Legal

Privacy Policy

Last updated: April 22, 2026

GDPR Compliance

Memorama fully respects the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and Romanian Law no. 190/2018. You have full rights over your personal data at all times.

1. Who We Are

Memorama is a digital event management and memory-sharing platform. As Data Controller, we are responsible for the personal data you provide when using our services. For any data-related questions contact us at [email protected].

2. What Data We Collect

Account & Identity Data

  • Full name
  • Email address
  • Password (stored as a cryptographic hash — never in plain text)

Event Data

  • Guest names, email addresses, and RSVP status
  • Seating arrangements
  • Budget entries and financial notes
  • Event notes and co-organizer details

Memory Album Content

  • Photos, videos, and text messages uploaded by you or your guests
  • AI-generated face grouping metadata (used solely to power the grouping feature — not shared)

Usage Data

  • Pages visited and features used
  • Browser type and device information
  • IP address (used for security and abuse prevention)

3. How We Use Your Data

  • Providing the service — running your events, managing guests, seating, budget, and memory album.
  • Account management — authentication, password reset, account settings.
  • Service notifications — email confirmations, memory album expiry reminders, and important account alerts.
  • Security — detecting and preventing unauthorized access, abuse, and fraud.
  • Service improvement — anonymous aggregated usage analytics to improve features.
  • Legal obligations — compliance with applicable laws and regulatory requirements.

4. Data Sharing

We never sell your personal data.

We do not use any third-party marketing or advertising services. Data is shared only with the sub-processors listed below strictly to deliver the service, and with authorities only when required by law or a lawful court order.

Authorised Sub-processors

NETOPIA Payments

Romania — European Union

Purpose: Payment processing for paid plans.

Receives: Billing name, email address, and card data entered on NETOPIA's secure payment page. We never store or see full card numbers — all payment data is handled directly by NETOPIA Payments.

Privacy policy →

If additional sub-processors are introduced in the future, this policy will be updated and you will be notified in advance.

5. Data Storage & Security

All data is stored on servers located within the European Union. Security measures include:

  • SSL/TLS encryption for all communications
  • Passwords stored as irreversible cryptographic hashes
  • Role-based access control — only authorised personnel can access data
  • Automated daily backups with encryption
  • Continuous monitoring for unauthorised access

In the event of a data breach that may affect your rights, we will notify the relevant supervisory authority within 72 hours and affected users within 96 hours.

6. Data Retention

Account data

For the duration of the account, plus 3 years after last activity

Event data (guests, seating, budget, notes)

For the duration of the account

Memory album content

Until the album expiry date for your plan; you will be reminded before expiry and can download all data

Security logs

2 years

Billing and invoicing data

10 years, as required by the Romanian Accounting Act

You can request deletion of your personal data at any time by contacting [email protected]. Certain data may be retained to fulfil legal obligations.

7. Your GDPR Rights

Under GDPR you have the following rights regarding your personal data:

Right of Access (Art. 15)

Request a complete copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your data (“right to be forgotten”), unless we are required to retain it by law.

Right to Data Portability (Art. 20)

Export your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing for purposes other than the direct provision of the service.

Right to Restrict Processing (Art. 18)

Request temporary suspension of processing in certain legally-defined situations.

To exercise any of these rights, send a request to [email protected]. We will respond within 30 calendar days. See also our GDPR Rights page for a step-by-step guide.

8. Cookies

Memorama uses only strictly necessary cookies. No tracking, analytics, or advertising cookies are set. The cookies in use are:

CookiePurposeTypeDuration
authTokenKeeps you authenticated between page loadsStrictly necessarySession / persistent (based on "Remember me")
X-XSRF-TOKENPrevents cross-site request forgery (CSRF) attacksStrictly necessarySession

Because these cookies are strictly necessary for the service to function, they do not require your consent under GDPR. You can disable cookies in your browser settings, but doing so will prevent you from signing in.

9. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian data protection authority:

ANSPDCP

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal

Website: www.dataprotection.ro

10. Contact

For all data protection enquiries:

PLACEHOLDER SRL

CUI: ROXXXXXXXX

Nr. Reg. Com.: JXXXXXXXXXX