Legal

Privacy Policy

TL;DR (The Plain English Version)

  • We don't own your photos; the photographer does.
  • We only use facial recognition to find your photos and send them to you.
  • We never sell your data, biometrics, or selfies to anyone.
  • Biometric data is ephemeral and used solely for matching during the event lifecycle.

Last updated: 7/20/2026

At Ayojan, we recognize that the integration of facial recognition technology into event photography transforms a conventional image hosting service into an active processor of sensitive biometric data. We are committed to an uncompromising standard of privacy, security, and statutory compliance, particularly regarding the Digital Personal Data Protection Act, 2023 (DPDPA) and the Information Technology Act, 2000.

This Privacy Policy meticulously maps the lifecycle of your data as it traverses our cloud infrastructure. It governs all interactions with the Ayojan platform.

1. Juridical Definitions and the Fiduciary-Processor Bifurcation

To ensure precise accountability and transparency, Ayojan strictly bifurcates its operational roles regarding data processing as mandated by the DPDPA 2023.

  • The "Organizer": The professional photographer, corporate entity, or event host who registers an account, pays the subscription fee, and uploads event galleries. Regarding the Organizer’s account information, billing details, and platform telemetry, Ayojan acts as the Data Fiduciary, determining the purpose and means of processing to fulfill our commercial software-as-a-service (SaaS) contract.
  • The "Guest": The end-user attendee who uploads a selfie to securely retrieve their photographs. Regarding the vast repositories of event photographs uploaded by the Organizer and the biometric selfies uploaded by Guests, Ayojan acts strictly as a Data Processor. Ayojan does not own the event photographs, does not determine the purpose of the event photography, and executes facial recognition matching solely upon the algorithmic instruction initiated by the Organizer and the consenting Guest.

2. Exhaustive Categorization of Collected Information

We explicitly enumerate the data vectors we collect to ensure total transparency.

From the Organizer

Ayojan collects personally identifiable information (PII) necessary for commercial operation. This includes:

  • Individual or corporate name.
  • Physical billing address.
  • Primary email address and authenticated phone number.
  • Statutory tax identifiers, such as the Goods and Services Tax (GST) Number, to facilitate lawful invoicing.
  • Event-specific metadata, including the nomenclature, date, and geographic location of the managed events.

From the Guest

To facilitate the delivery of personalized galleries, Ayojan collects:

  • The individual's name, email address, and authenticated contact number.
  • The highly sensitive scanned "selfie" required exclusively to initiate the biometric processing sequence.

Automated Telemetry Data

Ayojan routinely captures platform telemetry, which encompasses Log Files (Internet Protocol (IP) addresses, browser classifications, Internet Service Provider (ISP) routing data) and precise temporal date/time stamps associated with platform interactions. We deploy cookies and similar tracking technologies strictly for session management, security authentication, and behavioral analytics. You reserve the right to disable such tracking via your browser configurations, though it may impair platform functionality.

3. Purpose Limitation and the Lawful Basis for Processing

Every byte of data processed by Ayojan is tethered to a specific, lawful justification under the DPDPA 2023.

  • Contractual Necessity: The processing of the Organizer’s administrative and financial data is justified under Contractual Necessity, as it is required to fulfill the terms of the SaaS subscription agreement.
  • Explicit and Verifiable Consent: The ingestion of the Guest’s selfie and the subsequent extraction of facial geometry vectors are justified exclusively under Explicit and Verifiable Consent. Ayojan categorically rejects the legal concept of implied consent for biometric processing.
  • Legitimate Interest: The collection of automated telemetry and log data is justified under Legitimate Interest. This data is vital for maintaining network security, preventing distributed denial-of-service (DDoS) attacks, identifying fraudulent activity, and conducting necessary platform optimization analytics.

4. Supply Chain Transparency and Sub-Processor Disclosure

Ayojan operates within a highly integrated cloud ecosystem and utilizes specialized third-party infrastructure. We do not hide our infrastructure partners. The following entities provide the secure backend server compute and database storage necessary to process event photographs and execute our AI matching algorithms:

  • Amazon Web Services (AWS) / Google Cloud Platform (GCP) / Cloudflare R2:For secure database storage and server compute operations.
  • Cloudflare: Utilized as a Content Delivery Network (CDN) to accelerate image delivery. Cloudflare inherently processes Guest selfies and encrypted images during transit across global server nodes.
  • Authentication & Analytics Partners: Data such as hashed email IDs and frontend interaction telemetry may be transmitted to providers like Google Firebase (for credential management) or Microsoft Clarity (for dashboard behavioral analytics).

5. Data Retention Limits and Ephemeral Storage Doctrines

Ayojan adheres strictly to data minimization principles. We do not engage in indefinite data hoarding.

  • Administrative Account Data: Organizer account information is retained for the active duration of the SaaS relationship and for a legally mandated period thereafter (e.g., seven years) to comply with Indian corporate tax and financial auditing requirements.
  • Event Media Payloads: Ayojan is not a permanent archiving service. Event galleries are processed and hosted solely for a specified duration corresponding to the Organizer’s active subscription tier. Upon expiration, these media assets are systematically purged from our servers to minimize the platform's liability surface.
  • Ephemeral Biometric Data: Guest facial vectors and selfies are retained strictly for the ephemeral duration necessary to perform the computational search. They are subsequently deleted or irreversibly anonymized upon the fulfillment of the photo retrieval request. (Further detailed in our Biometric Consent Notice).

6. Enumeration of Statutory Data Principal Rights

In compliance with the DPDPA 2023, Ayojan guarantees the following rights to our users (Data Principals):

  • Right to Access: Users may request a comprehensive summary of their personal data currently undergoing processing, along with the identities of all third-party sub-processors with whom the data has been shared.
  • Right to Correction and Erasure: Users are empowered to demand the rectification of inaccurate database entries and the immediate deletion of their data once the original purpose of processing has been achieved.
  • Right to Nominate: Users possess the legal right to nominate another individual to exercise their data privacy rights in the event of their death or physical/mental incapacity.

Grievance Management: Ayojan commits to resolving all Data Subject Rights (DSR) requests within a statutory window of 30 days. To exercise your rights, or to contact our designated Data Protection Officer (DPO), please reach out to our dedicated privacy support team at privacy@ayojan.in.