Legal
Privacy Policy
This policy explains how Ultimasoft Yazılım ve Teknoloji A.Ş. processes personal data when you use Phomo websites, applications, and related services.
Last updated: July 5, 2026
This Privacy Policy describes how Ultimasoft Yazılım ve Teknoloji A.Ş. ("Phomo", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit phomo.io, use our mobile applications, create or access event galleries, or otherwise interact with our services (collectively, the "Services"). By using the Services, you acknowledge that you have read this Privacy Policy. If you do not agree with this policy, please do not use the Services.
1. Data Controller
The data controller responsible for your personal data is Ultimasoft Yazılım ve Teknoloji A.Ş., located at Feneryolu Mah. Yazıcıbaşı Sk. No: 19/15, Kadıköy, İstanbul, Türkiye.
For privacy-related requests, contact us at hello@phomo.io or through our contact page.
2. Scope of This Policy
This policy applies to personal data processed by Phomo in connection with account registration, event creation, photo and video uploads, gallery access, Find Me face search, billing, customer support, marketing communications, and website or application use.
This policy does not apply to third-party websites, services, or applications that may be linked from the Services. Those parties operate under their own privacy policies, and we encourage you to review them separately.
Where you use Phomo as an event organizer, photographer, collaborator, or guest, additional responsibilities may apply to you under applicable law, including obtaining appropriate notices or consents from individuals whose data you upload or make available through an event gallery.
3. Personal Data We Collect
We collect personal data that you provide directly, that is generated through your use of the Services, and that we receive from third parties where permitted by law.
3.1 Account and identity information
- Name, email address, profile photo, and account credentials
- Authentication data, including magic-link or sign-in activity
- Communication preferences and support correspondence
3.2 Event and gallery information
- Event names, dates, locations, descriptions, branding, and privacy settings
- Uploaded photos, videos, thumbnails, metadata, and related gallery content
- Collaborator invitations, attendee registrations, and approval requests
- QR codes, gallery links, passwords, and access-control settings you configure
3.3 Face recognition and Find Me data
- Selfies or reference images submitted for Find Me searches
- Facial feature data and face indexes generated from uploaded photos for matching within an event gallery
- Search results, confidence scores, and related gallery filtering activity
3.4 Payment and billing information
- Billing details, transaction history, invoices, and purchased photo credits or video storage
- Payment status and subscription or top-up records
- Payment card or payment-method details processed by our payment providers; we do not store full card numbers on our own systems where a payment processor handles that information
3.5 Technical and usage information
- IP address, browser type, device identifiers, operating system, and language settings
- Log files, session data, error reports, and security records
- Pages viewed, features used, upload/download activity, and interaction with notifications
- Cookie and similar technology data, as described below
3.6 Information from third parties
- Authentication or profile information from identity providers, where you choose to use them
- Payment confirmation and fraud-prevention data from payment processors
- Infrastructure, analytics, and support data from service providers assisting us in operating the Services
4. How We Use Personal Data
We process personal data for the purposes described below and only where we have an appropriate legal basis under applicable law, including the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR").
- Providing, operating, maintaining, and improving the Services
- Creating and managing accounts, events, galleries, collaborations, and access controls
- Processing uploads, generating thumbnails, applying enhancements, watermarks, frames, and delivering downloads
- Operating Find Me face search and related indexing within event galleries
- Processing payments, managing credits and video storage, and providing billing support
- Sending service-related communications, security alerts, and account notifications
- Responding to support requests and handling complaints or disputes
- Monitoring, detecting, preventing, and investigating fraud, abuse, security incidents, or unlawful activity
- Complying with legal obligations, regulatory requests, and enforceable governmental orders
- Conducting analytics, troubleshooting, product development, and internal reporting in aggregated or de-identified form where possible
- Sending marketing communications where permitted by law and subject to your choices
5. Legal Bases for Processing
Depending on your location and the nature of the processing, we rely on one or more of the following legal bases:
- Performance of a contract: to provide the Services you request, manage your account, and fulfill purchases
- Legitimate interests: to secure, improve, and market the Services, prevent abuse, and support users, provided those interests are not overridden by your rights
- Consent: where required, such as for certain cookies, marketing messages, or optional features
- Legal obligation: to comply with applicable laws, tax rules, court orders, or regulatory requirements
- Vital interests or public interest: only where expressly required and permitted by law
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal, subject to contractual or legal limitations.
6. Face Recognition and Find Me
Phomo offers optional face recognition features, including Find Me, that allow guests to submit a selfie or reference image and view photos in an event gallery in which they may appear. Face recognition is designed for still photos and does not apply to video content.
When enabled for an event, uploaded photos may be analyzed to create face indexes used solely to support matching within that event gallery, subject to the event organizer's settings and applicable law.
Face recognition technology is probabilistic and may produce incomplete, inaccurate, or false matches or non-matches. We do not guarantee the accuracy, completeness, or availability of face recognition results.
Event organizers are responsible for determining whether face recognition is appropriate for their event, configuring privacy settings, providing required notices to guests, and obtaining any consents required under applicable law before enabling face-related features or uploading images of identifiable individuals.
Guests should only use Find Me if they are comfortable submitting a facial image for matching within the relevant event gallery. You may request deletion of certain face-related data as described in the Your Rights section, subject to legal retention requirements and technical limitations.
8. Data Retention
We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this policy, provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
Retention periods may vary depending on the type of data, your account status, event settings, billing records, legal requirements, and backup or archive systems. For example, gallery content may remain available after a hosting period transitions to archive storage according to your plan and product settings.
When data is no longer required, we take reasonable steps to delete, anonymize, or restrict access to it, subject to technical limitations and lawful retention needs.
9. Security
We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption in transit where supported, monitoring, and vendor management.
No method of transmission over the internet or electronic storage is completely secure. Accordingly, we cannot and do not guarantee absolute security of personal data. You are responsible for maintaining the confidentiality of your account credentials and for using appropriate privacy settings for your events.
If you believe your account or data has been compromised, please contact us promptly at hello@phomo.io.
10. Your Rights
Depending on your location and applicable law, you may have some or all of the following rights regarding your personal data:
- The right to know whether your personal data is being processed
- The right to request access to personal data we hold about you
- The right to request correction of inaccurate or incomplete data
- The right to request deletion or restriction of processing in certain circumstances
- The right to object to certain processing, including direct marketing where applicable
- The right to data portability where technically feasible and required by law
- The right to withdraw consent where processing is based on consent
- The right to lodge a complaint with a supervisory authority
To exercise your rights, contact us at hello@phomo.io. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law, subject to lawful exceptions.
If you interact with Phomo primarily through an event organized by another person or company, some requests may need to be directed to that organizer, and we may assist where appropriate.
11. Children's Privacy
The Services are not directed to children under 18, and we do not knowingly collect personal data from children under 18 without appropriate authorization. If you believe a child has provided personal data to us without required consent, please contact us and we will take reasonable steps to review and address the request in accordance with applicable law.
13. Event Organizers and Guest Data
If you create events, upload photos or videos, invite collaborators, or configure gallery access, you may process personal data of guests, attendees, photographers, or other individuals. In many cases, you are responsible for providing appropriate privacy notices, obtaining required permissions, and complying with applicable data-protection laws for that processing.
Phomo processes such data on your instructions as part of providing the Services. We are not responsible for your collection, upload, disclosure, or use of third-party personal data outside what we reasonably provide through the platform features you choose to enable.
14. Automated Processing
Some features, including face recognition, duplicate detection, image enhancement, and content organization, involve automated processing. These features assist gallery operation but do not, by themselves, produce legal or similarly significant effects concerning you unless expressly stated in a separate agreement or required feature description.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or Services. The updated version will be posted on phomo.io with a revised "Last updated" date. Material changes may also be communicated through the Services or by email where appropriate. Your continued use of the Services after the effective date of an update constitutes acknowledgment of the revised policy, except where further consent is required by law.
Privacy questions or requests
If you have questions about this Privacy Policy or wish to exercise your data-protection rights, contact us using the details below.
Ultimasoft Yazılım ve Teknoloji A.Ş.
Feneryolu Mah. Yazıcıbaşı Sk. No: 19/15
Kadıköy, İstanbul, Türkiye
Tax Office: GÖZTEPE T.O.
Tax No: 8871295480
Email: hello@phomo.io