GDPR compliance seal

GDPR Compliance

How Kamero protects the personal data of individuals in the European Economic Area, the United Kingdom, and Switzerland under the General Data Protection Regulation.

Last updated: July 21, 2026[email protected]

Your Rights at a Glance

Under the GDPR you have the following rights over your personal data. Exercise any of them anytime.

Right to Access

Request a copy of the personal data we hold about you and information on how it is processed.

Right to Rectification

Ask us to correct inaccurate personal data or complete information that is incomplete.

Right to Erasure

Request deletion of your personal data where there is no lawful reason for us to keep it.

Right to Restrict Processing

Ask us to pause processing of your data while a concern about its accuracy or use is resolved.

Right to Object

Object to processing based on legitimate interests or to direct marketing at any time.

Rights on Automated Decisions

Not be subject to decisions based solely on automated processing that significantly affect you.

Right to Withdraw Consent

Withdraw consent at any time where processing is based on your consent, without affecting prior processing.

Exercise a right

Email our data protection team and we'll action verified requests.

[email protected]

01Our Commitment to GDPR

The General Data Protection Regulation (EU) 2016/679 ("GDPR") gives individuals in the European Economic Area ("EEA"), and equivalent laws give individuals in the United Kingdom and Switzerland, strong rights over their personal data.

Kamero AI Solutions Private Limited ("Kamero", "we", "us") is committed to processing personal data lawfully, fairly, and transparently. This page explains, in plain language, how we apply GDPR principles to the data we handle across our mobile app, white-label apps, website, and desktop application (together, the "Services").

We are committed to your privacy: we collect only what we need, anonymize biometric data, delete data promptly when it is no longer needed, and give you straightforward ways to access or delete your information.

This GDPR notice supplements our Privacy Policy. Where this notice and the Privacy Policy differ for EEA, UK, or Swiss users, this notice prevails.

02Data Controller & Contact

For most personal data processed through the Services, Kamero acts as the data controller. When event organizers and photographers use Kamero to manage their own event galleries and guest lists, they may act as controllers and Kamero acts as their data processor.

If you are in the EEA, UK, or Switzerland and wish to exercise your rights, contact us using the details above. We respond to verified requests within 30 days.

04Personal Data We Collect

We collect only the data needed to provide the Services:

  • Account & contact data — first name, last name, email address, and phone number (required for verification and security). Country and city are optional.

  • Event & gallery data — event names, dates, locations, and guest lists provided by organizers.

  • Biometric data (face vectors) — mathematical feature vectors derived from a selfie you voluntarily upload for the "Find My Photo" feature. We do not store your selfie image on our servers; only anonymized vectors keyed to randomly generated UUIDs and randomly generated photo IDs are processed, never linked to your identity.

  • Transaction data — records of photo purchases and orders (payment card details are handled by our payment processors, not stored by us).

  • Technical & usage data — IP address, device and browser type, timestamps, and interaction logs collected automatically.

We apply data minimization: we do not collect more than we need, and optional fields remain optional.

05How We Process Your Data

We use personal data strictly for the purposes for which it was collected, including:

  • Creating, verifying, and securing your account (including OTP verification via email/SMS)
  • Delivering event galleries and enabling authorized photo sharing
  • Matching your face vector against event photos to power "Find My Photo"
  • Processing photo purchases and maintaining order history
  • Sending service, security, and account communications
  • Sending marketing communications only with your consent
  • Detecting, preventing, and investigating fraud and abuse
  • Meeting legal and regulatory obligations

We do not sell your personal data, and we do not use your biometric data to train generative AI models.

06Data Storage & International Transfers

Kamero is based in India, and personal data may be processed in India and other countries that may not offer the same level of data protection as your home jurisdiction.

Where your photos and media live: Uploaded photos, albums, and related media are stored in Cloudflare R2 object storage, which may be replicated across multiple regions (cross-region buckets) on Cloudflare's global cloud infrastructure for reliability, durability, and fast delivery. Cloudflare acts as our storage sub-processor and applies encryption at rest and in transit.

When we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with additional technical and organizational measures where needed.

Anonymized face vectors used for recognition are processed and stored on the secure infrastructure of our sub-processor SightRadar under a written Data Processing Agreement, and only to perform face matching on our behalf.

07Data Retention

We keep personal data only for as long as necessary for the purpose it was collected, or as required by law:

  • Photos, albums & event media — retained for the validity period of the event or the associated subscription. The moment an event, album, or individual photo is deleted from our platform — or the event/subscription expires — the corresponding files are immediately deleted from our cloud storage (Cloudflare R2), across all regions where they were replicated.

  • Face vector data — retained only for the validity of the user's event or subscription. As soon as the subscription or event expires, the event/album/photo is deleted, or the user deletes their selfie, the associated face vectors are deleted. Face vectors are never linked to a person's name or identity (see the Security section). Once deleted, they cannot be restored.

  • Account data — retained while your account is active. On account deletion, or on a verified deletion request sent to support, we delete your personal data within two working days, except where limited retention is legally required.

  • OTP codes — automatically deleted after verification or expiry (typically within 10 minutes).

  • Incomplete registrations — deleted automatically after 24 hours.

  • Transaction records — retained only as long as required by applicable tax and accounting laws.

08Security Measures

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption in transit over HTTPS/TLS for all data exchanged with the Services, and encryption at rest for photos and media stored in Cloudflare R2
  • Hashed passwords — never stored in plain text — and token-based (JWT) authentication
  • Fully anonymized biometric storage — for the "Find My Photo" feature we store only the resulting mathematical face vectors. These vectors are keyed to randomly generated UUIDs and randomly generated photo IDs, and are never linked to any person's name, email, phone number, or any other identity. There is no way to reverse a stored vector back to an individual's identity.
  • Access controls limiting personal data to authorized personnel on a need-to-know basis
  • Sub-processor due diligence and Data Processing Agreements with vendors such as SightRadar and Cloudflare
  • Regular security reviews of systems and infrastructure

No method of transmission or storage is completely secure, but we are committed to protecting your privacy and continually work to detect and respond to threats.

09Third Parties & Sub-Processors

We share personal data only with trusted service providers who process it on our behalf under contractual confidentiality and security obligations. Key sub-processors include:

  • SightRadar — provides the large-scale face recognition API behind "Find My Photo". It processes only anonymized face vectors, strictly as our sub-processor, and is contractually prohibited from selling, leasing, trading, independently using, or training generative AI on that data.

  • Cloudflare — provides R2 object storage (including cross-region replication) and content delivery for photos, albums, and media, with encryption at rest and in transit.

  • Payment processors — handle photo purchase transactions securely; card details are processed by them, not stored by us.

  • Communication providers — deliver transactional email and SMS (including OTPs).

We disclose personal data to authorities only where legally required, or to protect the rights and safety of Kamero, our users, or others.

10Your Rights & How to Exercise Them

If you are in the EEA, UK, or Switzerland, you have the rights listed above. To exercise any of them:

  1. Email [email protected] or [email protected] from the address associated with your account, or use the in-app account settings.
  2. Tell us which right you wish to exercise. We may ask you to verify your identity to protect your data.
  3. We action verified requests promptly — deletion requests are completed within two working days. More complex requests may take longer, in which case we will let you know.

Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.

Self-service deletion: Many rights can be actioned directly in the app. You can delete your account yourself from account settings, and you can delete your uploaded selfie (and its face vector) at any time. You can also request account deletion by writing to [email protected], and we will delete your data within two working days. We are committed to your privacy and to giving you real control over your data.

11Complaints & Supervisory Authority

We hope to resolve any concern you have about how we handle your personal data. Please contact us first at [email protected] so we can help.

If you are not satisfied, you have the right to lodge a complaint with your local data protection supervisory authority:

  • EEA — the supervisory authority in your country of residence, work, or where the alleged infringement took place.
  • United Kingdom — the Information Commissioner's Office (ICO).
  • Switzerland — the Federal Data Protection and Information Commissioner (FDPIC).

12Data Breach Notification

We maintain procedures to detect, report, and investigate personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, where feasible, and will inform affected individuals without undue delay when the breach is likely to result in a high risk.

13Changes to This Notice

We may update this GDPR notice from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice. We encourage you to review this page periodically.

Have a question about your data?

Reach our data protection team to exercise your rights or raise a concern. We respond to verified requests promptly.

Sign Up Today and Get Your First Event Free!

Explore Kamero and discover our powerful features for seamless photo sharing. Don't forget to check out our mobile app for the best experience!

No credit card required · First event free · No guest limits

Events Mockup

Try Kamero App

Best-in-class AI photo viewing experience. Organize, search, and share your memories effortlessly.

Download on the App StoreGet it on Google Play
WhatsApp