Logo

Legal

Privacy Policy

This policy explains how Ultimasoft Yazılım ve Teknoloji A.Ş. processes personal data when you use Phomo websites, applications, and related services.

Last updated: July 5, 2026

This Privacy Policy describes how Ultimasoft Yazılım ve Teknoloji A.Ş. ("Phomo", "we", "us", or "our") collects, uses, stores, shares, and protects personal data when you visit phomo.io, use our mobile applications, create or access event galleries, or otherwise interact with our services (collectively, the "Services"). By using the Services, you acknowledge that you have read this Privacy Policy. If you do not agree with this policy, please do not use the Services.

1. Data Controller

The data controller responsible for your personal data is Ultimasoft Yazılım ve Teknoloji A.Ş., located at Feneryolu Mah. Yazıcıbaşı Sk. No: 19/15, Kadıköy, İstanbul, Türkiye.

For privacy-related requests, contact us at hello@phomo.io or through our contact page.

2. Scope of This Policy

This policy applies to personal data processed by Phomo in connection with account registration, event creation, photo and video uploads, gallery access, Find Me face search, billing, customer support, marketing communications, and website or application use.

This policy does not apply to third-party websites, services, or applications that may be linked from the Services. Those parties operate under their own privacy policies, and we encourage you to review them separately.

Where you use Phomo as an event organizer, photographer, collaborator, or guest, additional responsibilities may apply to you under applicable law, including obtaining appropriate notices or consents from individuals whose data you upload or make available through an event gallery.

3. Personal Data We Collect

We collect personal data that you provide directly, that is generated through your use of the Services, and that we receive from third parties where permitted by law.

3.1 Account and identity information

  • Name, email address, profile photo, and account credentials
  • Authentication data, including magic-link or sign-in activity
  • Communication preferences and support correspondence

3.2 Event and gallery information

  • Event names, dates, locations, descriptions, branding, and privacy settings
  • Uploaded photos, videos, thumbnails, metadata, and related gallery content
  • Collaborator invitations, attendee registrations, and approval requests
  • QR codes, gallery links, passwords, and access-control settings you configure

3.3 Face recognition and Find Me data

  • Selfies or reference images submitted for Find Me searches
  • Facial feature data and face indexes generated from uploaded photos for matching within an event gallery
  • Search results, confidence scores, and related gallery filtering activity

3.4 Payment and billing information

  • Billing details, transaction history, invoices, and purchased photo credits or video storage
  • Payment status and subscription or top-up records
  • Payment card or payment-method details processed by our payment providers; we do not store full card numbers on our own systems where a payment processor handles that information

3.5 Technical and usage information

  • IP address, browser type, device identifiers, operating system, and language settings
  • Log files, session data, error reports, and security records
  • Pages viewed, features used, upload/download activity, and interaction with notifications
  • Cookie and similar technology data, as described below

3.6 Information from third parties

  • Authentication or profile information from identity providers, where you choose to use them
  • Payment confirmation and fraud-prevention data from payment processors
  • Infrastructure, analytics, and support data from service providers assisting us in operating the Services

4. How We Use Personal Data

We process personal data for the purposes described below and only where we have an appropriate legal basis under applicable law, including the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR").

  • Providing, operating, maintaining, and improving the Services
  • Creating and managing accounts, events, galleries, collaborations, and access controls
  • Processing uploads, generating thumbnails, applying enhancements, watermarks, frames, and delivering downloads
  • Operating Find Me face search and related indexing within event galleries
  • Processing payments, managing credits and video storage, and providing billing support
  • Sending service-related communications, security alerts, and account notifications
  • Responding to support requests and handling complaints or disputes
  • Monitoring, detecting, preventing, and investigating fraud, abuse, security incidents, or unlawful activity
  • Complying with legal obligations, regulatory requests, and enforceable governmental orders
  • Conducting analytics, troubleshooting, product development, and internal reporting in aggregated or de-identified form where possible
  • Sending marketing communications where permitted by law and subject to your choices

6. Face Recognition and Find Me

Phomo offers optional face recognition features, including Find Me, that allow guests to submit a selfie or reference image and view photos in an event gallery in which they may appear. Face recognition is designed for still photos and does not apply to video content.

When enabled for an event, uploaded photos may be analyzed to create face indexes used solely to support matching within that event gallery, subject to the event organizer's settings and applicable law.

Face recognition technology is probabilistic and may produce incomplete, inaccurate, or false matches or non-matches. We do not guarantee the accuracy, completeness, or availability of face recognition results.

Event organizers are responsible for determining whether face recognition is appropriate for their event, configuring privacy settings, providing required notices to guests, and obtaining any consents required under applicable law before enabling face-related features or uploading images of identifiable individuals.

Guests should only use Find Me if they are comfortable submitting a facial image for matching within the relevant event gallery. You may request deletion of certain face-related data as described in the Your Rights section, subject to legal retention requirements and technical limitations.

7. How We Share Personal Data

We do not sell personal data. We may share personal data only as described below:

  • Service providers: cloud hosting, storage, content delivery, payment processing, email delivery, analytics, customer support, security, and face-recognition infrastructure providers that process data on our behalf under contractual safeguards
  • Event organizers and collaborators: where you participate in an event gallery, certain information may be visible to the organizer, moderators, photographers, or other authorized collaborators according to event settings
  • Other users or guests: according to the privacy mode you or the organizer selects, including public galleries, password-protected access, private Find Me-only viewing, or approved attendee access
  • Professional advisers: lawyers, auditors, insurers, or consultants where reasonably necessary
  • Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law
  • Legal and safety reasons: where required by law, regulation, legal process, or governmental request, or where we reasonably believe disclosure is necessary to protect rights, safety, property, or the integrity of the Services

Our infrastructure may involve subprocessors located in Türkiye or other countries. Where personal data is transferred internationally, we implement appropriate safeguards as required by applicable law.

8. Data Retention

We retain personal data only for as long as reasonably necessary to fulfill the purposes described in this policy, provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.

Retention periods may vary depending on the type of data, your account status, event settings, billing records, legal requirements, and backup or archive systems. For example, gallery content may remain available after a hosting period transitions to archive storage according to your plan and product settings.

When data is no longer required, we take reasonable steps to delete, anonymize, or restrict access to it, subject to technical limitations and lawful retention needs.

9. Security

We implement reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption in transit where supported, monitoring, and vendor management.

No method of transmission over the internet or electronic storage is completely secure. Accordingly, we cannot and do not guarantee absolute security of personal data. You are responsible for maintaining the confidentiality of your account credentials and for using appropriate privacy settings for your events.

If you believe your account or data has been compromised, please contact us promptly at hello@phomo.io.

10. Your Rights

Depending on your location and applicable law, you may have some or all of the following rights regarding your personal data:

  • The right to know whether your personal data is being processed
  • The right to request access to personal data we hold about you
  • The right to request correction of inaccurate or incomplete data
  • The right to request deletion or restriction of processing in certain circumstances
  • The right to object to certain processing, including direct marketing where applicable
  • The right to data portability where technically feasible and required by law
  • The right to withdraw consent where processing is based on consent
  • The right to lodge a complaint with a supervisory authority

To exercise your rights, contact us at hello@phomo.io. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law, subject to lawful exceptions.

If you interact with Phomo primarily through an event organized by another person or company, some requests may need to be directed to that organizer, and we may assist where appropriate.

11. Children's Privacy

The Services are not directed to children under 18, and we do not knowingly collect personal data from children under 18 without appropriate authorization. If you believe a child has provided personal data to us without required consent, please contact us and we will take reasonable steps to review and address the request in accordance with applicable law.

12. Cookies and Similar Technologies

We use cookies and similar technologies to operate the Services, remember preferences, maintain sessions, and improve user experience. A detailed list of cookies, providers, durations, and your choices is available in our Cookie Policy.

13. Event Organizers and Guest Data

If you create events, upload photos or videos, invite collaborators, or configure gallery access, you may process personal data of guests, attendees, photographers, or other individuals. In many cases, you are responsible for providing appropriate privacy notices, obtaining required permissions, and complying with applicable data-protection laws for that processing.

Phomo processes such data on your instructions as part of providing the Services. We are not responsible for your collection, upload, disclosure, or use of third-party personal data outside what we reasonably provide through the platform features you choose to enable.

14. Automated Processing

Some features, including face recognition, duplicate detection, image enhancement, and content organization, involve automated processing. These features assist gallery operation but do not, by themselves, produce legal or similarly significant effects concerning you unless expressly stated in a separate agreement or required feature description.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or Services. The updated version will be posted on phomo.io with a revised "Last updated" date. Material changes may also be communicated through the Services or by email where appropriate. Your continued use of the Services after the effective date of an update constitutes acknowledgment of the revised policy, except where further consent is required by law.

Privacy questions or requests

If you have questions about this Privacy Policy or wish to exercise your data-protection rights, contact us using the details below.

Ultimasoft Yazılım ve Teknoloji A.Ş.

Feneryolu Mah. Yazıcıbaşı Sk. No: 19/15

Kadıköy, İstanbul, Türkiye

Tax Office: GÖZTEPE T.O.

Tax No: 8871295480

Email: hello@phomo.io

Contact us