Privacy and GDPR
Where your photos are stored, who is the controller of your clients’ data, what we don’t do and what SilverAlbum support can see.
Updated:
Where your photos are
We store files in Cloudflare R2 storage in the European Union region. The storage is private: we serve each file through a short-lived address, and only after checking that the person has access to the gallery. Password and link-only galleries don’t end up in search engines.
Who is responsible for what
- You are the controller of your clients’ data. You have the contracts with them and their consent to use their image. You decide who gets the link and password.
- SilverAlbum is the processor (GDPR Art. 28). We store and serve files on your instructions, nothing more.
- Your client doesn’t create an account with us. When selecting photos, they only give an email address.
The data processing agreement isn’t a separate document to sign. It’s § 12 of the terms (the Polish text is binding; this is a translation) and applies to every account from day one. It covers the scope of data, sub-processors, breach notification within 48 hours and the right to audit.
What we don’t do
- We don’t do face recognition, and it isn’t on our roadmap. A face scan is biometric data, and photos from family and school sessions are mostly of children. With us, a person’s image stays an ordinary photo.
- We don’t train any AI models on your photos.
- We don’t use your photos to promote SilverAlbum.
- We don’t sell data and we have no advertising cookies.
What SilverAlbum support can see
SilverAlbum’s admin panel doesn’t show photos or thumbnails from galleries. To handle support requests, this is all we need:
- account email and name, plan and storage used,
- gallery titles, number and size of files,
- processing queue status and a log of emails sent.
We don’t know gallery passwords — we only store their hashes. If we need to look at a specific gallery to solve a problem, we’ll ask you for the link.
When someone asks for their photo to be removed
The person in the photo sends their request to you, because you’re the controller. You can delete a single photo in the Photos tab or the whole gallery in Settings. Deleting removes the files from storage, not just the entry in the list. If someone writes to us about it, we’ll pass it on to you and help you sort it out.