Privacy Policy

Last updated: December 28, 2025

1. Introduction

Welcome to SnapTank.ai ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered event photo distribution platform.

This policy is compliant with the EU General Data Protection Regulation (GDPR), UAE Personal Data Protection Law (PDPL), and India Digital Personal Data Protection Act (DPDP).

2. Data Controller

SnapTank.ai is the data controller responsible for your personal data. For any privacy-related inquiries, contact us at:

  • Email: snaptankai@gmail.com
  • Data Protection Officer: snaptankai@gmail.com

3. Data We Collect

We collect the following categories of personal data:

3.1 Biometric Data (Photos)

We collect and process photographs containing your facial image for the purpose of AI-powered facial recognition matching. This enables us to identify and deliver event photos to you automatically.

Important: Facial recognition data is classified as special category/sensitive personal data. We process this data only with your explicit consent.

3.2 Contact Information

  • Email address
  • Phone number (for WhatsApp/SMS notifications)
  • Name

3.3 Location Data

  • Event venue information
  • GPS coordinates (when enabled for photo geotagging)
  • Country/region for compliance purposes

3.4 Technical Data

  • IP address
  • Browser type and version
  • Device information
  • Cookie identifiers

4. Legal Basis for Processing

We process your personal data under the following legal bases:

  • Explicit Consent (Article 6(1)(a) & 9(2)(a) GDPR): For processing biometric/facial recognition data
  • Contract Performance (Article 6(1)(b) GDPR): To deliver event photos you registered for
  • Legitimate Interest (Article 6(1)(f) GDPR): For service improvement and fraud prevention
  • Legal Obligation (Article 6(1)(c) GDPR): To comply with applicable laws

5. How We Use Your Data

  • Match your face with event photographs using AI facial recognition
  • Deliver your event photos via email, WhatsApp, or SMS
  • Send event-related notifications
  • Improve our AI matching algorithms
  • Prevent fraud and ensure platform security
  • Comply with legal obligations

6. Data Sharing

We may share your data with:

  • Event Organizers: To facilitate photo distribution for their events
  • Photographers: Limited access to manage photo uploads
  • Cloud Service Providers: For secure data storage and processing
  • Analytics Providers: Anonymized data for service improvement

We do not sell your personal data to third parties.

7. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions by relevant authorities
  • Binding Corporate Rules where applicable

8. Data Retention

Event Photos

12 months after event

Unless earlier deletion requested

Facial Recognition Data

30 days

After photo delivery complete

Account Data

Account duration + 3 years

For legal compliance

Technical Logs

90 days

For security & debugging

9. Your Rights

Under GDPR, UAE PDPL, and India DPDP, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to certain processing activities
  • Right to Withdraw Consent: Withdraw consent at any time

10. Security Measures

We implement industry-standard security measures including:

End-to-end encryption for data in transit
AES-256 encryption for data at rest
Regular security audits and penetration testing
Access controls and authentication
Employee training on data protection

11. Children's Privacy

Our service is not intended for children under 16. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes via email or prominent notice on our platform. Continued use after changes constitutes acceptance.

13. Contact & Complaints

For privacy inquiries or to file a complaint:

You also have the right to lodge a complaint with your local data protection authority.