Zásady ochrany osobních údajů
Srozumitelné shrnutí pro období předběžného přístupu. S růstem Liberia se může změnit.
1. Who we are and our role
This Privacy Policy explains how the operator of Liberio ("Liberio", "we", "us") handles personal data when you use the Service. The responsible legal entity will be named in full when this policy is published; until then, reach us at [email protected].
For studio account information, service administration, security, and business communications, we may act as a data controller. For personal data that studios upload or manage in Liberio, such as client details, photos, galleries, and selections, the studio is usually the data controller and we act as a processor or service provider on the studio's behalf.
2. Data we collect
Account information: names, email addresses, passwords stored in hashed form, studio details, login information, authentication data, and team roles such as StudioOwner, Editor, and Worker.
Customer Content: photos, files, customer information, shoot details, gallery information, and other content uploaded or managed by studios.
Client gallery data: anonymous gallery access tokens, favorites, notes, selections, submissions, and related activity made by clients through shared galleries.
Usage and log data: IP address, device and browser information, pages viewed, actions taken in the Service, timestamps, error logs, and security events.
Billing data: if billing is enabled, we may collect billing-related information. Payment processing details may be handled by third-party payment providers under their own terms and privacy policies.
3. How we use data
We use personal data to provide and operate the Service, authenticate users, manage accounts, deliver galleries, store files, record client selections, provide support, maintain security, prevent abuse, troubleshoot errors, comply with legal obligations, and improve the platform.
We may also use contact information to send service messages, account notices, security alerts, and important updates. We do not sell personal data.
4. Legal bases under GDPR and KVKK
Where the GDPR applies, we rely on one or more legal bases, including performance of a contract, legitimate interests, legal obligations, and consent where required. Our legitimate interests may include securing the Service, preventing fraud and abuse, improving Liberio, supporting users, and maintaining reliable operations.
For Turkish users, we process personal data consistent with the Turkish Law on the Protection of Personal Data (KVKK) on comparable grounds. When we process studio-managed client data as a processor, the studio is responsible for identifying the applicable legal basis for that processing.
5. Data storage
Photos, files, and related content may be stored using S3-compatible object storage. Other service data may be stored in databases, application systems, backups, logs, and related infrastructure.
We use hosting, storage, and technical service providers as needed to operate Liberio. Some deleted data may remain temporarily in backups or logs before being securely removed according to normal retention cycles.
6. Cookies and local storage
We use browser local storage, cookies, and similar technologies for essential functions such as keeping studio staff signed in with JSON Web Tokens (JWTs), remembering language preferences, securing sessions, and maintaining gallery sessions for clients using anonymous access tokens.
You can control cookies and local storage through your browser settings, but disabling them may prevent parts of the Service from working correctly.
7. Third-party processors
We may use third-party processors and service providers for hosting, object storage, databases, email delivery, analytics, logging, security, support, and payment processing if billing is enabled.
These providers may process personal data only as needed to provide their services to us and are expected to protect personal data under appropriate contractual and technical safeguards.
8. Data retention
We retain personal data for as long as needed to provide Liberio, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and support backups and disaster recovery.
Studios are responsible for managing retention of their own customer content and client data, unless otherwise agreed. Studios can request export or deletion of their data, and some deleted data may remain temporarily in backups or logs before removal according to normal retention cycles.
9. Your rights under GDPR and KVKK
Depending on your location and applicable law, including GDPR and KVKK, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing is based on consent.
If you are a studio staff user, contact us at [email protected] to exercise rights regarding data we control. If you are a studio client whose data appears in a gallery or photo shoot, you should usually contact the photography studio first because the studio controls that data. We will support studios in responding to lawful data protection requests where required.
10. International transfers
Personal data may be processed in countries other than where you live or where your studio is located. These countries may have different data protection laws.
Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, contractual protections, or other lawful transfer mechanisms under GDPR, KVKK, or other applicable laws.
11. Children's data
The Service is not intended for use by children as account holders, and we do not knowingly collect personal data directly from children.
Studios may upload photos or information that include children as part of their photography services. Studios are responsible for ensuring they have the required consent or other legal basis to collect, upload, share, and manage children's data through Liberio.
12. Security
We use reasonable technical and organizational measures designed to protect personal data, including access controls, password hashing, encryption in transit, secure authentication, logging, and storage protections. Studio staff authentication uses JWTs, and anonymous customer access to galleries uses secure, scoped tokens.
No method of transmission or storage is completely secure. You are responsible for using strong credentials, limiting access to authorized staff, and protecting gallery access links and tokens.
13. Changes to this policy
We may update this Privacy Policy from time to time. If changes are material, we will take reasonable steps to notify users, such as by email or in-app notice. The updated Privacy Policy will apply from the effective date shown in the policy.
14. Contact
For privacy questions or to exercise data protection rights, email us at [email protected].