Skip to content
Relivo
Data Processing Agreement

Relivo signs a DPA with every customer.

Last updated 12 August 2026

When your organization uses Relivo, Digitalstories BV acts as a processor of your attendees' personal data under the GDPR. We formalize that relationship in a Data Processing Agreement (DPA) before your first event. Request the current version at info@relivo.io.

  1. What the DPA covers

    The DPA sets out how Digitalstories BV processes personal data on your behalf: the subject matter and duration of processing, the nature and purposes of processing, the types of personal data (including selfie-derived face embeddings used for photo matching), the categories of data subjects, and the obligations and rights of both parties under Article 28 of the General Data Protection Regulation.

  2. Our processing commitments

    • Consent-first design: attendees opt in explicitly with a selfie and email, and consent is revocable at any time from a one-click link in every email.
    • EU hosting: personal data is processed on EU infrastructure.
    • Proprietary AI: our facial-recognition stack is trained, deployed and operated entirely in-house. No third-party models process your attendees' biometric data.
    • Retention controls: you set the retention window per event (90 days by default), after which face embeddings and personal galleries are deleted automatically.
    • Sub-processors: we maintain and publish a sub-processor list, available with the DPA on request.
    • Security: technical and organisational measures protect personal data against loss, unlawful access and any other form of unlawful processing.
  3. How to get a signed DPA

    Email info@relivo.io and we'll share the current DPA, sub-processor list and supporting security documentation before you sign anything. Enterprise customers can also request our data protection impact assessment (DPIA) documentation as part of procurement.