Eventiere is built privacy-first. Face data is never sold, never shared and never used to train anything. Enterprise security as standard - not an upsell.
Photos, face data and contact details are encrypted in transit and at rest. Nothing moves between services in plaintext.
Face data does one job: matching a guest to their own photos at your event. It is never sold, never licensed and never passed to a third party. No one can rebuild a guest's face from what the platform holds.
No face is processed without the guest choosing to opt in first. That choice is logged with a timestamp and can be reversed at any point - we don't make withdrawal difficult.
We're built for events across the GCC, UK, India and Southeast Asia, which means covering GDPR, UAE PDPL, India DPDPA and Singapore PDPA. Need data to stay in a specific region? We can do that.
Ask us to remove an event's data and we remove it. Guests can request removal themselves from the privacy page, and every request is tracked through to completion.
Organisers, photographers and admins each see only what they need to. Every action is audit-logged. A guest's photos are visible only to that guest - no shared galleries, no browsing other people's images.
A lot of companies say "privacy-first" without showing their working. Here's the full pipeline from photo upload to deletion, with nothing left out.
Your photographer's images go into a private, locked folder only your team can access. Nothing is public-facing.
Our AI creates a mathematical fingerprint for each face it finds. The original photos stay untouched and the fingerprint can never be used to recreate a face.
When a guest takes a selfie, we compare it against those fingerprints to find their photos. Only their results come back - we never mix guests or share results across events.
Photos are sent directly to the guest by email. We never store guest contact details with the delivery provider.
Ask us and an event's face data is removed. Your photos follow your own policy, not ours.
| Regulation | Region | Status | Key requirement met |
|---|---|---|---|
| GDPR | European Union | ✓ Compliant | Explicit consent, right to erasure, data portability, DPO available on request |
| UAE PDPL | United Arab Emirates | ✓ Compliant | Consent-based processing, data localisation options, breach notification within 72 hours |
| India DPDPA 2023 | India | ✓ Compliant | Notice and consent framework, data fiduciary obligations, grievance redressal |
| PDPA | Singapore | ✓ Compliant | Purpose limitation, accuracy obligation, retention limits, transfer restrictions |
| PDPA | Qatar | ✓ Compliant | Lawful basis for processing biometric data, data subject rights |
| UK GDPR | United Kingdom | ✓ Compliant | Post-Brexit UK adequacy, Article 9 special category data safeguards |
Yes. Eventiere is fully GDPR compliant. We capture explicit consent before facial recognition, allow data deletion on request, and offer Data Processing Agreements.
Face data does one job: matching a guest to their own photos at your event. It stays inside Eventiere, it is never sold, licensed or passed to a third party, and no one can rebuild a guest's face from what the platform holds. A guest can ask for their data to be removed at any time.
Yes. Guests can submit a data removal request at any time via our GDPR / Data Removal page or by contacting privacy@eventiere.com. We process all requests within 72 hours and provide confirmation.
It isn't. A guest's face data stays inside Eventiere's infrastructure and is never sold, licensed or passed to any third party. Our cloud providers process encrypted data only - they have no access to that face data itself.
By default we use the data centre closest to your event. If your legal or procurement team needs data to stay in a specific country, UAE, India, EU and Singapore are all available - just let us know before the event is set up.
We have a documented breach response plan with a 72-hour notification commitment to affected organisations and relevant authorities. Every system action is logged to a tamper-evident audit trail, so we can trace exactly what happened and when.
Yes. A standard DPA is available for all paid plans. Custom DPAs are available for enterprise customers. Contact privacy@eventiere.com to request your DPA.
We don't train on guest data. A guest's face is used for one purpose only - finding their photos at your event - and nothing else.