Momelya
GDPR & Data Protection Notice
This notice summarizes how Momelya approaches GDPR-style data protection rights and privacy principles.
Last updated: 2026-07-14
1. Data controller
The Momelya operator acts as the data controller for account, event, guest, and uploaded media data processed through the service, unless a separate agreement states otherwise.
2. Categories of personal data
Momelya may process:
- Identity and contact data, such as account email and display name.
- Guest data, such as guest display name and access code.
- Event data, such as event title, date, settings, and plan information.
- Media data, such as uploaded photos, videos, thumbnails, and metadata.
- Technical and security data, such as logs and abuse-prevention records.
3. Purposes of processing
Data is processed to operate event pages, enable uploads, protect media access, manage accounts, provide support, prevent abuse, and comply with legal duties.
4. Legal bases
Depending on the context, processing may be based on contract performance, legitimate interests, consent, legal obligations, or the establishment and protection of legal claims.
5. Data subject rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent.
6. Deletion requests
Event owners can request deletion of their event data. Guests can request deletion of media they uploaded. Requests may require enough information to verify the relevant event, upload, or guest code.
7. International transfers
Service providers may process data in different countries. Where required, appropriate safeguards should be used for international data transfers.
8. Security
Momelya uses access controls, signed media URLs, guest access codes, and operational security measures to reduce unauthorized access risk.
