Privacy Policy
Last updated: 1 September 2026
1. Data Controller
The data controller for portraitdesk.com and all PortraitDesk products is:
TimmiStudio di VD
Trading as PortraitDesk
Italy
Email: info@portraitdesk.com
For any questions relating to this policy or to exercise your rights, contact us at the address above.
2. Data We Collect
Data you provide directly
- Account registration: name, email address, password (stored as a bcrypt hash — never in plain text), studio name.
- Payment: billing name and email. Card details are processed directly by Stripe and are never stored on our servers.
- Support enquiries: any information you include when contacting us by email.
Data collected automatically
- Usage data: pages visited, time on page, browser type, operating system, approximate geographic location (country level) — collected via Google Analytics 4, only with your explicit consent.
- Server logs: IP address, request timestamp, HTTP status code. Retained for 30 days for security purposes.
- Consent records: when you accept or decline cookies, we log the decision, timestamp, approximate country, and page URL.
Data about your clients (photographers only)
If you are a photographer using HeadshotQueue or another PortraitDesk platform, you may upload or collect data about your own clients (names, email addresses, photographs, registration details). In this context, you are the data controller for your clients' personal data and we act as a data processor on your behalf. We process this data solely to provide the platform service and never use it for our own purposes.
3. Legal Basis for Processing (GDPR)
- Contract performance (Art. 6(1)(b)): processing your account and payment data to provide the service you subscribed to.
- Legitimate interests (Art. 6(1)(f)): server log retention for security and fraud prevention.
- Consent (Art. 6(1)(a)): analytics and non-essential cookies — only collected after you explicitly accept via the consent banner.
- Legal obligation (Art. 6(1)(c)): retaining transaction records as required by Italian fiscal law.
4. How We Use Your Data
- To create and manage your account
- To process payments and send transaction receipts
- To operate, maintain, and improve the platform
- To send transactional emails (gallery delivery notifications, password resets) — we do not send marketing emails without explicit opt-in
- To measure and analyse platform usage (only with your consent)
- To detect, investigate, and prevent security incidents and abuse
- To comply with legal obligations
We do not sell your data to any third party. We do not use your data for advertising.
5. Third-Party Services
Stripe
Payment processing. When you subscribe, you interact with Stripe's secure payment form. Stripe collects and processes your card data under their own privacy policy — we receive only a payment confirmation and customer reference.
stripe.com/privacy
Google Analytics 4
Used to analyse website traffic and user behaviour — only when you have given consent. We have enabled IP anonymisation and do not use Google Analytics advertising features. Google may process data in the United States under Standard Contractual Clauses.
policies.google.com/privacy ·
Opt-out browser add-on
Amazon Web Services (S3)
Photos, logos, and other files are stored on Amazon S3 in a data centre in the European Union. AWS processes data solely to store and serve files on our behalf and does not access or use content for its own purposes.
aws.amazon.com/privacy
Hosting Provider
The platform is hosted on servers based in the European Union. The hosting provider processes server access logs for security purposes.
6. Data Retention
- Account data: retained while your account is active and for 2 years after closure.
- Payment records: retained for 10 years as required by Italian fiscal law.
- Client data uploaded by photographers: deleted within 30 days of account deletion or on written request.
- Analytics data: retained for 14 months in Google Analytics, then automatically deleted.
- Server logs: retained for 30 days.
- Consent records: retained for 3 years as evidence of consent, then automatically deleted.
7. Your GDPR Rights
If you are in the EEA or United Kingdom, you have the following rights. See our GDPR Rights page for full details and how to exercise them.
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time
- Right to lodge a complaint with the Italian Data Protection Authority or your national supervisory authority
To exercise any right, email info@portraitdesk.com. We respond within 30 days.
8. International Data Transfers
Google Analytics may transfer data to the United States under the EU-US Data Privacy Framework and Google's Standard Contractual Clauses (Art. 46 GDPR). Stripe operates under Standard Contractual Clauses for any transfers outside the EEA. AWS stores data within the EU.
9. Security
We implement appropriate technical and organisational measures including:
- HTTPS encryption on all pages (TLS 1.2+)
- Passwords stored as bcrypt hashes — never in plain text
- Payment card data never stored on our servers
- Access to production systems limited to authorised personnel
In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Arts. 33–34.
10. Changes to This Policy
We may update this policy from time to time. We will update the date at the top of this page and notify you by email at the address on your account for material changes. Continued use after changes constitutes acceptance.
11. Contact
TimmiStudio di VD (trading as PortraitDesk)
Italy
info@portraitdesk.com