Privacy Policy

How we collect, use, store, and safeguard your personal data at Lenzeit

Our Privacy Policy

1. Introduction

At Lenzeit, we are committed to protecting your privacy. This Privacy Policy outlines how we collect, use, store, and safeguard the personal data of our users, including photographers, studios, and event clients, both locally and internationally.

2. Data We Collect

From Photographers:

  • Personal Information: Name, email address, phone number
  • IP Address and Device Information
  • Subscription and Billing Details

From Clients (via Photographers):

  • Photographs of Clients
  • Client Email Addresses (for delivery purposes)
  • Facial Data for Recognition (processed by AI, but not shared)

Automatically Collected:

  • Event Metadata: Uploaded by photographers and used solely for photo organization and delivery
  • IP Address & Browser Information: For analytics and security

3. Purpose of Data Collection

We use your information for the following purposes:

  • Account creation and management
  • Photo organization and secure delivery to clients
  • Subscription billing and payment processing
  • Customer service and technical support
  • Analytics to improve user experience and AI accuracy

4. Facial Recognition & Biometric Data Processing

Our platform uses AI-based facial recognition to identify and sort individuals in uploaded photographs. This is used solely to organize photos into folders that are accessible only by intended recipients.

Biometric Data Processing: We use AI-powered facial recognition technology to provide our photo delivery services. When a photographer uploads event photos, our system creates a unique mathematical representation (face embedding) of the faces captured. This is classified as Sensitive Personal Data under the UAE PDPL. We process this data solely for the purpose of identifying and delivering your photos to you securely.

  • Facial data is stored after processing until event expires
  • Data is not used for surveillance, resale, or identification beyond this context
  • Face embeddings are mathematical vectors and cannot be reverse-engineered into photographs

5. User Consent

  • Photographers must obtain proper consent from clients before uploading their images
  • By registering and using Lenzeit, photographers provide consent for data usage in accordance with this policy
  • Photographers may manage, export, or delete their data from their dashboard

6. Album Transfer (Secure File Delivery)

Album Transfer lets a photographer upload one ZIP archive and share it with a client through a secure link. It is a delivery service only and is entirely separate from our AI features.

We do not open, extract, or analyse a transferred archive.

  • The ZIP file is stored exactly as uploaded and delivered exactly as uploaded
  • No facial recognition, biometric processing, or AI analysis is performed on it
  • No thumbnails or previews are generated, and the photos inside are never viewed by our systems
  • Archives are held in private storage; download links are short-lived and signed per request

For each transfer we store the album name, the optional note written for the client, the file name, the file size, a content checksum, and the expiry you chose. If you set an album password we store only a one-way hash of it, never the password itself. The share link is also stored only as a one-way hash, which is why copying a link again issues a new one and retires the previous one.

Download records. When someone downloads a shared album we record the time, the outcome, the browser user-agent string, and a salted one-way hash of the IP address. We do not store raw IP addresses for downloads. These records are kept for 90 days and then deleted automatically.

Anyone holding a share link can download the album until it expires, its download limit is reached, or the photographer revokes it. Photographers are responsible for who they send a link to, and can add a password or a download limit for albums that must stay private.

7. Data Retention and Deletion

  • Client Event Data & Photos: Stored temporarily for 14 days after event goes live, then permanently deleted from our servers
  • Photographer Account Data: Retained for up to 12 months after account inactivity unless manually deleted
  • Backups: Only taken during maintenance; no permanent archives or photo backups are kept

Album Transfer archives

  • Album expiry. Every shared album has an expiry date chosen by the photographer, within the range their plan allows. On the Freemium plan the only option is 7 days. When an album reaches its expiry date the link stops working and the archive is permanently deleted. We email the photographer a reminder one day beforehand.
  • Albums with no expiry. Paid plans may share an album with no expiry date. Those archives are kept for as long as the plan remains active.
  • Manual deletion. Deleting an album from your dashboard removes the archive immediately and permanently. This cannot be undone.

If a paid plan lapses

We do not delete anything when a payment fails. Your plan first enters a short grace period during which nothing changes at all. After that the account is placed on hold:

  • Your files are not deleted, and your account is not closed. You can still sign in and download everything you have stored with us.
  • New uploads, new events and new share links are paused until the plan is renewed.
  • Album links you had already shared with clients keep working until their own expiry date, so your clients are not affected by your billing.
  • If the account is still on hold 60 days after the hold began, stored Album Transfer archives are permanently deleted to recover storage. We email you a warning 7 days before this happens, in addition to earlier notices when the hold starts and one week into it. Your account, your event records and your billing history are retained; only the stored archive files are removed.
  • Renewing at any point before that deadline restores full access immediately.

If you choose to move to a smaller plan and your stored data exceeds the new plan's limits, we will tell you how much you are over and let you decide what to keep or download. We never choose which of your albums to delete. If you explicitly ask us to delete your Album Transfer data as part of a downgrade, we delete it immediately and record your instruction.

If users delete their data manually, Lenzeit is not responsible for recovery or restoration.

8. Third-Party Services

We use the following third-party payment processors:

  • Stripe
  • PayFast

These platforms may process personal and billing data subject to their own privacy policies. We may expand to other services such as Google Pay in the future.

9. Security Measures

We implement multiple layers of digital and infrastructure security:

  • Secure access codes sent directly to clients via email
  • AES-level encryption for stored content
  • Strict access control to ensure only authorized users access photos
  • 14-day code expiration after event goes live and automatic deletion to protect privacy

10. International Users & GDPR Compliance

Lenzeit welcomes users globally. If you are accessing our services from the European Union (EU), the United Kingdom, or other jurisdictions with privacy laws like the General Data Protection Regulation (GDPR), you have additional rights:

  • Right to Access – Request your data
  • Right to Rectify – Correct incorrect or outdated data
  • Right to Erasure – Delete your account or personal information
  • Right to Object – Restrict processing for specific use cases
  • Right to Data Portability – Receive a copy of your data

Requests can be made via email to [email protected] and will be handled within 30 days.

11. Children's Privacy

Our services are not intended for use by individuals under 13 without parental consent. Photographers are responsible for obtaining necessary permissions when uploading images of minors.

12. Changes to This Policy

We reserve the right to update this Privacy Policy at any time. Material changes will be communicated via email or website notice. Continued use of the platform after such updates constitutes agreement with the revised policy.

13. Contact Us

For questions or concerns about this Privacy Policy or your personal data, please contact:

Email: [email protected]

Or visit our contact page.

We use cookies to improve your experience. By using our site, you accept our cookie policy