Picvelo Privacy Policy
This Privacy Policy describes the rules for processing personal data in the Picvelo service, a SaaS platform for photographers used to share photo galleries with end clients so that they can select photos.
This document has been drawn up in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: GDPR) and with the applicable provisions of Polish law.
1. Data controller
The controller of your personal data is:
- Name: Jakub Ciepielowski
- Contact: [email protected]
Referred to below in this document as: "Picvelo", "we" or the "Controller".
2. Contact
2.1 General contact
You can contact us on any matter concerning the processing of personal data:
- Email: [email protected]
2.2 Data Protection Officer (DPO)
3. Picvelo's two roles under the GDPR
Picvelo operates in two different roles depending on the type of data being processed:
3.1 Controller, photographer accounts
With regard to the data of photographers (Users) who register an account in the service, Picvelo is the controller of personal data. We collect and process:
- Identification and contact data: first name and surname or company name, email address
- Authentication data: password (stored as a bcrypt hash), 2FA keys (optional)
- Billing data: invoicing details (name, address, tax ID), subscription history, payment method (card details are stored solely by Stripe)
- Technical data: IP address, browser type, activity logs, HTTP headers
- Profile data: service preferences, gallery settings, SMTP configuration
- OAuth data (optional): identifier and email from Google, Facebook (Meta) or Apple services, if the user uses social login
3.2 Processor, data of photographers' end clients
With regard to the data of end clients (people who receive a link to a gallery and select photos), Picvelo acts as a processor on the instructions of the photographer (the controller), within the meaning of Article 28 GDPR.
In this role we process only the data entrusted to us by the photographer:
- First name and surname or nickname of the end client (if the photographer entered them)
- Email address of the end client (if the photographer provided it)
- IP address and technical data from the gallery browsing session
- Information about the photo selections made (list of IDs of selected photos, notes)
The photographer, as the controller, is responsible for the compliance of the processing of end client data with the GDPR. Picvelo processes such data solely in accordance with the concluded Data Processing Agreement (see Data Processing Agreement).
4. Purposes and legal bases of processing
4.1 Photographers' data (Picvelo as controller)
| Purpose of processing | Legal basis under the GDPR |
|---|---|
| Conclusion and performance of the contract (provision of SaaS services) | Art. 6(1)(b), necessity for the performance of a contract |
| Settlements, issuing invoices | Art. 6(1)(c), legal obligation (tax law) |
| Handling complaints and disputes | Art. 6(1)(b) and (c) |
| Ensuring the security of the service, detecting abuse | Art. 6(1)(f), legitimate interest of the controller |
| Own marketing, notifications about changes to the service | Art. 6(1)(f), legitimate interest (existing customers) or Art. 6(1)(a), consent |
| Analytics and improvement of the service | Art. 6(1)(f), legitimate interest of the controller |
| Login via OAuth (Google/Facebook/Apple) | Art. 6(1)(b), performance of a contract / (a), consent |
4.2 End clients' data (Picvelo as processor)
Processing takes place solely on the documented instructions of the photographer. The photographer, as the controller, is obliged to have their own legal basis in relation to end clients.
5. Data retention period
A detailed table of retention periods is available in the Data Retention Policy.
In short:
- Photographer account data: for the duration of the contract plus 90 days from its end, then anonymisation or deletion
- Billing data / invoices: 5 years, in accordance with Article 86 of the Polish Tax Ordinance Act
- System logs: 90 days on a rotating basis
- End clients' data: deleted together with the galleries (subscription plus a 30-day grace period)
- Policy acceptances and consents: 6 years from the end of the relationship
6. Data recipients and subprocessors
6.1 Categories of recipients
Your data may be shared with:
- Processors (subprocessors) providing services to Picvelo, only to the extent necessary to deliver the service
- Public authorities, solely on the basis of a legal obligation (e.g. tax authorities, law enforcement authorities acting on a final ruling)
- Stripe, to the extent of the data necessary to process payments
Picvelo does not sell personal data to third parties.
6.2 List of subprocessors
The current list of subprocessors is available at Subprocessors List.
Subprocessors are contractually obliged to protect data at a level at least equivalent to this Policy, in accordance with Article 28 GDPR.
7. Transfer of data outside the European Economic Area (EEA)
Some of Picvelo's subprocessors are established in, or process data outside, the EEA (mainly in the USA). Every such transfer is safeguarded by appropriate legal instruments:
| Entity | Country | Transfer mechanism |
|---|---|---|
| Cloudflare Inc. | USA | Standard Contractual Clauses (SCCs) |
| Google LLC (GA4, Ads) | USA | SCCs + Data Privacy Framework (DPF) |
| Stripe Inc. | USA | SCCs + DPF |
| Sentry / Functional Software | USA | SCCs + DPF |
| Google, Meta, Apple (OAuth) | USA | SCCs + DPF |
Standard Contractual Clauses (SCCs) are model contracts approved by the European Commission that ensure an adequate level of data protection (Commission Implementing Decision 2021/914). The Data Privacy Framework (DPF) is a certification mechanism for entities in the USA, recognised by the European Commission as ensuring an adequate level of protection (Decision 2023/1795).
The core hosting (OVH SAS, France) remains within the EEA. Photo files may be stored in the Cloudflare R2 object storage service (transfer safeguarded by SCCs, see the table above).
8. Your rights
As a data subject, you have the following rights under the GDPR:
8.1 Right of access (Art. 15 GDPR)
You have the right to obtain confirmation from us as to whether we process your personal data and, if so, access to that data together with information about how it is processed.
8.2 Right to rectification (Art. 16 GDPR)
You have the right to request the immediate rectification of inaccurate personal data or the completion of incomplete personal data.
8.3 Right to erasure (Art. 17 GDPR)
You have the right to request the erasure of personal data (the "right to be forgotten") where: the data is no longer necessary for the purposes for which it was collected; you withdraw consent (where processing was based on consent); you lodge an effective objection; the data was processed unlawfully. This right does not apply, among other cases, where processing is necessary for compliance with a legal obligation.
8.4 Right to restriction of processing (Art. 18 GDPR)
You have the right to request the restriction of processing in specific situations (for example where you contest the accuracy of the data or have lodged an objection).
8.5 Right to data portability (Art. 20 GDPR)
Where processing is based on consent or on a contract and is carried out by automated means, you have the right to receive your data in a structured, commonly used format (JSON, for you to download yourself from the panel in the Data export section) and to transfer it to another controller.
8.6 Right to object (Art. 21 GDPR)
You have the right to object at any time to processing based on the legitimate interest of the controller (Art. 6(1)(f)), including to profiling. Picvelo will cease processing unless it demonstrates compelling legitimate grounds which override your interests.
8.7 Right to withdraw consent (Art. 7(3) GDPR)
Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
8.8 How rights are exercised
Please send requests to the email address: [email protected]. We reply without undue delay, no later than within 1 month of receiving the request (the deadline may be extended to 3 months in complex cases, of which we will inform you).
9. Right to lodge a complaint with a supervisory authority
If you believe that we process your data unlawfully, you have the right to lodge a complaint with a supervisory authority. In Poland this authority is:
President of the Personal Data Protection Office (PUODO) ul. Stawki 2, 00-193 Warsaw Telephone: +48 22 531 03 00 Email: [email protected] Website: uodo.gov.pl
10. Automated decision-making
Picvelo does not use automated decision-making, including profiling, that would produce legal effects or similarly significantly affect natural persons within the meaning of Article 22 GDPR.
Service analytics (Google Analytics 4) serves statistical purposes and the improvement of the service only, and is not used to make decisions concerning individual users.
11. Cookies
Picvelo uses cookies and similar tracking technologies. Detailed information, including a list of all cookies, their purpose and how to manage them, is available in the Cookie Policy.
12. Data security
Picvelo applies appropriate technical and organisational measures ensuring a level of security appropriate to the risk, in accordance with Article 32 GDPR:
- Encryption in transit: HTTPS (TLS 1.2+) for all connections, HSTS
- Password encryption: the bcrypt algorithm with an appropriate cost factor
- Two-factor authentication (2FA): optional for photographers, based on TOTP
- Protection against attacks: Content Security Policy (CSP), CSRF protection, SQL prepared statements
- Access control: the principle of least privilege, access audit logs
- Backups: automatic daily backups of the database and configuration with 30-day retention
- Monitoring: automated error tracking (Sentry) with anonymised data
- Security testing: automated static code analysis and dependency vulnerability checks on every code change (CI)
In the event of a personal data breach that may result in a risk to the rights and freedoms of natural persons, Picvelo will report it to PUODO within 72 hours (Art. 33 GDPR) and notify the affected persons where the risk is high (Art. 34 GDPR).
13. Changes to the Privacy Policy
Picvelo may update this Privacy Policy. We will give notice of significant changes:
- By email to the address assigned to the photographer's account, at least 14 days before the changes take effect
- By a message in the administration panel of the service
- By updating the date "Last updated" at the bottom of this document
Continued use of the service after the changes take effect means that you accept them. If you do not accept the changes, you may terminate the contract in accordance with the Terms and Conditions.
Archived versions of the Policy are available on request at: [email protected]
This document was prepared on the basis of the legal situation as at 2026-05-26. Last updated: 2026-05-26.