Sipix
← Back to the homepage

This page is a translation provided for information purposes only. Only the French version of these documents is authoritative; in the event of any discrepancy, the French version prevails.

Privacy policy

Last updated: 1 August 2026

This policy describes, in accordance with Regulation (EU) 2016/679 (GDPR) and the French loi “Informatique et Libertés” (the French data protection act), how the Sipix Service processes personal data. Capitalised terms (Publisher, Organiser, Guest, Service) have the meaning given to them in the terms of use and sale.

1. Data controller

The data controller is TODO: nom / dénomination de l’éditeur, TODO: adresse de l’éditeur (ou domiciliation) (see the legal notice). For any question or to exercise your rights: contact@sipix.eu.

2. Data processed

Organisers (account holders)

  • account data: email address, authentication details;
  • event data: the couple’s first names, date, theme, settings;
  • technical data: connection logs, session data;
  • if a paid plan is purchased: payment data (bank card) and billing data (name, address and, for business customers, SIREN/SIRET number and VAT number) are collected and stored directly by our payment provider Stripe at the time of the order; the Publisher has no access to them and keeps only transaction references (technical identifiers, plan purchased, amount, date) and the corresponding invoice.

Guests and data subjects

  • uploaded content: photos, videos and voice messages, together with their associated metadata (e.g. the date the picture was taken and, where the device records them, location coordinates [GPS] and device information). The original file you upload is kept as it is and can be downloaded by the other guests who have the link: its metadata, including any location data, is then accessible to them. Turn off your camera’s geolocation before the event if you do not wish to share it;
  • optional data: a first name and a little note accompanying an upload (photo, video or voice message). The first name is visible only to the Organiser, never to the other guests;
  • “favourites”: when a Guest likes a photo or video, that reaction is recorded together with a random identifier generated on their device, specific to the event. This identifier does not make it possible to identify the Guest and is used solely to count reactions and avoid duplicates;
  • the image and voice of the persons appearing in the uploaded content.

3. Purposes and legal bases

Provision of the Service
collection, hosting, display, slideshow and download of content; legal basis: performance of the contract (and, for the persons photographed, the Organiser’s legitimate interest in preserving the memory of their event).
Automatic enrichment
thumbnail generation and image-quality estimation (technical processing performed locally, always active) and, when the Organiser enables automatic analysis, moderation of explicit or violent content, addition of scene tags and transcription of voice messages; legal basis: legitimate interest (quality and security of the Service).
Security and abuse prevention
rate limiting, bot protection (Cloudflare Turnstile, a component loaded with no visible interaction on the organisers’ sign-in and sign-up forms, see the cookie policy) and the prevention of abusive use; legal basis: legitimate interest.
Account management and legal obligations
account creation, invoicing where applicable; legal basis: contract / legal obligation.

4. Automated processing (AI)

Thumbnail generation and image-quality estimation are technical processes performed locally, without artificial intelligence, and always active. By contrast, analysis by artificial intelligence (detection of explicit or violent content for moderation, addition of scene tags and transcription of voice messages) takes place only when the Organiser enables it for their event; when it is disabled, no content (image or sound) is sent to an analysis model. This processing is not intended to identify individuals, and no facial recognition is used. No decision producing legal effects is taken solely on the basis of automated processing: automatic moderation may hide content provisionally, but any permanent measure requires human review (article 22 of the GDPR). Should a facial-recognition feature ever be introduced in the future, it would be the subject of specific information and would require your explicit consent.

5. Recipients and processors

Your content (photos, videos, written and voice messages) is hosted in the European Union. Data is neither sold nor used for advertising purposes. It is processed on the Publisher’s behalf by technical processors:

  • Vercel Inc.: Hosting of the application (FR region).
  • Cloudflare, Inc.: Media storage (EU region).
  • Supabase Pte. Ltd.: Database and authentication (FR region).
  • Scaleway SAS: AI enrichment when the organiser enables it: photo analysis (moderation and automatic tagging) and transcription of voice messages; processing carried out in France (European Union), with no retention of content by the provider.
  • Cloudflare, Inc. (Turnstile): Bot protection (Turnstile) on the organisers’ sign-in and sign-up forms, when active: analysis of technical browser signals (including the IP address) to distinguish legitimate visitors from automated programs, with no advertising purpose and no cross-site tracking.
  • Resend, Inc.: Sending of transactional emails (authentication emails and archive download reminders); transfers outside the EU governed by a data processing agreement (DPA) including the standard contractual clauses.
  • Stripe Payments Europe, Ltd.: Payment processing when a paid plan is purchased: payment data (bank card) and billing data (name, address) are collected and stored directly by Stripe, which also processes them as a data controller for its own obligations (in particular fraud prevention); the Publisher never has access to the card number and keeps only transaction references.
  • Indy (Georges Tech SAS): Invoicing and accounting when a paid plan is purchased: issuing and legally archiving invoices (platform accredited for electronic invoicing).

As some of these providers are established outside the European Union, any transfers are governed by appropriate safeguards within the meaning of Chapter V of the GDPR (in particular the European Commission’s standard contractual clauses).

6. Retention period

An event’s content is kept for as long as the event is active: the event is archived two (2) months after activation (or earlier if the Organiser archives it manually), and its content is then permanently deleted ten (10) months after archiving. Some plans may provide for different periods; the periods and deadlines applicable to an event are shown to the Organiser in their dashboard. These periods are determined in light of the purpose of preserving memories and the principle of data minimisation. Reminders invite the Organiser to download their archive before the deadline. Account data is kept for as long as the account is active.

Billing data (invoices and transaction references relating to purchases) is kept for ten (10) years in accordance with article L123-22 of the Code de commerce (the French commercial code), including after the account is deleted: this retention meets a legal obligation (article 17(3)(b) of the GDPR) and does not prevent the erasure of all other data. Payment data itself is kept by the payment provider in accordance with its own policy.

When an item of content is deleted individually, a copy may remain for up to seven (7) days within a downloadable archive that has already been generated, before that archive is automatically purged.

Operational logs (technical monitoring of the Service: aggregated counters, system events and anonymised error reasons, with no content and no guest data) are kept for a maximum of 30 days for routine events and 90 days for errors; logs attached to an event are deleted at the same time as the event.

7. Persons appearing in content

Where a person appears in content uploaded by a Guest, their data is collected indirectly (article 14 of the GDPR); its source is the Organiser and their Guests. In practice, these persons are informed by the Organiser, who undertakes to obtain their consent (see the terms of use and sale). As individually informing each person appearing in content proves impossible or would involve disproportionate effort (article 14(5)(b) of the GDPR), that information is provided by this policy, which is made publicly accessible, and is relayed by the Organiser. Anyone may request the deletion of content in which they appear by writing to contact@sipix.eu or via the Report content page.

8. Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time where processing is based on consent. Where processing is based on legitimate interest, you may object to it at any time on grounds relating to your particular situation (article 21 of the GDPR). To exercise these rights, write to contact@sipix.eu. You may also lodge a complaint with a supervisory authority: in France, the CNIL (www.cnil.fr); if you reside in another Member State of the European Union, the supervisory authority of your country of residence or place of work (article 77 of the GDPR).

9. Security and access to content

Access to an event’s gallery relies on links containing random, unguessable identifiers specific to each event: only those who have the link can view the content. The Organiser may also enable an access code, which protects the upload and gallery-viewing features; however, the direct address of a file that has already been distributed (for example the URL of a photo that has been copied or reshared) remains accessible to anyone who holds it. Sharing links should therefore be given only to the people invited to the event.

10. Cookies

The use of cookies is described in the cookie policy.

11. Contact

For any question about your data: contact@sipix.eu.