Legal
Privacy Policy
Last updated: July 2026
Protecting personal data is a top priority for us.
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data when using Pixxta, in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
2. Hosting
The website and application are operated via the provider Laravel Cloud on servers in Frankfurt am Main (Germany).
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in operating the website securely and efficiently).
A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.
3. Cookies
This website uses only technically necessary cookies, in particular:
- Session cookies
- Security and CSRF cookies
- Login cookies for registered hosts
No tracking, profiling, or cross-site analysis takes place.
Legal basis: Art. 6(1)(f) GDPR.
4. Registration as a host
Creating and managing events requires a user account. This involves storing your name, email address, and password (encrypted).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
5. Participation as a guest
Guests take part without their own account. The following is processed:
- the name or nickname provided
- optionally, a profile picture
- uploaded photos, videos, greeting messages and audio messages
The content is visible only to the participants of the respective event; access is via an event-specific link or QR code.
Guests provide photos and messages voluntarily. Anyone who uploads photos showing other people is responsible for obtaining their consent.
Legal bases: Art. 6(1)(b) GDPR (providing the service) and Art. 6(1)(a) GDPR (consent).
6. Storage of photos and videos
All uploaded photos, videos and profile pictures are stored with the provider Cloudflare (object storage “R2”). The storage location is restricted to the European Union (EU jurisdiction); the files do not leave the EU.
A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.
Legal basis: Art. 6(1)(b) GDPR (provision of the service).
7. Automated image analysis
So that the photos of an event can be presented in an ordered way, every uploaded photo is analysed automatically once after upload. The analysis serves three purposes:
- Framing: it is determined where faces are located in the image so that preview images are not spoiled by an unfavourable crop.
- Tagging: terms describing the content are assigned to the image (e.g. “cake”, “dance floor”, “group photo”). The gallery's themes view is built from these.
- Grouping: using these terms and the time of capture, related shots are combined into moments and perspectives.
The service Amazon Rekognition (Amazon Web Services) is used for this in the Frankfurt am Main region (eu-central-1), under a data processing agreement pursuant to Art. 28 GDPR. What is transmitted is not the original photo but a downscaled copy with a maximum edge length of 1600 pixels.
No identification of depicted persons takes place. Faces are located solely as an area of the image; no biometric templates are created, no persons are recognised and no comparisons with external databases are carried out.
The transmitted images are not used to develop or improve AI models — neither by us nor by Amazon Web Services. The opt-out provided for this purpose (AI services opt-out) is permanently enabled for our AWS account.
The analysis results are used solely within the respective event and are deleted together with it.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing and findable presentation of the content).
8. AI-assisted text and title functions
For certain text-based functions the service OpenAI is used: translating the keywords assigned during image analysis (section 7) into further languages, and automatically naming the gallery’s “moments”.
Only individual terms or short text fragments are transmitted – no photos, no names and no contact details. The transmitted content is not used to train AI models. Processing by OpenAI takes place in the USA (see section 12).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a multilingual and clearly organised presentation of the content).
9. Email delivery and waiting list
For sending emails (e.g. confirmations and notifications) the service Resend is used. The email address and the content of the respective message are transmitted.
Anyone who signs up in advance for the waiting list consents to the email address provided being stored with Resend in order to be informed about the launch of the service. Registration is voluntary and consent can be withdrawn at any time with effect for the future (e.g. via unsubscribe link or email). Processing by Resend takes place in the USA (see section 12).
Legal bases: Art. 6(1)(b) GDPR (email delivery as part of the service) and Art. 6(1)(a) GDPR (waiting list).
10. Push notifications
If consent is given, push notifications can be displayed in the browser or on the device (e.g. when the shared gallery is ready). For this purpose, the technical delivery endpoint provided by the browser is stored.
Consent is voluntary and can be withdrawn at any time in the browser or device settings.
Legal basis: Art. 6(1)(a) GDPR (consent).
11. Payment processing
Payment processing when activating an event is handled by Paddle.com as merchant of record. The data required for payment is collected and processed directly by Paddle.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
12. Data transfer to third countries
Some of the services used (OpenAI, Resend) process data in the USA. Insofar as personal data is transferred to a third country, this is done on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR – in particular the EU Standard Contractual Clauses or a certification under the EU-U.S. Data Privacy Framework.
The storage of photos and videos (Cloudflare R2) and the automated image analysis (Amazon Web Services, eu-central-1) take place within the European Union.
13. Retention period and deletion
Photos, messages, and guest data are stored for the duration of the event and the subsequent gallery period.
- Guests can delete their own photos themselves at any time.
- Hosts can delete individual content items or the entire event along with all its content.
- Once an event is deleted, all associated photos, messages, and guest data are permanently removed.
14. Contact
When you contact us by email, the data you submit is used exclusively to process your inquiry.
Legal basis: Art. 6(1)(b) GDPR.
15. Rights of data subjects
Data subjects have the right, at any time, to:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interest (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR)
Please send inquiries to: hello@pixxta.app
In addition, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
16. Changes to this privacy policy
We reserve the right to update this privacy policy.
The current version is published on this website.