Legal

Privacy Policy

Last updated: July 2026

Protecting personal data is a top priority for us.

This privacy policy informs you about the nature, scope, and purpose of the processing of personal data when using Pixxta, in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

Christian Adams

Zum Hirtenweg 6

66620 Nonnweiler

Germany

Email: hello@pixxta.app

2. Hosting

The website and application are operated via the provider Laravel Cloud on servers in Frankfurt am Main (Germany).

Processing is based on Art. 6(1)(f) GDPR (legitimate interest in operating the website securely and efficiently).

A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider.

3. Cookies

This website uses only technically necessary cookies, in particular:

  • Session cookies
  • Security and CSRF cookies
  • Login cookies for registered hosts

No tracking, profiling, or cross-site analysis takes place.

Legal basis: Art. 6(1)(f) GDPR.

4. Registration as a host

Creating and managing events requires a user account. This involves storing your name, email address, and password (encrypted).

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

5. Participation as a guest

Guests take part without their own account. The following is processed:

  • the name or nickname provided
  • optionally, a profile picture
  • uploaded photos, videos, greeting messages and audio messages

The content is visible only to the participants of the respective event; access is via an event-specific link or QR code.

Guests provide photos and messages voluntarily. Anyone who uploads photos showing other people is responsible for obtaining their consent.

Legal bases: Art. 6(1)(b) GDPR (providing the service) and Art. 6(1)(a) GDPR (consent).

6. Storage of photos and videos

All uploaded photos, videos and profile pictures are stored with the provider Cloudflare (object storage “R2”). The storage location is restricted to the European Union (EU jurisdiction); the files do not leave the EU.

A data processing agreement pursuant to Art. 28 GDPR is in place with the provider.

Legal basis: Art. 6(1)(b) GDPR (provision of the service).

7. Automated image analysis

So that the photos of an event can be presented in an ordered way, every uploaded photo is analysed automatically once after upload. The analysis serves three purposes:

  • Framing: it is determined where faces are located in the image so that preview images are not spoiled by an unfavourable crop.
  • Tagging: terms describing the content are assigned to the image (e.g. “cake”, “dance floor”, “group photo”). The gallery's themes view is built from these.
  • Grouping: using these terms and the time of capture, related shots are combined into moments and perspectives.

The service Amazon Rekognition (Amazon Web Services) is used for this in the Frankfurt am Main region (eu-central-1), under a data processing agreement pursuant to Art. 28 GDPR. What is transmitted is not the original photo but a downscaled copy with a maximum edge length of 1600 pixels.

No identification of depicted persons takes place. Faces are located solely as an area of the image; no biometric templates are created, no persons are recognised and no comparisons with external databases are carried out.

The transmitted images are not used to develop or improve AI models — neither by us nor by Amazon Web Services. The opt-out provided for this purpose (AI services opt-out) is permanently enabled for our AWS account.

The analysis results are used solely within the respective event and are deleted together with it.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an appealing and findable presentation of the content).

8. AI-assisted text and title functions

For certain text-based functions the service OpenAI is used: translating the keywords assigned during image analysis (section 7) into further languages, and automatically naming the gallery’s “moments”.

Only individual terms or short text fragments are transmitted – no photos, no names and no contact details. The transmitted content is not used to train AI models. Processing by OpenAI takes place in the USA (see section 12).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a multilingual and clearly organised presentation of the content).

9. Email delivery and waiting list

For sending emails (e.g. confirmations and notifications) the service Resend is used. The email address and the content of the respective message are transmitted.

Anyone who signs up in advance for the waiting list consents to the email address provided being stored with Resend in order to be informed about the launch of the service. Registration is voluntary and consent can be withdrawn at any time with effect for the future (e.g. via unsubscribe link or email). Processing by Resend takes place in the USA (see section 12).

Legal bases: Art. 6(1)(b) GDPR (email delivery as part of the service) and Art. 6(1)(a) GDPR (waiting list).

10. Push notifications

If consent is given, push notifications can be displayed in the browser or on the device (e.g. when the shared gallery is ready). For this purpose, the technical delivery endpoint provided by the browser is stored.

Consent is voluntary and can be withdrawn at any time in the browser or device settings.

Legal basis: Art. 6(1)(a) GDPR (consent).

11. Payment processing

Payment processing when activating an event is handled by Paddle.com as merchant of record. The data required for payment is collected and processed directly by Paddle.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

12. Data transfer to third countries

Some of the services used (OpenAI, Resend) process data in the USA. Insofar as personal data is transferred to a third country, this is done on the basis of appropriate safeguards within the meaning of Art. 44 et seq. GDPR – in particular the EU Standard Contractual Clauses or a certification under the EU-U.S. Data Privacy Framework.

The storage of photos and videos (Cloudflare R2) and the automated image analysis (Amazon Web Services, eu-central-1) take place within the European Union.

13. Retention period and deletion

Photos, messages, and guest data are stored for the duration of the event and the subsequent gallery period.

  • Guests can delete their own photos themselves at any time.
  • Hosts can delete individual content items or the entire event along with all its content.
  • Once an event is deleted, all associated photos, messages, and guest data are permanently removed.

14. Contact

When you contact us by email, the data you submit is used exclusively to process your inquiry.

Legal basis: Art. 6(1)(b) GDPR.

15. Rights of data subjects

Data subjects have the right, at any time, to:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent (Art. 7(3) GDPR)

Please send inquiries to: hello@pixxta.app

In addition, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

16. Changes to this privacy policy

We reserve the right to update this privacy policy.

The current version is published on this website.

Pixxta

Pixxta is almost ready

Pixxta isn't publicly available yet – but it won't be long. Sign up and we'll let you know the moment you can get started.

Email address

We use cookies

This website uses cookies in order to enhance the overall user experience. Take a look at our Cookies Policy for more information.

Essential cookies

There are some cookies that we have to include in order for certain web pages to function. For this reason, they do not require your consent.

Immer aktiv
  • pixxta_cookie_consent 1 year

    Used to store the user's cookie consent preferences.

  • pixxta-session 2 hours

    Used to identify the user's browsing session.

  • XSRF-TOKEN 2 hours

    Used to secure both the user and our website against cross-site request forgery attacks.