Where are your event's photos stored?

At a wedding almost nobody asks this. At a company party it is the question procurement gets stuck on, and rightly so, because at a lot of suppliers the answer is nowhere to be found.

8 min read

the short answer

With us the files sit on European servers. They are never openly reachable on the internet: every link to a photo is signed and expires by itself, so an address that works today does not work next month. If you want to judge a supplier, look at three things: a country with a name, a hosting party with a name, and a data processing agreement you can read.

Where exactly are your event's photos stored?

On European servers. The files your guests upload sit there at full size, and they cannot be reached through an ordinary web address. There is no folder you can find by guessing a URL, and there is no browsable page with other events. Google does not index the album.

Access runs through signed links with an expiry time. Every time somebody asks for a photo, an address is made that is valid for a while and after that is not. That is the difference between a key that fits and a door standing open.

What else applies: the event has an active period of 45 days on the entry plan and up to 365 days on the larger ones, counted from the first time you publish. After that it closes for guests and goes into archive mode, in which you as the organiser can keep downloading. Publishing is reversible, so taking it offline removes guest access immediately.

Confetti above the crowd at a party
the confetti at half past eleven, and the question of where that photo is tomorrow

How do you check this at any given supplier?

You do not have to be a lawyer to judge a privacy statement. Open it, look for five things, and within two minutes you know whether you are dealing with something serious. The rule of thumb: a page that only says the service is GDPR compliant says nothing. There is no body that hands out that stamp and nobody checks it in advance.

If you cannot find those five answers, that is the answer in itself. The point is not that a supplier outside the EU is necessarily worse, but that you have to be able to know before you let a hundred colleagues upload.

  • Country: is a country named in the text, or only that data stays inside the EU.
  • Party: is the hosting party named, with the country alongside.
  • Processing agreement: can you request it without a call with sales first.
  • Transfers: is there a line about transfers outside the EEA, and if so, under which safeguard.
  • Retention: is there a period, or only that data is kept no longer than necessary.

What does that look like at real suppliers?

supplierwhat the privacy statement nameswhat you know from it
QuipicHetzner in Germany, Supabase in an EU region, Bunny in Slovenia, Mollie in the Netherlandsthe whole chain, with the party and the country
Kiekjeservers in the Netherlands and Germany only, never outside the EUthe countries, but not the parties
FotifyLumenlio LLC in Delaware, sub-processors only as a categorywho runs the service, not where your photos are
EventSnapstorage on European servers, and signed links with an expiry timethe region and how the access works

This is how far apart two privacy statements can sit. Quipic names the chain party by party, with the country alongside down to the payment provider. We name the region and how access works: storage in the EU, and links that expire instead of an album that stays public. Fotify is here as a counter-example, not out of schadenfreude: their own policy names Lumenlio LLC in Delaware as the operating company and lists sub-processors only as a category, so where the files sit cannot be worked out from it. Checked on 30 August 2026, and privacy statements change, so look for yourself.

how we do this

EU storage, and no file left open on the internet

Your guests' photos sit on European servers and are only reachable through signed links that expire by themselves. You pull the whole event down as a zip at any moment, at full size.

Why does a company take this more seriously than a couple?

Because a couple decides about their own photos, and an employer decides about a hundred other people's. The moment you collect photos of colleagues on behalf of an organisation, you are the controller under the GDPR. The supplier of the tool is then the processor, and that means you need a data processing agreement. With a cloud service that is almost always the case, because the files go to another party's server.

That is also why this question so often comes from procurement or IT and not from whoever is organising the party. They have to be able to explain where the data sits and who can reach it, and a page without a country and without a party gives them no answer. What you further need in terms of lawful basis and the duty to inform is in what you may do with photos of employees after the company party, and the practical setup in collecting photos at a company party.

What procurement and IT ask us

Can we sign a data processing agreement?

Yes, and that is how it should be. You are the controller for your colleagues' photos, we are the processor. Such an agreement sets out the purpose, the duration, which kinds of data it concerns and who does what in a data breach. That last part is not theoretical: a breach has to be reported to the Dutch DPA (Autoriteit Persoonsgegevens) within 72 hours.

What happens to the photos when the event ends?

After the active period (45 days on the entry plan, up to 365 days on the larger ones) the event closes for guests and goes into archive mode. You can keep downloading. Which period belongs to which plan is at what it costs, and exactly what happens when it runs out is in how long the photos stay up.

Are our photos used to train anything?

No. Your guests' photos are not used to train models, and they are not sold or passed to third parties for that purpose. We do nothing with facial recognition or automatic selection either, so no analysis runs over your pictures.

How long may we keep those photos ourselves?

You decide that yourself, and you write the reasoning next to it. The Dutch DPA explains that the GDPR sets no concrete retention period and that the starting point is that you keep data no longer than you need for the purpose. Put your period in your privacy statement and your colleagues know where they stand.

Can somebody who is forwarded the link get in?

Only while the link is valid, and only while the event is published. The links to the files are signed and expire by themselves, so an old address from an email last year yields nothing. Take the event offline and guest access drops away immediately.

What if something is in there that has to go?

You take it out, and the file stays in the bin for fourteen days in case you change your mind. If you would rather arrange it in advance than afterwards, turn moderation on: then nothing joins the album before somebody has seen it. Both routes are worked out in what to do when a guest uploads something that does not belong.

Read next

European storage, and links that close by themselves

You pull everything down as a zip at any moment, at full size.

Start your event