MomelyaGDPR & Data Protection Notice

Momelya

GDPR & Data Protection Notice

This notice summarizes how Momelya approaches GDPR-style data protection rights and privacy principles.

Last updated: 2026-07-14

1. Data controller

The Momelya operator acts as the data controller for account, event, guest, and uploaded media data processed through the service, unless a separate agreement states otherwise.

2. Categories of personal data

Momelya may process:

  • Identity and contact data, such as account email and display name.
  • Guest data, such as guest display name and access code.
  • Event data, such as event title, date, settings, and plan information.
  • Media data, such as uploaded photos, videos, thumbnails, and metadata.
  • Technical and security data, such as logs and abuse-prevention records.

3. Purposes of processing

Data is processed to operate event pages, enable uploads, protect media access, manage accounts, provide support, prevent abuse, and comply with legal duties.

4. Legal bases

Depending on the context, processing may be based on contract performance, legitimate interests, consent, legal obligations, or the establishment and protection of legal claims.

5. Data subject rights

Depending on applicable law, individuals may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent.

6. Deletion requests

Event owners can request deletion of their event data. Guests can request deletion of media they uploaded. Requests may require enough information to verify the relevant event, upload, or guest code.

7. International transfers

Service providers may process data in different countries. Where required, appropriate safeguards should be used for international data transfers.

8. Security

Momelya uses access controls, signed media URLs, guest access codes, and operational security measures to reduce unauthorized access risk.

For questions about these terms, privacy, or data deletion, please contact the relevant Momelya team.

privacy@momelya.com