth shot and your text input — not your name, not your identifier, not your other images and not other guests' images.

6.6 Labelling. Photobooth results are visibly labelled as AI-generated in the application (Art. 50(4) AI Act).


7. Protection against automated abuse (Cloudflare Turnstile)

7.1 On the forms that trigger a generation or send an email we use Cloudflare Turnstile — a privacy-friendly alternative to picture puzzles.

7.2 What is processed. The check module loads from challenges.cloudflare.com and evaluates signals from your browser. For server-side confirmation we transmit to Cloudflare the issued verification token and your IP address.

7.3 What does not happen. We have measured that Turnstile leaves neither a cookie nor any other entry in your browser's storage on our domain. No advertising identifier is set and no cross-site profile is built.

7.4 Legal basis. Art. 6(1)(f) GDPR (recital 49: network and information security, fraud prevention). Loading the check module is strictly necessary for the function you requested and therefore requires no consent under § 25(2) no. 2 TDDDG.

7.5 Recipient and third country. Cloudflare, Inc., USA, and Cloudflare Germany GmbH. Transfers to the USA take place on the basis of the EU-US Data Privacy Framework and additionally the standard contractual clauses.


8. Further processing in operations

8.1 Abuse limits for the free demo. So that the free try-it-out function is not exploited by automated means, we count generations per access pass and per network range. Your IP address is not stored: it is first truncated to a network range (IPv4 /24, IPv6 /64) and that value is then irreversibly reduced using a cryptographic hash function. Only this hash and a counter are stored. Retention: 2 days. Legal basis: Art. 6(1)(f) GDPR (protection against abuse and uncontrolled costs).

8.2 Payment processing. We process payments through Stripe (Stripe Payments Europe, Ltd., Ireland). Payment and invoicing data are transmitted directly to Stripe; full card details never reach our systems. If you pay with PayPal, that happens as a payment method inside Stripe. Legal basis: Art. 6(1)(b) GDPR, and for tax documentation Art. 6(1)(c) GDPR. Stripe also processes payment data in part as an independent controller for fraud prevention and to comply with its own regulatory obligations.

8.3 One-time-code sign-in and key recovery. To sign in to the portals we send a six-digit one-time code to the address given. The code is valid for 10 minutes and is deleted afterwards. Via the recovery function we send admin keys exclusively to the address on file. Legal basis: Art. 6(1)(b) GDPR.

8.4 Organiser, partner and referral accounts. We process name, email address, region, booked events, invoicing and payment data and — for partners — company name, website, country, logo and brand colour, and — in the referral programme — the personal code, associated redemptions and points balance. Legal basis: Art. 6(1)(b) GDPR, and for tax-relevant data Art. 6(1)(c) GDPR.

8.5 Internal console. Our staff see business metrics, event and account master data, codes, redemptions and partner data in the internal console. Access is restricted to an explicitly configured list of addresses and all staff are bound to confidentiality.


9. Storage on your device

Snapories stores only what is strictly necessary for the service you requested. Concretely that is: one cookie set by our server (snap_id) in the guest app, and a few entries in your browser's local storage for the access pass, language choice, appearance, last-opened event and the offline version of the app.

There is no analytics, advertising or profiling storage. That is why no consent banner appears: § 25(2) no. 2 TDDDG requires information, not consent, for strictly necessary storage.

The complete, always-current list of every single entry — key, purpose, lifetime, provider — is available at snapories.com/en/cookies. That list is generated directly from the source code and enforced by an automated check: a new storage entry in the code makes the test fail until it is declared there. The disclosure therefore cannot go stale.


10. Recipients of your data

We pass on personal data only where necessary for operation or where we are legally obliged to do so. Categories of recipients:

  • Hosting and storage: Amazon Web Services (data centres in Frankfurt or Northern Virginia, depending on the event's data region), and the delivery of images over the same provider's content delivery network (clause 12)
  • AI generation: Google (clause 6)
  • Abuse protection: Cloudflare (clause 7)
  • Payment processing: Stripe (clause 8.2)
  • Email delivery: our sending service provider
  • Advisers and authorities: tax advisers, legal advisers, auditors, and authorities and courts where legally required

The named, always-current list with registered office, place of processing and transfer basis is in the Sub-processor list.

Your data is not passed to advertising networks, data brokers or analytics providers. No sale takes place.


11. Transfers to third countries

Transfers to countries outside the European Economic Area take place for AI generation (Google, USA), for abuse protection (Cloudflare, USA) and for the delivery of images (Amazon Web Services): while an event is running, the images are cached transiently at edge locations for delivery, outside the EU as well (clause 12). The basis is:

  • the adequacy decision of the European Commission of 10 July 2023 on the EU-US Data Privacy Framework, to the extent the receiving company is certified, and
  • additionally the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914) together with a transfer impact assessment and additional safeguards (encryption in transit and at rest, data minimisation, no transfer of names or identifiers to the AI provider).

A copy of the respective safeguards is available on request at privacy@snapories.com.


12. Data region (EU / US)

A data region is set for every event at booking. It determines in which region that event's data is stored and processed by us:

  • EU → Frankfurt am Main (eu-central-1)
  • US → Northern Virginia (us-east-1)

Personal data is not mirrored between the regions. Each region has its own databases and its own storage areas.

Delivery of images. So that images arrive quickly and reliably everywhere, we deliver them over a content delivery network (Amazon CloudFront). In the process they are cached transiently at edge locations — outside the EU as well; the footprint covers the United States, Canada, Europe and Israel. That caching exists only while the event is running; when the event ends we purge the cache and nothing can be retrieved by this route any more. The stored copy of an image does not leave the data region.

What the data region covers and what it does not: the data region determines where an image is stored, processed and deleted — not every place a byte is briefly held for delivery. Also not covered are the calls to external providers described in clauses 6 and 7. Those process independently of the chosen data region; clause 11 governs there.


13. Your rights

Under the GDPR you have the right to:

RightReferenceWhat it means
AccessArt. 15You learn whether and which data we process about you.
RectificationArt. 16Inaccurate data is corrected.
ErasureArt. 17Your data is deleted unless a retention obligation applies.
RestrictionArt. 18Processing is frozen instead of deleted.
Data portabilityArt. 20You receive your data in a common format.
ObjectionArt. 21You can object to processing based on legitimate interests.
Withdrawal of consentArt. 7(3)Effective for the future; prior processing remains lawful.

How to exercise your rights: informally by email to privacy@snapories.com. We respond without undue delay and at the latest within one month. Where we cannot identify you without additional information — which is the normal case for account-free use of the guest app — we need details that make attribution possible (Art. 11(2) GDPR), such as the event's join code, the name you used and the approximate time.

Special case: persons depicted. If you appear in an image without using the app, contact privacy@snapories.com and describe the event and the image as precisely as possible. We will remove the image, or — for business events where we are a processor — forward the request to the responsible organisation without undue delay and support them in handling it.

Right to lodge a complaint. You have the right to lodge a complaint with a data protection supervisory authority, in particular the one competent for us:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27, 91522 Ansbach, Germany
https://www.lda.bayern.de


14. Storage periods at a glance

DataPeriod
Images of a booked event and associated metadatastored for at least 30 days after the end of the event. Guests' access ends when the event ends; during that period the images are available to the Organiser, who can make them available to guests through a time-limited share link. No entitlement to availability beyond that; deleted on request within 30 days
Booth shots (input images, not in the gallery)with the event
Images and data of a demo event7 days
Access pass in your browser · identity cookie90 days · up to 400 days
Personal recovery linkup to 400 days
One-time sign-in codes10 minutes
Abuse counters (hash of the network range)2 days
Organiser, partner and referral accountsfor the duration of the business relationship
Invoices, booking and tax records10 years (§ 147 AO, § 257 HGB)
Aggregated counts without personal referenceindefinitely (no personal reference)

15. No automated decision-making

There is no automated decision-making in individual cases, including profiling, within the meaning of Art. 22 GDPR. The AI photobooth creates an image; it makes no decision about a person and has no legal effect. Decisions about the removal of content are taken by humans.


16. Security

We implement technical and organisational measures under Art. 32 GDPR. These include transport encryption (TLS), encryption of data at rest, strict separation of the data regions, access-restricted internal systems, signed short-lived access tokens for image files, server-side abuse protection and regular updating of the components used. Details are in Annex 2 of the Data Processing Agreement.


17. Changes to this policy

We adapt this policy when the service, the providers used or the legal situation change. The current version is available at snapories.com/privacy.html; the date at the top shows its status.


18. Binding language version

Only the German version of this privacy policy is legally binding. Versions in other languages are provided for information purposes only. In the event of any discrepancy, the German version prevails. Towards data subjects who relied on a non-German version provided by us, this applies only to the extent the German version is not less favourable to them.