1. Introduction & Operational Role
This platform provides cloud storage, facial recognition indexing, and album distribution services to independent event photographers.
Under the Saudi Personal Data Protection Law (PDPL):
- The Photographer is the Data Controller who captures, uploads, and manages the event gallery.
- Our Platform acts as the Data Processor, executing technical operations (cloud hosting, AI face matching, and automated deletion) strictly according to the photographer’s instructions.
2. Information We Process
We adhere to strict data minimization principles:
A. Photographer Data
- Account Credentials: Name and email address used for account management. We do not collect or store phone numbers.
- Billing Information: Payments are processed directly through Tap Payments. Raw payment details (credit cards, mada) are handled on Tap’s encrypted servers and are never stored on our local infrastructure.
B. Guest & Event Data
- Event Photos: Uploaded directly by the photographer.
- Temporary Selfies: Scanned by guests in their browser to find their matching photos.
- Facial Data Vectors: Mathematical representations extracted from selfies and event photos via AWS Rekognition to perform instant visual searches within an album.
- Technical Logs: Standard IP addresses and device browser metadata used for platform security and error prevention.
3. Purpose of Processing & Guest Consent
- Facial Matching: Biometric facial data is processed strictly to locate photos of a guest within a specific event gallery.
- No Profiling: Facial data is bound exclusively to the specific album. We never build global facial profiles, track individuals across events, or sell biometric data.
- Explicit Consent: Guests provide explicit consent when opening their camera or uploading a selfie to initiate the photo match.
4. Data Storage & Automated Deletion Schedule
We enforce automated data destruction rules to ensure information is not retained longer than necessary:
- Guest Scan Selfies: Processed instantly in memory and discarded immediately after rendering results.
- Free Trial Albums (300 photos): Completely deleted from cloud storage and AI collections 30 days after creation.
- Paid Event Albums: High-resolution photos, thumbnails, and facial vectors are automatically hard-deleted from our cloud servers 90 days after album creation.
5. Third-Party Service Providers
We rely on certified infrastructure providers to deliver our services:
- Amazon Web Services (AWS): Secure storage (S3) and facial processing (AWS Rekognition).
- Tap Payments: Payment gateway processing payments securely in KSA and the GCC.
- Vercel Inc.: Frontend application hosting and serverless routing.
6. Photo Removal & Guest Rights
Because the photographer is the Data Controller of their event gallery, guests wishing to have specific photos removed or excluded should primarily contact the event photographer directly.
However, we provide multiple avenues for guests to exercise their rights under KSA PDPL:
- In-App Photo Removal: Guests can use the “Report / Request Removal” link next to any image in the gallery view.
- Platform Support: If a guest cannot reach the photographer, they may email privacy@wayni.app with the album link and photo reference. As the cloud processor, we will assist in deleting the requested image from our storage servers.
7. Updates to This Policy
We may update this Privacy Policy from time to time. The latest version will always be published on this page with an updated “Effective Date.”