
Privacy Policy
Effective 27 July 2026
This policy explains how Poses (“we”, “us”) collects and uses personal data when you use poses.pro and the Poses photo-matching service. It is written to meet the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, where it applies, the EU/UK GDPR. For any privacy question or to exercise your rights, contact hello@poses.pro.
Poses is a service operated by Novae technologies, a Dubai sole establishment (Dubai trade licence No. 1640581) based in Dubai, UAE.
1. Who this policy is for
Guests who scan a selfie to find their photos; photographers / organisers with a Poses account; and people who appear in uploaded photos even if they never used Poses.
2. What data we collect
If you are a Guest:
We do not store your selfie image. It is processed in memory to create the face template and then discarded. The template is a set of numbers and cannot be turned back into a photo of you.
If you are a photographer/organiser: account email, name, password (stored only as a secure hash), your plan, and - on paid plans - billing identifiers handled by our payment processor. If you appear in an uploaded photo, our system detects faces and creates face templates so guests can be matched (see section 4). We also keep basic security logs and IP addresses. We do not use advertising cookies or third-party trackers.
3. Why we use your data
To match you to your photos using facial recognition and show you your gallery; to deliver your gallery link and (if you opt in) tell you when new photos of you are added; to let photographers manage albums; to keep the service secure (including detecting fake/spoofed selfies); and to take payment from photographers on paid plans. We do not sell your data, use it for advertising, or use it to train facial-recognition models.
4. Legal basis
You can withdraw consent at any time (see section 7); this does not affect processing already carried out.
5. Who we share data with
We host and run Poses ourselves and use a few trusted providers, each bound by a data-processing agreement and acting only on our instructions: Hostinger (server hosting & email delivery), Cloudflare R2 (photo storage, Asia-Pacific region), Backblaze B2 (encrypted backups, stored in the EU), and Stripe (card payments, photographers only). We do not share your personal data with anyone else except where required by law.
6. International transfers & retention
Photos are stored with Cloudflare R2 in the Asia-Pacific region. Face templates and account data are held on our server in India. Our encrypted backups are stored in the EU. Where your data is transferred outside the UAE we rely on appropriate safeguards, and backups are encrypted before they leave our server. On retention: free-trial albums are deleted 7 days after creation; on paid plans, albums are deleted 30 days (monthly plans) or 365 days (yearly plans) after the last activity, and 30 days after a subscription ends; and you can have your Guest data deleted at any time on request. Backups and security logs are kept for a limited period.
7. Your rights
To exercise any right, use the in-gallery links or email hello@poses.pro. We respond within one month and verify your identity before acting on a request.
8. How we protect your data
We use encryption in transit (HTTPS/TLS); encryption at rest for photos and backups; securely hashed passwords; strict per-account access separation; network isolation; rate limiting and upload validation; liveness detection to reject fake/screen selfies; audit logging; and encrypted off-site backups. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents.
9. Children
Poses is not directed at children. Events may include minors in photographs; where required, the organiser is responsible for obtaining any necessary parental/guardian consent.
10. Changes & contact
We may update this policy and will post the new version here with a revised effective date. Contact us any time at hello@poses.pro.