Privacy policy of fotkyzakce.cz

Last updated: 5 September 2026

This Privacy policy explains how personal data are processed when using the fotkyzakce.cz service, in particular on the website https://fotkyzakce.cz, in an Organizer account and in private Albums available through a QR code or link.

At the date of the last update the Service is operated as a closed beta.

Personal data controller

For personal data for which fotkyzakce.cz itself determines the purposes and means of processing, the controller is:

Tomáš Pukowiec

Dětmarovice 368, 735 71 Dětmarovice, Czech Republic

IČO 75241587, DIČ CZ8502085603

E-mail for questions and requests concerning personal data: hello@fotkyzakce.cz. Phone: +420 608 251 214.

The operator has not appointed a data protection officer.

Who this policy concerns

This policy concerns in particular:

  • Organizers who have an account and create Albums;
  • Guests who enter an Album without an account;
  • persons captured in photos or videos, even if they themselves do not use the Service;
  • visitors of marketing, help and legal pages;
  • persons who contact support or submit a request or complaint.

Roles of the Organizer and fotkyzakce.cz for Album content

For personal data of the Organizer account, security logs, analytics, support and the Service’s own operation, fotkyzakce.cz acts as an independent controller.

For personal data contained in a specific Album, the purpose of the Album, the circle of invited people and the sharing rules are determined primarily by the Organizer.

If the Organizer acts as a controller under the GDPR when using an Album, fotkyzakce.cz processes Album content to the necessary extent on the Organizer’s instructions as a processor. The arrangement under Article 28 GDPR is part of the Terms of service.

For private family or similar events the Organizer’s legal position may differ, for example because of the exemption for purely personal or household activity. This does not change our duties in relation to personal data we process for the Service’s own operation.

If in a specific situation we process Album data as an independent controller, we limit such processing to what is necessary for operation and security of the Service, handling notices, complying with legal obligations and protecting legal claims.

What data we process

Organizer account

We may process in particular:

  • name;
  • e-mail address;
  • a cryptographic hash of the password;
  • information about e-mail verification;
  • an internal account identifier;
  • the date of account creation and changes;
  • temporary tokens for e-mail verification and password reset;
  • account and theme settings;
  • the list and settings of Albums.

We do not store the Organizer’s original password in readable form.

Sessions and account security

We process technical data needed for sign-in, security and protection of the Service, for example:

  • a session token;
  • the date of last activity;
  • IP address and technical server logs if they are captured by ordinary infrastructure;
  • information needed to protect against abuse, attacks and excessive traffic;
  • technical information about errors and requests to the extent needed for diagnosis.

We do not use User-Agent, phone model or a browser fingerprint as a lasting Guest identity.

Album settings

For an Album we store in particular:

  • name and optional description;
  • a random non-public Album identifier;
  • a hash of the optional PIN;
  • color and font settings;
  • settings for allowing uploads and the upload time window;
  • the type and technical identifiers of the chosen storage;
  • data needed for QR, live slideshow and shared ZIP download.

Guest data

A Guest does not create an account and does not ordinarily enter an e-mail or phone number.

We may process in particular:

  • a random Guest identifier bound to one specific Album;
  • an optional display name;
  • the time of first visit and upload;
  • the link of uploaded Media to a specific Guest;
  • technical information on whether the Guest is authorized to enter the Album after entering a PIN.

The last used display name may for convenience be stored locally in the Guest’s browser and pre-filled in another Album. This is not a server-side linking of Guest identity across Albums.

Photos, videos and their metadata

For uploaded Media we may process in particular:

  • the photo or video itself;
  • file type and MIME type;
  • size;
  • the original file name;
  • upload time;
  • capture time, if it can be read from the file;
  • the technical file identifier at the storage provider;
  • the link to the Album and Guest;
  • a hidden or deleted flag;
  • JPEG previews created for the gallery and live slideshow.

By default we do not store:

  • GPS coordinates from EXIF;
  • phone make and model as a Guest profile;
  • device serial number;
  • a browser fingerprint;
  • a Guest’s e-mail or phone number.

We do not use facial recognition or biometric identification of people in photos.

Connecting Google Drive and OneDrive

If the Organizer connects Google Drive or OneDrive, we process data needed for that connection, in particular:

  • the e-mail or identifier of the connected account;
  • the identifier of the managed folder;
  • OAuth access credentials and a refresh token to the extent needed for the connection to work.

We store the refresh token encrypted on our API, not in public frontend code. The token never goes to a guest’s phone.

For Google Drive we request the drive.file permission: the folder and files this app creates, or that the organizer expressly opens. We do not use Drive data for ads, profiling, or sale. This follows the Google API Services User Data Policy (Limited Use). For OneDrive we support a personal account and the application folder.

How Drive connection works is on the page How Google Drive works.

How OneDrive connection works is on the page How OneDrive works.

Support, complaints and notices of unlawful content

If you contact us, we may process:

  • your name and contact details;
  • the content of the communication;
  • identification of the account, Album or Media the communication concerns;
  • materials needed to handle a request, complaint, security incident or notice of unlawful content.

Analytics of marketing and organizational pages

With your consent we may use Google Analytics 4 on selected pages for basic traffic measurement.

Analytics may concern in particular:

  • information about the visit;
  • approximate country or region;
  • browser and device type;
  • visited pages and basic interactions.

We do not use Google Analytics in guest Albums, on the PIN page, in live slideshow or on the ZIP link. We do not send a specific Album identifier to Google Analytics as an analytics event.

Where we obtain data from

We obtain data:

  • directly from the Organizer during registration and use of the account;
  • directly from the Guest when uploading Media or entering an optional name;
  • from files uploaded by the Organizer or Guest;
  • from Google or Microsoft when the Organizer requests a storage connection;
  • automatically from the technical operation of the Service;
  • from notifiers if they report unlawful or objectionable content to us.

If you are only a person captured in a photo or video and you did not use the Service yourself, we ordinarily obtained your image recording from the Organizer or Guest who uploaded the Media to the Album.

Purposes and legal bases

PurposeTypical legal basis / role
Creating and operating the Organizer accountperformance of a contract
E-mail verification, sign-in and sessionsperformance of a contract; security also a legitimate interest
Creating and managing Albumsperformance of a contract
Technical operation of upload, gallery, live and ZIPperformance of a contract towards the Organizer; for Album content, processing on the Organizer’s instructions if the Organizer is a controller
Security, prevention of attacks and abuselegitimate interest in secure operation
Technical logs and diagnosislegitimate interest in reliability and security
Support and complaintsperformance of a contract, legal obligation or legitimate interest depending on the situation
Notices of unlawful content and legal orderslegal obligation and legitimate interest in lawful operation
Defence and assertion of legal claimslegitimate interest
Google Analytics on selected non-guest pagesconsent
Accounting and tax data after a future launch of a paid servicelegal obligation and performance of a contract

If we process Album content as a processor, the legal basis for the processing of the content itself is determined by the relevant controller, typically the Organizer. Our activity is in that case based on their instructions and the processing agreement.

If, given the nature of a specific private Album, the Organizer does not act as a controller under the GDPR and we process some data as an independent controller, we rely for necessary technical processing in particular on a legitimate interest in providing the feature that the Organizer and Guests expect, while keeping limited access, minimization and the ability to remove content.

Where originals, previews and metadata lie

Organizer’s Google Drive

If the Organizer chooses Google Drive:

  • originals are stored in a managed folder in their Google account;
  • the gallery and live use JPEG previews stored with us in Cloudflare R2;
  • original download, video and ZIP may be loaded from Google Drive through our API.

Organizer’s OneDrive

If the Organizer chooses personal OneDrive:

  • originals are stored in the application folder in their Microsoft account;
  • previews are with us in Cloudflare R2;
  • original download, video and ZIP may be loaded through our API.

Internal beta storage

For selected internal or test accounts the Operator may in beta mode also store original Media on Cloudflare R2. This is not yet a publicly available paid offering.

Database

Account, Album, Guest and Media metadata are stored in a database operated through Railway infrastructure in the EU region according to the current Service configuration.

Providers and recipients of data

To operate the Service we use in particular:

ProviderPurpose
Vercelhosting and distribution of the web interface
RailwayAPI, database, infrastructure and technical logs; the backend is in the EU region according to the current configuration
Cloudflare R2JPEG previews; for selected beta accounts also originals
ForpsiDNS and related domain services
Resendtransactional e-mails, for example account verification and password reset
GoogleGoogle Drive if the Organizer chooses it; Google Analytics only after consent on selected pages
Microsoftpersonal OneDrive if the Organizer chooses it

Providers may process technical data to the extent needed for their services and according to the applicable contractual and legal rules.

Files in Google Drive or OneDrive are at the same time subject to the Organizer’s separate relationship with Google or Microsoft.

Transfers of data outside the EEA

Some providers may also have a seat or infrastructure outside the European Economic Area, in particular in the United States.

If personal data are transferred outside the EEA, we use the mechanism required by law for the specific recipient, for example:

  • a European Commission adequacy decision, if it applies;
  • the EU-US Data Privacy Framework for participants to which it applies;
  • European Commission standard contractual clauses and any supplementary measures.

Information about the specific mechanism used for a given provider can be requested at hello@fotkyzakce.cz.

Who can see Album content

An Album is designed as non-public, not as a public catalogue.

Content may be seen in particular by:

  • persons who know the random Album link;
  • persons who also know the PIN, if a PIN is enabled;
  • the Organizer;
  • the Operator to the technically necessary extent for administration, support, security, handling notices or a legal obligation;
  • technical providers to the extent needed to operate the infrastructure.

The Service is not end-to-end encrypted storage, and the claim “private album” does not mean the Operator cannot technically access the data.

A separate ZIP link is its own access key to all available Album originals and is not protected by the gallery PIN.

Retention period and deletion

We do not keep data longer than needed for the given purpose, Album operation, a legal obligation or the protection of legal claims.

Category / eventPeriod or consequence
Organizer accountfor the lifetime of the account; after deletion, removal according to the rules below
Organizer sessionabout 7 days from the last relevant activity; it may be renewed while in use
Guest guest_sessionat most 30 days for a specific Album, unless the Guest deletes it earlier
Album and its metadatauntil the Album or account is deleted, or until the service ends and technical erasure
Media and previewsuntil the Media or Album is deleted; for third-party storage with the limits described below
Hidden Mediaremain stored until they are removed
Verification and reset tokensonly for their technical validity and subsequent secure removal
Technical security logsfor a limited period reasonable for security, diagnosis and incident handling
Support and legal-request communicationsfor the time needed to handle them and, if applicable, to protect legal claims
Google Analytics dataaccording to Analytics settings and the consent given; only on non-guest pages

Deleting Media

Deletion of their own Media by a Guest or of Media by the Organizer leads to removal of the relevant record and files that the Service technically controls, including previews.

Hiding Media

Hiding means the content stops being shown to Guests in the gallery and live slideshow, but the file remains stored so the Organizer can show it again or delete it.

Deleting an Album

Album deletion is irreversible. We remove metadata, Guest data bound to the Album, previews and other managed objects.

For Google Drive or OneDrive the Service will try to remove files in the managed folder. If permission was previously revoked or storage is unavailable, we may not be able to remove files in the external account and the Organizer must remove them themselves.

Disconnecting Drive or OneDrive

Disconnecting storage removes the stored login permission for that feature, but files stored in the Organizer’s account remain.

Deleting the account

Deleting the account leads to removal of the account and its Albums. Some minimal data may remain for the necessary period if retention is required by law, an ongoing security incident, a dispute or the protection of legal claims.

Cookies and browser local storage

The Service uses necessary cookies and localStorage for example for:

  • Organizer sign-in;
  • recognizing a Guest within a specific Album;
  • remembering PIN status;
  • choosing a light, dark or system theme;
  • a hint of the Guest’s last name;
  • live slideshow settings;
  • storing the analytics choice;
  • remembering the website language.

Google Analytics is activated only after consent and only on selected non-guest pages.

Details are in the separate Cookie and similar technologies policy.

Children and persons captured in photos

The Service does not verify Guest age, and it is common that photos from family, school, camp or wedding events capture children.

The Organizer and the uploading person are responsible for taking and sharing content in accordance with applicable law and the rights of the persons concerned.

fotkyzakce.cz does not use photos of children or other persons for facial recognition, profiling or advertising.

If you are in a photo or video and want the content removed, we recommend first contacting the Organizer of that Album. You may also contact hello@fotkyzakce.cz and provide the Album address and a sufficient description of the specific content so it can be identified.

Your rights

Depending on the circumstances and the legal role in which we process the data, you may in particular have the right to:

  • obtain information about processing and access to your personal data;
  • request rectification of inaccurate data;
  • request erasure;
  • request restriction of processing;
  • receive data in a portable format if the legal conditions are met;
  • object to processing based on a legitimate interest;
  • withdraw consent at any time if processing is based on consent;
  • lodge a complaint with a supervisory authority.

If for the content of a specific Album we act only as a processor for the Organizer, we may forward your request to the Organizer or help them handle it.

A request may be sent to hello@fotkyzakce.cz. Before handling a request we may reasonably verify the identity or the requester’s relationship to the specific data, in particular so that someone else’s private Album is not disclosed.

We will respond to a request within the statutory time limits.

Supervisory authority

In the Czech Republic the competent supervisory authority is:

Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic

Automated decision-making and AI

fotkyzakce.cz does not carry out automated individual decision-making that would have legal or similarly significant effects on the user.

The Service does not use AI to recognize people in photos, to rate Guests, or to decide who may use an Album.

Sale of data, advertising and AI training

We do not sell personal data, photos or videos.

We do not use Album content for advertising profiling or to train artificial intelligence models.

In guest Albums we do not use Google Analytics or advertising systems.

Security

We use reasonable technical and organizational measures to protect data against unauthorized access, alteration, loss or misuse.

Depending on the type of data these measures include in particular:

  • HTTPS and encrypted transmission;
  • password hashing;
  • PIN hashing;
  • time-limited sessions and file links;
  • random, unguessable Album identifiers;
  • the Organizer’s ability to hide or delete content;
  • limited OAuth permissions for supported external storage;
  • keeping secret keys and tokens only on the backend, and encrypting stored OAuth refresh tokens;
  • limits on the size and types of uploaded files.

No system can guarantee absolute security.

An Album is not end-to-end encrypted, and a random link or PIN does not replace careful sharing of access by the Organizer.

Security breach

If a personal data breach occurs, we will proceed according to the GDPR and other applicable law, including notification of the relevant controller, supervisory authority or affected persons if such notification is required.

Changes to this policy

We may update this policy in particular when the Service, providers, legal rules or the way of processing change.

The current version is marked with the date of the last update.

If a change is material for registered Organizers, we may also inform them by e-mail or a notice in the Service.

If a change requires new consent, we will ask for a new choice before starting such processing.

Contact

Questions and requests concerning personal data protection:

E-mail: hello@fotkyzakce.cz. Phone: +420 608 251 214.

Tomáš Pukowiec, Dětmarovice 368, 735 71 Dětmarovice, Czech Republic