PhotoLuxieΕλληνικά

Privacy Policy

Version: 1.3

Last updated: 24 September 2026

Effective date: 25 September 2026

This Policy explains which personal data PhotoLuxie processes for its own purposes, why, for how long, and what rights you have.

1. Who we are

PhotoLuxie is a service for photographers: galleries for their clients, file storage and studio-organization tools. The controller for everything described on this page is:

Aikaterini Seirli
Registered office: 2 Konitsis Street, 184 54 Nikaia, Attica, Greece
VAT number: 167935800
Privacy contact: [email protected]

We have not appointed a Data Protection Officer: we have assessed the criteria in Article 37 GDPR against the current scale and nature of our processing, and we will reassess them when these change. For any question, write to us at [email protected].

2. Two different roles

For photographers who have an account, we decide what we keep and why: we are the "controller". That is what this page describes.

For the photos and client information of a photographer (names, phone numbers, contracts, questionnaires and so on), the photographer is the controller. We store and display them only on the photographer's behalf, under the Data Processing Agreement they accept together with the Terms of Service (https://app.photoluxie.com/legal/en/dpa). If you are a photographer's client or a gallery visitor and want to exercise a right, contact your photographer first; if you come to us, we will forward your request to them.

3. What we keep about photographers

What is required. Your email, studio name, password and acceptance of the Terms are needed to create and run the account, and payment details are needed for a paid subscription; without them we cannot provide the service or the plan. Anything else you add in your studio settings (for example a logo) is optional.

4. Gallery visitors

When someone opens or downloads from a gallery, the visit is recorded with the IP address and device type, so that the photographer can see statistics. The IP and device are erased automatically after 90 days; only the visit itself (day, gallery, action) remains. Wrong access codes are kept with the IP for at most one day. We process these on the photographer's behalf (section 2).

5. Illegal-content reports

If you send a report about illegal content (https://app.photoluxie.com/legal/en/report), we keep what you write (where the content is, what kind it is, your explanation, your name and email) to examine it, reply to you and be able to show how we handled it. If you give us an email address, we send you an automatic confirmation of receipt straight away. Your IP address is used only to limit the number of reports and is erased after one day; it is not stored with the report. We do not reveal your identity to the photographer whose content the report concerns, unless it is needed to examine the report (for example in a copyright complaint) or required by law. The location of the content, its type and your explanation are necessary for us to examine a report, as are your name and email, except in reports of child sexual abuse or exploitation, where they are optional; without an email, however, we cannot reply to you.

6. Cookies and storage on your device

We use only cookies that the service needs to work:

In addition, a few practical details stay locally in your browser and are sent nowhere: in the Admin, the sort order you chose and the progress of an interrupted upload; on a gallery page, the access code and your place in the gallery, only while the tab is open.

No advertising or analytics cookies, no third-party tracking tools. Fonts are loaded from our own servers, not from Google.

7. Who we share it with

The full list, with what each company does and where, is on the "Third-party services" page (https://app.photoluxie.com/legal/en/services). We do not sell data and do not use it for advertising.

8. Why (legal basis)

9. Where it is stored

The database is in the European Union and the files are in Cloudflare's Eastern Europe region. In addition, before changes to the system, the system operator keeps a temporary copy of the database (not of the photos and files) on an encrypted computer in Greece, to recover if something goes wrong; the copy is deleted within 7 days.

Cloudflare and Resend are US companies, and Stripe may transfer data to the US. Where data leaves the European Union, the transfer relies on the company's certification under the EU–US Data Privacy Framework and on the European Commission's Standard Contractual Clauses.

10. How long we keep it

11. Your rights

You can ask for access to your data, correction, deletion, restriction or portability, or object to processing based on legitimate interests. Write to us at [email protected]; we will reply within one month. We may ask you to confirm that the request is yours, for example by writing from your account email. You also have the right to complain to the Greek Data Protection Authority (https://www.dpa.gr).

12. Changes

When this Policy changes, we update the version and date at the top. For significant changes we inform photographers by email or in the Admin.