How Lensmora treats personal data
Lensmora helps photographers, studios, and event organizers create private galleries where guests can find photos and videos using a selfie. To make that work, Lensmora may process event photos, videos, guest selfies, face-search metadata, event details, account details, support messages, and payment metadata.
We design the product so guest search is private by default. A selfie is used to find that person's matching media inside the relevant event gallery; it is not meant to create a public guest profile or expose identity labels to other guests.
Controller and processor roles
For event galleries, the photographer, studio, or event organizer usually decides why media is collected, who can access the event, how long the gallery stays live, and whether guest uploads or downloads are enabled. In that context, Lensmora generally acts as a processor or service provider.
For Lensmora's own website, account administration, billing, product security, and support communications, Lensmora may act as an independent controller.
Lawful bases we may rely on
- Contract performance to create galleries, process uploads, index event media, and deliver the service requested by a customer.
- Consent where a guest is asked to submit a selfie or where local law requires explicit permission for a specific processing activity.
- Legitimate interests for fraud prevention, product security, support, service improvement, and abuse monitoring.
- Legal obligation for accounting, tax, payment, dispute, or regulatory records.
Your GDPR rights
If GDPR applies to you, you may request access, correction, deletion, restriction, portability, objection to certain processing, or withdrawal of consent by emailing [email protected]. We may need to verify your identity and the event gallery involved before acting on a request.
If your request relates to a gallery controlled by a studio or event organizer, we may need to coordinate with that customer because they decide the event-level privacy settings and retention instructions.
Security, retention, and deletion
- Event media and related face-search metadata are retained according to the event plan, expiry settings, customer instructions, or lawful operational needs.
- We use access controls, HTTPS, limited internal access, audit-minded workflows, and cloud infrastructure safeguards to reduce unauthorized access risk.
- Customers can request deletion of event data, and guests can contact us if they want help locating the right organizer or removing their personal data from a Lensmora-powered gallery.
International transfers and subprocessors
Lensmora may use trusted infrastructure, storage, payment, analytics, email, and support providers to run the service. Where data is transferred internationally and GDPR applies, we use appropriate safeguards such as contractual commitments and processor controls.
For a data processing addendum, subprocessor question, or vendor review, email [email protected].
