OneDisplayMoments
Back to MomentsTermsPrivacyYour choices

Legal

Privacy Policy

Version 2026-08-25
Effective 25 August 2026

1. Who is responsible2. Data we collect3. Why we use it4. Photos and AI5. Sharing6. International transfers7. Retention8. Your rights9. Security10. Children11. Contact and changes

Moments uses a Guest's name, email and photo to create and deliver the photo experience. Photos may be shown on the relevant Venue's screens. We do not sell Guest photos or use them to train our own AI model. Venue marketing emails or broader promotional reuse by a Venue require separate permission from the Guest.

1. Who is responsible for your data

OneDisplay AB, organisation number 559452-5858, Harmonigatan 10, 854 63 Sundsvall, Sweden, provides and operates the Moments platform. You can contact us at hello@onedisplay.se.

For Venue account administration, platform security, billing and OneDisplay's legal obligations, OneDisplay is the data controller. For a Guest-facing Moment, the Venue shown on the registration screen normally decides the event purpose, theme, audience, moderation and screen display. The Venue is therefore normally the controller for that use, while OneDisplay processes data to provide the platform. The actual roles depend on what each party decides and does; contact either the Venue or OneDisplay if you are unsure.

2. Personal data we collect

  • Venue account data: name, business email, Venue name, membership, login and account settings.
  • Billing data: company details, billing address, VAT number, payment status, invoices and limited payment-method identifiers. Card details are handled by the payment provider.
  • Guest registration data: name, email, Moment, verification state and acceptance records.
  • Image data: original uploads, processing crops, AI-generated images, final branded renders and moderation status.
  • Moment data: prompts, theme, logos, timing, credit use, participant and upload records.
  • Technical and security data: session identifiers, IP-derived rate-limit data, request metadata, error and security logs, device/browser information and timestamps.
  • Support data: messages and information you provide when contacting us.

A photograph of an identifiable person is personal data. A photo can also reveal sensitive information depending on its content. Moments does not use facial recognition to identify people or create biometric identity profiles.

3. Why we use data and our legal bases

PurposeTypical dataLegal basis
Create and administer Venue accounts and MomentsAccount, Moment and contact dataContract; legitimate interests in providing a business service
Register Guests, verify email, process photos and deliver resultsName, email, uploads, generated resultsGuest Terms/contract; Venue's documented legal basis for its event
Display approved results on the relevant event screensFinal render and limited attribution where configuredGuest Terms/contract and the Venue's event purpose
Send Venue marketing emails or reuse finished images in Venue marketingEmail and finished resultsYour optional, Venue-specific consent
Take payment, issue receipts and keep accounting recordsBilling, transaction and company dataContract and legal obligation
Prevent abuse, secure the service and troubleshoot failuresTechnical logs, sessions, identifiers and relevant ContentLegitimate interests in security and reliability; legal obligation where applicable
Handle requests, disputes and legal claimsAccount, support, transaction and relevant activity recordsLegal obligation and legitimate interests in establishing or defending claims

If a Venue wants to reuse a Guest image for unrelated advertising, later campaigns or public social-media promotion, it must obtain a separate valid permission and explain that use. Marketing email and finished-image use are separate choices. Declining either use must not prevent the Guest from taking part in the Moment. Guests can review or withdraw these permissions through their privacy choices.

4. What happens to photos and AI inputs

When AI enhancement is enabled, the original photo or a processing crop and the selected prompt are sent to an AI processing provider to create a result. OneDisplay then stores the returned result long enough to render, moderate, display and deliver the Moment. When AI is disabled, the photo is processed into the selected layout without generative transformation.

We currently use Replicate's API for production AI processing. According to Replicate's published API documentation, prediction inputs, outputs and logs are removed automatically after one hour by default. OneDisplay stores its own required copies under the retention schedule below. We do not use Guest uploads to train our own AI model.

Generated images are synthetic and can be inaccurate or unexpectedly resemble real people, products, characters or brands. See the AI section in our Terms.

5. Who receives personal data

We disclose data only as needed to:

  • the Venue operating the relevant Moment and authorised members of its account;
  • people at the event who can see approved results on the Venue's slideshow screens;
  • infrastructure and object-storage providers that host the application and images;
  • Replicate and the selected model provider for AI processing;
  • email providers for verification links and result delivery;
  • Stripe for checkout, saved payment methods, tax and payment administration;
  • security, error-reporting and professional advisers where necessary; and
  • authorities or other recipients where law requires it or it is necessary to protect legal rights.

We do not sell personal data or Guest photos.

6. Processing outside the EU/EEA

Some service providers may process data outside the EU/EEA. Where this happens, the responsible controller must use an approved transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, and assess whether additional safeguards are needed. Contact us for information about the safeguard relevant to a specific provider.

7. How long we keep data

Our standard production asset schedule is:

  • Original Guest photos: eligible for deletion 30 days after creation once the Moment has ended or been cancelled.
  • AI input crops and generated intermediate files: eligible for deletion after 7 days once the Moment has ended or been cancelled.
  • Final branded results: eligible for deletion after 90 days once the Moment has ended or been cancelled.
  • Expired login, verification and session records: removed by scheduled cleanup after expiry.

Active Moments may retain assets for longer so the service can operate. Venue account, transaction, acceptance and audit data are retained while the account is active and afterward for accounting, security, dispute and statutory limitation periods. Backups rotate separately and deleted information can remain in a protected backup until that backup expires.

A Venue may delete individual uploads earlier through its dashboard. We may retain a minimal record where necessary to document deletion, payment, consent, abuse prevention or a legal claim.

8. Your data-protection rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent at any time without affecting earlier lawful processing.

To make a request, contact the Venue named in the Moment or email hello@onedisplay.se. Include the Venue/Moment name, the email used to register and enough information to identify the upload. We may need to verify your identity. We will route the request to the responsible controller where appropriate.

You may complain to the Swedish Authority for Privacy Protection (IMY) at imy.se, or to the supervisory authority where you live or work.

9. Security and cookies

We use access controls, private asset delivery, time-limited sessions, rate limits, encryption in transit, backups, logging and retention controls designed to protect the service. No system is completely secure, so please contact us promptly if you suspect unauthorised access.

Moments uses essential cookies or equivalent browser storage for Venue authentication, Guest verification and session continuity. These are necessary for the requested service. This version of Moments does not use advertising cookies.

10. Children

Moments is intended for adults. A person under 18 should participate only with permission from a parent or legal guardian. Venues running family events must provide age-appropriate information, obtain any guardian permission required, avoid behavioural advertising, and apply suitable moderation. Contact us to remove a child's image if it may have been uploaded without appropriate permission.

11. Contact and policy changes

We may update this Policy when the service, providers or law changes. We will publish the new version and effective date here and provide additional notice for material changes where appropriate.

Privacy questions: hello@onedisplay.se
OneDisplay AB, Harmonigatan 10, 854 63 Sundsvall, Sweden.

© 2026 OneDisplay AB · Org. no. 559452-5858
TermsPrivacyYour choices