Privacy Policy
Effective date: 26 June 2026 · Version 2.0
EventLens DOO Zrenjanin (“EventLens”, “we”, “us”, “our”) is the data controller for the personal data described in this Privacy Policy. This document explains what we process, why, on what legal basis, who we share it with, how long we keep it, and what your rights are.
EventLens is a photo platform that helps event attendees find and receive photographs of themselves and others, taken at events by professional photographers, using facial-recognition technology to match a selfie to event photos.
Because we process biometric data (a mathematical representation of your face), we have written this policy to be explicit about what that data is, how we use it, how long we keep it, and how you can have it deleted.
In short:
- We use a selfie you provide to find photos of you at an event you attended.
- We never sell your data, and we never use your face or your photos to train AI models.
- You can ask us to delete your data at any time at info@eventlens.rs.
- Facial recognition runs only with your explicit consent, which you can withdraw at any time.
- After your account is deleted, your data is removed following a 30-day recovery grace period; anonymized order and invoice records are kept only as long as tax law requires.
- Payments in RSD are processed by OTP Banka; payments in other currencies are handled by Paddle as Merchant of Record under its own terms.
1. Who we are (Data Controller)
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin
Republic of Serbia
Company ID: 21998303 · TIN (PIB): 114277204
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
Website: https://www.eventlens.rs
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may contact us at the addresses above to exercise the rights in Section 9.
2. Who this policy applies to
- Account holders — event organizers, photographers, and registered guests who create an EventLens account.
- Guests (no account) — people who scan to find and buy their photos without creating an account.
Where a section applies only to one group, we say so.
3. The data we process
3.1 Identity and contact data
Name, email address, and the identifier from your sign-in provider (account holders). For guests (no account) : the email provided at checkout and a temporary session identifier.
3.2 Biometric data (special category)
When you choose to find your photos by face, our facial-recognition provider, Amazon Web Services Rekognition, creates a facial template (“faceprint”) — a unique mathematical representation of your face — from your selfie, in order to match you to event photos.
The faceprint is a mathematical vector. It cannot be turned back into a recognizable image of you, and it is not used to identify you anywhere outside EventLens. This is special-category data under Article 9 GDPR (and Article 17 of Serbia’s Zakon o zaštiti podataka o ličnosti, “ZZPL”), and we process it only on the basis of your explicit consent. Section 11 explains how facial recognition works in detail.
3.3 Business profile (organizers and photographers)
Business contact details, links, and a profile photo you provide.
3.4 Photos
Event photos uploaded by organizers and photographers, and the selfie you submit to search.
3.5 Commercial data
Orders, amounts, currency, and purchase history. Payments are processed by a PCI DSS–compliant payment processor; we receive confirmation and limited, non-sensitive data (for example, the card brand), but we never store your full card number.
3.6 Technical data
IP address (recorded when a session is created and on security events such as rate-limit denials), device and browser information, and the cookies / session data needed to operate and secure the Service. We do not derive your geographic location from your IP address, and we do not run analytics, advertising, or third-party tracking.
4. Why we process your data, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Matching your selfie to event photos (facial recognition) | Explicit consent — Art. 9(2)(a). You may withdraw it at any time. |
| Operating your account and fulfilling purchases | Performance of a contract — Art. 6(1)(b) |
| Issuing fiscal receipts (fiskalni račun) for purchases | Legal obligation — Art. 6(1)(c) |
| Sending service and transactional messages | Performance of a contract / legal obligation |
| Event notifications (new photos, event expiring, etc.) | Legitimate interest — Art. 6(1)(f), with an opt-out in your settings |
| Securing and improving the Service | Legitimate interest — Art. 6(1)(f) |
| Keeping order and tax records | Legal obligation — Art. 6(1)(c) |
We do not use your selfie, your faceprint, or your photos to train any general-purpose AI or facial-recognition model. Your biometric data is used solely to find your photos within the specific event(s) you take part in.
5. Sharing your data
We do not sell your personal data. We share it only with service providers acting on our behalf under contract, and with authorities where legally required.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (S3, Cognito, Rekognition) | Hosting, authentication, facial recognition | EU and/or US |
| OTP Banka Srbija (via the SIA payment gateway) Paddle.com Market Ltd | Card payment processing in RSD Merchant of Record and payment processing for payments in currencies other than RSD | Serbia / EU UK / EU / US |
| Email delivery provider | Sending transactional and notification emails | EU / US |
Payments outside RSD (Paddle as Merchant of Record). For payments in currencies other than RSD, our reseller Paddle (Paddle.com Market Ltd) acts as the Merchant of Record. This means Paddle — not EventLens — is the seller of record for that transaction and acts as an independent data controller for the payment data it collects (such as your billing details and card information), under its own Privacy Policy. We receive only confirmation and limited, non-sensitive order data. You can review Paddle’s terms and privacy notice here:
- Buyer Terms: https://www.paddle.com/legal/checkout-buyer-terms
- Privacy Notice: https://www.paddle.com/legal/privacy
We will update this policy when we add or change a significant processor — including any new payment processor.
Joint processing with organizers
For the photos of a specific event, EventLens and the event organizer act as joint controllers under Article 26 GDPR. The organizer is responsible for informing attendees and collecting their consent at the ticketing stage; EventLens is responsible for the technical processing, hosting, and delivery. You can request the essence of this arrangement at info@eventlens.rs.
6. International transfers
Some providers (primarily AWS) may process data in the European Union and/or the United States. Where data is transferred outside the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards under Article 46 GDPR — typically the European Commission’s Standard Contractual Clauses, combined with encryption in transit and at rest.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data | While your account is active. After you request deletion, the account remains recoverable by logging in for a 30-day grace period, after which it is anonymized; associated data (including selfies and faceprints) is deleted from our systems and from our facial-recognition provider. |
| Guest (no account) scan data | The search selfie and its faceprint are deleted when the event is cleaned up (about 30 days after the event ends). Session data expires within 7 days. The email and order data of a guest purchase are retained with the (anonymized) order records for the legal retention period, even though the account-level data does not exist. |
| Event photos | While the event is active; deleted when the event is deleted by the organizer (after its retention period). |
| Orders and fiscal receipts | Retained as required by accounting and tax law — accounting records for 10 years under Article 28 of Serbia’s Zakon o računovodstvu, and individual invoices for 5 years — kept in anonymized form where possible, even after account deletion. |
| Server logs | Up to 90 days, then deleted or aggregated. |
At the end of processing, data is permanently deleted or irreversibly anonymized.
8. How we protect your data
We apply industry-standard measures: encryption in transit (TLS) and at rest; access limited to authorized team members with a business need; passwords handled entirely by AWS Cognito (we never store them); card details handled by our PCI DSS–compliant payment processor (we never store them); and rate-limiting and fraud-prevention controls on scan and payment endpoints. Because our facial-recognition processing is large-scale and involves a special category of data, we have carried out a Data Protection Impact Assessment (Article 35 GDPR) and keep it under review. No system is completely secure; where a personal-data breach affects you, we will notify you and the relevant authority where the law requires it.
9. Your rights
Subject to the law, you may access, rectify, erase, restrict, or object to the processing of your data; withdraw consent; and obtain a portable copy of your data. Account holders can export their data from within the app at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and withdrawing facial-recognition consent means the face-search feature can no longer be provided to you.
To exercise any right, or to complain, contact info@eventlens.rs. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why. You may also lodge a complaint with your local data-protection authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), Bulevar kralja Aleksandra 15, 11000 Belgrade.
10. Automated processing and AI
The face-matching that decides whether a photo is “of you” is automated (an AI system), but it does not produce legal or similarly significant effects on you — at worst it shows a photo that is not of you, or misses one that is. You can re-scan with a different selfie, ask the organizer to adjust tagging, or ask us to reset matching for a specific event at info@eventlens.rs. We do not use your data for any other automated decision-making with significant effects.
Our facial-recognition feature is a biometric system within the meaning of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). We provide clear notice that automated facial recognition is in use, keep the system under human oversight, and let you request human review of any match. We do not use it for untargeted scraping of facial images, for biometric categorization by sensitive characteristics, or for any prohibited purpose under that Act.
11. How facial recognition works (biometric data in detail)
This section explains, in plain terms, exactly how we handle the most sensitive data we process — your face.
What we create. When you take or upload a selfie to search, our facial-recognition provider, Amazon Web Services Rekognition, analyzes it and generates a faceprint: a numerical vector that represents the geometry of your face. We compare that faceprint against the faces detected in a specific event’s photos to find the ones you appear in.
Why this needs explicit consent. A faceprint is biometric data used to uniquely identify you. Under Article 9 GDPR and Article 17 ZZPL it is a special category of personal data, which may be processed only with your explicit, freely given consent. We collect that consent separately from our general Terms and this Privacy Policy, on a dedicated Biometric Data Consent screen shown before you scan for the first time — this separation is a legal requirement, not a formality.
What we do and do not do with it. – We use your selfie and faceprint only to find your photos at the event(s) you take part in. – We never sell them, never share them with the event organizer or photographers, and never use them to train AI models. – The faceprint cannot be reconstructed into a recognizable photograph of you, and is never used to identify you outside EventLens.
Who processes it. Matching is performed by AWS Rekognition acting on our instructions under a data-processing agreement, with EU Standard Contractual Clauses where data is processed outside the EEA (see Section 6).
How long we keep it. – If you scan as a guest without an account, your search selfie and its faceprint are deleted when the event is cleaned up (about 30 days after the event ends). – If you have an account, your selfie and faceprint are kept while your account is active and are deleted — including from AWS Rekognition — when you delete your account, after the 30-day recovery grace period.
Your choice and withdrawal. Face search is an optional feature in the sense that you give a distinct consent for it; however, because matching a selfie to event photos is the core function of EventLens, the Service cannot find your photos without it. You can withdraw your consent at any time — in the app via Account Settings → Account Deletion, or by emailing info@eventlens.rs. Withdrawal triggers deletion of your faceprint and stops further processing, and does not affect the lawfulness of processing carried out before withdrawal.
12. Children
EventLens is not directed at children under the minimum age set in your country (16 in much of the EU), and we do not knowingly process their data. Children may appear in photos uploaded by organizers and photographers; in that case the organizer is responsible for obtaining parental consent and the lawful basis for those images. If you believe we hold a child’s data without proper authorization, contact info@eventlens.rs.
13. Cookies and similar technologies
We use cookies and local browser storage only for purposes that are strictly necessary to run the Service or that reflect a preference you set yourself. We do not use advertising, analytics, or third-party tracking cookies, and no tracking, advertising, or analytics SDK is loaded anywhere in the app or website.
Strictly necessary (no consent required — the Service cannot function without these):
- Session and authentication cookies/tokens that keep you signed in (handled by AWS Cognito).
- A device identifier we generate to prevent fraud and abuse, and to apply rate limits.
- Short-lived storage used to carry you through sign-in, confirmation, and password-reset flows.
- UI state such as whether the navigation menu is expanded.
Functional preferences (a choice you make yourself, remembered for your convenience):
- Your language preference.
- Your currency preference.
- Your light/dark theme preference.
The app degrades gracefully if browser storage is unavailable (for example in private-browsing mode): the device identifier falls back to a per-session value, and language, currency, and theme fall back to sensible defaults.
Because we set no advertising or analytics cookies, there is nothing non-essential to consent to, and we therefore do not show a cookie consent banner. If we ever introduce analytics or marketing technologies, we will ask for your consent first, keep those technologies dormant until you opt in, and never gate essential storage on that choice.
14. Changes to this policy
We may update this policy from time to time. When we do, we change the version and effective date above. For material changes, we give reasonable advance notice — by email or in-app — and, where consent is the basis for processing, we ask for it again. The current version is always available at https://www.eventlens.rs/privacy-policy.
15. Contact
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin, Republic of Serbia
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
Privacy Policy
Effective date: 27 July 2026 · Version 2.0
EventLens DOO Zrenjanin (“EventLens”, “we”, “us”, “our”) is the data controller for the personal data described in this Privacy Policy. This document explains what we process, why, on what legal basis, who we share it with, how long we keep it, and what your rights are.
EventLens is a photo platform that helps event attendees find and receive photographs of themselves and others, taken at events by professional photographers, using facial-recognition technology to match a selfie to event photos.
Because we process biometric data (a mathematical representation of your face), we have written this policy to be explicit about what that data is, how we use it, how long we keep it, and how you can have it deleted.
In short:
- We use a selfie you provide to find photos of you at an event you attended.
- We never sell your data, and we never use your face or your photos to train AI models.
- You can ask us to delete your data at any time at info@eventlens.rs.
- Facial recognition runs only with your explicit consent, which you can withdraw at any time.
- After your account is deleted, your data is removed following a 30-day recovery grace period; pseudonymized order and invoice records are kept only as long as tax law requires.
- Payments in RSD are processed by OTP Banka; payments in other currencies are handled by Paddle as Merchant of Record under its own terms.
1. Who we are (Data Controller)
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin
Republic of Serbia
Company ID: 21998303 · TIN (PIB): 114277204
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
Website: https://www.eventlens.rs
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may contact us at the addresses above to exercise the rights in Section 9.
EventLens is primarily intended for users in Europe, and our data-protection practices are aligned with European requirements. If you access the Service from the United States or other jurisdictions, local rules may grant you additional rights. To exercise any such rights, or if you have questions about how we handle your data, contact info@eventlens.rs.
2. Who this policy applies to
- Account holders — event organizers, photographers, and registered guests who create an EventLens account.
- Guests (no account) — people who scan to find and buy their photos without creating an account.
Where a section applies only to one group, we say so.
3. The data we process
3.1 Identity and contact data
Name, email address, and the identifier from your sign-in provider (account holders). For guests (no account) : the email provided at checkout and a temporary session identifier.
3.2 Biometric data (special category)
When you choose to find your photos by face, our facial-recognition provider, Amazon Web Services Rekognition, creates a facial template (“faceprint”) — a unique mathematical representation of your face — from your selfie, in order to match you to event photos.
The faceprint is a mathematical vector. It is designed so that it cannot practically be turned back into an image of you, and we do not use it to identify you outside EventLens. This is special-category data under Article 9 GDPR (and Article 17 of Serbia’s Zakon o zaštiti podataka o ličnosti, “ZZPL”), and we process it only on the basis of your explicit consent. Section 11 explains how facial recognition works in detail.
See our stand-alone Biometric Data Consent for full detail on what we do with your faceprint, how long we keep it, and how to withdraw at any time.
3.3 Business profile (organizers and photographers)
Business contact details, links, and a profile photo you provide.
3.4 Photos
Event photos uploaded by organizers and photographers, and the selfie you submit to search.
3.5 Commercial data
Orders, amounts, currency, and purchase history. Payments are processed by a PCI DSS–compliant payment processor; we receive confirmation and limited, non-sensitive data (for example, the card brand), but we never store your full card number.
3.6 Technical data
IP address (recorded when a session is created and on security events such as rate-limit denials), device and browser information, and the cookies / session data needed to operate and secure the Service. We do not derive your geographic location from your IP address, and we do not run analytics, advertising, or third-party tracking.
4. Why we process your data, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Matching your selfie to event photos (facial recognition) | Explicit consent — Art. 9(2)(a). You may withdraw it at any time. |
| Operating your account and fulfilling purchases | Performance of a contract — Art. 6(1)(b) |
| Issuing fiscal receipts (fiskalni račun) for purchases | Legal obligation — Art. 6(1)(c) |
| Sending service and transactional messages | Performance of a contract / legal obligation — Art. 6(1)(b) and (c) GDPR |
| Event notifications (new photos, event expiring, etc.) | Legitimate interest — Art. 6(1)(f), with an opt-out in your settings |
| Securing and improving the Service | Legitimate interest — Art. 6(1)(f) |
| Keeping order and tax records | Legal obligation — Art. 6(1)(c) |
We do not use your selfie, your faceprint, or your photos to train any general-purpose AI or facial-recognition model. Your biometric data is used solely to find your photos within the specific event(s) you take part in.
5. Sharing your data
We do not sell your personal data. We share it only with service providers acting on our behalf under contract, and with authorities where legally required.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (S3, Cognito, Rekognition) | Hosting, authentication, facial recognition | EU and/or US |
| OTP Banka Srbija (via the SIA payment gateway) | Card payment processing in RSD | Serbia / EU |
| Paddle.com Market Ltd | Merchant of Record and payment processing for payments in currencies other than RSD | UK / EU / US |
| Email delivery provider | Sending transactional and notification emails | EU / US |
Payments outside RSD (Paddle as Merchant of Record). For payments in currencies other than RSD, our reseller Paddle (Paddle.com Market Ltd) acts as the Merchant of Record. This means Paddle — not EventLens — is the seller of record for that transaction and acts as an independent data controller for the payment data it collects (such as your billing details and card information), under its own Privacy Policy. We receive only confirmation and limited, non-sensitive order data. You can review Paddle’s terms and privacy notice here:
- Buyer Terms: https://www.paddle.com/legal/checkout-buyer-terms
- Privacy Notice: https://www.paddle.com/legal/privacy
We will update this policy when we add or change a significant processor.
Joint processing with organizers
For the photos of a specific event, EventLens and the event organizer act as joint controllers under Article 26 GDPR. The organizer is responsible for informing attendees and collecting their consent at the ticketing stage; EventLens is responsible for the technical processing, hosting, and delivery. You can request the essence of this arrangement at info@eventlens.rs.
6. International transfers
EventLens is established in Serbia, which has not yet been recognized by the European Commission as providing a level of data protection equivalent to the EU. Transfers of your data from the EEA to EventLens in Serbia therefore rely on appropriate safeguards under Article 46 — Standard Contractual Clauses, encryption in transit and at rest, and a transfer risk assessment. Onward transfers to processors outside the EEA (primarily AWS in the US) rely on the same safeguards, with additional reliance on the EU–US Data Privacy Framework where the processor is certified under it. Copies of the relevant safeguards are available on request at info@eventlens.rs.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data | While your account is active. After you request deletion, the account remains recoverable by logging in during a 30-day grace period (the period during which you can restore your account simply by signing in). After the grace period, your account is pseudonymized and associated biometric data (selfies and faceprints) is permanently deleted from our systems and from our facial-recognition provider. |
| Shop-visitor scan data | The search selfie and its faceprint are permanently deleted when the event is cleaned up (the internal removal process for event data, triggered about 30 days after the event ends). Session data expires within 7 days. The email and order data of a guest purchase are retained with the order records for the statutory retention period, in pseudonymized form where the law allows. |
| Event photos | While the event is active; deleted when the event is deleted by the organizer, or after the event retention period. |
| Orders and fiscal receipts | Retained as required by accounting and tax law — accounting records for 10 years under Article 28 of Serbia’s Zakon o računovodstvu, and individual invoices for 5 years. The buyer’s email is retained with the order record so that the fiscal receipt remains valid; data is held in pseudonymized form, even after account deletion. |
| Server logs | Up to 90 days, then deleted or aggregated. |
At the end of processing, biometric data is permanently deleted; other data is pseudonymized or irreversibly anonymized where possible without breaching statutory retention obligations.
8. How we protect your data
We apply industry-standard measures: encryption in transit (TLS) and at rest; access limited to authorized team members with a business need; passwords handled entirely by AWS Cognito (we never store them); card details handled by our PCI DSS–compliant payment processor (we never store them); and rate-limiting and fraud-prevention controls on scan and payment endpoints. We maintain contractual confidentiality obligations on personnel with access to personal data, and periodic security review of our vendors. Because our facial-recognition processing is large-scale and involves a special category of data, we have carried out a Data Protection Impact Assessment (Article 35 GDPR) and keep it under review. No system is completely secure; where a personal-data breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours where required, and inform you without undue delay where the breach is likely to result in a high risk to you.
9. Your rights
Subject to the law, you may access, rectify, erase, restrict, or object to the processing of your data; withdraw consent; and obtain a portable copy of your data. Account holders can export their data from within the app at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and withdrawing facial-recognition consent means the face-search feature can no longer be provided to you. Withdrawing your facial-recognition consent immediately stops further biometric processing and triggers deletion of your faceprint, without requiring you to delete your account.
To exercise any right, or to complain, contact info@eventlens.rs. We handle requests free of charge and may ask you to verify your identity before we act, to protect your data. We respond within one month, extendable by two further months for complex requests, in which case we will explain the reason. You may also lodge a complaint with your local data-protection authority.
10. Automated processing and AI
The face-matching that decides whether a photo is “of you” is automated (an AI system), but it does not produce legal or similarly significant effects on you — at worst it shows a photo that is not of you, or misses one that is. You can re-scan with a different selfie, ask the organizer to adjust tagging, or ask us to reset matching for a specific event at info@eventlens.rs. We do not use your data for any other automated decision-making with significant effects.
Our facial-recognition feature is a biometric system within the meaning of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). We provide clear notice that automated facial recognition is in use, keep the system under human oversight, and let you request human review of any match. We do not use it for scraping of facial images, for biometric categorization by sensitive characteristics, or for any prohibited purpose under that Act.
11. How facial recognition works (biometric data in detail)
Face-recognition processing runs only with your separate explicit consent under Article 9(2)(a) GDPR. Because a faceprint is special-category data, the law requires that you agree to it separately from these general terms.
The complete Biometric Data Consent — what data we create, how we use it, who processes it, how long we keep it, and how to withdraw at any time — is a stand-alone document you review and accept on a dedicated screen before your first face scan. You can also read it at any time at Biometric Data Consent.
If you have not given this consent, we do not create a faceprint from your selfie and face search is not available to you. You can still use EventLens to browse public galleries, buy photos manually, and access your past purchases.
12. Children
EventLens is intended solely for users who are at least 18 years old. We do not knowingly process the data of individuals under 18 through account creation or active use of the app (including face search). Children may appear in photos uploaded by organizers and photographers; as joint controllers, EventLens and the organizer share responsibility for lawful processing of minors’ images, with the organizer being required to warrant that parental consent has been obtained for identifiable minors and that a lawful basis exists for such images. If you believe we hold data of anyone under 18 without proper authorization, contact info@eventlens.rs — we will delete such data without undue delay upon notification.
13. Cookies and similar technologies
We use cookies and local browser storage only for purposes that are strictly necessary to run the Service or that reflect a preference you set yourself. We do not use advertising, analytics, or third-party tracking cookies, and no tracking, advertising, or analytics SDK is loaded anywhere in the app or website.
Strictly necessary (no consent required — the Service cannot function without these):
- Session and authentication cookies/tokens that keep you signed in (handled by AWS Cognito).
- A device identifier, used solely to detect fraud and abuse and to enforce rate limits, and kept no longer than necessary for that security purpose.
- Short-lived storage used to carry you through sign-in, confirmation, and password-reset flows.
Functional preferences (a choice you make yourself, remembered for your convenience):
- Your language preference.
- Your currency preference.
The app defaults if browser storage is unavailable (for example in private-browsing mode): the device identifier falls back to a per-session value, and language and currency fall back to sensible defaults.
Because we set no advertising or analytics cookies, there is nothing non-essential to consent to, and we therefore do not show a cookie consent banner. If we ever introduce analytics or marketing technologies, we will ask for your consent first, keep those technologies dormant until you opt in, and never gate our Service on that choice.
14. Changes to this policy
We may update this policy from time to time. When we do, we change the version and effective date above. For material changes, we give reasonable advance notice — by email or in-app — and, where consent is the basis for processing, we ask for it again. The current version is always available at https://www.eventlens.rs/privacy-policy.
15. Contact
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin
Republic of Serbia
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
Biometric Data Consent
Effective date: 27 July 2026 · Version 1.0
This is a stand-alone consent, separate from our Terms of Service and Privacy Policy. Under Article 9 GDPR (and Article 17 of Serbia’s ZZPL), the processing of biometric data requires your explicit, freely given consent — collected separately from other terms. You will see this document on a dedicated consent screen before your first face scan, and you can read it at any time from our Privacy Policy.
If you decline, you can still use EventLens to browse public galleries, buy photos manually, and access purchases already in your account; only face-based search will be unavailable.
You must be at least 18 years old to give this consent. If you are under 18, do not proceed with face search.
1. What we create. When you take or upload a selfie to search, our facial-recognition provider, Amazon Web Services Rekognition, generates a faceprint from it — a mathematical vector that describes the geometry of your face. It is designed so that it cannot practically be turned back into a recognizable image of you, and it is never used to identify you outside EventLens.
2. What we use it for. We compare your faceprint against the faces detected in the photos of the specific event(s) you take part in, so that we can show you the photos you appear in. That is the only purpose. We never sell your faceprint, never share it with the event organizer or the photographers, and never use it — or your selfie, or any photo of you — to train any AI or facial-recognition model.
3. Who processes it. Matching is performed by AWS Rekognition acting on our written instructions under a data-processing agreement. Where processing takes place outside the European Economic Area, EU Standard Contractual Clauses apply. Full detail on international transfers is in Section 6 of our Privacy Policy.
4. How long we keep it.
- Guests (no account): your search selfie and your faceprint are permanently deleted when the event is cleaned up — the internal removal process for event data, triggered about 30 days after the event ends.
- Account holders: your selfie and your faceprint are kept while your account is active, and are deleted — including from AWS Rekognition — when you delete your account (after a 30-day recovery grace period) or when you turn face search off (see #5 below).
5. How to withdraw this consent. You can withdraw at any time, without deleting your account, by turning face search off in the app (Account Settings → Face Search) or by emailing info@eventlens.rs. Withdrawal immediately stops further biometric processing and triggers deletion of your faceprint from our systems and from AWS Rekognition. It does not affect the lawfulness of processing carried out before withdrawal.
6. Why this consent qualifies as freely given. Face search is the specific service you are asking for when you submit a selfie. Your consent is therefore freely given even though the feature does not work without it — we do not condition any other part of the Service on this consent, and we do not bundle it with our Terms or Privacy Policy.
7. Objections from people appearing in photos. If a person objects to their appearance in event photographs, we delete their faceprint and remove them from active face search and from the event’s public gallery. Photographs that also depict other people remain available to buyers who have already purchased them, to the extent that this does not disproportionately affect the rights of the objecting person. Objections can be sent to info@eventlens.rs.
8. Human oversight and AI Act notice. Face-matching is an automated biometric system within the meaning of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). We provide clear notice that automated facial recognition is in use, keep the system under human oversight, and let you request human review of any specific match by emailing info@eventlens.rs.
Legal basis. Article 9(2)(a) GDPR (explicit consent for special-category data) and Article 17 of Serbia’s Zakon o zaštiti podataka o ličnosti.
Contact. EventLens DOO Zrenjanin, Klajnova 18, 23000 Zrenjanin, Republic of Serbia · info@eventlens.rs · +381 (0)62 944 96 76
