Data Protection at PhotoDeck
This page explains the personal-data provisions in our Terms and Conditions; only the Terms are contractually binding.
PhotoDeck’s business approach has always been to place product quality center and front, and on strong ethical foundations. Deep respect for and attention to personal data are part of our DNA.
We collect only what is necessary to 1) provide the service our members contract, 2) allow our company’s legitimate operations, and 3) comply with the laws we’re subject to. We store as little personal data as needed, for a limited duration, and it would naturally be out of question to share our users’ data with third parties outside of the scope described above.
PhotoDeck is based in the European Union and is subject to the General Data Protection Regulations (GDPR). The platform’s design choices as well as the tools we provide also help our members conform with the same GDPR.
We distinguish our members’ websites’ and customers’ data from data controlled by PhotoDeck.
Data related to PhotoDeck members and visitors
PhotoDeck is Data Controller for data concerning our members (subscribers) and visitors.
Website traffic analysis and PhotoDeck visitor’s data
We use the Matomo software to analyse the traffic and performance of our website. The software is configured in a restrictive manner, in order to avoid the use of persistent cookies and the recording of personally identifiable data. For example, visitors’ IP addresses are anonymized.
PhotoDeck Subscriber’s personal data
We keep for 10 years from the end of the last subscription (including the grace period) data subject to a legal retention obligation: orders and invoices (including first and last names, e-mail addresses, address) and financial transactions.
Data processed for account, subscription, service use and support management — e.g. account creation and expiry dates, contract acceptance date, language, subscriptions, salted cryptographic password hash, address book, payment details and preferences, order carts, service activity details and history, IP addresses, equipment — is deleted from the operational database at the end of the grace period (max 2 months) following the last subscription (contract termination). E-mail correspondence with our members and other contacts (e.g. support requests) is kept for a maximum of 4 years after receipt.
Data processed for security, service improvement or business development on the basis of our legitimate interest — e.g. low-level logs (including IP addresses), observed network response times, file import speeds, affiliation data, referral URLs and campaigns — is deleted from the operational database at the end of the grace period (max 2 months), or kept for up to two years for low-level logs.
Newsletter
We also occasionally send a newsletter to our current and former members, as well as to other visitors who have subscribed to the newsletter. For this we require prior explicit consent, independent from use of the service, revocable at any time via the unsubscribe links provided in each message or on request to support@photodeck.com.
Content and data relating to PhotoDeck members’ websites, visitors, customers and team members
A PhotoDeck member is responsible (Data Controller) for their own data hosted on the PhotoDeck platform and for data relating to their visitors, customers and team members.
PhotoDeck is then a subcontractor (Data Processor) in the GDPR sense: we process data on behalf and under instruction of the member, and we don’t use that data outside of the scope of the service contracted by that member.
In other words, the data of a member’s website and customers belong exclusively to that member, who control them fully.
This data includes, in addition to members’ uploaded images and video clips and their website customization and configuration settings, any other personal data stored via the tools provided by PhotoDeck: for example, login credentials of website customers and account team members, data relating to carts, selections (lightboxes), orders, comments, IP addresses and physical addresses. It also includes facial-recognition data from files submitted by the member for analysis.
The data are transmitted to third-parties, other than the subcontractors we use (and within the GDPR requirements), only upon instruction from the member (for example, order details transmitted to a lab for fulfillment or images sent for analysis to AI providers).
The data is automatically deleted from our operational database at the end of the grace period (up to 2 months) following the last subscription (contract termination). The uploaded images, video clips and documents may be kept for an additional 2 months.
Our commitment to our members
- we don’t use their customers’ data to our own benefit, nor collect data from their customers for any other purpose than serving our members
- we maintain high data security standards and inform without undue delay of any identified data breach
- we inform them of any new subcontractor that might process their data
- we help them, via features in the PhotoDeck service, to conform with the applicable regulations, including the GDPR
General backup
A general database backup (excluding files uploaded by our members) is maintained at all times. This general backup is a contingency for a potential disastrous technical failure concerning the whole database, and is also meant to help analyse and repair a potential issue occurring progressively over time in the database. As it is a “low-level” backup, data in this backup file are not directly accessible or usable.
Each backup file is encrypted before being stored on a Cloud located in the European Union, and is kept for one year.
Subcontractors and data location
The main data is stored with OVH (France).
Static files (files uploaded by our members, general backups, order delivery files…) are stored on the OVH, Scaleway and/or Amazon clouds. Files of our European members (identified by their IP address at account creation) are stored by default in the EU, except files imported before May 2019, stored in the USA under appropriate GDPR safeguards, and since September 2026, preference is given to European storage providers.
Content displayed on members’ sites may be temporarily cached by content delivery networks (CDN) close to the visitor, including outside Europe, for technical performance and security reasons, with the appropriate safeguards provided for in our Terms, or by otherwise limiting delivery to locations within the European Economic Area.
Technical support to our members may be provided by a contractor located in Europe.
In connection with the payment of PhotoDeck services via a third-party payment provider, some data are provided to the payment provider (e.g. name, first name, billing address) as part of the redirection to the payment provider’s website.
Security measures
Physical access to the data, to the servers and the datacentres it is located in, is ensured by the operators of these datacentres.
PhotoDeck ensures remote access security by limiting access at several software layers, on a “prohibited if not explicitely allowed” basis. Administrative access to the servers and the overal database is limited to the strict minimum.
Members’ and administrators’ connections to the web service, from outside the datacentres, are secured (SSL encryption). Connections to members’ websites are also secured with SSL.
The general backups are encrypted before being stored with the cloud provider who ensures the physical security of the encrypted files. The decryption key is stored separately, offline.
The contractor(s) providing support to members have a limited remote access, via a web interface secured with individual credentials.
Computer system security updates are performed as soon as possible following their release, as a result of specialized communication channels monitoring.