Your moments.
Your privacy.

This English version is a convenience translation. In case of discrepancies, the German version prevails.

1. Controller and contact

The controller within the meaning of the GDPR is Just Viral GmbH & Co. KG, Reinholdstraße 5, 21073 Hamburg, Germany. Contact: [email protected]. Full details are in the legal notice. We are not required to appoint a data protection officer under Section 38 BDSG; please send enquiries to the address above.

Sammelmomente is made for private celebrations. The host is responsible for who is photographed and for sharing the event photos; we provide the technology and process the photos only in order to make them available within the event. For processing inside an event the host is therefore your contact as well.

2. What is processed

For hosts: email address, account identifier, event settings, payment references and the version and time of the terms of use accepted. For guests: a random event session, an optional display name, photos, the times a photo was taken and uploaded, and the version and time of consent. For anyone replying to an invitation: name, acceptance or refusal and number of people – visible only to the hosts and deleted together with the event. Payments are handled by Digistore24 as the seller; we only receive the order number, package and amount – no card or bank details.

3. Purposes and legal bases

Accounts and booked packages serve the performance of the contract (Art. 6(1)(b) GDPR). Taking part in the camera is voluntary and based on your consent (Art. 6(1)(a)). Security and capacity measures protect against misuse and keep the service running (Art. 6(1)(f); legitimate interest in a working, non-overloaded service). Invoice and order records are kept where commercial and tax law require it (Art. 6(1)(c)). Hosts must obtain the necessary rights of the people shown; for children, the consent of those with parental responsibility.

4. Private storage and recipients

Photos are kept in private storage on our own server. Only the host and – where enabled – guests with event access can view them. Temporary image links are valid for two minutes at most. Anyone holding the event link can join the event, so only share it within the intended circle. Downloaded copies may continue to exist outside our system.

The application, database, sign-in and photos run on our own server rented from netcup GmbH (Karlsruhe, Germany) in its Nuremberg data centre. We operate the database and storage services there ourselves, so there is no further recipient for these. The individual service providers are:

Cloudflare – delivery and protection

Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA sits in front of the site as a content delivery network and as protection against overload and attacks. Cloudflare processes the IP address, the requested path, the time and browser and device identifiers of every request; the connection is decrypted and re-encrypted there. Cloudflare may set a technically necessary cookie to tell humans and automated access apart. The legal basis is our legitimate interest in a reachable service protected against attacks (Art. 6(1)(f) GDPR).

Resend – sign-in links and notifications

Emails are sent by Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). The email address, the content of the message and delivery logs are stored on servers in the USA; choosing a sending region does not change this. Without it there would be no sign-in link – the processing is necessary to perform the contract (Art. 6(1)(b) GDPR).

Signing in with Google

On the sign-in page you may optionally sign in with a Google account. If you choose that route you are redirected to Google, where Google’s privacy notices apply. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which relies on Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google learns that you are signing in to Sammelmomente and passes us your email address, your Google identifier and the confirmation that the address is verified. We receive no password and no access to your Google account. The legal basis is your consent to this sign-in route (Art. 6(1)(a) GDPR), which you can avoid for the future by choosing another route. You can always sign in with an email link instead; Google is then not involved.

Digistore24 – sale of paid packages

Paid packages are sold by Digistore24 GmbH, St.-Godehard-Straße 32, 31139 Hildesheim, Germany, as an independent controller and as your contractual partner for the purchase (reseller). Its privacy policy applies to the payment. We only receive the order number, package and amount in order to unlock the event.

Data processing agreements under Art. 28 GDPR are in place with netcup, Cloudflare and Resend. Transfers to the USA are covered by the EU-US Data Privacy Framework, to which Cloudflare, Resend and Google LLC have self-certified, and additionally by the EU standard contractual clauses. We do not sell data and do not pass it on for advertising.

5. Cookies and local photo storage

Technically necessary cookies secure sign-in, the guest session and the language choice; they do not require consent (Section 25(2) no. 2 TDDDG). We set no cookies for advertising, tracking or third-party analytics – which is why this site has no cookie banner. Uploads that have not been confirmed sit in local browser storage (IndexedDB) and are removed once the upload is confirmed. Until then, do not clear your browser data. You can download pending images to your device. Clearing browser data loses photos still waiting locally. Operating systems may remove local storage when space runs short.

6. Retention and deletion

Events and photos are available for 7 days after the event on free events and for 90 days on paid ones. Access is blocked from that point; technical deletion happens with the next daily clean-up run. Hosts can delete photos, events and their entire account themselves at any time. Guests can delete their own photos in the gallery at any time and thereby withdraw their consent. Invoices are retained by Digistore24 for the statutory periods; on our side a paid package leaves only an order record, which we keep until the commercial and tax retention periods expire. Photos are not part of database backups, so a deleted photo is gone immediately.

7. Measurement without photo content

We count selected product actions purely as daily totals. No names, email addresses, event identifiers or photo content go into those counters. We likewise count page views, visitors, referrers and device type as daily totals – without cookies and without recognising anyone beyond the day: the identifier derived from IP address and browser signature, encrypted with the date, is deleted after two days at the latest. “Do Not Track” is respected. To limit abuse we use short-lived, cryptographically derived IP identifiers. Our web server additionally logs requests with time, status code and browser signature for troubleshooting and abuse prevention; event links are redacted, and the logs rotate and are overwritten after a short time.

8. Your rights

You may request access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20), and you may withdraw consent at any time with effect for the future (Art. 7(3)). You may object to processing based on our legitimate interest on grounds relating to your particular situation (Art. 21). Contact the operator or the host. A withdrawal does not affect the lawfulness of processing carried out beforehand.

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.

Providing your data is neither required by law nor by contract. Without an email address, however, we cannot create an account for you, and without consent you cannot take part in the event camera. There is no automated decision-making or profiling within the meaning of Art. 22 GDPR. No face recognition, no AI training on photos, no advertising in private galleries.

Last updated: September 2026.