Privacy Policy
Version: 1.3
Last updated: 24 September 2026
Effective date: 25 September 2026
This Policy explains which personal data PhotoLuxie processes for its own purposes, why, for how long, and what rights you have.
1. Who we are
PhotoLuxie is a service for photographers: galleries for their clients, file storage and studio-organization tools. The controller for everything described on this page is:
Aikaterini Seirli
Registered office: 2 Konitsis Street, 184 54 Nikaia, Attica, Greece
VAT number: 167935800
Privacy contact: [email protected]
We have not appointed a Data Protection Officer: we have assessed the criteria in Article 37 GDPR against the current scale and nature of our processing, and we will reassess them when these change. For any question, write to us at [email protected].
2. Two different roles
For photographers who have an account, we decide what we keep and why: we are the "controller". That is what this page describes.
For the photos and client information of a photographer (names, phone numbers, contracts, questionnaires and so on), the photographer is the controller. We store and display them only on the photographer's behalf, under the Data Processing Agreement they accept together with the Terms of Service (https://app.photoluxie.com/legal/en/dpa). If you are a photographer's client or a gallery visitor and want to exercise a right, contact your photographer first; if you come to us, we will forward your request to them.
3. What we keep about photographers
- Account: email, studio name, the address of the studio's page (e.g. your-studio.photoluxie.com) and the role of each member of the account.
- Password: never in readable form — only a fingerprint that lets us check it at sign-in. The same applies to recovery codes.
- Sign-up: the email, studio name and plan you chose, together with the confirmation code we email you (it expires in 15 minutes). To stop mass sign-ups we keep the IP address and a fingerprint of the email of each sign-up attempt for one day.
- Acceptance of the Terms: which version of the Terms of Service and the Data Processing Agreement you accepted, when, from which account and from which IP address.
- Usage: when you last opened the Admin, your plan, the storage you use, and your studio's language, settings and logo.
- Subscription and payments: the state of your subscription (plan, renewal or end date, whether a payment failed) and the customer ID Stripe gives you. The details you enter on the checkout page (name, email, phone, address, optionally VAT number, card details) are received by Stripe. We never see or store your card number. See section 7.
- Security: failed sign-in and recovery attempts, with the IP address, for at most one day, so that we can stop anyone guessing passwords.
- Communication: the emails we send you (sign-up code, notices about your account, subscription or inactivity) and anything you write to us.
What is required. Your email, studio name, password and acceptance of the Terms are needed to create and run the account, and payment details are needed for a paid subscription; without them we cannot provide the service or the plan. Anything else you add in your studio settings (for example a logo) is optional.
4. Gallery visitors
When someone opens or downloads from a gallery, the visit is recorded with the IP address and device type, so that the photographer can see statistics. The IP and device are erased automatically after 90 days; only the visit itself (day, gallery, action) remains. Wrong access codes are kept with the IP for at most one day. We process these on the photographer's behalf (section 2).
5. Illegal-content reports
If you send a report about illegal content (https://app.photoluxie.com/legal/en/report), we keep what you write (where the content is, what kind it is, your explanation, your name and email) to examine it, reply to you and be able to show how we handled it. If you give us an email address, we send you an automatic confirmation of receipt straight away. Your IP address is used only to limit the number of reports and is erased after one day; it is not stored with the report. We do not reveal your identity to the photographer whose content the report concerns, unless it is needed to examine the report (for example in a copyright complaint) or required by law. The location of the content, its type and your explanation are necessary for us to examine a report, as are your name and email, except in reports of child sexual abuse or exploitation, where they are optional; without an email, however, we cannot reply to you.
6. Cookies and storage on your device
We use only cookies that the service needs to work:
__Host-admin_session— the photographer's sign-in to the Admin (up to 90 days).__Host-gallery_session— a visitor's access to a gallery after entering the code (up to 30 days, and never after the gallery expires).admin_lang— the language (Greek or English) you chose in the Admin, so that your device remembers it (up to 1 year).
In addition, a few practical details stay locally in your browser and are sent nowhere: in the Admin, the sort order you chose and the progress of an interrupted upload; on a gallery page, the access code and your place in the gallery, only while the tab is open.
No advertising or analytics cookies, no third-party tracking tools. Fonts are loaded from our own servers, not from Google.
7. Who we share it with
- Cloudflare (hosting, database, file storage, network protection) — processes on our behalf the data that passes through or is stored in PhotoLuxie (account, usage, security, reports); it does not receive your card details, which you give directly to Stripe.
- Resend (email delivery) — receives the address and content of every email we send you.
- Stripe (Stripe Payments Europe, Limited, Ireland — payments) — receives your payment details directly from you and tells us only the state of your subscription. Stripe processes part of this data as an independent controller too (for example for fraud prevention and its own legal obligations), under its own privacy policy: https://stripe.com/privacy.
- Authorities, only where the law requires it.
The full list, with what each company does and where, is on the "Third-party services" page (https://app.photoluxie.com/legal/en/services). We do not sell data and do not use it for advertising.
8. Why (legal basis)
- To provide the service you asked for, charge you for it and send you the necessary notices — performance of a contract (Article 6(1)(b) GDPR).
- To secure the service, prevent abuse, prove acceptance of the Terms and handle illegal-content reports — legitimate interests (Article 6(1)(f)) and the obligations of Regulation (EU) 2022/2065 on digital services (Article 6(1)(c)).
- For what the law requires, such as tax records of payments — legal obligation (Article 6(1)(c)).
9. Where it is stored
The database is in the European Union and the files are in Cloudflare's Eastern Europe region. In addition, before changes to the system, the system operator keeps a temporary copy of the database (not of the photos and files) on an encrypted computer in Greece, to recover if something goes wrong; the copy is deleted within 7 days.
Cloudflare and Resend are US companies, and Stripe may transfer data to the US. Where data leaves the European Union, the transfer relies on the company's certification under the EU–US Data Privacy Framework and on the European Commission's Standard Contractual Clauses.
10. How long we keep it
- While the account is active.
- A Free account that has not been signed into for 180 days may be deleted, after a warning email and 30 days without a sign-in.
- If a subscription is not paid (or its files do not fit in the Free plan after it ends): days 1–3 everything works, from day 4 the account is suspended, on day 7 we send a last email, and from the following day the account and its files may be permanently deleted. We send an email at every step.
- After deletion, database records may remain in the provider's point-in-time recovery for up to 30 days, and in the copies described in section 9, only for disaster recovery.
- The record of your acceptance of the Terms is kept for as long as the account exists.
- The payment details we need for our tax records are kept for as long as tax law requires, even after the account is deleted.
- Illegal-content reports: until their handling is complete, and afterwards only as long as needed to establish, exercise or defend related legal claims or as the law requires. We review them once a year and delete those no longer needed.
11. Your rights
You can ask for access to your data, correction, deletion, restriction or portability, or object to processing based on legitimate interests. Write to us at [email protected]; we will reply within one month. We may ask you to confirm that the request is yours, for example by writing from your account email. You also have the right to complain to the Greek Data Protection Authority (https://www.dpa.gr).
12. Changes
When this Policy changes, we update the version and date at the top. For significant changes we inform photographers by email or in the Admin.