At a glance
- Uploaded photographs and videos are private by default; access is governed by the owner's setting and a server-side authorization decision.
- Camera frames are not continuously uploaded. Mark and photograph recognition primarily run on the device.
- Emlivo does not receive or store full payment-card details.
- We currently use no advertising or behavioural analytics; only storage necessary for security and operation is active.
- You may request access, correction, deletion, restriction, portability or object through the privacy contact.
- Document version
- 2026-09-27
- Effective date
- 2026-09-27
Controller
The following service provider is the controller of personal data processed through Emlivo and determines the purposes and essential means of processing. The current operation does not require the appointment of a data protection officer; privacy questions may be sent directly to the controller.
- Controller / service provider
- Fodor Máté Áron
- Legal form
- egyéni vállalkozó
- Registered address
- Magyarország, 2700 Cegléd, Árpa utca 3. ép.: 1.A.
- Tax number
- 91889102-1-33
- Registration number
- 62061557
- Statistical number
- 91889102-6310-231-13
- Contact and customer support
- support@emlivo.hu
- Privacy requests
- privacy@emlivo.hu
- Consumer complaints
- panasz@emlivo.hu
Scope and principles
This notice covers emlivo.hu, the Emlivo mobile application, accounts, orders, photograph and video uploads, digital production, AR and fullscreen playback, service notifications, support and security logs. Payment, email and physical-fulfilment providers enter scope only when the relevant function is actually activated.
We follow purpose limitation, data minimisation, accuracy, storage limitation, confidentiality and accountability. We do not sell personal data or use family photographs or videos for advertising, face recognition or training artificial-intelligence models.
Purposes, data and legal bases
| Activity | Data | Purpose and legal basis |
|---|---|---|
| Account and sign-in | User ID, email, confirmation state, display name, language, country, identity provider and session data. Supabase Auth verifies passwords; readable passwords are not stored. | Account, authentication and security. Contract or pre-contract steps (GDPR Art. 6(1)(b)); legitimate interests (f) for security logs. |
| Creating a Memory | Title, description, photograph, video, file size/type/duration, processing status, reference photograph and access mode. | Producing and operating the requested service. Contract (b). |
| Upload and video processing | Upload session, technical metadata, provider video ID, status, error codes and retry attempts. | Resumable upload, renditions and troubleshooting. Contract (b); legitimate interests (f) for reliability and security. |
| Viewer access and AR | Print Token, access mode, short-lived grant, pseudonymous device ID, request time, IP and request metadata, reference image and playback state. | Recognition, policy enforcement, anti-enumeration and playback. Contract (b); legitimate interests (f) for security. |
| Order and billing | Customer, item, variant, price, currency, tax, country, billing and, when relevant, delivery address, status and provider IDs. | Contract (b); accounting and tax law (c). |
| Payment | Order ID, amount, currency, status and Stripe or app-store transaction IDs. No full card number or CVC is received. | Payment, refund and fraud prevention. Contract (b), legal obligation (c), legitimate interests (f). |
| App notifications | Notification preference, platform, app-installation identifier, APNs/FCM delivery token, app version, delivery state and the related account event. | Delivering requested order, processing, security and account updates. Contract (b); legitimate interests (f) for reliable delivery. System permission can be withdrawn and marketing push is not enabled. |
| Support and complaints | Name, email, order/Memory ID, message, attachments, responses and actions. | Support, contract and legal claims (b), (c), (f). |
| Security and administration | Login attempt, IP, device/browser, time, admin role/action/target, safe audit metadata and correlation ID. | Account and system security, abuse prevention and audit. Legitimate interests (f), sometimes legal obligation (c). |
| Marketing | Email and consent evidence only if separately enabled later. | Freely given, withdrawable consent (a). Service and security messages are not marketing. |
Media and data about other people
A Memory may reveal children, family events or information suggesting health, religion or other sensitive circumstances. We do not request this to infer sensitive traits; it is processed because the user chooses that memory for storage and playback.
- Upload only content you are entitled to use and have Emlivo process.
- Where another person is identifiable, provide the required information and obtain consent or another legal basis where necessary.
- For children, respect their best interests and parental responsibility.
- Illegal, non-consensual intimate, hateful, exploitative or rights-infringing content is prohibited.
A person who believes a Memory violates personality, copyright or privacy rights may request investigation and temporary restriction through Report content after a successful scan or through the complaints address. The in-app report asks for a category and at most a short description; do not send more sensitive evidence than necessary.
Camera and device permissions
The app requests camera access to recognise the Emlivo mark and printed photograph and place video over it. Continuous camera analysis occurs on the device; frames are not live-streamed to Emlivo, automatically recorded or used for face recognition.
Only media expressly selected or captured by the user is uploaded. Camera, microphone, photo-library and local-file permissions may be revoked in system settings, which can prevent the relevant feature from working.
Printed identifiers and guest viewing
The printed mark carries a stable random identifier, not a permanent media URL or authorization. The server checks access mode, revocation and entitlement for each request and issues only short-lived access.
- Unlisted means not searchable, not secret: anyone who sees or photographs the print may request access.
- Public requires an explicit owner choice.
- A PIN is never shown or stored reversibly.
- The owner can disable access. A fully offline device may retain a previously issued grant until its bounded expiry.
Processors and recipients
Data is shared only with providers necessary to operate Emlivo and subject to appropriate contractual duties. The list follows actual activation and is updated for material changes.
- Supabase, Inc.
- Authentication, PostgreSQL, private image/file storage, server functions and access control.
- Cloudflare, Inc.
- Direct resumable video upload, processing and authorized adaptive playback.
- Vercel Inc.
- Hosting and server-side execution of emlivo.hu, network and security logs.
- Stripe group
- Web payments and fraud prevention once live Stripe payments are enabled. Stripe may be an independent controller for some payment data.
- Apple / Google
- App distribution, APNs/FCM notification delivery and, once enabled, social sign-in or native digital purchases. Push delivery uses an app/device-level delivery identifier; they may act as independent controllers for some operations under their notices.
- Resend, Inc. (EU region)
- Account, security and order-email delivery. Only the verified address, required language and minimal message/order context are transmitted; no media or permanent download URL.
- Print and logistics partner
- Only after physical fulfilment is enabled and only the production file and address data necessary to make and deliver the order.
Data is disclosed to authorities or courts only on a valid legal basis and to the necessary extent.
Transfers outside the EEA
Some providers or subprocessors operate in the United States or other countries outside the EEA. Restricted transfers must rely on an adequacy decision, valid EU–US Data Privacy Framework participation, European Commission Standard Contractual Clauses or another safeguard under GDPR Chapter V.
Selecting an EU primary region is useful but not a complete legal guarantee. DPAs, subprocessor lists and transfer mechanisms must be reviewed before launch and regularly thereafter.
Retention
- Account data: while the account exists and through any necessary closure/legal period.
- Draft and unissued Memories: while the service operates or until earlier owner deletion. Purchased and issued Emlivos: after account deletion, only the detached reference, Print Token association and optimized playback needed for scanning remain while Emlivo operates, or until earlier access revocation, refund, legal/safety action or technical discontinuity.
- Original video: under the active original-recovery/archive policy and separately from optimized playback assets.
- Order, invoice and accounting records: for mandatory Hungarian tax/accounting periods; accounting documents are generally retained for at least eight years.
- Consumer complaint records and responses: three years.
- Security and audit logs: for a bounded, risk-based period, extended only for an incident or claim.
- Backups rotate out; deleted data may remain temporarily isolated in backup but is not restored into ordinary use on its own.
Security
- HTTPS and private media storage;
- row- and owner-level database policies with default denial;
- short-lived signed playback and download grants;
- a printed token that identifies but never permanently authorizes;
- separation of public, mobile-safe and server-secret configuration;
- role-limited, audited administration;
- resumable uploads, idempotent processing and backup/restore procedures.
No system can guarantee absolute security. Where a personal-data breach is likely to create high risk, affected people and the authority are notified as required by the GDPR.
Your rights
Depending on the processing, you may request information and a copy, correction, deletion, restriction and portability, and object to processing based on legitimate interests. Consent can be withdrawn at any time without affecting earlier lawful processing.
Send requests to privacy@emlivo.hu. We request only what is necessary to verify identity. We normally respond within one month, subject to the GDPR's permitted extension for complex or numerous requests.
Deletion does not override mandatory retention, legal claims, fraud prevention or the rights of others.
Children
Guest viewing requires no account. An account and paid contract may be created only by a person with legal capacity; a minor may use creator and ordering functions only with appropriate involvement of a legal representative.
If we learn that a child's data was processed without an appropriate basis, we delete or restrict it. A report should include the Memory reference and only information necessary to establish the relationship.
Automated decisions
Emlivo does not make solely automated decisions producing legal or similarly significant effects and does not build advertising profiles. Automated technical checks may validate files, processing, authorization and abuse signals; disputed outcomes can be submitted for human support review.
Complaints and changes
Please contact us first so we can investigate promptly. You may nevertheless complain to the supervisory authority for your habitual residence, workplace or the alleged infringement, and seek a judicial remedy.
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9–11, Hungary
- Postal address
- 1363 Budapest, PO Box 9, Hungary
- ugyfelszolgalat@naih.hu
- Telephone
- +36 1 391 1400
Material changes receive a new version and effective date. Where an existing contract or rights are materially affected, appropriate advance notice is provided and new consent is obtained where required.