Jogi dokumentumok
Privacy Policy
Information under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) for Pixelka (pixelka.sk), Pozýva (pozyva.sk) and the Pixelka Android app. This is a translation; in case of doubt the Slovak version prevails.
- Controller and contact
- Who is responsible for what: the host and us
- What data we process, why and on what basis
- Where data is stored and who has access
- How long we keep data
- Your rights
- Cookies and local storage
- Security
- Children
- Changes to this policy
1. Controller and contact
| Controller | VitaCore s. r. o., Matúšova 8027/54, Bratislava – mestská časť Staré Mesto, 811 04, Slovakia, company ID 56 093 667, tax ID 2122201774, Commercial Register of the Municipal Court Bratislava III, Section: Sro, Insert No.: 176563/B |
|---|---|
| E-mail for data questions | info@eventpixel.eu |
| Data protection officer | not appointed — the scope of processing does not require one; all requests are handled by the company’s managing director at the e-mail above |
| Supervisory authority | Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk |
This policy applies to the websites pixelka.sk (including language versions and galleries on subdomains), pozyva.sk, the e-mails and notifications we send, and the Pixelka app on Google Play (a wrapper around the same web service). The EventPixel event agency (eventpixel.eu) has its own policy.
2. Who is responsible for what: the host and us
For host data (who created the gallery, payment, communication with us) we are the controller.
For gallery content — photos, videos, voice messages, guest-book messages, RSVP replies and guest contacts — the host decides the purpose: they invited the guests, they decide who sees the content and what happens to it. If the host is a company, agency, school or other business, they are the controller of that data and we are their processor under Art. 28 GDPR on the basis of the Data Processing Agreement. If the host is a private individual (wedding, family celebration), this is a purely personal activity to which the GDPR does not apply (Art. 2(2)(c)); we are nevertheless equally responsible for secure storage and everything below about protecting content applies.
In both cases: we do not enter galleries, do not use content for our own purposes, do not sell it, do not display it outside the gallery and do not train any models on it.
3. What data we process, why and on what basis
Host
| Account and gallery | e-mail, name (if given), event name and date, gallery settings, manager link, sign-in times. Purpose: providing the service, sign-in, e-mails with links and end-of-period notices. Basis: performance of a contract (Art. 6(1)(b)). |
|---|---|
| Payment and invoice | chosen plan, amount, payment reference, for transfers the payer details from the bank statement, for cards the data Stripe returns to us (last 4 digits, payment status — we never see the card number), billing details, delivery address for printed cards. Purpose: fulfilling the order, accounting. Basis: contract and legal obligation (Accounting Act, Art. 6(1)(c)). |
| Communication | e-mails you send us and our replies. Purpose: support, complaints. Basis: contract and legitimate interest (Art. 6(1)(f)). |
| Mobile notifications | if you enable them: the technical identifier of your browser’s push subscription (endpoint and encryption keys). Purpose: notifying you of new photos and RSVP replies. Basis: consent (Art. 6(1)(a)) — switch off in your browser or in gallery management. |
| News | we e-mail hosts about new features at most a few times a year on the basis of legitimate interest (existing customer); unsubscribe via the link in every e-mail. |
Guest
| Uploaded photos, videos, voice messages | the files including what they capture (people’s likenesses) and metadata (upload time; we keep the original as uploaded, including EXIF metadata — displayed previews and thumbnails contain no metadata). Purpose: display in the host’s gallery. Basis: at corporate events the controller is the host (usually the guest’s consent, which the host can require before upload, or the host’s legitimate interest); at private events the host’s personal activity; on our side, performance of the contract with the host. |
|---|---|
| Guest book, song requests, reactions | the message text and the name you choose (can be a nickname). Basis: as above. |
| RSVP and invitation | name, number of people, meal choice, note, e-mail or phone if the host collects them or sent the invitation to your contact; time the personal link was opened. Purpose: the host organising the event. Basis: the host is the controller. |
| Face search (optional) | if the host enables it and you use it: your selfie is sent to Amazon Rekognition (Frankfurt region), compared with faces in the gallery’s photos and immediately discarded — we do not store it. For photos in the gallery only numeric face vectors are stored, deleted together with the gallery. Basis: your consent expressed by using the feature (Art. 9(2)(a) — biometric data). |
| Consent before upload (corporate events) | if the host enables it: the consent text and time of acceptance are stored with each of your photos so the host can prove consent. |
| Gallery traffic | a random identifier in the gallery_visitor cookie (not linked to you) and an HMAC hash of it — the host sees only daily view and unique-visit counts, not IP addresses or identities. Basis: the host’s and our legitimate interest (service statistics). |
| Deleting your own photo | a cookie signing your uploads so you can delete your own photo within 24 hours from the same device. |
Every visitor
| Technical logs | IP address, time, requested address, browser type — in web-server logs and the application error log. Purpose: security, defence against attacks, troubleshooting. Basis: legitimate interest (Art. 6(1)(f)). Retention: short-term, normally up to 30 days; application error records until resolved plus 30 days. |
|---|---|
| Abuse protection | for voting, uploads and form submissions we count limits by IP address converted to an HMAC hash with a secret key so it cannot be reversed. |
| Cookies and local storage | see section 7 — no third-party advertising or analytics cookies. |
We do not use data for automated decision-making or profiling and do not sell it to anyone.
4. Where data is stored and who has access
Photos, videos and voice messages are stored on a server in Germany; the database (accounts, settings, texts, RSVP) in Slovakia. Data is not transferred outside the European Union, with the two exceptions below (Stripe, push).
Only people who need the data have access: the host and co-hosts (their own gallery’s content), guests with the link or password (the gallery wall to the extent the host allows) and we as the operator (technical server administration, support at your request). Galleries are not publicly searchable (noindex) and their addresses cannot be guessed.
Processors and recipients
| Websupport, s. r. o. (Slovakia) | web hosting, database, mail server, storage of encrypted backups |
|---|---|
| Contabo GmbH (Germany) | virtual server for photos, videos and voice messages |
| Amazon Web Services EMEA SARL (Luxembourg), region eu-central-1 Frankfurt | optional face search (Rekognition) only, if the host enables it |
| Stripe Payments Europe, Ltd. (Ireland) | card payments — you enter card details directly with Stripe; Stripe may process some data in the USA under standard contractual clauses and the EU-US Data Privacy Framework |
| Your browser’s push service provider (Google, Mozilla, Apple) | delivery of notifications; the message content is end-to-end encrypted, the provider sees only that a message arrived |
| Accountant and tax adviser | invoices to the extent required by the Accounting Act |
| Public authorities | only where required by law (e.g. court, police) — we inform the host of such requests where the law allows |
Processors are bound by contracts under Art. 28 GDPR. If we change a processor we update this list; business hosts are informed by e-mail under the DPA.
5. How long we keep data
- Gallery content: until the end of the plan’s retention period (12 or 24 months after the event) or until deleted by the host, whichever comes first; then permanently from the server and within 14 days from backups. The host is notified 30 and 7 days in advance.
- A photo deleted by the host or a guest: immediately from the gallery and server, within 14 days from backups.
- Host account: while it has at least one gallery; then up to 12 months after the last gallery is deleted (so you can come back), or sooner on request.
- Invoices and payment data: 10 years under the Accounting Act.
- Push subscriptions: until switched off or the gallery is deleted.
- Technical logs: normally up to 30 days; application error records until resolved plus 30 days.
- Support communication: 3 years after the matter is closed (limitation period).
6. Your rights
You have the right to access your data, to rectification, erasure, restriction of processing, data portability (in a machine-readable format) and to object to processing based on legitimate interest. Consent (push, face search) can be withdrawn at any time without affecting the lawfulness of prior processing.
Write to info@eventpixel.eu from the e-mail you used in the service, or give the gallery address and the photo concerned. We reply within 30 days, usually within a few days. If the host is the controller of the content (corporate event), we pass the request on and help resolve it; a guest can also contact the host directly.
A guest can delete their own photo within 24 hours of upload directly in the gallery from the same device. Later through the host or through us.
If you believe we are infringing your rights, you can lodge a complaint with the supervisory authority (Office for Personal Data Protection of the Slovak Republic, contact in section 1). We would appreciate hearing from you first.
7. Cookies and local storage
We use only cookies and local storage that are necessary for the service to work. We use no third-party advertising, tracking or analytics tools (Google Analytics, Meta Pixel and the like), which is why we show no cookie banner — under Section 109 of Slovak Act No. 452/2021 Coll. on electronic communications, consent is not required for strictly necessary cookies.
gallery_lang | chosen language (6 months) |
|---|---|
gallery_owner_session | host sign-in (until sign-out, max. 30 days) |
gallery_unlock_* | that you entered the gallery password (30 days) |
gallery_visitor | random identifier for counting unique visits without identifying the person (12 months) |
gallery_voter, gallery_owner_* | so you do not vote twice (12 months) and can delete your own photo (30 days) |
| Browser local storage | upload in progress, chosen view, dismissal of the “add to home screen” prompt, offline copy of pages (service worker) — stays on your device, not sent to us |
You can delete cookies in your browser settings; the service keeps working, you will just need to sign in again.
8. Security
- encrypted transport (HTTPS/TLS) everywhere, including galleries on subdomains and outgoing e-mail (TLS, DKIM, SPF, DMARC)
- manager links and gallery passwords with long random tokens; passwords stored only as hashes
- keys to external services encrypted in the database; server access only via SSH keys; administration accessible only to the operator
- daily off-server backup encrypted with AES-256; the backup key is not stored with the storage provider
- independent availability monitoring, error logging without photo content
- gallery isolation: each has its own storage space, address and access tokens
In the event of a personal data breach posing a high risk to you, we notify you without undue delay and the supervisory authority within 72 hours (Art. 33 and 34 GDPR); business hosts within 48 hours under the DPA.
9. Children
The service is intended for hosts aged 18 and over. Guests may be younger — whether children take or appear in photos at an event is decided by the host and parents. We do not knowingly collect data of children under 16 for our own purposes; if we learn this has happened without parental consent, we delete the data.
10. Changes to this policy
We update this policy when we add a feature that changes processing, or when a processor or the law changes. The current version is always at this address with its effective date; hosts are informed of material changes by e-mail. Effective from 2026-09-13.



