· · ·
Legal · Your data

Privacy Policy

How Studionity collects, uses and protects your personal data — including the face data that lets each guest see only their own photos. Consent-based, purpose-limited and deletable, aligned with India's Digital Personal Data Protection Act, 2023.

Last updated: 19 July 2026

1.Who we are

Studionity ("Studionity", "we", "us") is a face-matched photo delivery and event operations platform for photographers, studios and event organizers in India. The service is operated by Ganatech Solutions.

This policy explains what personal data we handle and why, and the choices and rights you have. It applies to guests who join an event, and to the photographers and organizers who run events on Studionity. If you have any question about it, contact us at contact@studionity.com.

2.What Studionity does

Studionity runs events of every shape — from weddings and sangeets to corporate summits, conferences, expos, fairs and college fests. An organizer creates an event and uploads its photos. Guests join with a QR code or short code, verify a contact detail (mobile number or email) with a one-time password (OTP), and register a selfie. From the selfie we compute a mathematical face embedding and use it to match faces in the event's photos, so each guest sees only the photos they appear in — not the whole gallery.

Optionally, an organizer may enable FaceGate, a separate opt-in walk-in entry feature where a guest who consents can be recognised at the venue instead of showing a pass.

3.Data we collect

From guests

  • Contact detail — the mobile number or email you join with, and whether it was OTP-verified.
  • Selfie image and the face embedding derived from it (a 512-number vector; see section 4).
  • Consent records — that you agreed, and when, including a separate record if you opt in to FaceGate.
  • Your matches — which event photos you appear in, plus favourites and downloads you choose.
  • Basic device and usage data needed to run and secure the gallery session.

From photographers and organizers

  • Account details — name, email or mobile, and login credentials.
  • Event details and the photos you upload.
  • Billing details for paid plans (payments are handled by Razorpay when paid plans go live; see our Terms).

Automatically

  • Server logs and minimal cookies used only to keep your session signed in (a photographer auth cookie, and a per-event guest session cookie). We do not use advertising or cross-site tracking cookies.

4.Face data

Your selfie and its face embedding are biometric personal data and we treat them with extra care.

  • Purpose-limited. Embeddings are used only to match you to photos within the event you joined (and, if you opt in, for FaceGate entry at that event). They are not a general identity database.
  • Consent-based. We compute face data only after you register a selfie and consent. FaceGate requires its own separate opt-in.
  • Not sold, not for training. We do not sell your face data and do not use it to train general-purpose machine-learning models.
  • Revocable and deletable. You can withdraw consent and delete your selfie, embedding and matches at any time — see Data Deletion.
  • Own-photos-only by default. A guest sees only the photos their face appears in; full-gallery browsing is a permission the event host grants.

5.How we use data

  • Match photos to guests and deliver each guest their own gallery.
  • Verify contact details with an OTP and keep your session secure.
  • Issue passes and, where enabled, run FaceGate walk-in entry.
  • Send OTPs, passes and event updates by WhatsApp, email or SMS on the organizer's behalf (see section 6).
  • Operate the event — RSVPs, announcements and related organizer tools.
  • Keep the service secure, prevent abuse, and meet legal obligations.

6.Messaging you receive

To run an event, Studionity sends transactional messages — one-time passwords, entry passes and event updates — over WhatsApp, email and SMS. These are sent on the organizer's behalf and only to the contact you provided when joining. We do not use your contact for unrelated marketing. You can stop event updates by replying to opt out, or by asking us to remove your contact (see Data Deletion).

7.Consent & legal basis

We process your personal data on the basis of the consent you give when you join an event and register a selfie, and — for photographers and organizers — to provide the service you signed up for. Consent is recorded with a timestamp, and FaceGate consent is recorded separately. You may withdraw consent at any time; withdrawing it does not affect processing already carried out before the withdrawal.

8.Sharing & processors

We do not sell your personal data. We share it only with service providers who process it on our instructions to run Studionity:

  • Cloud hosting and storage — our servers, and object storage on Backblaze B2 (EU) for photos, selfies and derivatives.
  • Messaging providers — WhatsApp Business (Meta), an email provider and an SMS provider, to deliver OTPs, passes and updates.
  • Payments — Razorpay, for paid plans when they go live.

The organizer of your event also determines what is done with their guest list and photos and is a data controller for that event alongside us. We may disclose data if required by law.

9.Storage & security

Studionity is an India-focused service. Personal data is processed on our infrastructure, and photo and face objects are stored on Backblaze B2 in the EU. This means some data is processed outside India under appropriate contractual safeguards. We protect data in transit with encryption, limit access on a need-to-know basis, and design deletion to be real deletion of the stored objects and their derivatives — not just database rows.

10.Retention

Retention is tied to the event lifecycle. By default, guest selfies and face embeddings auto-delete 90 days after the event; organizers can set a shorter window, and guests can delete instantly at any time (see Data Deletion). When an organizer deletes an event, or when you ask us to delete your data, we delete the associated selfie, face embedding and contact record — within 30 days. Limited records we are required to keep by law (for example, billing records) are retained only as long as the law requires.

11.Your rights

Under the DPDP Act, 2023 you can:

  • Access the personal data we hold about you.
  • Correct data that is wrong or out of date.
  • Delete your data and withdraw consent, including your selfie and face embedding.
  • Raise a grievance and have it addressed.

The quickest way to exercise these is from your gallery profile screen, or by emailing us. Step-by-step instructions are on the Data Deletion page.

12.Children's data

Studionity is used at family celebrations where children may appear in photos or attend. We do not knowingly let a child register on their own. A child's selfie or FaceGate entry must be set up with the consent of a parent or guardian. If you believe a child's data has been added without guardian consent, contact us and we will remove it.

13.Changes to this policy

We may update this policy as the service grows. When we make a material change we will update the "last updated" date above and, where appropriate, notify organizers. Continued use after an update means you accept the revised policy.

14.Contact & grievance

For any privacy question, or to raise a grievance or exercise your rights, contact us:

Entity
Ganatech Solutions
Email
contact@studionity.com
WhatsApp
WhatsApp