Privacy Policy

Last updated: August 12, 2026

1. Who is responsible

This policy covers the Patifot website, dashboard and iPad application. They are operated by PATIFOT, a French société par actions simplifiée unipersonnelle (SASU) with share capital of €30,000, registered with the Paris Trade and Companies Register under number 983 410 473, at 58 rue de Monceau, CS 48756, 75008 Paris, France ("Patifot", "we"). Privacy questions: [email protected].

Two roles matter here. For operator accounts and this website, Patifot is the data controller. For photos and related data of event guests, the booth operator (our customer) is the controller and Patifot processes the data on the operator's behalf.

2. Operator accounts

When we create an operator account we process your name, business contact details, company information, the identifiers of the iPads you activate, and the content you upload to prepare events (frames, prompts, idle screens). We use this data to provide the service under our contract with you. Account data is kept while the account is active, then deleted or anonymized unless the law requires us to keep records longer (for example, invoices).

The self-service account deletion flow remains disabled until the server rollout is complete. Once enabled, Brevo will deliver one-time deletion codes and status messages. It will process the operator's email address and delivery headers for that purpose. Brevo transaction logs are kept for one month, message previews are disabled, and tracking is anonymous.

3. Guest photos at events

When a guest uses a booth, we process the original photo, the finished result, technical session identifiers and the record of the choices made on screen. If the guest selects an AI mode, we also process the AI result and the information needed to send the accepted photo for image generation.

  • Closed event archive: originals and results are uploaded to Patifot servers in the EU and placed in a closed archive for the event operator or host. This release does not provide guest delivery by QR code or PIN.
  • Retention: server deletion is scheduled 90 days after the later of the end of the local event day and the latest confirmed upload. Accepted photos, rejected takes and generated results follow that same deadline. Classic capture can continue during a network outage, but queued files upload when the connection returns.
  • Retakes and local copies: if a guest retakes a photo, the rejected original remains inside the same closed event archive and follows the same deadline. Files already uploaded are normally removed from the iPad after seven days. A file still waiting for upload or printing may remain on the device until that obligation is completed or deletion is authorized.
  • Technical accountability record: production event publication under this policy remains disabled until these controls have been deployed and checked. Once enabled, raw booth telemetry and technical request logs will be kept for no more than 90 days. A minimal record without the guest's name or photo will remain in the live database until the end of five full local calendar years after the event. It will be used only for accountability and for establishing, exercising or defending legal claims. A restricted disaster-recovery backup copy may remain for no more than 15 additional days after the record is actually deleted from the live database. The backup will be used only to recover the service. Before a restored service accepts traffic, the original expiry will be reapplied and every overdue record removed. A documented legal hold may extend live retention only while required. When the hold is released, the original deadline will apply again. If it has passed, the live record will be deleted and the backup copy may remain for no more than 15 days from that actual deletion.
  • No face recognition: we do not run face search and do not create or store face embeddings.
  • Action before capture: the guest must press Start shooting after seeing the Patifot notice. AI processing starts only after an explicit action: the guest selects an AI mode when that choice is shown, or presses Start shooting in an AI-only event after the AI disclosure. The event operator determines the lawful basis for the event and must obtain any additional permission required for marketing or publication.
  • Children: a parent, legal guardian or an adult authorized by one of them must start a session for a child. The event operator remains responsible for any additional permission required by local law.

4. AI processing

Production AI events under this policy are not enabled yet. Before they can be enabled, Patifot must verify the OpenAI EU project, DPA and active data controls. In the approved flow, only the accepted photo is sent through Patifot's EU servers to OpenAI's European API endpoint to create the requested image. The iPad never contacts OpenAI directly. Patifot will not opt API content into model training. OpenAI may retain an image in limited safety cases permitted by the active data controls or by law. xAI and other AI providers are not used under this policy. Using another provider would require a new policy version shown before capture.

5. Booth telemetry

Booths report technical status to the dashboard: device health, printer and paper state, error events, configuration version. This data concerns devices rather than people; where log entries reference a session, they contain identifiers, not photos. Before commercial guest processing begins, Patifot will activate and verify a 90-day deletion schedule for these technical logs.

6. This website

The website is static and sets no tracking cookies. Cloudflare serves the site and processes standard connection logs, including IP address and user agent, to run and protect its network.

7. Payments

When billing is enabled, credit purchases are processed by Paddle as merchant of record. Paddle is responsible for payment data; we never receive full card numbers. Paddle's privacy policy applies to its checkout.

8. Subprocessors and recipients

ProviderPurposeLocation of processing
OpenAI (EU endpoint)AI image generationEuropean Union
xAINot used under this policyNot applicable
UpCloudApplication servers and storageEuropean Union
CloudflareDNS, CDN, website hosting and network securityEU / US (Data Privacy Framework, SCCs)
BrevoDelivery of account, security and operational email; one-month transaction logs and no message previewsEU
Cloudflare Email Routing and Google GmailForwarding and storage of incoming support and privacy emailEU / US (Data Privacy Framework, SCCs)
PaddleCredit purchases and invoicing, when enabledUK / EU

Guest photo archives are delivered to the host of the event (the operator's client) as disclosed in the booth notice and on the event operator's instructions. We do not sell personal data and we do not run advertising.

9. International transfers

Patifot application servers are in the European Union. The approved but not yet enabled AI flow uses OpenAI's European API endpoint. Cloudflare may process connection data outside the EU under the EU-US Data Privacy Framework and standard contractual clauses. xAI and other AI providers are not used under this policy.

10. Security

Data travels encrypted (TLS). Access to production systems is restricted and logged. Production event publication remains disabled until the archive deadline, accountability retention, backup expiry and restore-before-traffic deletion gates have been deployed and checked.

11. Your rights

Under the GDPR you can request access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. Write to [email protected]; we answer within a month. You can also complain to the French supervisory authority, the CNIL (cnil.fr), or to your local authority.

If you are an event guest, the operator who ran the event is the controller of your photos. The fastest route is the event operator or host. We help operators answer these requests. Event photos are also deleted automatically when the archive retention period ends.

12. Changes

We will update this policy as the service evolves and note the date of the last change at the top. For material changes affecting operators, we give notice by email.

Translations of this policy are provided for convenience. In case of divergence, the English version prevails.