Legal
Privacy Policy
Last updated: April 22, 2026
GDPR Compliance
Memorama fully respects the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and Romanian Law no. 190/2018. You have full rights over your personal data at all times.
1. Who We Are
Memorama is a digital event management and memory-sharing platform. As Data Controller, we are responsible for the personal data you provide when using our services. For any data-related questions contact us at [email protected].
2. What Data We Collect
Account & Identity Data
- Full name
- Email address
- Password (stored as a cryptographic hash — never in plain text)
Event Data
- Guest names, email addresses, and RSVP status
- Seating arrangements
- Budget entries and financial notes
- Event notes and co-organizer details
Memory Album Content
- Photos, videos, and text messages uploaded by you or your guests
- AI-generated face grouping metadata (used solely to power the grouping feature — not shared)
Usage Data
- Pages visited and features used
- Browser type and device information
- IP address (used for security and abuse prevention)
3. How We Use Your Data
- Providing the service — running your events, managing guests, seating, budget, and memory album.
- Account management — authentication, password reset, account settings.
- Service notifications — email confirmations, memory album expiry reminders, and important account alerts.
- Security — detecting and preventing unauthorized access, abuse, and fraud.
- Service improvement — anonymous aggregated usage analytics to improve features.
- Legal obligations — compliance with applicable laws and regulatory requirements.
4. Data Sharing
We never sell your personal data.
We do not use any third-party marketing or advertising services. Data is shared only with the sub-processors listed below strictly to deliver the service, and with authorities only when required by law or a lawful court order.
Authorised Sub-processors
NETOPIA Payments
Romania — European UnionPurpose: Payment processing for paid plans.
Receives: Billing name, email address, and card data entered on NETOPIA's secure payment page. We never store or see full card numbers — all payment data is handled directly by NETOPIA Payments.
Privacy policy →If additional sub-processors are introduced in the future, this policy will be updated and you will be notified in advance.
5. Data Storage & Security
All data is stored on servers located within the European Union. Security measures include:
- SSL/TLS encryption for all communications
- Passwords stored as irreversible cryptographic hashes
- Role-based access control — only authorised personnel can access data
- Automated daily backups with encryption
- Continuous monitoring for unauthorised access
In the event of a data breach that may affect your rights, we will notify the relevant supervisory authority within 72 hours and affected users within 96 hours.
6. Data Retention
Account data
For the duration of the account, plus 3 years after last activity
Event data (guests, seating, budget, notes)
For the duration of the account
Memory album content
Until the album expiry date for your plan; you will be reminded before expiry and can download all data
Security logs
2 years
Billing and invoicing data
10 years, as required by the Romanian Accounting Act
You can request deletion of your personal data at any time by contacting [email protected]. Certain data may be retained to fulfil legal obligations.
7. Your GDPR Rights
Under GDPR you have the following rights regarding your personal data:
Right of Access (Art. 15)
Request a complete copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete data.
Right to Erasure (Art. 17)
Request deletion of your data (“right to be forgotten”), unless we are required to retain it by law.
Right to Data Portability (Art. 20)
Export your data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing for purposes other than the direct provision of the service.
Right to Restrict Processing (Art. 18)
Request temporary suspension of processing in certain legally-defined situations.
To exercise any of these rights, send a request to [email protected]. We will respond within 30 calendar days. See also our GDPR Rights page for a step-by-step guide.
9. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian data protection authority:
ANSPDCP
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
Website: www.dataprotection.ro
10. Contact
For all data protection enquiries:
Email: [email protected]
General: [email protected]
PLACEHOLDER SRL
CUI: ROXXXXXXXX
Nr. Reg. Com.: JXXXXXXXXXX