IquraPhotos
Privacy
Privacy & data

Privacy & data

Face search involves biometric data, so we keep it simple and accountable. Here's what's processed, who's responsible, how long it's kept, and the rights you have. This policy follows the Law of Ukraine "On Personal Data Protection" No. 2297-VI. IquraPhotos is offered in Ukraine only.

Last updated 19 August 2026 · applies to all events run on IquraPhotos

Biometric data, handled lawfully

Face templates are sensitive personal data under Article 7 of the Law of Ukraine "On Personal Data Protection". They're processed on one ground only — the unambiguous consent the event organizer collected from you.

Your selfie is never stored

One selfie, or one uploaded photo, is used only to run the search: it's sent to our biometric matching provider — a specialist third-party face-recognition service — for that one comparison, then dropped. It never lands in a database — ours or the provider's.

Short-term by design

Face embeddings are deleted within 30 days and event photos within 90 days, automatically. We're a search tool for the weeks around an event, not a long-term archive.

Ukraine only

We serve Ukraine and nowhere else — Ukrainian organizers, events in Ukraine, attendees in Ukraine. Data is hosted in the European Economic Area, which Article 29 of the Law recognises as providing adequate protection, under a no-training commitment: never used for advertising, model training, or third parties.

Anonymous usage statistics

We count searches, visits and downloads per event as anonymous totals only. No cookies, no persistent identifiers, no link to your selfie or any biometric data.

Step by step

What happens when you search

1

You accept the terms

Searching is disabled until you tick the consent box. No selfie is processed before that.

2

Your selfie becomes numbers

Face detection turns your selfie into a face template — computed by our biometric matching provider, a specialist third-party face-recognition service, and used purely for comparison.

3

We compare, not collect

Your selfie is compared against the event gallery's face templates by the provider. We surface the closest matches to you.

4

Everything temporary is cleared

Your selfie and its embedding are deleted as soon as results are shown.

Who's responsible

Roles & responsibilities

Data controller

The event organizer

The organizer provides the photos and decides how they're used. They configure the event in their CRM — visibility (public, private, or closed), whether search is by selfie or upload, and any sponsors — and collect a valid consent before any search happens. They can upload or delete photos, but never access the biometric information.

Data processor

IquraPhotos

We act only on the organizer's documented instructions — submitting photos and selfies to our biometric matching provider, running the match, and returning results. We don't decide the purpose, and we never use the data for anything beyond that event.

Retention

What we process & how long

Event photos

Provided by the organizer; stored on object storage in the European Economic Area and sent to our biometric matching provider to detect faces and build face templates.

Deleted within 90 days

Your selfie

One selfie (or one upload) used to generate a query embedding for the search.

Never stored — dropped after the search

Face embeddings

Numeric vectors derived from faces — they can't be turned back into a photo.

Deleted within 30 days

Technical logs

Minimal request/security logs with no biometric content.

Short, rolling retention

Anonymous analytics

Aggregate search, visit and download counts per event. No cookies or personal identifiers — visitor hashes are salted daily and cannot identify you.

Aggregates: indefinite · Visitor hashes: ≤ 90 days
Your rights

You stay in control

Article 8 of the Law of Ukraine "On Personal Data Protection" lets you request access, rectification, erasure or destruction, restrict how your data is processed, object to processing, and withdraw consent at any time — a request is answered within 30 calendar days. You can also delete your own face templates in-product without waiting: verify it's you with a token and a live selfie, then select and remove your matches. To remove an actual photo, contact the event organizer, who is the controller. If you're not satisfied, you can complain to the Ukrainian Parliament Commissioner for Human Rights.

Access your data
Correct it
Erase it
Restrict processing
Object to processing
Withdraw consent

Questions about a specific photo or your data at an event? Contact that event's organizer first. For anything about how IquraPhotos processes data, reach us at [email protected].

Full policy

Privacy Policy in full

This Privacy Policy explains how IquraPhotos processes personal data when you use face search inside an event's photo gallery. It is written to comply with the Law of Ukraine "On Personal Data Protection" No. 2297-VI. IquraPhotos is provided to event organizers on a business-to-business basis: the organizer is the controller (володілець персональних даних) and IquraPhotos acts as a processor (розпорядник персональних даних) on their instructions. The Service is offered in Ukraine only.

1.Who we are and our role

The Platform is operated by IquraPhotos. For anything to do with your personal data, write to [email protected] — we answer it ourselves.

  • The event organizer is the controller — they publish the photos, configure the event, and obtain your consent for face search.
  • IquraPhotos is the processor — we run the detection and matching on the organizer's documented instructions, and nothing else.
  • For operating the website, security logging and talking to organizers, we act as an independent controller.

2.Where we operate — Ukraine only

IquraPhotos is built for the Ukrainian market and offered in Ukraine only: organizers based in Ukraine, events held in Ukraine, attendees who are in Ukraine when they use it.

  • We do not offer, market or direct the Service to people outside Ukraine, and we do not take on organizers whose events are held elsewhere.
  • Every organizer undertakes, in their agreement with us, that the event is held in Ukraine and that they will not make face search available to attendees in another country.
  • If you are outside Ukraine, please do not use face search. You may still be able to browse the gallery where the organizer has made it public.

This is a deliberate limit. Face search processes biometric data, and we would rather do that properly under one legal regime than spread ourselves across several. If we ever extend the Service to another country, we will publish the terms that apply there first.

3.What data we process

  • Your selfie or query photo (biometric): one selfie or uploaded photo per search. It is sent to our biometric matching provider — a specialist third-party face-recognition service — as part of the search request, compared against the event's indexed faces, and then discarded. Neither we nor the provider store it.
  • Face templates of event photos (biometric): a biometric identifier our provider computes for each face it detects, held in a collection isolated to that event. We keep no copy: our database stores only a bounding box, a confidence score and an internal reference. A template cannot be turned back into a photograph, and the provider does not use it — or the images it came from — to train its own models.
  • Event photos: uploaded and owned by the organizer; sent to our provider for face detection within seconds of upload. An exact duplicate is recognised by its file hash and not processed twice.
  • Expression metadata (not biometric): for each detected face, our provider also returns how that face looks in that one photograph — a label such as "happy" or "calm" with a confidence score, whether it appears to be smiling, whether the eyes look open, and two image-quality measures. We store this as ordinary metadata. It cannot identify or distinguish anyone; its only use is the "Filter by Expression" control in your own search results, and it is deleted together with the face record it describes.
  • Technical data: minimal request and security logs (timestamps, IP address, errors) with no biometric content.
  • Anonymous usage analytics: aggregate counts per event only — searches, page visits, downloads, and an approximate number of unique visitors per day.

We do not ask for your name, email or an account. Face search is anonymous to us — we never link a face template to your identity.

5.How face search works

  • You accept the consent terms in the event gallery.
  • Your selfie is sent to our biometric matching provider as part of the search request — not stored by us, and not added to the provider's collection.
  • The provider compares them against the event's indexed face templates and returns the closest matches.
  • We show you the matching photos. Your selfie is discarded from memory as soon as the response is returned.

6.How self-service erasure works

Under Articles 8 and 15 of the Law of Ukraine "On Personal Data Protection" you may withdraw your consent and require your data to be deleted. You can do it yourself, immediately, with a single-use token from the event organizer:

  • Get your erasure token from the organizer — one per attendee, distributed privately. It proves you attended.
  • Open the gallery, tap "Remove my photos" and enter the token. We verify it by hash; the raw token is never stored.
  • Take a selfie. It is used only to find your face and is never stored.
  • Review the photos found — all pre-selected. Deselect any you want to keep.
  • Confirm. Before deleting, the server re-checks each selected face against your selfie, so a token holder cannot erase someone else's data.

Deleted: your face template(s), removed from the provider's collection for this event — the identifier that made you findable — and the face metadata record in our database, including its expression metadata.

Not deleted: the source photographs, which belong to the organizer (contact them to have a photo removed); a non-biometric tombstone — filename and bounding box only — that stops your face being re-indexed if the same photos are re-imported; and an audit entry recording that an erasure happened, with no biometric content.

The erasure is permanent and cannot be undone. Your token is consumed on first use.

7.Where data is processed and stored

Event photos are stored on Cloudflare R2 object storage in an EU region. Face detection and matching run on our biometric matching provider's service in Ireland. The application runs on servers in the European Economic Area.

This is a cross-border transfer, and Article 29 of the Law of Ukraine No. 2297-VI governs it: personal data may go to a foreign recipient only where that state ensures an adequate level of protection. The Article recognises members of the European Economic Area, and states party to Council of Europe Convention ETS No. 108, as doing so — every state our infrastructure sits in is both. Ukraine is itself a party to Convention 108, which is why this Policy reads familiarly to anyone used to European data-protection documents.

Hosting abroad does not change who the Service is offered to. It is offered in Ukraine only.

8.Usage analytics

So organizers can see how their gallery is used, we record anonymous aggregate counts per event, per day: searches, landing-page visits and photo downloads.

To approximate unique visitors without identifying you, our server derives a one-way hash from your IP address and user-agent combined with the current day. The day is part of the hash, so it changes every 24 hours and cannot track you over time; the raw values are never stored and the hash cannot be reversed. Download counts are per-photo totals only, never linked to who downloaded them.

No cookies, no persistent identifiers, no link to your selfie or any biometric data, never sold and never used for advertising. Our legal basis is our and the organizer's legitimate interest in measuring the service (Article 11(1)(6)); because the data is anonymous and aggregate, no consent banner is required.

9.How long we keep data

We are deliberately short-term storage. IquraPhotos is a search tool for the weeks around an event, not a photo archive — the organizer keeps the master copies, and you should download anything you want to keep as soon as you find it.

  • Selfie / query photo and its embedding: not stored — discarded immediately after the search.
  • Face templates of event photos: deleted no later than thirty (30) days after they are created, or after the event ends if that is later. From then on, face search finds no one in that event.
  • Expression metadata: erased on the same sweep, to the same deadline. It never outlives the face record it describes.
  • Event photos: deleted no later than ninety (90) days after upload, or after the event ends if that is later — together with the web-optimised copies — unless the organizer removes them sooner.
  • Technical / security logs: short rolling retention.
  • Anonymous analytics: aggregate counters may be kept for trend reporting; the daily visitor hashes are deleted within ninety (90) days.
  • Encrypted backups: maximum thirty (30) days.

These deletions are automatic — a scheduled job runs daily, so nothing depends on someone remembering to do it.

10.Your choices and rights

You can search anonymously, browse the gallery without searching, or not use face search at all.

Article 8 of the Law of Ukraine "On Personal Data Protection" gives you the right to know what data about you is held and where it came from, to access it, to require it to be corrected or destroyed, to object to its processing, to withdraw your consent, and to be protected against unlawful processing. A request is answered within thirty (30) calendar days.

You do not have to wait that long for erasure: the self-service flow above removes your face templates on the spot.

Your image is protected separately from your data. Under Article 307 of the Civil Code of Ukraine, consent to being photographed is presumed where the filming is done openly at a conference or other public event — but that presumption covers the photograph only, never the biometric processing of it, which still needs your separate consent. Under Article 308 a photograph of you may generally be publicly displayed only with your consent. These rights are exercised against whoever publishes the photograph — the organizer — not against us.

Because the organizer is the controller, address requests about an event to them first; we will help carry them out. If you are not satisfied, you may complain to the Ukrainian Parliament Commissioner for Human Rights, who supervises data protection in Ukraine, or go to court. You can also write to us directly at [email protected].

11.Database backups and erasure

We keep encrypted database backups for disaster recovery, for a maximum of 30 days, under the same access controls as the live database.

A backup taken before you erased yourself will still contain the face metadata row (bounding box, confidence score) — though never the face template, which lives only in the provider's collection. If a backup is ever restored, we are required to re-apply every erasure tombstone before it serves traffic: a documented procedure deletes the resurrected template at the provider and removes the metadata row. Backups expire within 30 days in any case.

12.Security

Article 24 of the Law of Ukraine No. 2297-VI requires us to protect personal data against unlawful processing and accidental loss. In practice:

  • Encryption in transit (HTTPS / TLS).
  • Face templates live only in our provider's secured, per-event collection, under its own security certifications — never in our database, which holds non-biometric metadata alone. Templates cannot be reversed into images.
  • A SHA-256 hash of each photo lets us skip biometric processing for an exact duplicate.
  • Least-privilege access, individually attributable accounts, and strict separation between one organizer's data and another's.
  • Organizers manage photos through their CRM but never have access to any face template.
  • Encrypted backups with a maximum 30-day retention; erased data is re-removed before any restored backup goes live.

13.The organizer, sponsors and sharing

The organizer configures each event: whether search is by selfie, by gallery photo or both; whether the event is public, private or closed; and they may display sponsors under their contract. Sponsors appear as branding only — we share no biometric data or selfie with them, or with anyone, for marketing.

We use sub-processors strictly to run the service — hosting and object storage in the European Economic Area, and a specialist third-party service for biometric face-matching. We never sell personal data and never use it for advertising, and we have applied the provider's AI-services opt-out to our account so it cannot train on the photos, selfies or templates that pass through it either.

We name that provider in the agreement we conclude with each organizer, and will identify it to you on request — write to [email protected].

14.Children

The service is intended for adult attendees. Where an event may involve children, the organizer is responsible for obtaining consent from the child's parent or guardian under the Civil Code of Ukraine before any photograph of that child is uploaded for face search.

15.If the service shuts down permanently

IquraPhotos is a small, independent service. We may decide to close it for good — if it does not turn out to be commercially viable, or for any other reason. If that happens, face search stops working and the galleries go offline.

  • Everything is deleted. Photos, face templates, metadata, logs and organizer accounts are erased on shutdown. Nothing keeps running quietly in the background.
  • Nothing is sold or handed over. We will never sell, licence or transfer personal data to another company as part of a shutdown, wind-up or insolvency. If the service were taken over as a going concern, organizers would be told in advance and could object and require deletion instead.
  • Organizers get as much warning as we reasonably can give — normally at least thirty (30) days — so they can download their photos. They hold the master copies anyway.
  • Download what you want to keep. Photos in "Saved" live in your browser but point at images on our servers: once the galleries are gone, they no longer load.

We would rather say this plainly now than surprise anyone later. It is also why we hold your biometric data for the shortest window we can, and why the photos always remain the organizer's.

16.Changes to this Policy

We may update this Policy from time to time; the "last updated" date changes accordingly. Material changes affecting attendees are reflected in the event gallery.

17.Contact

IquraPhotos — [email protected]. That is the address for every question about personal data: access, correction, erasure, withdrawal of consent, or anything you would like explained.

For your event's photos, contact your organizer first — they are the controller, and they publish the gallery.

Get in touch

Want this at your event?

Tell me about your conference or meetup — size, dates, where the photos live — and I'll help you set up face search for your attendees.

Response time
Usually within a day