Skip to main content

Security & Trust

BUILT TO BE READ
BY YOUR LEGAL TEAM.

Event photos and face data are sensitive personal data. This page describes, plainly, how TIME&SPACE handles them: what we collect, where it lives, when it is deleted, and what paperwork we can put on the record for you.

Explicit consent, per person

Face search is opt-in. Every guest makes a dedicated, unticked consent choice before any biometric processing. Declining changes nothing about their event; they are simply never searchable.

EU data residency

Photos, selfies and face data are stored and processed in the European Union: database and storage in Frankfurt, face-recognition service in the Netherlands.

Deletion on a schedule

Guest selfies are deleted within 30 days. The face index of event photos expires after one year at most, earlier if the event or photo is deleted. The schedule is published in our terms.

Paperwork for your legal team

A data processing agreement with GDPR Art. 28 terms and our sub-processor register are available on request, along with venue signage and consent copy.

Biometric data

HOW FACE SEARCH HANDLES PERSONAL DATA.

  • Consent is collected in-product, before camera access, as an explicit unticked checkbox. Consent records are versioned and logged (timestamp, hashed IP, withdrawal state).
  • Consent is never a condition of attending an event. Guests who decline can browse public galleries like anyone else.
  • Face embeddings are used only to match a consenting guest's selfie against the photos of the event being searched. They are never used to train models and never shared or sold.
  • Guests have a self-service deletion path for their data, without needing an account.
  • Retention is fixed and published: selfies within 30 days; unmatched-search data within 30 days; the photo face index no later than 1 year from upload.

Application security

THE CONTROLS AROUND THE DATA.

  • All traffic is encrypted in transit (TLS). Photo storage is private by default; photos are served through signed, time-limited URLs only.
  • Role-based access for event teams (owner, team member, photographer) with per-event scoping. Administrative access is restricted and logged.
  • A web application firewall and per-endpoint rate limiting protect guest-facing routes, including the scan and search endpoints.
  • Secrets live in platform secret stores, never in code. Error monitoring runs in an EU region.
  • Payments are processed by Stripe; card data never touches TIME&SPACE systems.

Sub-processors

WHO ELSE TOUCHES THE DATA, AND WHERE.

These providers process personal data to deliver the service. Biometric data (photos, selfies, face embeddings) is stored and processed in the EU. Consent-gated analytics (Google Analytics, Meta, Microsoft Clarity) run only after a visitor’s explicit cookie consent and are not part of delivering an organiser’s event.

ProviderPurposeLocation
SupabaseDatabase, photo storage, authenticationEU (Frankfurt)
RailwayFace-recognition processingEU (Netherlands)
VercelWeb hosting and computeEU deployment region; global edge
CloudflareDNS, CDN, firewallGlobal edge
StripePaymentsEU / US
ResendTransactional emailUS (SCCs)
SentryError monitoringEU region
UpstashRate limitingEU (eu-west-1)
ExpoPush notifications (consumer app)US (SCCs)
Google / AppleOptional sign-in; organiser-initiated Drive importEU / US

Compliance posture

WHAT WE CLAIM, AND WHAT WE DON'T.

TIME&SPACE processes biometric data under GDPR Art. 9 on the basis of each guest’s explicit consent, and treats its face-matching system as high-risk AI under the EU AI Act (Annex III), with a documented risk-management, transparency and human-oversight programme. Our lead supervisory authority is the CNPD (Portugal).

We describe capabilities, not guarantees: for your event, you remain the data controller and we act as your processor under a data processing agreement. We do not currently hold SOC 2 or ISO 27001 certification; our controls are documented and available for review instead.

Full details: Privacy Policy and Terms of Service.

NEED THE DPA, OR FOUND
SOMETHING WE SHOULD KNOW?

Request our data processing agreement and sub-processor register, ask a security question, or report a vulnerability. We read everything.

legal@timeandspace.earth