Notice
Privacy and cookies
Only two things: the details you write in the enquiry form, and the photos we take at your event. No tracking cookies, no profiling, no sharing with third parties for marketing. Here are the details, in plain words. This notice is also available in Italian.
Data controller
The data controller is Flash Fever Photo Booth, P. IVA (VAT no.) 02962410995. For any request about your data, write to info@flashfever.it: a person replies, not a form. We have not appointed a Data Protection Officer (DPO), as we are not required to.
Enquiry form data
When you write to us through the form, we only collect what you choose to give us:
- Data collected
- Required: name, email, event location, type of event and date (or that you do not have one yet). Optional: phone, your message and how you heard about us. We also record which button on the site opened the form, without linking it to any other browsing data.
- Purpose
- Only one: to read your request and reply with availability and a proposal. No newsletter, no profiling, no advertising.
- Legal basis
- Steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). We do not ask for separate consent, because the data is used exactly and only to reply to you.
- Providing data
- Voluntary: nobody has to write to us. Without the required details, however, we cannot reply with availability and a quote.
If you prefer to write to us by email or on WhatsApp, we handle what you send in the same way and for the same purpose. WhatsApp is a service of WhatsApp Ireland Ltd., which processes message data under its own privacy notice.
Photos taken at events
A photo booth produces images of many people: it is the most important processing we owe you an account of. This is how it works.
During the event we photograph only people who step up to the set voluntarily. Nobody is photographed without knowing it: the booth is visible and run by one of our attendants, and anyone who does not want to be photographed simply does not pose. Every shot is printed and handed to the people in it on the spot.
- Data processed
- The photographic image of the people who choose to be photographed. To receive the digital photo we ask for neither an email address nor a phone number: guests scan the QR code shown on screen (Android and iPhone) or receive it by AirDrop (iPhone).
- Purpose
- To deliver the service commissioned by the client (the couple or the company), hand the prints to the guests and send the digital files to anyone who asks for them.
- Legal basis
- Performance of the contract with the client (Art. 6(1)(b) GDPR) and legitimate interest in delivering the photo service (Art. 6(1)(f)), balanced by the fact that taking part is voluntary and the photo is handed straight to the person in it. For digital delivery, the guest’s own request.
- Who is the controller
- Flash Fever Photo Booth, for the photos it takes. The client who hired us is an independent controller for how they use the images they receive.
The QR code opens a page in the browser where guests download their own photo. AirDrop transfers it straight from the photo booth to the phone, without going through external servers. In neither case do we collect guests’ contact details.
Promotional use and how to object
Like any photo studio, we select some images to show our work: the portfolio on this site, our Instagram profile and proposals sent to potential clients. The legal basis is our legitimate interest in promoting the business (Art. 6(1)(f) GDPR), limited to images of festive moments, never embarrassing or demeaning to the people shown.
We never pass the photos to third parties for their own advertising, we do not sell them and we do not upload them to image banks.
Children
Children are photographed only with a parent or guardian present and consenting, who receives the print together with the child. Images of children are never used for promotion, on any channel, unless a person with parental responsibility asks for it explicitly and in writing.
How long we keep data
- Enquiries (form, email, WhatsApp)
- Up to 12 months from the last contact, if they do not become a confirmed event. You can ask us to delete them sooner.
- Event photo files
- 90 days from the date of the event, enough time for the client to download everything. After that the files are deleted from our archives and backups: ask us to recover anything before then, not after.
- Images selected for the portfolio
- For as long as they help represent our work, and in any case until you object (see section 4).
- Accounting records
- Invoices and tax data for 10 years, as Italian law requires (Art. 2220 of the Civil Code).
Who we share data with
We do not sell or pass on your data. We only rely on technical providers acting as processors, appointed under Art. 28 GDPR:
- Vercel Inc.: website hosting.
- Resend (Plus Five Five, Inc.): sending the email that delivers your request to us.
- Plausible Analytics: aggregate, anonymous visit statistics without cookies (only if enabled; it does not identify individual visitors).
- The photo booth software provider: hosts the page where guests download their photos via the QR code, and the client’s private gallery.
- Google (Google Workspace): business email.
- Our accountant: only for the tax obligations relating to confirmed events.
The photos are not published on publicly accessible platforms. The download page opened by the QR code and the client’s full gallery are hosted by the photo booth software provider, which processes them on our behalf.
Transfers outside the EU
Some of the providers listed above are based in the United States. In that case the transfer relies on the safeguards in Chapter V of the GDPR: standard contractual clauses approved by the European Commission and, where applicable, the provider’s participation in the EU-US Data Privacy Framework.
Your rights
At any time you can ask us to access your data, correct it, delete it, restrict its processing, receive it in a portable format or object to processing based on legitimate interest, including the promotional use of photos. Just write to info@flashfever.it: we reply within 30 days.
If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live, or go to court.
Cookies and tracking
This site sets no profiling cookies and no tracking tools, which is why you see no cookie banner: there would be nothing to consent to. The typefaces are hosted on our own site too: opening the pages does not make your browser contact any third-party server.
If and when we turn on visit statistics, we will use Plausible Analytics, which measures traffic in aggregate and anonymously, without cookies and without identifying individual visitors. Third-party content (for example an Instagram profile) stays a plain link: opening it takes you off this site, and that service’s privacy notice applies.
Security
We take technical and organisational measures appropriate to the risk: encrypted connections across the whole site, password-protected access with two-factor authentication on the services that handle data, encrypted devices for the photo archives, and access limited to the people working on the event.
Changes to this notice
If we change how we handle data, we will update this page and the date below. Substantial changes will be emailed to clients with a confirmed event.
Last updated: September 2026.