Poses

Privacy Policy

Effective 27 July 2026

In plain language: Poses helps you find photos of yourself from an event. You take a selfie; we turn it into a numeric “face template”, compare it to the event’s photos, and show you the ones you’re in. We don’t keep your selfie image. Your face data is used only for matching, you can download or delete your data at any time, and everything is deleted after the event.

This policy explains how Poses (“we”, “us”) collects and uses personal data when you use poses.pro and the Poses photo-matching service. It is written to meet the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies, the EU/UK GDPR. For any privacy question or to exercise your rights, contact hello@poses.pro.

Poses is a service operated by Novae technologies, a Dubai sole establishment (Dubai trade licence No. 1640581) based in Dubai, UAE.

1. Who this policy is for

Guests who scan a selfie to find their photos; photographers / organisers with a Poses account; and people who appear in uploaded photos even if they never used Poses.

2. What data we collect

If you are a Guest:

Face template (biometric)
A numeric representation of your face, created from your selfie, used to match you to photos. This is sensitive (special-category) personal data.
Name, email, phone
Optional - only if you enter them, to receive your gallery link and updates.
Consent record
The date/time and IP address at which you gave consent.
Photo matches & gallery link
Which photos you appear in, and your private gallery URL.

We do not store your selfie image. It is processed in memory to create the face template and then discarded. The template is a set of numbers and cannot be turned back into a photo of you.

If you are a photographer/organiser: account email, name, password (stored only as a secure hash), your plan, and - on paid plans - billing identifiers handled by our payment processor. If you appear in an uploaded photo, our system detects faces and creates face templates so guests can be matched (see section 4). We also keep basic security logs and IP addresses. We do not use advertising cookies or third-party trackers.

3. Why we use your data

To match you to your photos using facial recognition and show you your gallery; to deliver your gallery link and (if you opt in) tell you when new photos of you are added; to let photographers manage albums; to keep the service secure (including detecting fake/spoofed selfies); and to take payment from photographers on paid plans. We do not sell your data, use it for advertising, or use it to train facial-recognition models.

4. Legal basis

Your face template (Guest)
Your explicit consent, given on the scan screen before any processing.
Name / email / phone, gallery delivery
Consent / providing the service you requested.
Face-indexing of people in uploaded photos
The legitimate interests of the photographer/organiser in running their event and letting attendees find their photos.
Photographer accounts & billing
Performance of a contract.
Security, anti-fraud, audit logs
Legitimate interests / legal obligation.

You can withdraw consent at any time (see section 7); this does not affect processing already carried out.

5. Who we share data with

We host and run Poses ourselves and use a few trusted providers, each bound by a data-processing agreement and acting only on our instructions: Hostinger (server hosting & email delivery), Cloudflare R2 (photo storage, Asia-Pacific region), Backblaze B2 (encrypted backups, stored in the EU), and Stripe (card payments, photographers only). We do not share your personal data with anyone else except where required by law.

6. International transfers & retention

Photos are stored with Cloudflare R2 in the Asia-Pacific region. Face templates and account data are held on our server in India. Our encrypted backups are stored in the EU. Where your data is transferred outside the UAE we rely on appropriate safeguards, and backups are encrypted before they leave our server. On retention: free-trial albums are deleted 7 days after creation; on paid plans, albums are deleted 30 days (monthly plans) or 365 days (yearly plans) after the last activity, and 30 days after a subscription ends; and you can have your Guest data deleted at any time on request. Backups and security logs are kept for a limited period.

7. Your rights

Access
Get a copy of your data - Guests: use “Download my data” at the bottom of your gallery.
Erasure
Have your data deleted - Guests: use “Remove my data” at the bottom of your gallery. Album photos belong to the photographer and are not affected.
Withdraw consent
Stop us using your face data going forward.
Object / opt out
Unsubscribe from notification emails using the link in any email.
Rectification & portability
Correct inaccurate data; receive your data in a machine-readable format.
Complain
To the UAE Data Office (or your local authority if in the EU).

To exercise any right, use the in-gallery links or email hello@poses.pro. We respond within one month and verify your identity before acting on a request.

8. How we protect your data

We use encryption in transit (HTTPS/TLS); encryption at rest for photos and backups; securely hashed passwords; strict per-account access separation; network isolation; rate limiting and upload validation; liveness detection to reject fake/screen selfies; audit logging; and encrypted off-site backups. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents.

9. Children

Poses is not directed at children. Events may include minors in photographs; where required, the organiser is responsible for obtaining any necessary parental/guardian consent.

10. Changes & contact

We may update this policy and will post the new version here with a revised effective date. Contact us any time at hello@poses.pro.