Privacy Policy
Last updated: July 30, 2026
1. Who is responsible
This policy covers the Patifot website, dashboard and iPad application, operated by SAS Patifot, 58 rue de Monceau, CS 48756, 75008 Paris, France, registered in Paris under number 983 410 473 ("Patifot", "we"). Privacy questions: support@patifot.app.
Two roles matter here. For operator accounts and this website, Patifot is the data controller. For photos and related data of event guests, the booth operator (our customer) is the controller and Patifot processes the data on the operator's behalf.
2. Operator accounts
When we create an operator account we process your name, business contact details, company information, the identifiers of the iPads you activate, and the content you upload to prepare events (frames, prompts, idle screens). We use this data to provide the service under our contract with you. Account data is kept while the account is active, then deleted or anonymized unless the law requires us to keep records longer (for example, invoices).
3. Guest photos at events
When a guest uses a booth, the following is processed for the operator running the event: the photos taken at the booth, the AI-styled versions where the guest chose an AI mode, the delivery code (QR or PIN) used to pick up the photos, and the record of consent given at the booth screen.
- Retention is short and defined per event: photos and delivery links are deleted 24 to 72 hours after the event ends; the operator sets the exact window in advance.
- No face recognition: photos are delivered by QR code or PIN, never by face search. We do not build or store face embeddings.
- Consent at the booth: before photos are taken, the booth shows a consent notice describing what happens with the pictures, including delivery of the event archive to the event's host. Marketing use requires a separate consent.
- Offline events: an event can be configured as offline-only. In that case photos never leave the iPad and none of the cloud processing described here takes place.
4. AI processing
For AI photo modes, the guest photo is sent to our AI provider, OpenAI, through its European endpoint with EU Data Residency, under a data processing agreement. The photo is used only to produce the styled image. It is not used to train models. AI styling transforms the whole picture; it does not identify anyone.
5. Booth telemetry
Booths report technical status to the dashboard: device health, printer and paper state, error events, configuration version. This data concerns devices rather than people; where log entries reference a session, they contain identifiers, not photos. Technical logs are kept for up to 90 days.
6. This website
The website is static and sets no tracking cookies. We use Cloudflare Web Analytics, which is cookie-free and does not profile visitors across sites. Cloudflare, which serves the site, processes standard connection logs (IP address, user agent) to run and protect its network.
7. Payments
When billing launches, purchases will be processed by a payment partner acting as merchant of record (Paddle). The partner is responsible for payment data; we never see full card numbers. Its own privacy policy applies to the checkout.
8. Subprocessors and recipients
| Provider | Purpose | Location of processing |
|---|---|---|
| OpenAI (EU endpoint) | AI image generation | European Union |
| UpCloud | Application servers and storage | European Union |
| Cloudflare | DNS, CDN, website hosting, web analytics | EU / US (Data Privacy Framework, SCCs) |
| Paddle | Payments, invoicing (once billing launches) | UK / EU |
Guest photo archives are delivered to the host of the event (the operator's client) as part of the service, under the consent shown at the booth. We do not sell personal data and we do not run advertising.
9. International transfers
Application data and AI processing stay in the European Union by design. Where Cloudflare processes connection data outside the EU, transfers rely on the EU-US Data Privacy Framework and standard contractual clauses.
10. Security
Data travels encrypted (TLS). Access to production systems is restricted and logged. Short retention windows for guest photos limit what could ever be exposed.
11. Your rights
Under the GDPR you can request access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. Write to support@patifot.app; we answer within a month. You can also complain to the French supervisory authority, the CNIL (cnil.fr), or to your local authority.
If you are an event guest, the operator who ran your event is the controller of your photos: the fastest route is the contact given at the booth or by the event's host. We help operators honor these requests, and given the 24 to 72 hour retention, deletion usually happens on its own before a request is needed.
12. Changes
We will update this policy as the service evolves and note the date of the last change at the top. For material changes affecting operators, we give notice by email.
Translations of this policy are provided for convenience. In case of divergence, the English version prevails.