Legal
LensDeliver Privacy Policy
Effective date: 2026-06-13
Data controller: Szymon Gruszczyński, NIP 5361958833, REGON 520718806, address: woj. ŁÓDZKIE, pow. rawski, gm. Sadkowice, miejsc. Kaleń, nr 89, lok. 3, 96-206, Poland.
Privacy contact: privacy@lens-deliver.com
1. Scope
This Privacy Policy explains how personal data is processed in connection with LensDeliver, including:
account users,
photographers and studios using the service,
end recipients of client galleries,
persons contacting LensDeliver,
technical and operational data needed to run the service.
2. Roles
For account, billing, security, support, and service administration data, LensDeliver acts as controller.
For customer-uploaded client data and gallery content, LensDeliver typically acts as processor on behalf of the customer using the service.
3. Categories of data
Depending on the use case, LensDeliver may process:
account data such as name, email address, login credentials, role, and settings,
organization and tenant data such as studio name, contact details, limits, and configuration,
gallery data such as titles, files, tags, descriptions, cover images, PINs, and publication settings,
client and recipient data such as name, email address, and gallery access activity,
technical and security data such as IP address, user agent, session identifiers, tokens, logs, webhook payloads, and event metadata,
billing and administrative data where needed to operate the service.
If a visitor accepts analytics cookies on the public landing page, LensDeliver also processes landing-page analytics data through Google Analytics 4.
4. Purposes of processing
LensDeliver processes personal data for purposes including:
account registration and management,
authentication and session handling,
hosting and delivery of galleries,
email and service communications,
diagnostics, security, abuse prevention, and operational logging,
landing-page analytics after consent,
billing, limits, and service administration,
legal compliance and dispute handling.
5. Legal bases
Depending on the context, LensDeliver relies on:
performance of a contract or steps prior to entering into a contract,
compliance with legal obligations,
legitimate interests, including security, fraud prevention, service administration, and operational continuity,
consent where required, including analytics cookies on the landing page.
6. Recipients and subprocessors
Data may be shared with service providers supporting hosting, storage, database, email delivery, authentication, analytics, and related technical operations.
This includes providers such as:
Cloudflare,
Fly.io,
Neon,
Resend,
Google,
and, where applicable, future monitoring or operational tooling.
A current operational subprocessor register is maintained separately.
7. International transfers
LensDeliver aims to keep the main application infrastructure, database, and storage in Europe where reasonably available and operationally justified.
Some supporting providers may nevertheless process data outside the EEA.
In practice, this currently concerns mainly email delivery services and certain Google services used for authentication or analytics.
Where a transfer outside the EEA occurs, LensDeliver relies on appropriate legal safeguards under the provider's applicable documentation and transfer mechanisms.
8. Retention
Data is retained only for as long as necessary for the relevant purpose, including:
while an account remains active and for a limited operational period afterward,
while galleries remain active, deactivated, scheduled for purge, or otherwise subject to configured lifecycle rules,
while technical logs and security records remain reasonably necessary for diagnostics, security, and accountability,
while webhook raw payloads and similar operational data remain within short internal retention windows,
as long as required by law, billing, compliance, backup, or dispute handling.
9. Data subject rights
Where applicable, individuals may request:
access to their personal data,
rectification,
erasure,
restriction of processing,
portability,
objection where processing is based on legitimate interests,
withdrawal of consent where processing is based on consent.
Requests may be sent to privacy@lens-deliver.com.
10. Security
LensDeliver applies technical and organizational safeguards appropriate to risk, including access controls, session and token controls, event logging, rate limiting, tenant isolation, and infrastructure-level protections.
11. Public galleries
End recipients may access public or private galleries only through the mechanisms configured by the customer, such as links, PINs, or controlled access windows.
LensDeliver also processes gallery access data for security, abuse prevention, and delivery functionality.
12. Complaints
If you believe personal data is being processed unlawfully, you may contact privacy@lens-deliver.com and may also lodge a complaint with a competent supervisory authority.
