How Memora collects, processes and protects information — including face-recognition data — when delivering personal photos to event guests.
Memora ("Memora", "we", "the Service") is a SaaS platform that enables event photographers and organizers to share photos from events (weddings, corporate events, parties and more) so that each guest automatically receives only their own photos via WhatsApp, SMS or email. Matching each guest to their photos is performed using AI-based face-recognition technology.
The Service is operated by [full legal/business name], licensed dealer (Osek Murshe) no. [dealer no.], of [address], Israel ("the Operator").
Controller vs. processor. With respect to event photos and guest data uploaded by the photographer/organizer, the photographer/organizer is typically the Data Controller and Memora acts as a Data Processor on their behalf, under a Data Processing Agreement (DPA). With respect to the marketing site, business customers and user accounts, Memora is the Controller. This distinction must be confirmed by counsel and fixed in the DPA. [pending legal review]
| Type | Examples | From whom |
|---|---|---|
| Contact & delivery details | Name, mobile number, email address | Guests, customers |
| Event photos | Photos uploaded by the photographer/organizer | Customers |
| Matching selfie | A face photo the guest takes to find their photos | Guests |
| Face-recognition data (face embeddings) | A mathematical vector representation of facial features — see §4 | Derived from photos/selfie |
| Account data | User details, password, brand settings, billing | Customers |
| Delivery data | WhatsApp/SMS/email send status | Generated by system |
| Technical usage data | IP address, browser/device type, logs, cookies | Visitors, users |
This is the most sensitive and important part of this policy, and we commit to full transparency about it.
What we do not do with face data:
Face data may constitute a "special category" of personal data (biometric data) under Article 9 GDPR, and "sensitive information" under the Israeli Protection of Privacy Law, 5741-1981 and its regulations. Accordingly we apply heightened safeguards, an explicit-consent legal basis, and short retention/deletion policies (§§6–8). [final classification pending counsel]
| Purpose | Legal basis (GDPR / Israeli law) |
|---|---|
| Matching a guest to their photos via face recognition | Explicit consent of the guest (Art. 9(2)(a) GDPR); consent under Israeli law |
| Delivering photos via WhatsApp/SMS/email | Performance of the service / guest consent |
| Providing the service to the business customer & account management | Performance of a contract |
| Security, fraud prevention and logging | Legitimate interest |
| Marketing communications (to businesses/sign-ups) | Consent (opt-in) |
| Compliance with legal obligations | Legal obligation |
We keep information only as long as needed for the purpose for which it was collected:
Every guest may request deletion of their face data and photos at any time, for any reason. Requests should be sent to support@memora-ai.cloud and will be handled within [X days]. Upon deletion we remove the embeddings, the selfie and the photos associated with the guest (subject to third-party rights and legal retention duties).
Where the photographer/organizer is the Controller, we forward relevant deletion requests to them and assist in fulfilling them.
We rely on trusted sub-processors to provide the Service. We do not sell personal data. Main providers:
| Provider | Purpose | Data |
|---|---|---|
| Meta / WhatsApp Business | Delivering photos and messages to guests | Phone, message content |
| SMS provider [name] | Delivering SMS messages | Phone, content |
| Email provider [name] | Delivering email | Email, content |
| Cloud infrastructure (AWS, EU regions) | Storage and processing | All data types |
| Face-recognition / AI provider [name] | Generating embeddings and matching | Photos, selfie, embeddings |
| Payments provider [name] | Billing business customers | Billing data |
Each sub-processor is bound by a data processing agreement and confidentiality and security obligations. [final list pending confirmation]
Storage of guest data and face data takes place on servers in the European Union (EU). To the extent any transfer occurs outside the EU/EEA, it will rely on a lawful transfer mechanism (such as Standard Contractual Clauses) with appropriate safeguards. As an Israeli operator, we also comply with the Israeli Protection of Privacy Law. [final storage architecture pending confirmation]
Subject to the GDPR and the Israeli Protection of Privacy Law, you have the following rights:
To exercise rights, contact support@memora-ai.cloud.
We apply technical and organizational security measures, including encryption in transit and at rest, access controls, environment separation, and data minimization. Face data is handled under heightened safeguards. [measures pending engineering & legal confirmation]
The Service is not intended for the proactive collection of information from minors. Where minors appear at an event, responsibility for notice and obtaining parental/guardian consent rests with the photographer/organizer and event host. We will prioritize any deletion request concerning a minor. [age policy pending counsel]
The site uses essential cookies and marketing/analytics cookies subject to your consent via the cookie banner. You can change preferences at any time. Marketing communications are sent only after opt-in and can be unsubscribed at any time.
We may update this policy from time to time. Material changes will be posted on the site and may also be sent directly. The update date appears at the top of this document.
For any question, rights request or privacy matter:
Email: support@memora-ai.cloud
Legal/business name: [to complete] · Licensed dealer (Osek Murshe): [no.]
Privacy officer / contact: [name and details — pending]