Privacy & Data Protection Policy (GDPR / RGPD)
1 September 2026 · v1.0
This policy explains how Photohawk handles personal data under the EU General Data Protection Regulation (GDPR) and its French equivalent, the RGPD (Règlement Général sur la Protection des Données), as well as the UK GDPR. RGPD and GDPR are the same law.
1. Who we are
Photohawk is an event-photography platform that lets photographers and organisers publish, search and sell event photos.
- Legal entity: CLOUDCONCUR LTD (company number 13399913), a company registered in England & Wales, trading as Photohawk.
- Registered address: 23 Caldey Gardens, Ingleby Barwick, Stockton-on-Tees, TS17 5HW, United Kingdom.
- Data Protection Officer (DPO): Andrew Hammond — contact support@photohawk.com.
- EU representative (GDPR Art. 27): we have not appointed an EU representative, on the basis that our processing of EU residents' data is occasional and not our main activity (Art. 27(2)). We keep this under review and will appoint a representative if our processing changes.
- Supervisory authorities: the UK Information Commissioner's Office (ICO) for the UK, and EU authorities including the French CNIL for individuals in the EU.
2. Our two roles — controller and processor
Photohawk deals with two kinds of people, and our legal role differs for each:
- Photographers and organisers (our customers). For your account data (name, email, business details, login, billing and payout information) Photohawk is the data controller.
- Event attendees and buyers (your customers). For the data of the people in and buying the photos, you (the photographer/organiser) are the data controller and Photohawk is your data processor — we process that data on your instructions to run the galleries, search and sales you have set up. A Data Processing Agreement (see §11) governs this relationship.
3. What personal data we process
For photographers/organisers (we are controller):
- Identity and contact: name, email, phone, business name, address.
- Account & security: login credentials (via AWS), sessions.
- Financial: subscription/billing data (via Stripe) and payout details (via Trolley).
For event attendees/buyers (we are processor, on the organiser's behalf):
- Identity and contact: name, email, phone number, postal/billing address.
- Photographs of attendees.
- Biometric data — where face/selfie search is enabled (see §4).
- Order and payment data (processed via our payment providers; we do not store full card numbers).
- Marketing consent status, where the attendee opts in.
4. Face and selfie search (special-category biometric data)
Where an organiser enables selfie/face search, Photohawk creates a mathematical representation of faces so an attendee can find their own photos.
- Purpose: solely to match a person to their own event photos.
- Where: processed and stored in the European Union (AWS, Ireland region).
- Retention: face/biometric data is automatically deleted when a gallery ages out (within ~60 days) and when a gallery is deleted — whichever comes first.
- Legal basis (GDPR Art. 9): biometric data is a special category, processed on the basis of the individual's explicit consent. As the data controller for attendees, the organiser is responsible for obtaining the explicit consent required before enabling face search. To support this, Photohawk provides an in-product consent step: an attendee is asked to consent before their selfie is used for face search, and can decline.
- Minors: see §13.
5. Why we use data and our legal bases
- To provide the service (host galleries, run search, process orders): performance of a contract.
- Payments, payouts, tax and accounting records: performance of a contract and compliance with a legal obligation.
- Face/selfie search: the individual's explicit consent (Art. 9), obtained as described in §4.
- Marketing emails/messages: only with the recipient's consent (opt-in), which can be withdrawn at any time.
- Analytics and advertising cookies: only with your consent, given via our cookie banner (see §12).
- Security, fraud prevention and service improvement: our legitimate interests, balanced against your rights.
6. Where your data is stored and international transfers
- Data residency: attendee and account data — including photos and biometric face data — is hosted in the European Union (AWS, Ireland / eu-west-1). Our identity service (AWS) is also in the EU.
- International transfers: some of our sub-processors (see §7) operate outside the EU/UK (e.g. in the United States). Where personal data is transferred outside the EU/UK, we rely on an adequacy decision where one applies, and otherwise on the European Commission's Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum, plus additional safeguards where needed.
7. Sub-processors
We use a small number of vetted providers to deliver the service, each under a data-processing agreement (and SCCs/UK Addendum where they process data outside the EU/UK):
| Provider | Purpose | Data involved |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, identity, face search, transactional email — EU region | All personal data, photos, biometric data |
| Cloudflare (incl. R2) | CDN, custom domains, object storage | Photos, request data |
| Stripe | Card payments & subscriptions | Buyer & customer payment data |
| Xendit | Payments (Southeast Asia) | Buyer payment data |
| Paystack | Payments (Africa) | Buyer payment data |
| Trolley | Photographer payouts | Payee identity & bank details |
| Postmark | Transactional email | Names, email addresses |
| Twilio / WhatsApp | Photo delivery & notifications | Names, phone numbers |
| Google (Google Analytics) | Website usage analytics (consent-based) | Usage/device data, identifiers |
| Meta Platforms (Meta Pixel) | Advertising & conversion measurement (consent-based) | Usage data, identifiers |
A current list is available on request.
8. How long we keep data (retention)
- Face / biometric data: deleted within ~60 days of a gallery ageing out, and on gallery deletion (see §4).
- Photos and videos: retention is controlled by the account owner (the organiser/photographer). Content is kept for as long as the account owner keeps it; account owners can delete photos, videos, galleries and attendee records at any time, and we delete it when they do. Photohawk does not impose a fixed lifetime on this content.
- Orders and financial records: kept for 7 years to meet tax and accounting obligations.
- Attendee/buyer contact records: controlled by the organiser — kept while the organiser keeps them, and deleted when the organiser deletes them or on a verified erasure request.
- Marketing lists: kept until consent is withdrawn.
- Operational/security logs are retained for 30 days.
9. How we protect data
- In transit: encrypted over HTTPS/TLS everywhere.
- At rest: photos and content are stored on AWS and Cloudflare R2, which encrypt data at rest by default; sensitive credentials (e.g. connected-account tokens) are additionally encrypted with AWS.
- Access controls: authenticated access via AWS; staff access is limited to what is needed to operate the service.
10. Your rights
Under the GDPR/RGPD and UK GDPR you have the right to: access your data; rectify it; erase it (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent at any time. You also have the right to complain to a supervisory authority (the ICO in the UK, or your local authority such as the CNIL in France).
How to exercise them:
- Photographers/organisers (we are controller): contact our DPO at support@photohawk.com. We respond within one month.
- Event attendees/buyers (the organiser is controller): please contact the photographer or organiser who ran your event. Photographers can delete an attendee's personal data — including their photos and any face-search data — from within Photohawk, and Photohawk will action a verified request on the organiser's behalf.
Closing a Photohawk account cancels billing but does not by itself erase stored data; ask us to erase data if that is what you need.
11. Data Processing Agreement (DPA)
For photographers/organisers, our processing of your attendees' data is governed by a Data Processing Agreement under GDPR Art. 28, which we make available on request at support@photohawk.com.
12. Cookies and similar technologies
- Strictly necessary cookies (for login, security and core functionality) are always active; they don't require consent.
- Analytics and advertising cookies — Google Analytics and the Meta Pixel (see §7) — are non-essential and load only after you opt in through our cookie consent banner. You can change or withdraw your choice at any time via the banner / cookie settings. Declining leaves the service fully usable.
- More detail is set out in our separate Cookie Policy.
13. Children's data
Events may include minors. Face/selfie search consent is the organiser's responsibility (see §4); where minors may be present, the organiser must obtain consent from a parent or guardian before enabling face search for them. Photohawk does not knowingly create biometric data for a child without that consent, and the in-product consent step reinforces this.
14. Data breaches
If a personal-data breach occurs, Photohawk will notify the affected data controller without undue delay after becoming aware of it, and will assist them in meeting their own notification obligations to supervisory authorities and individuals (GDPR Arts. 33–34).
15. Changes to this policy
We may update this policy; the “Effective date” above shows the current version. Material changes will be communicated to account holders.
16. Contact
Data Protection Officer — Andrew Hammond. CLOUDCONCUR LTD (company no. 13399913), trading as Photohawk. Email: support@photohawk.com · 23 Caldey Gardens, Ingleby Barwick, Stockton-on-Tees, TS17 5HW, United Kingdom.
