Privacy

Privacy Policy

How Eventik collects, uses, and protects your personal and biometric data.

Last updated 24 July 2026
Contents

Interpretation and Definitions

Interpretation

Words with initial capital letters have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

Definitions

For the purposes of this Privacy Policy:

  • Account: A unique account created for You to access our Service or parts of our Service.
  • Company (referred to as "the Company", "We", "Us", or "Our"): Aillegent Private Limited, doing business as Eventik, 602 Synergy Space, D-Mart Road, Kudasan, 382421, Gujarat, India.
  • Cookies: Small files placed on Your device by a website, containing details of Your browsing activity among their many uses.
  • Device: Any device that can access the Service such as a computer, cell phone, or digital tablet.
  • Personal Data: Any information that relates to an identified or identifiable individual.
  • Service: The Website (https://eventik.ai), our mobile applications, and other services operated by the Company.
  • Service Provider / Subprocessor: Any third party that processes data on behalf of the Company to facilitate or provide the Service.
  • Usage Data: Data collected automatically, either generated by the use of the Service or from the Service infrastructure itself.
  • You: The individual accessing or using the Service, or the entity on whose behalf such individual is accessing or using the Service.

User vs. Guest User Processing Roles

To understand how we handle data, it is important to distinguish between the two types of users on our platform:

  • User (Studio Admin/Photographer): Anyone who creates an account to create event links, upload photographs, and manage client projects. In this context, the User acts as the Data Controller for the uploaded event media.
  • Guest User (Event Guest/Attendee): Anyone who accesses the Service through an event link or QR code created by the User to retrieve their photographs.

Processing Role: We act as a Data Processor in respect of Guest Users who retrieve photos via event links. This processing takes place strictly on the instruction of, and on behalf of, the User (the photographer/studio). We do not carry out any independent processing of the event photographs — we only provide the technology platform through which the matching service is delivered.

Information We Collect

We collect personal information that you voluntarily provide when you register, express interest in our products, or interact with our services.

Account User Data (Photographer/Studio)

Contact and billing information required to maintain your studio account: name, email address, contact phone number, company/studio name, physical address, and Tax/GST number.

Guest User Data (Attendee)

Details required to match and deliver your photos: name, email address, mobile number, and the selfie image you choose to upload for face recognition.

Automatically Collected Information

Like most cloud platforms, we automatically collect certain technical log data: IP addresses, browser type and version, device identifiers, operating system, and date/time stamps, together with basic usage data.

Biometric & Face Recognition Data

Eventik uses face recognition technology to help guests find their own photos from an event. This involves processing biometric data, which we handle under strict controls and only with your consent:

  • How it works: When a Guest User voluntarily uploads a selfie, our system creates a secure facial template — a set of numerical features derived from the image. This template is not a photograph and is used only to identify you within the photos of the specific event you are accessing.
  • Purpose limitation: Your selfie and facial template are used solely to surface the photographs in which you appear. They are never used for advertising, profiling, surveillance, or any purpose unrelated to delivering your event photos.
  • Protection: Your selfie and facial template are stored securely on our own infrastructure with encryption at rest, and access is restricted on a need-to-know basis. They are never sold, rented, or shared with advertisers, data brokers, or third-party AI services.
Your control & deletion: You can replace your selfie at any time from the Profile screen, which overwrites the previous template. If you delete your account or withdraw consent, your selfie and facial template are removed from our active systems within 7 days and from encrypted backups within 30 days.

Cookies & Tracking Technologies

We use cookies and similar technologies to operate and secure the Service, and we keep these to the minimum needed to run the platform.

  • Strictly necessary cookies: Required to sign you in and keep your session secure (for example, authentication and session tokens). The Service cannot function without these.
  • Functional cookies:Remember your preferences and choices so you don't have to re-enter them.
  • Analytics (where enabled): We may use privacy-respecting analytics to understand aggregate usage and improve the Service. Such data is used in aggregate and not to identify you individually.

Most browsers let you refuse or delete cookies through their settings. Please note that blocking strictly necessary cookies may prevent you from logging in or using core features.

Purpose and Legal Basis of Processing

We use and process your personal data for the following purposes, each based on a valid legal foundation:

  • Consent: For Guest Users, we process your selfie and facial template solely on the basis of your explicit consent, given when you request to find your photos. You may withdraw consent at any time.
  • Contract performance: For Studio Admins, we process your account details, subscriptions, and billing logs to fulfil our contractual terms, manage payments, and deliver the SaaS features.
  • Transactional communication: To deliver user-triggered messages required to operate the Service, such as sign-up verification OTPs, team invitations, and subscription confirmations.
  • Security and fraud prevention: To maintain the safety, integrity, and operational capacity of our systems, prevent unauthorized scraping of photos, and enforce our acceptable-use terms.

Marketing: We do not send unsolicited marketing emails. If we ever send optional product updates or offers, we will rely on your consent or our legitimate interest, and you can opt out at any time via the unsubscribe link in the email or by contacting us.

Third-Party Subprocessors

We share limited personal data only with essential, vetted infrastructure partners under data processing agreements. We do not sell or rent data to advertisers.

SubprocessorPurposeData sharedPrivacy policy
Amazon Web Services (AWS)Cloud hosting, databases, and transactional emailAccount data, usage logs, email addressesAWS Privacy
CloudflareImage storage and content delivery (CDN)Uploaded event images and guest selfiesCloudflare Privacy
RazorpayPayment processing and GST invoicingName, email, phone, billing details, GSTIN (card/bank details are entered directly with Razorpay)Razorpay Privacy

We may add or change subprocessors as the Service evolves; where we do, we will keep this list up to date and ensure equivalent contractual protections are in place.

How We Share and Disclose Information

Beyond the subprocessors above, we disclose personal information only in these limited situations:

  • Legal compliance: When required by applicable law, regulation, legal process, or a valid request from a public authority.
  • Protection of rights and safety: Where reasonably necessary to enforce our terms, prevent fraud or abuse, or protect the rights, property, or safety of Eventik, our users, or the public.
  • Business transfers: In connection with a merger, acquisition, financing, or sale of assets, your information may be transferred to the successor entity, which will remain bound by this Policy or a policy at least as protective. We will notify you of any such change in control.

We do not sell your personal data, and we do not share it with advertisers or data brokers.

International Data Transfers

Eventik is operated from India, and our infrastructure is primarily located in India. If you access the Service from outside India, your information may be transferred to, stored, and processed in India and in other countries where we or our subprocessors operate — jurisdictions whose data-protection laws may differ from those where you live.

Where such transfers occur, we take reasonable steps to ensure your data remains protected in line with this Policy and applicable law. By using the Service, you consent to this transfer to the extent permitted by law.

Data Retention and Deletion

We retain your personal data only for as long as is necessary to provide the services or comply with legal requirements:

  • Active accounts: Account profiles and active project configurations are retained for the lifetime of your subscription.
  • Deleted accounts: When you initiate account deletion, your profile records, uploaded selfies, and facial templates are queued for removal and permanently deleted from active systems within 7 days (and within 30 days from backups).
  • Deleted events: Photographs and metadata deleted by a Studio Admin go to a 7-day trash window, after which they are permanently purged from our secure storage.
  • Email suppression list: To protect our sending reputation, we permanently retain bounced or complained email addresses in a suppression list to block future outbound mail to those addresses.

Data Security

We take the security of your data seriously and use organizational and technical safeguards appropriate to the sensitivity of the data, including encryption in transit and at rest, access controls, and internal access restricted on a need-to-know basis.

However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data using commercially acceptable means, we cannot guarantee its absolute security. You are responsible for keeping your account credentials confidential.

Your Rights (DPDPA 2023 & GDPR)

Depending on your jurisdiction, you are entitled to several data protection rights:

Digital Personal Data Protection Act (DPDPA) – India

  • Right to Access: Request a summary of the personal data we process about you and the list of subprocessors.
  • Right to Correction & Erasure: Correct inaccurate data or request erasure of your data when it is no longer required.
  • Right of Grievance Redressal: Have readily available means of grievance redressal for any act or omission by us regarding our obligations.
  • Right to Nominate: Nominate an individual to exercise your rights in the event of death or incapacity.

GDPR – European Union & United Kingdom

You have the right to access, rectify, or request erasure of your data, restrict or object to its processing, withdraw consent, and request data portability.

To exercise any of these rights, contact us at info@eventik.ai. We will respond to your request within the time required by applicable law (and in any case within 30 days).

Children's Privacy

Our services do not target children. In line with the Digital Personal Data Protection Act, 2023 (DPDPA), we treat anyone under 18 years of age as a child and do not knowingly allow a child to create an account or upload a selfie without the verifiable consent of a parent or legal guardian. If you believe a child has created an account or provided personal information on our platform without such consent, contact us immediately at info@eventik.ai and we will promptly remove the account and delete the associated data, including any facial template.

Children may also appear in event photos uploaded by a photographer or event organizer (for example, at a wedding or a birthday). The photographer or organizer is responsible for having the appropriate permission to photograph and share those images; we process them only to provide the gallery and face-matching service on their behalf. A parent or guardian may ask us — or the event organizer — to remove a child's photos and any associated face data at any time by writing to info@eventik.ai (see Section 15 for our Grievance Officer contact).

We do not use children's data for behavioural tracking, targeted advertising, or any purpose other than providing the Service.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email or through a notice in the Service before the change takes effect.

We encourage you to review this Policy periodically. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

Grievance Officer and Contact Information

If you have questions, complaints, or requests regarding this Privacy Policy or your personal data, you may contact our Grievance Officer:

Aillegent Private Limited (Eventik)
602 Synergy Space, D-Mart Road, Kudasan, 382421, Gujarat, India