Privacy Policy
Last updated: July 2025
Who we are
Morfoto is operated by Elera Yazılım ve Bilgi Teknolojileri Ltd. Şti., based in Istanbul, Turkey. We are the data controller for personal data processed through morfoto.app. For questions about this policy, contact us at support@morfoto.com.
What data we collect
- Account and contact data: name, email address, phone number, company name (for photographers and customers).
- Payment and billing data: billing name and address, tax number (optional). Card details are processed exclusively by our payment provider (iyzico) and are never stored on our servers.
- Biometric data (opt-in only): where face recognition is enabled at an event, a mathematical vector derived from your selfie is used solely to match photos. We never store the raw facial image as a biometric template. This data is deleted automatically when the event ends.
- Photo content: event photos uploaded by photographers and digital photos you purchase.
- Usage and technical data: IP address, browser type, session data, interaction data collected via analytics tools.
Why we process your data
- To deliver the service: photo matching, download access, order fulfilment.
- To process payments and issue invoices.
- To provide customer support.
- To send optional notifications about new photos (only if you opt in).
- To maintain platform security and prevent abuse.
- To comply with legal obligations.
Legal basis (GDPR)
- Contract performance — processing necessary to fulfil your purchase or provide the service (Art. 6(1)(b)).
- Legal obligation — tax and accounting records (Art. 6(1)(c)).
- Legitimate interests — platform security and fraud prevention (Art. 6(1)(f)).
- Consent — biometric face data and optional marketing notifications (Art. 6(1)(a) / Art. 9(2)(a)).
Who we share your data with
- iyzico Payment Services Inc. — to process card payments securely.
- Print and shipping partners — order fulfilment for physical print products.
- Event photographers — order details limited to their own event.
- Infrastructure providers — cloud hosting and storage (data processed under data processing agreements).
- Analytics providers — Microsoft Clarity (session recordings, heatmaps). See our Cookie Policy.
- Authorities — when required by law or court order.
We do not sell your personal data to third parties.
International transfers
Our servers are located in the EU/EEA or countries with an adequacy decision. Where data is transferred outside these regions (e.g. to analytics providers), we rely on Standard Contractual Clauses or equivalent safeguards in accordance with GDPR Chapter V.
Retention
- Payment and invoice records: 10 years (statutory accounting requirement).
- Biometric data: deleted automatically within 30 days after the event closes.
- Event photos: retained for the period set by the photographer; deleted on request.
- Support correspondence: 2 years after the last interaction.
Your rights
Under GDPR (and equivalent laws), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten") where legally permitted.
- Restrict or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time (for consent-based processing such as biometrics).
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at support@morfoto.com.
Cookies
We use cookies and similar technologies. See our Cookie Policy for details.
Changes to this policy
We may update this policy from time to time. Material changes will be notified via the platform or email. The "Last updated" date at the top of this page reflects the most recent revision.