How is face data handled when guests find photos by selfie?
Answer·Last updated: ·By Ali Mert Güleç
Short answer
A face signature is biometric, special-category personal data under Türkiye's KVKK and the EU's GDPR, and generally needs explicit consent. In Photonza face matching runs only for guests who tick a separate consent box; signatures of guests who don't consent are computed on the fly and discarded, never stored. All photos and face data are deleted 30 days after the event ends.
Three layers in Photonza
- The guest's explicit consent. Face matching is optional and switched on with a separate consent. Guests who don't consent can still upload and browse the gallery.
- The organiser's notice commitment. Whoever creates the event commits to informing guests about face recognition.
- Only the data needed. A non-consenting guest's face signature is discarded without being written to disk unless it resembles a consenting guest.
What is stored and what isn't
| Data | Status |
|---|---|
| Selfie image | Never uploaded; the signature is computed on the phone |
| Consenting guest's selfie signature | Stored; the guest can delete it any time |
| Non-consenting guests' face signatures | Not stored (in a 1,000-photo test, 97.9% of face signatures were never written to disk) |
| Photos and face data | Deleted automatically 30 days after the event ends |
The models are open source (YuNet and SFace) and run on Photonza's own servers; faces are not sent to a third-party face recognition API.
Documents: biometric notice, privacy policy, data retention.
Frequently asked questions
Do guests have to use face recognition?
No. Face matching is optional; guests who don't consent can still upload and browse.
What happens to the face of someone in a photo who never consented?
The face position and a small face crop stay with the photo (to compare again if that person consents later); they aren't linked to any name and are deleted with the event. The face signature is not stored.