LegalPrivacy Policy
Last updated: 10 September 2026
1. Who We Are
Mémori (accessible at memoriqr.com) is a wedding photo-gallery sharing service operated by DrabbIT j.d.o.o., , Croatia (OIB , MBS , ).
We are the data controller for the personal data described in this policy. For all privacy matters contact us at privacy@memoriqr.com; for anything else, hello@memoriqr.com.
2. What Data We Collect and Why
2.1 Admin Accounts
- Name and business email address: to create and manage an admin account for the Mémori team.
- Login session data: stored in a secure, HTTP-only session cookie to keep you signed in.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
2.2 Couple Order Data
- Couple names and wedding date: used to create the gallery, generate the gallery code and the QR card, and label the photos.
- Email address: used to send the order confirmation and receipt, the gallery code and QR card, the notice that the gallery is live, and service messages about the gallery such as its expiry. We do not send marketing email without separate consent.
- Payment information: processed directly by Stripe, Inc. We never see or store card numbers; we keep only Stripe’s customer and payment identifiers and the amount paid.
- Partner code: if you enter a partner or referrer code, or arrive through a partner link (which sets a short-lived cookie), we record which partner referred the order so they can be credited.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); for partner attribution, legitimate interests (Art. 6(1)(f) GDPR).
2.3 Wedding Guests
- Guests view galleries using the wedding code (and, if the couple set one, a gallery password). No registration is required.
- A guest who asks to be notified when the gallery goes live gives us an email address, which we use only to send that one notice.
- A guest who requests all photos as a download gives us an email address, which we use only to send the time-limited download link.
- Standard server logs (IP address, browser type, timestamp) are generated automatically by our hosting infrastructure and retained for a short period for security and debugging.
Legal basis: performance of a contract for notifications and downloads the guest requested (Art. 6(1)(b) GDPR); legitimate interests for server logs (Art. 6(1)(f) GDPR).
2.4 Wedding Photos
- Photos are provided by the couple or their photographer and uploaded by the Mémori team on the couple’s behalf. They are stored at web resolution in our secure cloud storage.
- Galleries are accessible only via the unique wedding code (and optional gallery password) and stay online for 3 months from the day they are published, unless we extend them.
- When a guest requests all photos, an archive is packed by our processing service (Google Cloud, EU region) and kept for reuse until the gallery changes or expires.
- The couple may request permanent deletion of a gallery and all associated media at any time by contacting us.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
3. Third-Party Processors
We share data with the following sub-processors, all of whom are bound by data processing agreements:
| Processor | Purpose | Location |
|---|
| Supabase, Inc. | Database, file storage, authentication | EU (AWS eu-central-1) |
| Stripe, Inc. | Payment processing | USA (EU SCCs apply) |
| Resend, Inc. | Transactional email delivery | USA (EU SCCs apply) |
| Vercel, Inc. | Web hosting and edge infrastructure | USA / EU (EU SCCs apply) |
| Google Cloud EMEA Ltd. | Packing gallery download archives (Cloud Run) | EU (europe-west1, Belgium) |
SCCs = Standard Contractual Clauses (EU Commission Decision 2021/914), the lawful mechanism for transferring personal data to countries outside the European Economic Area.
4. Data Retention
- Gallery data and photos: kept while the gallery is online (3 months from publication, or longer if extended) plus up to 30 days after expiry, then permanently deleted.
- Guest email addresses given for a gallery-live notice or a download link: deleted together with the gallery.
- Order and payment records: retained for 7 years to comply with Croatian accounting and tax law (Zakon o računovodstvu).
- Admin account data: retained for the lifetime of the account; deleted within 30 days of account closure on request.
- Server logs: deleted after 30 days at the latest.
5. Your Rights Under GDPR
As a data subject under EU/EEA law you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: ask us to correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request deletion of your data where we have no overriding legal obligation to retain it.
- Restriction of processing: ask us to pause processing while a dispute is resolved.
- Data portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent (e.g. non-essential cookies), you may withdraw at any time.
To exercise any right, email us at privacy@memoriqr.com. We will respond within 30 days.
You also have the right to lodge a complaint with the Croatian Data Protection Authority (AZOP): azop.hr · azop@azop.hr.
6. Cookies
We use cookies as described in our Cookie Policy. You can manage your cookie preferences at any time using the banner on our website or by contacting us.
7. Security
We implement appropriate technical and organisational measures to protect your data, including: TLS encryption in transit, encrypted storage at rest, role-based access control, and regular security reviews. No system is perfectly secure; if you discover a vulnerability please report it responsibly to privacy@memoriqr.com.
8. Children
Our service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top and, for material changes, notify affected users by email.
10. Contact
DrabbIT j.d.o.o.
, Croatia
OIB
Email: privacy@memoriqr.com
Our Terms of Service describe the gallery service itself.