Privacy Policy
Effective date: 26 June 2026 · Version 2.0
EventLens DOO Zrenjanin (“EventLens”, “we”, “us”, “our”) is the data controller for the personal data described in this Privacy Policy. This document explains what we process, why, on what legal basis, who we share it with, how long we keep it, and what your rights are.
EventLens is a photo platform that helps event attendees find and receive photographs of themselves and others, taken at events by professional photographers, using facial-recognition technology to match a selfie to event photos.
Because we process biometric data (a mathematical representation of your face), we have written this policy to be explicit about what that data is, how we use it, how long we keep it, and how you can have it deleted.
In short:
- We use a selfie you provide to find photos of you at an event you attended.
- We never sell your data, and we never use your face or your photos to train AI models.
- You can ask us to delete your data at any time at info@eventlens.rs.
- Facial recognition runs only with your explicit consent, which you can withdraw at any time.
- After your account is deleted, your data is removed following a 30-day recovery grace period; anonymized order and invoice records are kept only as long as tax law requires.
- Payments in RSD are processed by OTP Banka; payments in other currencies are handled by Paddle as Merchant of Record under its own terms.
1. Who we are (Data Controller)
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin
Republic of Serbia
Company ID: 21998303 · TIN (PIB): 114277204
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
Website: https://www.eventlens.rs
If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, you may contact us at the addresses above to exercise the rights in Section 9.
2. Who this policy applies to
- Account holders — event organizers, photographers, and registered guests who create an EventLens account.
- Guests (no account) — people who scan to find and buy their photos without creating an account.
Where a section applies only to one group, we say so.
3. The data we process
3.1 Identity and contact data
Name, email address, and the identifier from your sign-in provider (account holders). For guests (no account) : the email provided at checkout and a temporary session identifier.
3.2 Biometric data (special category)
When you choose to find your photos by face, our facial-recognition provider, Amazon Web Services Rekognition, creates a facial template (“faceprint”) — a unique mathematical representation of your face — from your selfie, in order to match you to event photos.
The faceprint is a mathematical vector. It cannot be turned back into a recognizable image of you, and it is not used to identify you anywhere outside EventLens. This is special-category data under Article 9 GDPR (and Article 17 of Serbia’s Zakon o zaštiti podataka o ličnosti, “ZZPL”), and we process it only on the basis of your explicit consent. Section 11 explains how facial recognition works in detail.
3.3 Business profile (organizers and photographers)
Business contact details, links, and a profile photo you provide.
3.4 Photos
Event photos uploaded by organizers and photographers, and the selfie you submit to search.
3.5 Commercial data
Orders, amounts, currency, and purchase history. Payments are processed by a PCI DSS–compliant payment processor; we receive confirmation and limited, non-sensitive data (for example, the card brand), but we never store your full card number.
3.6 Technical data
IP address (recorded when a session is created and on security events such as rate-limit denials), device and browser information, and the cookies / session data needed to operate and secure the Service. We do not derive your geographic location from your IP address, and we do not run analytics, advertising, or third-party tracking.
4. Why we process your data, and on what basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Matching your selfie to event photos (facial recognition) | Explicit consent — Art. 9(2)(a). You may withdraw it at any time. |
| Operating your account and fulfilling purchases | Performance of a contract — Art. 6(1)(b) |
| Issuing fiscal receipts (fiskalni račun) for purchases | Legal obligation — Art. 6(1)(c) |
| Sending service and transactional messages | Performance of a contract / legal obligation |
| Event notifications (new photos, event expiring, etc.) | Legitimate interest — Art. 6(1)(f), with an opt-out in your settings |
| Securing and improving the Service | Legitimate interest — Art. 6(1)(f) |
| Keeping order and tax records | Legal obligation — Art. 6(1)(c) |
We do not use your selfie, your faceprint, or your photos to train any general-purpose AI or facial-recognition model. Your biometric data is used solely to find your photos within the specific event(s) you take part in.
5. Sharing your data
We do not sell your personal data. We share it only with service providers acting on our behalf under contract, and with authorities where legally required.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (S3, Cognito, Rekognition) | Hosting, authentication, facial recognition | EU and/or US |
| OTP Banka Srbija (via the SIA payment gateway) Paddle.com Market Ltd | Card payment processing in RSD Merchant of Record and payment processing for payments in currencies other than RSD | Serbia / EU UK / EU / US |
| Email delivery provider | Sending transactional and notification emails | EU / US |
Payments outside RSD (Paddle as Merchant of Record). For payments in currencies other than RSD, our reseller Paddle (Paddle.com Market Ltd) acts as the Merchant of Record. This means Paddle — not EventLens — is the seller of record for that transaction and acts as an independent data controller for the payment data it collects (such as your billing details and card information), under its own Privacy Policy. We receive only confirmation and limited, non-sensitive order data. You can review Paddle’s terms and privacy notice here:
- Buyer Terms: https://www.paddle.com/legal/checkout-buyer-terms
- Privacy Notice: https://www.paddle.com/legal/privacy
We will update this policy when we add or change a significant processor — including any new payment processor.
Joint processing with organizers
For the photos of a specific event, EventLens and the event organizer act as joint controllers under Article 26 GDPR. The organizer is responsible for informing attendees and collecting their consent at the ticketing stage; EventLens is responsible for the technical processing, hosting, and delivery. You can request the essence of this arrangement at info@eventlens.rs.
6. International transfers
Some providers (primarily AWS) may process data in the European Union and/or the United States. Where data is transferred outside the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards under Article 46 GDPR — typically the European Commission’s Standard Contractual Clauses, combined with encryption in transit and at rest.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account data | While your account is active. After you request deletion, the account remains recoverable by logging in for a 30-day grace period, after which it is anonymized; associated data (including selfies and faceprints) is deleted from our systems and from our facial-recognition provider. |
| Guest (no account) scan data | The search selfie and its faceprint are deleted when the event is cleaned up (about 30 days after the event ends). Session data expires within 7 days. The email and order data of a guest purchase are retained with the (anonymized) order records for the legal retention period, even though the account-level data does not exist. |
| Event photos | While the event is active; deleted when the event is deleted by the organizer (after its retention period). |
| Orders and fiscal receipts | Retained as required by accounting and tax law — accounting records for 10 years under Article 28 of Serbia’s Zakon o računovodstvu, and individual invoices for 5 years — kept in anonymized form where possible, even after account deletion. |
| Server logs | Up to 90 days, then deleted or aggregated. |
At the end of processing, data is permanently deleted or irreversibly anonymized.
8. How we protect your data
We apply industry-standard measures: encryption in transit (TLS) and at rest; access limited to authorized team members with a business need; passwords handled entirely by AWS Cognito (we never store them); card details handled by our PCI DSS–compliant payment processor (we never store them); and rate-limiting and fraud-prevention controls on scan and payment endpoints. Because our facial-recognition processing is large-scale and involves a special category of data, we have carried out a Data Protection Impact Assessment (Article 35 GDPR) and keep it under review. No system is completely secure; where a personal-data breach affects you, we will notify you and the relevant authority where the law requires it.
9. Your rights
Subject to the law, you may access, rectify, erase, restrict, or object to the processing of your data; withdraw consent; and obtain a portable copy of your data. Account holders can export their data from within the app at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and withdrawing facial-recognition consent means the face-search feature can no longer be provided to you.
To exercise any right, or to complain, contact info@eventlens.rs. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why. You may also lodge a complaint with your local data-protection authority — in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), Bulevar kralja Aleksandra 15, 11000 Belgrade.
10. Automated processing and AI
The face-matching that decides whether a photo is “of you” is automated (an AI system), but it does not produce legal or similarly significant effects on you — at worst it shows a photo that is not of you, or misses one that is. You can re-scan with a different selfie, ask the organizer to adjust tagging, or ask us to reset matching for a specific event at info@eventlens.rs. We do not use your data for any other automated decision-making with significant effects.
Our facial-recognition feature is a biometric system within the meaning of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). We provide clear notice that automated facial recognition is in use, keep the system under human oversight, and let you request human review of any match. We do not use it for untargeted scraping of facial images, for biometric categorization by sensitive characteristics, or for any prohibited purpose under that Act.
11. How facial recognition works (biometric data in detail)
This section explains, in plain terms, exactly how we handle the most sensitive data we process — your face.
What we create. When you take or upload a selfie to search, our facial-recognition provider, Amazon Web Services Rekognition, analyzes it and generates a faceprint: a numerical vector that represents the geometry of your face. We compare that faceprint against the faces detected in a specific event’s photos to find the ones you appear in.
Why this needs explicit consent. A faceprint is biometric data used to uniquely identify you. Under Article 9 GDPR and Article 17 ZZPL it is a special category of personal data, which may be processed only with your explicit, freely given consent. We collect that consent separately from our general Terms and this Privacy Policy, on a dedicated Biometric Data Consent screen shown before you scan for the first time — this separation is a legal requirement, not a formality.
What we do and do not do with it. – We use your selfie and faceprint only to find your photos at the event(s) you take part in. – We never sell them, never share them with the event organizer or photographers, and never use them to train AI models. – The faceprint cannot be reconstructed into a recognizable photograph of you, and is never used to identify you outside EventLens.
Who processes it. Matching is performed by AWS Rekognition acting on our instructions under a data-processing agreement, with EU Standard Contractual Clauses where data is processed outside the EEA (see Section 6).
How long we keep it. – If you scan as a guest without an account, your search selfie and its faceprint are deleted when the event is cleaned up (about 30 days after the event ends). – If you have an account, your selfie and faceprint are kept while your account is active and are deleted — including from AWS Rekognition — when you delete your account, after the 30-day recovery grace period.
Your choice and withdrawal. Face search is an optional feature in the sense that you give a distinct consent for it; however, because matching a selfie to event photos is the core function of EventLens, the Service cannot find your photos without it. You can withdraw your consent at any time — in the app via Account Settings → Account Deletion, or by emailing info@eventlens.rs. Withdrawal triggers deletion of your faceprint and stops further processing, and does not affect the lawfulness of processing carried out before withdrawal.
12. Children
EventLens is not directed at children under the minimum age set in your country (16 in much of the EU), and we do not knowingly process their data. Children may appear in photos uploaded by organizers and photographers; in that case the organizer is responsible for obtaining parental consent and the lawful basis for those images. If you believe we hold a child’s data without proper authorization, contact info@eventlens.rs.
13. Cookies and similar technologies
We use cookies and local browser storage only for purposes that are strictly necessary to run the Service or that reflect a preference you set yourself. We do not use advertising, analytics, or third-party tracking cookies, and no tracking, advertising, or analytics SDK is loaded anywhere in the app or website.
Strictly necessary (no consent required — the Service cannot function without these):
- Session and authentication cookies/tokens that keep you signed in (handled by AWS Cognito).
- A device identifier we generate to prevent fraud and abuse, and to apply rate limits.
- Short-lived storage used to carry you through sign-in, confirmation, and password-reset flows.
- UI state such as whether the navigation menu is expanded.
Functional preferences (a choice you make yourself, remembered for your convenience):
- Your language preference.
- Your currency preference.
- Your light/dark theme preference.
The app degrades gracefully if browser storage is unavailable (for example in private-browsing mode): the device identifier falls back to a per-session value, and language, currency, and theme fall back to sensible defaults.
Because we set no advertising or analytics cookies, there is nothing non-essential to consent to, and we therefore do not show a cookie consent banner. If we ever introduce analytics or marketing technologies, we will ask for your consent first, keep those technologies dormant until you opt in, and never gate essential storage on that choice.
14. Changes to this policy
We may update this policy from time to time. When we do, we change the version and effective date above. For material changes, we give reasonable advance notice — by email or in-app — and, where consent is the basis for processing, we ask for it again. The current version is always available at https://www.eventlens.rs/privacy-policy.
15. Contact
EventLens DOO Zrenjanin
Klajnova 18, 23000 Zrenjanin, Republic of Serbia
Email: info@eventlens.rs
Phone: +381 (0)62 944 96 76
