Polityka prywatności
Last updated: September 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation
(GDPR) is:
giant Computer Systems, Marc Breuer
Am Altengraben 23
90768 Fürth
Germany
Phone: +49 (0) 911 976912-0
Email: [email protected]
2. General information
The protection of your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, German Federal Data Protection Act, TDDDG). In this privacy policy we inform you about the most important aspects of data processing within our platform. Personal data is any data with which you can be personally identified.
3. Your rights
You generally have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent (Art. 7 (3) GDPR)
If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the competent supervisory authority (Art. 77 GDPR).
4. Hosting, delivery and media storage
Our platform is operated at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in a data centre located in Germany. The personal data collected on this website is stored on Hetzner's servers. We have concluded a data processing agreement with Hetzner in accordance with Art. 28 GDPR. The legal basis is our legitimate interest in the secure and efficient provision of our offer (Art. 6 (1) (f) GDPR).
This website is delivered through the content delivery network and security services of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany. Every request therefore passes through a Cloudflare server first. In doing so, Cloudflare processes your IP address, technical details about your browser and device and the address requested, in order to establish the connection, fend off attacks and deliver content faster. Cloudflare also tells us which country a request comes from; we use that information solely to suggest prices in a suitable currency. Your behaviour is not analysed, and Cloudflare sets no advertising or tracking cookies on our behalf. We have concluded a data processing agreement with Cloudflare in accordance with Art. 28 GDPR, including the EU standard contractual clauses. The legal basis is our legitimate interest in operating this website securely and quickly (Art. 6 (1) (f) GDPR).
The photos and videos uploaded by guests are additionally stored in the “R2” object storage of Cloudflare Germany GmbH, Rosental 7, 80331 Munich, Germany, and delivered via its content delivery network under our own domain cdn.momentum.photo. We exclusively use the EU storage location (“EU jurisdiction”), so the files are held within the European Union. For delivery they are temporarily cached on the content delivery network server answering the respective request. We have concluded a data processing agreement with Cloudflare in accordance with Art. 28 GDPR, including the EU standard contractual clauses. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract) and our legitimate interest in a fast and reliable presentation of the albums (Art. 6 (1) (f) GDPR).
5. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://".
6. Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and the IP address. This data is not merged with other data sources. The collection is carried out on the basis of Art. 6 (1) (f) GDPR for the technically error-free presentation and optimisation of the website and to ensure system security. Server log files are deleted automatically once they are more than 90 days old. They are kept for longer only where this is necessary to investigate a specific security incident; in that case the data concerned is retained until the investigation has been concluded.
7. Cookies
We use only technically necessary cookies that are required for the operation of the platform (e.g. session cookie, CSRF protection, storage of the chosen language, and a cookie to recognise registered guests within an event). These cookies contain no advertising or tracking functions. The legal basis is § 25 (2) TDDDG and Art. 6 (1) (f) GDPR.
8. Registration and customer account
When you create an account as an organiser, we process the data you provide (name, email address, password in encrypted form) to provide the account and to perform the contractual relationship. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). The data is deleted as soon as the account is closed and no statutory retention obligations conflict with this. You can delete your account yourself at any time in your profile; that also irrevocably deletes your events and all media stored in them.
9. Uploading photos and videos
The core of our service is collecting photos and videos. Guests can upload media via an event link, optionally providing a name. The uploaded content may contain personal data (e.g. depicted persons, metadata). The processing is carried out to run the respective event on the basis of Art. 6 (1) (b) and (f) GDPR and, where necessary, on the basis of your consent (Art. 6 (1) (a) GDPR). Please only upload content for which you hold the necessary rights and, where persons are recognisably depicted, for which their consent has been obtained. The album is accessible only via the unguessable event link; there is no public overview and no indexing by search engines. The individual files sit at randomly generated, unguessable addresses and no directory of the content is served. From the image versions shown in the album we remove all embedded additional information, in particular the place and time a picture was taken. We keep the unchanged original file with that information for the host; it is reachable exclusively via the event link, never at a public address. If the host hides a photo, the delivered image files are deleted and removed from the cache.
10. Photo tasks, likes and comments
Within an event, guests can give likes, write comments and complete photo tasks. The resulting data (e.g. name, comment text, timestamp) is processed to provide these functions (Art. 6 (1) (b) and (f) GDPR).
11. Payment processing
For paid events we offer payment through our payment service provider Stripe and by bank transfer.
When you pay through Stripe, the payment data is collected by Stripe directly: the input fields for card and account details are provided by Stripe and embedded into our payment page, for which a script is loaded from js.stripe.com when that page is opened. We neither process nor store complete card or account details ourselves. We transmit to Stripe the amount due, the currency, the payment reference (number and name of the event) and your country, so that Stripe can offer the payment methods available in your country. Which methods are offered, for example card, PayPal, Klarna, SEPA direct debit, Apple Pay or Google Pay, is determined by Stripe on the basis of that information and our settings. Stripe also processes technical data such as IP address and device information for fraud prevention. The provider is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland; transfers to Stripe, Inc. in the USA take place on the basis of the EU standard contractual clauses. Stripe's privacy policy (stripe.com/privacy) applies in addition. The legal basis is Art. 6 (1) (b) GDPR and our legitimate interest in preventing payment defaults and abuse (Art. 6 (1) (f) GDPR).
When paying by bank transfer, we process the information required to allocate the payment. The legal basis is Art. 6 (1) (b) GDPR. Tax and commercial retention periods remain unaffected.
12. Email notifications
If you provide your email address when joining an album, we send you notifications about likes and comments on your own uploads. As an organiser you also receive emails about the status of your event (e.g. expiry reminders). You can unsubscribe from these notifications at any time via the link at the end of every such email. The legal basis is Art. 6 (1) (b) and (f) GDPR.
13. Review invitations via Trustpilot
About a week after your event we ask you, as the organiser, once for a review of our service on the review platform Trustpilot. For this we pass your name, your email address, a reference number of your event and your language to Trustpilot. Trustpilot then sends you an invitation to review on our behalf; only this way is your review marked as verified. Whether you write a review is entirely up to you. If you do, Trustpilot's terms and privacy policy apply (legal.trustpilot.com).
The provider is Trustpilot A/S, Pilestræde 58, 5th floor, 1112 Copenhagen K, Denmark. The legal basis is our legitimate interest in honest feedback on our service and in verifiable customer reviews (Art. 6 (1) (f) GDPR). You can object to the use of your email address for review requests at any time, for example by briefly replying to one of our emails or via the unsubscribe link in Trustpilot's invitation. This incurs no costs other than the transmission costs at the basic rates.
14. Web fonts
The fonts used on this website are served from our own server. No third-party font service such as Google Fonts is called up in the process, and your IP address is not transmitted to anyone for that purpose.
15. Storage period and deletion
We store personal data only for as long as is necessary for the respective purposes. Event media is kept available for the duration of the event (6, 12 or 24 months depending on the plan booked). After the runtime expires, we provide a final ZIP archive for download; the media and associated data are subsequently deleted after a transition period, provided that no statutory retention obligations conflict with this.
16. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or in order to implement changes to our services. The new privacy policy will then apply to your next visit.