Security & Trust
Event photos and face data are sensitive personal data. This page describes, plainly, how TIME&SPACE handles them: what we collect, where it lives, when it is deleted, and what paperwork we can put on the record for you.
Explicit consent, per person
Face search is opt-in. Every guest makes a dedicated, unticked consent choice before any biometric processing. Declining changes nothing about their event; they are simply never searchable.
EU data residency
Photos, selfies and face data are stored and processed in the European Union: database and storage in Frankfurt, face-recognition service in the Netherlands.
Deletion on a schedule
Guest selfies are deleted within 30 days. The face index of event photos expires after one year at most, earlier if the event or photo is deleted. The schedule is published in our terms.
Paperwork for your legal team
A data processing agreement with GDPR Art. 28 terms and our sub-processor register are available on request, along with venue signage and consent copy.
Biometric data
Application security
Sub-processors
These providers process personal data to deliver the service. Biometric data (photos, selfies, face embeddings) is stored and processed in the EU. Consent-gated analytics (Google Analytics, Meta, Microsoft Clarity) run only after a visitor’s explicit cookie consent and are not part of delivering an organiser’s event.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, photo storage, authentication | EU (Frankfurt) |
| Railway | Face-recognition processing | EU (Netherlands) |
| Vercel | Web hosting and compute | EU deployment region; global edge |
| Cloudflare | DNS, CDN, firewall | Global edge |
| Stripe | Payments | EU / US |
| Resend | Transactional email | US (SCCs) |
| Sentry | Error monitoring | EU region |
| Upstash | Rate limiting | EU (eu-west-1) |
| Expo | Push notifications (consumer app) | US (SCCs) |
| Google / Apple | Optional sign-in; organiser-initiated Drive import | EU / US |
Compliance posture
TIME&SPACE processes biometric data under GDPR Art. 9 on the basis of each guest’s explicit consent, and treats its face-matching system as high-risk AI under the EU AI Act (Annex III), with a documented risk-management, transparency and human-oversight programme. Our lead supervisory authority is the CNPD (Portugal).
We describe capabilities, not guarantees: for your event, you remain the data controller and we act as your processor under a data processing agreement. We do not currently hold SOC 2 or ISO 27001 certification; our controls are documented and available for review instead.
Full details: Privacy Policy and Terms of Service.
Request our data processing agreement and sub-processor register, ask a security question, or report a vulnerability. We read everything.
legal@timeandspace.earth