⚠️
Draft for legal review — not legal advice. This is a working draft prepared for the founder and legal counsel to review before publication. Do not rely on it and do not publish it to the live site before legal sign-off. Fields marked […] need to be completed.

Privacy Policy

How Memora collects, processes and protects information — including face-recognition data — when delivering personal photos to event guests.

Last updated: [date] · Version 1.0 (draft) · גרסה בעברית

1.Who we are and our role in the data

Memora ("Memora", "we", "the Service") is a SaaS platform that enables event photographers and organizers to share photos from events (weddings, corporate events, parties and more) so that each guest automatically receives only their own photos via WhatsApp, SMS or email. Matching each guest to their photos is performed using AI-based face-recognition technology.

The Service is operated by [full legal/business name], licensed dealer (Osek Murshe) no. [dealer no.], of [address], Israel ("the Operator").

Controller vs. processor. With respect to event photos and guest data uploaded by the photographer/organizer, the photographer/organizer is typically the Data Controller and Memora acts as a Data Processor on their behalf, under a Data Processing Agreement (DPA). With respect to the marketing site, business customers and user accounts, Memora is the Controller. This distinction must be confirmed by counsel and fixed in the DPA. [pending legal review]

2.Who this policy covers

3.Information we collect

TypeExamplesFrom whom
Contact & delivery detailsName, mobile number, email addressGuests, customers
Event photosPhotos uploaded by the photographer/organizerCustomers
Matching selfieA face photo the guest takes to find their photosGuests
Face-recognition data (face embeddings)A mathematical vector representation of facial features — see §4Derived from photos/selfie
Account dataUser details, password, brand settings, billingCustomers
Delivery dataWhatsApp/SMS/email send statusGenerated by system
Technical usage dataIP address, browser/device type, logs, cookiesVisitors, users

4.Face & biometric data — the core of the Service

This is the most sensitive and important part of this policy, and we commit to full transparency about it.

What we create and store

What we do not do with face data:

  • We do not sell face data and do not share it with advertisers.
  • We do not use guests' photos or face data to train AI models.
  • We do not use embeddings to identify guests outside the event they belong to.
  • We do not build a cross-event facial-recognition database.

Legal status of the data

Face data may constitute a "special category" of personal data (biometric data) under Article 9 GDPR, and "sensitive information" under the Israeli Protection of Privacy Law, 5741-1981 and its regulations. Accordingly we apply heightened safeguards, an explicit-consent legal basis, and short retention/deletion policies (§§6–8). [final classification pending counsel]

5.Purposes and legal basis

PurposeLegal basis (GDPR / Israeli law)
Matching a guest to their photos via face recognitionExplicit consent of the guest (Art. 9(2)(a) GDPR); consent under Israeli law
Delivering photos via WhatsApp/SMS/emailPerformance of the service / guest consent
Providing the service to the business customer & account managementPerformance of a contract
Security, fraud prevention and loggingLegitimate interest
Marketing communications (to businesses/sign-ups)Consent (opt-in)
Compliance with legal obligationsLegal obligation

7.Retention periods

We keep information only as long as needed for the purpose for which it was collected:

8.Right to deletion and removal

Every guest may request deletion of their face data and photos at any time, for any reason. Requests should be sent to support@memora-ai.cloud and will be handled within [X days]. Upon deletion we remove the embeddings, the selfie and the photos associated with the guest (subject to third-party rights and legal retention duties).

Where the photographer/organizer is the Controller, we forward relevant deletion requests to them and assist in fulfilling them.

9.Sub-processors and data sharing

We rely on trusted sub-processors to provide the Service. We do not sell personal data. Main providers:

ProviderPurposeData
Meta / WhatsApp BusinessDelivering photos and messages to guestsPhone, message content
SMS provider [name]Delivering SMS messagesPhone, content
Email provider [name]Delivering emailEmail, content
Cloud infrastructure (AWS, EU regions)Storage and processingAll data types
Face-recognition / AI provider [name]Generating embeddings and matchingPhotos, selfie, embeddings
Payments provider [name]Billing business customersBilling data

Each sub-processor is bound by a data processing agreement and confidentiality and security obligations. [final list pending confirmation]

10.Transfers and EU storage

Storage of guest data and face data takes place on servers in the European Union (EU). To the extent any transfer occurs outside the EU/EEA, it will rely on a lawful transfer mechanism (such as Standard Contractual Clauses) with appropriate safeguards. As an Israeli operator, we also comply with the Israeli Protection of Privacy Law. [final storage architecture pending confirmation]

11.Your rights

Subject to the GDPR and the Israeli Protection of Privacy Law, you have the following rights:

To exercise rights, contact support@memora-ai.cloud.

12.Security

We apply technical and organizational security measures, including encryption in transit and at rest, access controls, environment separation, and data minimization. Face data is handled under heightened safeguards. [measures pending engineering & legal confirmation]

13.Children

The Service is not intended for the proactive collection of information from minors. Where minors appear at an event, responsibility for notice and obtaining parental/guardian consent rests with the photographer/organizer and event host. We will prioritize any deletion request concerning a minor. [age policy pending counsel]

14.Cookies and marketing

The site uses essential cookies and marketing/analytics cookies subject to your consent via the cookie banner. You can change preferences at any time. Marketing communications are sent only after opt-in and can be unsubscribed at any time.

15.Changes to this policy

We may update this policy from time to time. Material changes will be posted on the site and may also be sent directly. The update date appears at the top of this document.

16.Contact & privacy officer

For any question, rights request or privacy matter:

Email: support@memora-ai.cloud
Legal/business name: [to complete] · Licensed dealer (Osek Murshe): [no.]
Privacy officer / contact: [name and details — pending]


עיצוב ופיתוח: MADHOUSE