Privacy policy
This policy explains which data the Pellizz mobile app and the pellizz.app website process, why, for how long, and what your rights are. Pellizz is published by Hexalgo SAS (27 RUE DES GRANDES PANNES, 49100 ANGERS, FRANCE). For any question about your data: privacy@pellizz.app.
1. Who is responsible for your data
- Hexalgo SAS, publisher of Pellizz, is the data controller for running the service: accounts, events, gallery, challenges, security and moderation by the publisher.
- The organizer of an event is responsible for the data they bring and the choices they make: their guest list (the names they import or enter), the people they give the event code to, and the moderation of their event. For this processing, we act on their behalf.
- Professional use: when a company organizes an event (seminar, team building…), it is the controller of the guest list and the event's photos, and we act as its processor. Our commitments are set out in the data processing addendum (GDPR article 28) included in the terms of use; it is also available on request at privacy@pellizz.app.
2. Data we process
- Account: the first name or display name you choose and your language. For a full account: your e-mail address and your password (stored only as an irreversible hash). A guest account contains no e-mail address.
- Sign-in with Google or Apple (if you choose it): the identifier of your account with that provider and the e-mail address it sends us (Apple may provide a relay address). With Apple, we also keep an encrypted token that lets us revoke this sign-in when you delete your account. We never receive your Google or Apple password.
- Event participation: the events you joined, your role (organizer or participant), your table or team, the challenges completed and their times.
- Photos: the photos you send (and an event's cover photo), their capture time and dimensions. File metadata, including GPS location, is removed by the app before sending and again by our servers, including for the cover photo. Photos may show other people: see the terms of use.
- Reports, blocks and moderation: photo reports, their reason and whether they were sent to the publisher; photos hidden by organizers; the people you have blocked; account suspensions decided by the publisher.
- Guest list: the names organizers import or enter to prepare their event, and the link with the participant who recognizes themselves in it.
- Notifications: your phone's notification token (Firebase Cloud Messaging) and its platform (Android or iOS).
- Technical data: IP address, date and time of requests and date of last activity, in our server logs.
The app uses the camera only when you take a photo or scan a QR code, and only accesses the photos you pick. On Android, the QR code is read directly on the phone (Google ML Kit): the image is not sent. Pellizz contains no advertising, no third-party analytics and sells no data.
3. Why, and on what legal basis
- Providing the service (account, events, gallery, challenges, leaderboard, photo export, event transfer, verification, password, export, pre-deletion reminder and inactive-account warning e-mails): performance of the contract, i.e. the terms of use you accept (GDPR article 6.1.b).
- Push notifications: your consent, given by allowing notifications on your phone; you can withdraw it at any time in the phone settings.
- Guest list: the organizer's legitimate interest in preparing their event (article 6.1.f). The organizer informs the people on their list; anyone can object: the organizer or we then remove their name from the list.
- Security, abuse prevention and moderation (request rate limits, reports, blocks, account suspensions, logs): our legitimate interest in protecting the service and its users (article 6.1.f).
- Legal obligations: retention of connection data, answers to requests from the authorities and reporting of illegal content (article 6.1.c).
4. Who can see your data
- The event's participants see your display name, your table and your photos. There is no public gallery: the event code is needed to get in. You can block a participant: their photos are no longer shown to you, and they are not told.
- The event's organizers can also moderate photos, remove a participant, manage tables and the guest list, and download the export of all photos.
- The publisher's moderation team sees a photo, its event and the report when the photo is reported to it ("Also report to Pellizz" option, or automatically for the reason "My child / a minor is in the photo"); it handles the report within 24 hours.
- Our processors, only to run the service:
- OVHcloud (OVH SAS, France): hosting of the servers, the database and the photo storage, in the European Union;
- Brevo (Sendinblue SAS, France): sending transactional e-mails, in the European Union;
- Google (Firebase Cloud Messaging): delivery of push notifications, including to iPhones through Apple's notification service (APNs);
- Google (ML Kit), on Android: reading QR codes directly on the phone; the image is not sent, but the kit may send Google technical diagnostic and usage data (phone model and system, app version, performance, installation identifier);
- Apple (Sign in with Apple) and Google (Sign in with Google): sign-in with your Apple or Google account, only if you choose it.
5. Transfers outside the European Union
Your photos and your account are hosted in the European Union (OVHcloud). Google (notifications, QR code reader on Android, Sign in with Google) and Apple (iPhone notifications, Sign in with Apple) may process in the United States the data that goes through their services: notification tokens and contents, technical data from the QR code reader, sign-in identifiers. These transfers are covered by the EU–US Data Privacy Framework these companies adhere to and by the European Commission's standard contractual clauses.
6. For how long
- Events, photos and participation: until the event is deleted automatically, at the end of its plan's retention period (90 days after the event date for the free plan, 365 days for the Premium plan). Organizers get an e-mail reminder 7 days before; deletion only happens at least 7 days after this reminder. An event's date cannot be set more than 7 days in the past. An organizer can also delete the event earlier.
- Photo versions: when a photo is deleted or replaced, the storage keeps the previous version for 30 days at most, to protect against accidental deletion, then erases it.
- Reports: kept with the photo concerned and deleted with it.
- Full account: until you delete it; deletion is immediate. A full account inactive for 3 years is deleted, after a warning e-mail sent 30 days before.
- Guest account: deleted automatically when it no longer has a valid session or a participation in a still active event.
- Sign in with Apple token: kept encrypted until the account is deleted, then revoked with Apple.
- Database backups: kept 30 days at most, then erased.
- ZIP export of photos: link valid 7 days, then the file is deleted.
- Sessions: 30 days (full account) or 1 year (guest account) without use. Links sent by e-mail: 1 to 48 hours.
- Technical logs: 12 months at most.
7. Cookies and trackers
The pellizz.app website sets no cookies and uses no trackers: that is why it shows no consent banner. The app contains no advertising, no audience measurement tool and no advertising tracker.
8. Your rights
You have the right to access, rectify, erase, restrict, object to the processing of and port your data, and to set instructions for what happens to it after your death. You can change your name and language in the app ("Me" tab) and delete your account in the app or from this website. If you own an event, you must first, for each event, transfer it to another participant or delete it. If your name is on an event's guest list, you can ask the organizer or us to remove it.
For other requests, write to privacy@pellizz.app: we answer within one month. For a company event, we forward the requests that concern the organizing company to it and help it answer them. If you believe your rights are not respected, you can lodge a complaint with the CNIL (www.cnil.fr) or your local data protection authority.
9. Security
Traffic is encrypted (HTTPS). Photos are stored in a private space and can only be reached through temporary links given to the event's participants. Passwords are stored as irreversible hashes and session tokens are kept in the phone's secure storage.
10. Children
Pellizz is intended for people aged 13 and over. In France, a minor can consent alone to the processing of their data by an online service from the age of 15 (GDPR article 8 and article 45 of the French Data Protection Act). Between 13 and 15, using Pellizz requires the permission of a person with parental authority, and anything based on consent (notifications, for example) requires the joint consent of the minor and that person. Pellizz is not intended for children under 13: a child may appear in a photo taken by an adult, under that adult's responsibility.
A photo showing a minor is posted under its author's responsibility, who must have the parents' permission. Any parent can report a photo with the reason "My child / a minor is in the photo": the report is sent to the organizers and to the publisher, and the photo is removed quickly. You can also write to hello@pellizz.app.
11. Changes
We may update this policy; the date of the last update is shown at the top of the page. In case of a significant change, we will let you know in the app.