Privacy

Privacy policy.

We handle personal data with care and comply with the GDPR. Here's exactly how.

Last updated: July 2026. Data controller: Shareddd, part of Layer Group. Contact: app@shareddd.com.

1. Roles

For organisers' account data, Shareddd is the data controller. For the content guests upload to an event, the event's organiser is the data controller and Shareddd acts as processor — we process that content on the organiser's instructions.

2. What data we process

From organisers: name, email address, company name, any billing/company details (address, chamber of commerce number, VAT number) and payment data. From uploaders (guests): the uploaded photos and videos, an optional name, and technical data — including a hashed indication of the IP address and the browser user-agent — to prevent abuse. Photos and videos may contain images of people, which is personal data.

3. Purposes and legal bases

Providing the service (collecting, storing, moderating and displaying content) — basis: performance of the contract with the organiser.
Use of uploaded content by the organiser — basis: consent of the uploader (see point 4).
AI analysis (quality score, category, caption, transcription, filtering inappropriate content) — basis: legitimate interest / performance of the contract.
Billing and support — basis: contract and legal obligation (incl. tax retention).
Security and abuse prevention (hashed IP, rate limiting) — basis: legitimate interest.

4. Uploader consent

Before uploading, uploaders give explicit consent for the use of their content by the organiser of the event, via a consent text the organiser can customise. Consent can be withdrawn at any time via the organiser or via app@shareddd.com.

5. Sub-processors

We use carefully selected processors and never sell your data to third parties:

PartyPurposeLocation
CloudflareHosting, storage (R2/D1/KV), CDNEU / global*
OpenAIAI analysis of photos and videosUnited States
MolliePayments & direct debitEU (Netherlands)
MicrosoftTransactional email (Graph)EU / global*

* Storage is primarily within the EU; supporting processing may occur outside the EU under the relevant processor's safeguards.

6. Transfers outside the EU

For AI analysis, images are processed by OpenAI in the United States. This transfer takes place under OpenAI's data processing agreement with EU Standard Contractual Clauses (SCCs). Images are sent temporarily for analysis and are not used by OpenAI to train models. Other data is processed primarily within the EU.

7. Retention

Content is automatically deleted after the retention period of the chosen plan: 90 days (Free) or 365 days (Memory). On Studio/Business the organiser sets the retention period; after the subscription ends, the standard period applies again. Invoice data is kept as long as legally required.

8. Your rights

You have the right to access, rectify, erase, restrict, object to and port your data, and to withdraw a given consent. Are you a guest/uploader? Address your request first to the event's organiser; we assist them. Send your request to app@shareddd.com; we respond within the statutory period (at most one month).

9. Security

Data is stored encrypted and files are only accessible through temporary, signed links. Access is limited to those who need it, accounts can be secured with two-factor authentication (2FA), and we apply automatic deletion after the retention period.

10. Data breaches

In the event of a data breach posing a risk to individuals, we notify the Dutch Data Protection Authority within 72 hours and inform affected individuals where required.

11. Complaints

Have a complaint about how we handle your data? Contact us at app@shareddd.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority.

This policy may be updated; the date at the top reflects the latest change. Questions? app@shareddd.com.