Home › Photo booths and GDPR

For operators who work with companies

Photo booth and GDPR: what you must be able to prove

A photo and the e-mail entered to receive it are personal data. The one responsible is you, the booth operator. Here is what that means, and what the software does for you.

Practical information — not legal advice

Roles

Who is responsible for what

The first question your corporate client's DPO will ask.

You are the controller: you decide why photos are taken, how long they are kept and who gets them.

The software publisher is a processor (GDPR Article 28): it handles data on your instructions, to provide the service, and nothing else. Details in the privacy policy.

In practice

A corporate client's five questions

The ones in every tender, and what you can answer.

1. What data do you collect?

The photos taken at the guest's request, and — only if they enter it themselves — their e-mail or phone number, to send them their pictures. Nothing else is asked of the guest.

2. Where are the photos stored?

On the booth itself, under your control. If you turn on the online gallery, a compressed copy is hosted in Europe (Supabase, EU), reachable by a unique, unguessable link or QR code, over HTTPS/TLS. If you turn off the QR code and WhatsApp for an event, there is no online copy at all.

3. How long are they kept?

As long as you decide: the online gallery purges itself 7 to 90 days after the event, files and records included. You can also delete everything by hand at any time.

4. How does a guest exercise their rights?

They contact you, the booth operator. Photos can be deleted one by one from your account, so an erasure request takes seconds, during or after the event.

5. Is the data sold or reused?

No. Guests' contact details stay in an address book specific to the event, on the booth. Processors: Supabase (accounts and gallery, EU), Stripe (payments, Ireland) and Vercel (website and portal).

In the software

What the booth does for you

The safeguards are in the software, not in a binder of procedures.

  • A consent screen per event — shown on the booth before capture, adjustable to the context of the night.
  • Configurable retention — you decide, the software applies it.
  • Automatic purge — photos disappear on their own at the deadline, on the booth and in the online gallery.
  • Local storage by default — photos live on your machine first.
  • Hosting in Europe for everything that goes online, over HTTPS/TLS.
  • Unguessable gallery links — a random key per photo, no enumerable URL.
  • Self-service account deletion — from the portal or the Windows app, without writing to anyone.
  • Events with no hosting — turn off the QR code and WhatsApp: no photo leaves the machine.
To print

The notice to post next to the booth

Guests must be informed before capture. Here is a ready-to-use text.

“This booth takes your photo at your request. If you enter your e-mail or phone number, it is used only to send you your photo. If an online gallery is offered for this event, a link or QR code lets you view and download your photos; it is deleted automatically a few days after the event. Your data is not sold. For any request (access, deletion), contact the booth operator or support@boothapp.be.”

Print it on A5 or half-letter and place it next to the screen.

Questions

Frequently asked questions

Is a photo booth really subject to the GDPR?

Yes. A photo of an identifiable person is personal data, and so is the e-mail or phone number entered to receive it. As soon as a booth captures, keeps or sends them, the regulation applies.

Does every guest need to sign a consent form?

No. Visible information next to the booth and a consent screen before capture are enough: a guest who triggers the photo and enters their e-mail is acting voluntarily.

How long can photos be kept?

The GDPR sets no fixed number: it requires a period proportionate to the purpose, announced in advance and respected. Set it, announce it, and let the automatic purge handle it.

What if my client refuses any online hosting?

Turn off the QR code and WhatsApp in that event's settings: no photo is hosted online. Printing stays, and e-mail can go out through your own mail server, with the photo attached.

Do the photos leave Europe?

No. What goes online is hosted in Europe (Supabase, EU); payments go through Stripe (Ireland) and only concern your account, never guests' photos.

Can a guest have their photo deleted after the event?

Yes, during and after the event. They ask you, and deletion takes seconds from your account. Without a request, the photo disappears anyway at the retention date you set.

Practical information, not legal advice: your event's compliance remains your responsibility.

One more argument with corporate clients

14 days, every feature, 2 booths and the cloud included — no credit card.

Windows 10 / 11 · 64-bit · automatic updates built in