← All policies

Kynto Events — privacy policy

Last updated 2026-08-18

This service handles photos your guests took of each other, and if you turn it on, their faces as well. Both are worth spelling out properly rather than summarising.

Who is responsible

Marcel Meijer, acting as processor for whoever created the event. The organiser decides who's invited, what gets shown and how long it all lasts. I run the software and the storage. Contact: info@kynto.eu.

What each of us is responsible for is written down rather than left to be inferred, in the data processing agreement. It applies to every event automatically. Worth reading if you're the organiser; the rest of this page is what matters if you're a guest.

If you're a guest

What gets stored

You don't need an account

No sign-up, no password. Scanning the event's code is what gets you in, which does also mean anyone holding that code can see the album.

Location data gets stripped

Photos very often carry the coordinates of wherever they were taken. Guests never see that data on anyone else's photos, because it's deliberately left out of what the app sends to other guests. Uploading a picture from a private address shouldn't give the address away.

Face matching is opt-in

A guest can take a selfie and be shown the photos they turn up in. Doing that means working out a mathematical description of their face, which the GDPR treats as biometric data, and that needs explicit consent. Nothing less will do.

If you're an organiser

Your account holds an email address, a hashed password, your language preference and the settings for each event. Turn on two-factor authentication and the shared secret is stored too, so codes can be checked. Deleting the account takes your events and everything in them with it.

Deletion is scheduled, not hoped for

Every event has a date it gets wiped on: photos, thumbnails, face data, guest records, messages and any downloads built out of them. The organiser sets that date, gets a warning before it arrives and can push it back. It's how the thing behaves by default, not something anyone has to remember to switch on.

While the event is still open a guest can delete a photo they uploaded themselves, and the organiser can hide any photo at any point, which pulls it from every guest's view.

Where it's kept

On servers in the EU, with a European provider. Files move over TLS and are stored encrypted. Getting at a photo means a signed link that expires within minutes, and nothing is served from a public URL.

Who else sees it

No advertising, no analytics, no data brokers, and no third-party tracking in the guest app. The only sub-processors are the European hosting and storage provider and the mail provider that sends account email.

Your rights

Write to info@kynto.eu and you can ask for a copy of what's held about you, have it corrected, or have it erased. Where someone else uploaded a photo of you, the organiser is the one deciding what gets published, but ask for a specific photo to come down and it will. You can also complain to your national data protection authority, which in the Netherlands is the Autoriteit Persoonsgegevens.

Changes

If this policy changes, the date at the top changes with it.