Privacy Policy

Version 1.0 — Effective date: 18 August 2026

The protection of personal data is a fundamental principle of our operations. This Privacy Policy explains which personal data we process when you use the Application, Website and Services, the purposes and legal bases for which we process them, the recipients to whom we may disclose them, how long we retain them and the rights available to you.

Terms written with an initial capital letter and not defined in this Policy have the meanings assigned to them in the Terms of Use. This Policy primarily covers the processing activities for which we act as Controller. Processing activities that we carry out on behalf of the Organiser as Processor are also governed by the Data Processing Agreement.

1. Who we are and how you can contact us

The Cloudsnap platform, the Website and all Services provided are operated by SYAREX TECHNOLOGIES E.E., whose registered office is in Thessaloniki, at 83 Vasilissis Olgas Avenue, 546 42, and which is registered with the General Commercial Registry (GEMI) under number 184871106000 and with Tax Identification Number 802898595.

For any question concerning the processing of your personal data or the exercise of your rights, you may contact us by email at contact@cloudsnap.gr or by post at the above address.

2. Who this Policy applies to

This Policy applies to Website visitors, Platform Users, Organisers, Guests, persons who receive an invitation to participate in an Event, persons depicted or heard in Content, and any person who contacts us, requests support or submits a report or complaint.

3. Roles and responsibilities in personal data processing

3.1 When we act as Controller

We act as Controller only for activities for which we determine the purposes and essential means of processing.

This relates in particular to data that we process for Account creation and management, Platform login and security, the provision and billing of Plans, operational communications, User support, the management of consent and privacy choices, analysis of Platform use, fraud and abuse prevention, compliance with our legal obligations, the handling of reports, and the establishment, exercise or defence of legal claims.

3.2 The Organiser's responsibility for Event data

As Organiser, you create and manage your Event and determine the purpose for which it is created, the persons who are invited or obtain access, the participation, privacy and publicity settings, and the manner in which Content is collected, displayed and managed in the Event Album.

For personal data included in invitations, participation details and Event Content, you act, where data protection law applies, as Controller.

You are responsible for ensuring that the relevant data are collected, used and disclosed lawfully, that you have an appropriate legal basis and that you provide Guests and other persons with the information required under applicable law.

3.3 Our role as Platform provider and Processor

For personal data included in invitations, participation details and the Content of an Event, we provide the technical infrastructure for their storage, hosting, organisation, display and management in accordance with the Organiser's choices and instructions.

We do not determine the purpose of the Event, select the persons who are invited or obtain access, or decide which Content is uploaded or shared by Users.

For the above activities, we act as Processor on behalf of the Organiser, in accordance with the Data Processing Agreement and the Organiser's lawful instructions.

3.4 Each User's responsibility for the Content they upload

Each User is responsible for the Content that they upload, share or make available through the Platform and must ensure that they have the necessary rights, permissions or other lawful grounds for the specific use.

We do not select, create or pre-screen the photographs, videos or other Content uploaded by Organisers and Guests.

The above allocation of responsibility does not limit our obligations to review reports and take appropriate measures when we are notified of unlawful or harmful Content, in accordance with the Terms of Use and applicable law.

3.5 Processing for our own limited purposes

Even when we process data on behalf of the Organiser, we may process limited data as an independent Controller where necessary for the security and integrity of the Platform, fraud and abuse prevention, compliance with legal obligations, the review of reports, or the establishment, exercise or defence of legal claims.

Where the Organiser uses the Platform solely in the course of a personal or household activity, the processing carried out by the Organiser may, depending on the circumstances, fall outside the scope of the GDPR. This does not remove the Organiser's responsibility for the Content they create, upload, approve or share, nor does it affect our own obligations as Platform provider.

3.6 How we use Event Content

We do not sell, use for advertising purposes or commercially exploit the photographs, videos or other Content uploaded by Users to the Platform.

We do not acquire ownership of the Content or any right to use or exploit it independently. Rights in the Content remain with the User who uploads it or with the relevant lawful rightsholder.

We process Content only to the extent necessary to store, host, technically adapt, organise, display and manage it through the Platform, in accordance with the Organiser's choices and instructions and for the period provided for under the corresponding Plan.

4. Which personal data we process and where we obtain them

4.1 Account and profile data

When you create or manage an Account, we process your email address, name or display name, profile photograph if you choose to add one, language, notification preferences, Account identifier and the related creation or modification dates. These data are provided by you or generated by our system.

4.2 Login, identification and security data

Login takes place using your email address and a six-digit One-Time Password (OTP). We process the code in protected form, the time it was sent and verified, successful or unsuccessful login attempts, session identifiers, IP address, basic details of the device, operating system, browser or Application version, and logs necessary for security, troubleshooting and abuse prevention. Login may also take place through supported third-party identity providers, in which case a one-time password is not required.

4.3 Event, invitation and participation data

We process the information entered to create and manage an Event, such as its title, date and description, its access, participation, uploading and publicity settings, User roles, participation requests and approvals, as well as invitation details, such as recipient email addresses and the delivery or acceptance status of the invitation. These data are provided by the Organiser or another authorised User and are generally processed on behalf of the Organiser.

4.4 Event Content

We process photographs, videos and any other supported Content uploaded by the Organiser or Guests, as well as captions, comments, approval status, the identifier of the User who made the upload, the time of uploading, the file's technical information and, where supported, information concerning the viewing or downloading of Content. Technical metadata, including any location data, are automatically removed when the files are processed and before they are stored and made available.

4.5 Technical and usage data

When you use the Platform, technical data may be collected, such as your IP address, device type and settings, operating system, Application or browser version, language, date and time of access, screens or features used, performance data, errors and crash reports. Strictly necessary technical data are used for operation, security and troubleshooting. Optional usage analytics data are collected only in accordance with your consent choices.

4.6 Plan, payment and billing data

When you purchase or renew a Plan, we process the selected Plan, amount, currency, date and status of the transaction, payment identifier, billing and invoicing details, and any information necessary to complete the transaction, issue documents and support the payment. The payment provider processes payment details in accordance with its own privacy policy and may, depending on its role, act as an independent Controller for its own regulatory and operational obligations.

Payments are processed through Stripe. Further information about the categories of data it processes and its role is provided in Section 10.1.

4.7 Communications, support and reports

When you contact us, request support, exercise a right, or report Content or User conduct, we process your contact details, the content of the communication, any attachments or evidence, the action taken, and the outcome of the request or report.

4.8 Cookies and similar technologies

Through the Website and, where applicable, the Application, we may use cookies, device identifiers, SDKs, pixels and other similar technologies. Strictly necessary technologies are used for operation, security and the storage of your choices. Optional analytics or marketing technologies are enabled only if you have provided the required consent.

If you consent to the use of marketing technologies, the Meta Pixel may collect and transmit to Meta Platforms Ireland Limited technical and interaction data, such as your IP address, basic device and browser information, the date and time of your visit, the URL and referring page, cookie or advertising-click identifiers, and information indicating that a selected conversion event has occurred.

The Meta Pixel is not enabled on private Event pages, Event Albums, invitations, or screens used to upload, view or download Content. We do not transmit through it Event Content, Event titles or descriptions, invitation links or QR codes, email addresses, Account data, payment information or itemised transaction details.

Further information is provided in the Cookies Policy and Section 10.9 of this Privacy Policy.

5. When we receive your data from the Organiser or another User

We may receive your personal data even if you have not provided them to us yourself. This occurs, for example, where the Organiser enters your email address to send you an invitation, or where the Organiser or a Guest uploads a photograph or video in which you are depicted or can be heard.

In those cases, the source of the data is the Organiser or the User who entered or uploaded them. The data may include your email address, name or display name, invitation or participation status, image, voice, the Content in which you appear and the related Event information.

Where we process those data solely on behalf of the Organiser, the Organiser is responsible for informing you and determining the appropriate legal basis. You may contact the Organiser to exercise your rights or contact us at contact@cloudsnap.gr. We will inform you of the appropriate way to handle the request and, where we act as Processor, will forward it to the Organiser and assist the Organiser in responding.

If you believe that Content concerning you infringes your privacy, image rights, personal data protection or another right, you may request its removal in accordance with the Content reporting and removal procedure set out in the Terms of Use. Requests concerning minors are reviewed as a priority.

6. The purposes for which we process data and the legal bases on which we rely

6.1 Account creation and management – provision of the Services

We use the Account, login, Event and usage data necessary to create and manage your Account, provide you with Platform features, activate your Plan and perform our obligations under the Terms of Use. The legal basis is the performance of our contract with you or taking steps before entering into it.

6.2 Login, security and abuse prevention

We use login data, technical logs and audit logs to verify access, protect Accounts, detect and prevent fraud, unauthorised access, malicious use and technical attacks, and maintain the security, integrity and availability of the Platform. The legal basis is, as applicable, performance of the contract and our legitimate interest in providing secure and reliable Services and protecting Users and the Platform.

6.3 Payments, billing and financial administration

We use Plan, transaction and billing data to complete the purchase, activate or renew the Plan, issue documents, manage refunds and comply with our tax and accounting obligations. The legal basis is performance of the contract and compliance with legal obligations.

6.4 Operational communications

We send you messages necessary for the operation of the Services, such as OTP codes, confirmations, security alerts, Event updates, invitations sent on the Organiser's instructions, Plan and payment updates, and notices of the imminent expiry or deletion of Content. These communications are not marketing communications. The legal basis for communications that we send for our own purposes is performance of the contract. When we send invitations or other communications on behalf of the Organiser, we act in accordance with the Organiser's documented instructions, and the relevant legal basis is determined by the Organiser.

6.5 Support, reports and protection of rights

We use communications data, requests and reports to answer questions, provide technical support, review reports of unlawful or harmful Content, enforce the Terms of Use, protect the rights and safety of Users and third parties, and comply with our obligations. The legal basis is, as applicable, performance of the contract, compliance with a legal obligation and our legitimate interest in addressing abuse, protecting the Platform and resolving disputes.

6.6 Statistics and improvement of the Platform

We use strictly necessary technical and diagnostic data to maintain and debug the Platform and improve its reliability and security, on the basis of our legitimate interest. Optional usage analytics through cookies or similar technologies are carried out only with your consent, where consent is required.

6.7 Product updates and marketing communications

If you choose to receive updates about news, features, offers or other marketing communications, we will use your contact details on the basis of your consent or, where permitted, in the context of an existing customer relationship for similar Services. You may withdraw your consent or unsubscribe from those communications at any time, easily and free of charge, through the unsubscribe link included in each message or by contacting us.

6.8 Advertising and conversion measurement

If you have consented to the use of marketing technologies, we use the Meta Pixel to measure the effectiveness of our advertisements, attribute visits and selected conversion events to particular advertising campaigns, produce aggregated reports and optimise our marketing activities. Where the relevant features are enabled, the data may also be used to create advertising audiences or for retargeting.

The legal basis for this processing is your consent. You may withdraw it at any time through the “Cookie Settings” option. Withdrawal applies for the future and does not affect the lawfulness of processing carried out before it.

6.9 Legal obligations and legal claims

We may process or disclose data where necessary to comply with a lawful request or binding order of a competent authority, prevent or investigate unlawful activity, or establish, exercise or defend legal claims. The legal basis is compliance with a legal obligation or our legitimate interest in protecting our legal rights.

6.10 Processing on behalf of the Organiser

For Event Content and other data that we process solely as Processor, the legal basis, purpose and duration of processing are determined by the Organiser in accordance with applicable law. We process the data only on the basis of the Organiser's lawful and documented instructions and for the period resulting from the Organiser's choices, the selected Plan and applicable retention obligations, unless otherwise required by law.

7. Event Content and special categories of data

Depending on the subject matter and circumstances of the Event, Content may reveal information of a highly personal nature or information concerning, among other things, health, religion, ethnic origin or other special categories of data. We do not ask Users to provide such information and do not analyse Content for the purpose of drawing inferences about sensitive characteristics of the persons depicted.

Where the Organiser or another User uploads Content that includes special categories of data, they are responsible for ensuring that they have the required legal basis and that the specific use is lawful, necessary and proportionate. We do not use Content for advertising targeting, facial recognition, the creation of biometric templates or the training of artificial intelligence models.

We do not sell or rent personal data and do not use Event photographs or videos for our own advertising or other independent commercial purposes. Authorised personnel access to Content is limited to cases where it is necessary to provide support that you have requested, investigate a technical or security incident, review a report, comply with a legal obligation or protect legal rights.

Events are private by default. Content is made available to Organisers, Guests or other persons in accordance with the settings selected by the Organiser. If the Organiser chooses to make the Event public and searchable, the Content may be accessible to a wider audience and, depending on the technical implementation, may appear in search engines.

8. Which data are necessary

Certain data are necessary to enter into or perform the contract and provide the Services. Without a valid email address and the necessary login data, an Account cannot be created or used. Without the required Event details, the corresponding features cannot be used, while without the necessary transaction and billing details, a paid Plan cannot be purchased.

Other data, such as a profile photograph, certain optional Event details, optional marketing communications and data from optional cookies or analytics, are provided voluntarily. Failure to provide or withdrawal of consent to optional processing does not affect use of the Platform's core features, unless a specific feature technically depends on the corresponding choice.

9. Recipients of personal data

We disclose personal data only to the extent necessary for the purposes of this Policy and in accordance with applicable law. Depending on how the Platform is used, recipients may include:

  • a) the Organiser, Guests and other authorised Users, in accordance with the Event's access, viewing and, where possible, download settings, as well as, where the Organiser has enabled public access, other persons who access publicly available Content;
  • b) providers of hosting, cloud computing, object storage, content delivery networks and technical infrastructure;
  • c) providers of email delivery and operational notifications;
  • d) payment providers, banking institutions and invoicing or accounting support providers;
  • e) providers of consent and privacy-preference management, usage analytics, performance monitoring, error management, support, security, advertising and conversion measurement, advertising-audience creation or retargeting, including Meta Platforms Ireland Limited, only to the extent that the relevant functions are used lawfully and in accordance with your consent choices;
  • f) professional advisers, such as lawyers, accountants, auditors and insurers, where necessary for the provision of their services or the protection of our legal rights;
  • g) public, judicial, supervisory or law-enforcement authorities, where disclosure is required by law or a binding order;
  • h) prospective purchasers, investors or successors in the context of a corporate restructuring, merger, financing or transfer of business, subject to appropriate confidentiality and data-protection safeguards.

Providers acting as Processors are contractually bound to process data only in accordance with our instructions, implement appropriate security measures and comply with their obligations under applicable law.

10. Key service providers

To operate and provide the Services, we work with providers that process personal data only to the extent necessary to provide the relevant services.

10.1 Stripe

We use Stripe's services to process payments and manage transactions.

Depending on the payment method and technical integration, Stripe may process identification and contact details, billing details, information about the transaction, amount and selected Plan, technical device and connection details, and payment-method data.

Your full card details are entered directly in Stripe's environment and are not stored in our systems. We receive only the information necessary to confirm and manage the transaction, such as payment status, amount, currency, transaction identifier and, where available, limited information about the payment method.

Depending on the specific processing activity, Stripe may act as Processor on our behalf or as an independent Controller for its own purposes, such as payment security, fraud prevention and compliance with regulatory obligations.

10.2 Twilio SendGrid

We use Twilio SendGrid to send One-Time Passwords (OTPs), Event invitations, operational notifications, security updates and other messages connected with use of the Services.

For this purpose, the recipient's email address, name or display name, message content and subject, related links and information about sending, delivery or delivery failure may be processed.

Delivery information is used solely for operational purposes, in particular to verify the proper delivery of messages, troubleshoot issues and ensure service reliability. It is not used for commercial analysis, advertising purposes or profiling. We do not store in our systems information about the selection of links included in messages.

10.3 PostHog

We use the PostHog service to analyse use of the Platform, identify technical issues and improve features and the User experience.

In this context, pseudonymised User or device identifiers, information about the features and screens used, time and duration of use, basic device technical details, and performance or technical-error data may be processed.

We do not use the session recording functionality (session replay).

We do not use analytics data for advertising targeting or commercial profiling.

Use of the PostHog service is limited to analysing the operation and use of the Platform and is not intended to analyse or commercially exploit photographs, videos or other Event Content.

To the extent that the PostHog service is used for optional usage analytics, the relevant processing is carried out in accordance with your consent choices and, where required, only after your prior consent.

10.4 Hosting and storage provider

We use the services of Hetzner Online GmbH to host the Platform, databases, photographs, videos and other technical infrastructure.

Depending on use of the Services, the provider may process Account data, Event details, invitations, Content, technical logs and other data necessary for the operation of the Platform.

The primary infrastructure and backups are located within the European Union.

10.5 Elorus

We use Elorus to issue and manage accounting documents and transmit the prescribed information to the myDATA digital platform of the Independent Authority for Public Revenue.

For this purpose, the name, email address, postal address and, where applicable, tax identification number, as well as the information necessary to issue and manage the relevant document, are transferred to Elorus.

Processing is carried out to fulfil our tax and accounting obligations.

10.6 CookieYes

We use CookieYes to manage and record your choices concerning the use of cookies and similar technologies.

For this purpose, the consent choices you have made, the date and time at which they were recorded, a consent identifier and the technical information necessary to apply and demonstrate your choices may be processed.

We do not use CookieYes for advertising targeting or commercial profiling.

10.7 Google Analytics 4

We use Google Analytics 4 (GA4) to collect statistical information about use of the Platform, assess its operation and improve the Services.

Depending on the technical configuration, online identifiers, basic technical details of the device and browser, information about the pages or screens used and the related actions, and duration of use may be processed.

Google Analytics 4 is activated only after your prior consent and operates in accordance with the consent choices you have made. We do not use these data to analyse photographs, videos or other Event Content.

10.8 OpenStreetMap

We use OpenStreetMap to display maps and locations relating to Events.

When a map is displayed, the IP address, basic technical details of the device and browser, and information necessary to load and display the relevant map may be processed.

The service is not used to access or analyse photographs, videos or other Album Content.

10.9 Meta Pixel

We use the Meta Pixel technology provided by Meta Platforms Ireland Limited to measure the effectiveness of our advertisements, attribute selected conversion events to advertising campaigns, produce aggregated reports and optimise our marketing activities. Where the relevant features are enabled, the Meta Pixel may also be used to create advertising audiences or for retargeting.

Its use is limited to public marketing pages of the Website and specifically designated conversion-confirmation pages. Depending on the technical configuration, Meta may receive your IP address, basic device and browser information, the date and time of your visit, the URL and referring page, cookie or advertising-click identifiers such as _fbp and _fbc, and information indicating that selected actions have taken place on the Website.

We do not use the Meta Pixel on private Event pages, Event Albums, invitations, or screens used to upload, view or download Content. We do not transmit through it photographs, videos or other Event Content, Event titles or descriptions, invitation links or QR codes, email addresses, Account data, payment information or itemised transaction details. We do not use advanced matching to transmit hashed contact details.

The Meta Pixel is enabled only after you have given prior consent to the marketing-technologies category. If you refuse or withdraw your consent, the Meta Pixel remains disabled for your future visits, without affecting your use of the Platform’s core features.

Depending on the specific processing activity, Meta Platforms Ireland Limited may act as our Processor when providing matching, measurement, analytics and campaign-reporting services under the Meta Business Tools Terms and the Meta Data Processing Terms. To the extent that Cloudsnap and Meta jointly determine the purposes and means of collecting and transmitting certain Event Data, they act as Joint Controllers under the Meta Controller Addendum. For other processing activities whose purposes and means Meta determines independently, Meta acts as an independent Controller.

Further information about Meta’s processing of personal data and the choices available to you is provided in Meta’s Privacy Policy and in the privacy and advertising settings of its services.

10.10 Error monitoring (GlitchTip)

We use an error and technical performance monitoring tool (GlitchTip), self-hosted on our own servers inside the European Union, to detect and fix technical problems with the Platform. It is not a third-party service: the data is not transmitted outside our own infrastructure.

The tool sends technical data on every page load and on every navigation within the Platform, not only when an error occurs. Depending on the case, the data processed includes the IP address, basic device and browser information, the page URL and the previous page, the date and time, and the error message and technical stack trace. On the server side a pseudonymous Account identifier and a sample of performance data are also recorded.

We apply technical minimisation measures before transmission: credentials and cookies are stripped from headers, request bodies are not sent, and email addresses, one-time codes and access tokens are masked where detected. The IP address nevertheless unavoidably reaches the server as a technical property of the connection.

This processing is based on our legitimate interest in keeping the Platform secure, stable and functional, under Article 6(1)(f) GDPR, and not on consent. For that reason the tool operates on all pages, including Event pages and the signed-in area, without analysing photos, videos or other Event Content.

The tool uses no cookies and no other form of storage on your device. It is therefore not listed in the cookie register of the Cookie Policy.

11. Transfers of data outside the European Economic Area

We seek to use infrastructure and providers within the European Economic Area (EEA). However, certain providers, their affiliates or subcontractors may process data in a country outside the EEA or provide remote access from such a country.

In each such case, we ensure that the transfer is based on a lawful mechanism, such as a European Commission adequacy decision, approved Standard Contractual Clauses or another appropriate safeguard, and, where required, implement supplementary technical and organisational measures. You may request further information about the applicable safeguards by contacting contact@cloudsnap.gr.

12. How long we retain data

We retain personal data only for as long as necessary for the purpose for which they were collected, the provision of the Services, compliance with legal obligations, Platform security and the establishment, exercise or defence of legal claims. The main retention periods or criteria are as follows:

Data categoryRetention period or criterion
Account dataFor as long as the Account remains active. Once a deletion request has been submitted, a thirty (30)-day waiting period applies, during which the request may be withdrawn. Following permanent deletion, the data are deleted or anonymised, unless limited retention is required for a lawful purpose.
Cryptographic hash of email addressRetained in pseudonymised form solely to prevent abusive re-registration. It is not used for communications or marketing.
Event ContentFor the period provided for under the selected Plan, from thirty (30) to three hundred and sixty-five (365) days plus the grace period, in accordance with the Terms of Use, the Pricing Page and the information displayed when the Event is purchased or created. Following scheduled expiry, it is permanently deleted, subject to backups and any statutory retention obligation.
Event Content deleted by the OrganiserWhen the Organiser deletes the Event, the Event and its Content immediately cease to be available through the Platform. The related files and records are placed in a soft-deleted state and remain stored with restricted access until their permanent erasure is completed, in accordance with the applicable deletion process and subject to any statutory retention obligation.
Notice before Content deletionFor paid Plans, notices are sent fifteen (15) and seven (7) days before the scheduled deletion. A thirty (30)-day grace period is also provided, during which notifications are sent on the 15th and 23rd day. For the thirty (30)-day Free Plan, notices are sent fifteen (15) and seven (7) days before deletion.
BackupsDeleted data may remain in isolated backups for up to ninety (90) days, without being restored to active use, unless required for system recovery or by law.
OTP codes and identification logsThe OTP ceases to be valid after ten (10) minutes and is stored solely in cryptographically hashed form. The related record is deleted twenty-four (24) hours after its expiry.
Security, access and download logsRetained for 12 months, unless longer retention is required to investigate a specific incident, prevent abuse or pursue a legal claim.
Support requests and reportsRetained for 12 months after completion of the request, unless connected with a pending dispute, unlawful activity or legal obligation.
Transaction details and accounting documentsRetained for the period required under tax, accounting and other applicable law.
Consent and cookie-preference recordsRetained for up to five (5) years or for as long as necessary to demonstrate your choice and comply with the law.
Usage analytics dataGoogle Analytics 4 data are retained for fourteen (14) months. Event data from the PostHog analytics platform are retained for a period determined by the provider's subscription plan, which is currently seven (7) years. After the respective retention periods have elapsed, the data are deleted or anonymised.
Advertising-measurement data collected through the Meta PixelUnder the current technical configuration, the _fbp and _fbc cookies are retained for up to three (3) months unless you delete them earlier. Meta may retain Event Data for up to two (2) years under the Meta Business Tools Terms. Any advertising audiences are retained until they are deleted through the business-account tools, while aggregated campaign reports are retained only for as long as necessary to assess and internally document the relevant marketing activities.
Email sending and delivery logsRetained for twelve (12) months and then deleted or anonymised, unless longer retention is required for security, troubleshooting or compliance with a legal obligation.

When the relevant period expires, the data are securely deleted or anonymised, unless further retention is required or permitted by law. Anonymisation is used only where the data can no longer be linked, directly or indirectly, to an identifiable person.

13. How we protect personal data

We implement appropriate technical and organisational measures, taking into account the nature, scope, context and risks of processing, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

The measures include, as appropriate, access and permission controls, passwordless login using OTP, security-event logging, secure transmission protocols, backup and restoration procedures, limiting access to personnel for whom it is strictly necessary, contractual confidentiality obligations, provider assessments and security-incident management procedures.

We periodically review and assess the appropriateness and effectiveness of the measures we implement and adjust them where required, taking into account technological developments, changes in the operation of the Platform and the related risks.

In the event of a security incident, we follow procedures to detect, contain, investigate, respond to and document it. Where a personal data breach is identified, we assess its nature, scope and likely consequences and make the notifications to the competent supervisory authority and, where required, inform the affected persons, in accordance with applicable law.

Where an incident concerns personal data that we process on behalf of the Organiser, we inform the Organiser without undue delay and provide the assistance necessary to assess and respond to the incident.

14. Your rights

Depending on the circumstances and the legal basis of processing, you have the following rights:

  • a) to request information about and access to personal data concerning you and obtain a copy of them;
  • b) to request the rectification of inaccurate data or completion of incomplete data;
  • c) to request the erasure of your data where the statutory conditions are met;
  • d) to request restriction of processing;
  • e) to receive data that you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, request their transmission to another Controller;
  • f) to object, on grounds relating to your particular situation, to processing based on a legitimate interest;
  • g) to object at any time to processing for direct-marketing purposes;
  • h) to withdraw your consent at any time, without affecting the lawfulness of processing carried out before its withdrawal;
  • i) subject to the statutory conditions, not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

To exercise any right, you may contact contact@cloudsnap.gr. We will respond without undue delay and, as a rule, within one (1) month of receiving the request. That period may be extended by a further two (2) months, taking into account the complexity and number of requests, in which case we will inform you in good time of the extension and the reasons for it.

To protect your data, we may request reasonable information to verify your identity or your relationship with a specific Event. The exercise of rights is free of charge unless a request is manifestly unfounded or excessive, in particular because of its repetitive nature, in which case a reasonable fee may be charged or the request may be refused in accordance with the law.

Where your request concerns Content or data for which we act as Processor, the Organiser is generally responsible for deciding on the request. We will forward the request to the Organiser and provide the necessary assistance, without limiting your rights in relation to processing for which we act as Controller.

15. Minors

To independently create and use an Account, you must have reached the minimum age required under the law applicable in your place of residence for use of the Platform. If you have not reached that age, you may not independently create or use an Account on the Platform.

The Platform may host Content in which minors are depicted. The Organiser and the User uploading the Content must protect the minor's best interests, privacy, dignity and safety and have the required permissions or other lawful grounds.

We do not use minors' data for advertising targeting or profiling. Requests to remove Content concerning minors are reviewed as a priority.

16. Automated decision-making and profiling

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. We do not profile individuals on the basis of Event Content, use facial-recognition technology or create biometric templates from photographs or videos uploaded to the Platform.

If you have consented to the use of marketing technologies, Meta may associate your activity on the Website’s public pages with an existing account or advertising audience, in accordance with its own processing practices. This processing does not include Event Content and is not used by us to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

17. Changes to the Privacy Policy

We may amend this Policy to reflect changes in law, the Services, technologies or processing practices. The current version will be published on the Platform with a clear statement of its effective date.

If a change materially affects the way in which we process your personal data, we will inform you in good time through the email address associated with your Account, through the Platform or by another appropriate method. Where new or modified processing requires consent, we will separately ask for your consent before it begins. Merely continuing to use the Platform does not replace consent where consent is required by law.

18. Complaint to the supervisory authority

If you believe that the processing of your personal data infringes applicable law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or, if you are in another Member State of the European Union, with the supervisory authority for your place of habitual residence, place of work or the place of the alleged infringement.

Before lodging a complaint, we encourage you to contact us at legal@cloudsnap.gr so that we can review the matter and attempt to resolve it. Prior contact with us is not a condition for exercising your right to lodge a complaint with the competent supervisory authority.

Language of the Policy

This Policy has been drafted in Greek and may also be made available in other languages for your convenience. We make every reasonable effort to ensure that each translation accurately and completely reflects the Greek text. In the event of any discrepancy or inconsistency, the Greek text shall prevail.