⚠️
Draft for legal review — not legal advice. This is a working draft prepared for the founder, legal counsel and engineering team to review before publication. Do not rely on it and do not publish it to the live site before sign-off. Fields marked […] need to be completed.

Security & Trust

Your data — and especially the face data of event guests — is the most precious thing entrusted to us. Here is how we protect it.

Last updated: [date] · Version 1.0 (draft) · גרסה בעברית
🔒

End-to-end encryption

Encryption in transit and at rest for all data, including photos and face data.

🇪🇺

EU data residency

Guest data is stored on servers in EU regions.

🧬

Embeddings, not faces

Face data is stored as a mathematical vector — not a photo, not a biometric profile.

🗑️

Automatic deletion

Face data is deleted once matching / the gallery period ends.

1.Our approach to security

Memora delivers personal photos to event guests using face recognition. This is a sensitive domain, so security and privacy are not an "add-on" for us — they are at the heart of the product's design. This page explains, in plain language, what measures we take to protect your data and that of event guests. For the full legal detail, see our Privacy Policy.

2.Encryption in transit and at rest

3.Data residency (EU)

Guest data and face data are stored and processed on servers in the European Union (EU). To the extent any transfer occurs outside the EU/EEA, it relies on a lawful transfer mechanism (such as Standard Contractual Clauses) with appropriate safeguards. As an Israeli operator, we also comply with the Israeli Protection of Privacy Law.

4.Access controls

5.How we handle face data

Face data is stored as embeddings — not as a biometric profile.

  • We create a face embedding — a numerical vector describing facial features. It is a mathematical representation, and the original photo cannot be reconstructed from it.
  • Embeddings are used solely for matching within the specific event, not for general identification of a person.
  • We do not sell face data, do not use it to train models, and do not build a cross-event identification database.

6.Retention and deletion

7.Sub-processors

We rely on trusted sub-processors, each bound by a data processing agreement and security and confidentiality obligations:

ProviderPurpose
AWS (EU regions)Cloud infrastructure — storage and processing
Meta / WhatsApp BusinessDelivering photos and messages to guests
SMS provider [name]Delivering SMS messages
Email provider [name]Delivering email

The full list of sub-processors is available on request. [final list pending confirmation]

8.GDPR and Israeli-law alignment

We align with the principles of the GDPR and the Israeli Protection of Privacy Law, 5741-1981 — including data minimization, purpose limitation, an explicit-consent legal basis for processing face data, and data-subject rights (access, rectification, erasure, objection and portability). For full detail, see our Privacy Policy.

9.Responsible disclosure

Found a security vulnerability? We'd love to hear from you. Please report it responsibly, before any public disclosure, so we can fix it and protect users. We take every report seriously and will respond promptly.

Security contact: support@memora-ai.cloud (subject: "Security"). [dedicated security@ address pending]

10.Contact

For any question about security, privacy or trust:

Email: support@memora-ai.cloud
Legal/business name: [to complete] · Licensed dealer (Osek Murshe): [no.]


עיצוב ופיתוח: MADHOUSE