EIDOS PHOTOGRAPHY

Privacy & Cookie Policy

Effective 30 July 2026  |  Rome, Italy

1. Data controller

The controller of personal data is:

Jafar Razaghi, trading as Eidos Photography ("Eidos", "we", "us" or "our") Via Raffaele Stasi 36B, int. 14, 00189 Rome (RM), Italy Partita IVA: 17279541001 Email: hello@eidosphotography.com Phone / WhatsApp: +39 351 881 1978

This Policy covers eidosphotography.com, inquiries, bookings, sessions, galleries, delivery, support and related business activities.

2. Data we process

Depending on your interaction with us, we may process:

  • contact and identity details;
  • booking details, preferences, locations, participant information and communications;
  • photographs, video, audio, file metadata, selections and gallery activity;
  • payment status, transaction references, invoices and refunds;
  • emails, WhatsApp or social-media messages, reviews and complaints;
  • IP address, device, browser, referring page, site activity, security logs and cookie choices; and
  • marketing and photograph-publication preferences.

Payment-card or bank credentials are normally handled directly by the payment provider and are not stored by Eidos. Please do not send sensitive or health information unless genuinely necessary for safe planning.

3. Purposes and legal bases

We process data where necessary to:

  • answer inquiries and prepare a quote - steps requested before a contract;
  • confirm, manage, photograph, edit and deliver a booking - performance of a contract;
  • take payment, invoice and comply with tax or legal duties - contract and legal obligation;
  • provide support, prevent fraud, secure the site and handle or defend claims - contract, legal obligation and legitimate interests;
  • send optional newsletters - consent, unless another lawful basis applies;
  • publish identifiable Client images for promotion - separate express consent or another specifically documented lawful basis; and
  • use non-essential analytics or advertising technologies - consent.

Information needed to identify the Client, arrange the session, take payment and deliver the work is required to perform the contract. Optional marketing and portfolio consent are never conditions of the standard service.

Eidos does not make solely automated decisions that produce legal or similarly significant effects on Clients.

4. Photographs and portfolio publication

We process session images to provide the booked service, edit and deliver the agreed files, handle quality issues and protect legal rights.

Private delivery is separate from promotional publication. We do not treat acceptance of the Terms as consent to advertising use. Where consent is used, it is optional, specific and may be withdrawn for future use. For an identifiable child under 14, Eidos may require consent from both holders of parental responsibility before online promotional publication.

5. Recipients and international transfers

Data may be shared only as reasonably necessary with Eidos photographers, assistants and editors; website, hosting, booking, payment, gallery and communication providers; requested independent suppliers; accountants, insurers and lawyers; and public authorities where required by law.

Providers may include, where used, Webflow, Vercel, Bókun, PayPal, Pixieset, WhatsApp/Meta and Google services. Some providers act as independent controllers under their own policies.

Where data is processed outside the European Economic Area, we rely where required on an adequacy decision, the EU-US Data Privacy Framework for a participating recipient, Standard Contractual Clauses or another safeguard permitted by GDPR.

We do not sell Client contact details or photographs.

6. Retention

We keep data only as long as needed for the stated purpose, legal compliance and claims. Typical periods are:

  • unsuccessful inquiries: up to 12 months after the last substantive contact;
  • booking and support records: normally up to five years;
  • invoices and tax records: as required by Italian law, generally up to ten years;
  • delivered gallery: normally at least 30 days or the period shown in the delivery email;
  • RAW and unselected files: may be permanently deleted 14 days after final delivery;
  • marketing data: until consent is withdrawn, subject to a minimal suppression record; and
  • portfolio images: until consent is withdrawn or the material is no longer needed, subject to lawful prior use and printed materials already distributed.

A legal hold, dispute or statutory duty may require a different period.

7. Cookies and similar technologies

The site may use cookies, pixels, tags and local storage:

  • Strictly necessary: security, checkout, forms, fraud prevention and consent preferences. These may operate without optional consent where permitted.
  • Analytics: traffic and performance measurement.
  • Advertising: campaign measurement, attribution and personalised advertising.

Non-essential analytics and advertising technologies must remain disabled until valid consent is given where required. Visitors can accept, reject or choose categories and later change their decision through Manage Cookie Preferences in the footer.

The consent panel must show the current provider, purpose and duration for each cookie or similar technology detected on the live site. Google Tag Manager must not be used to bypass a visitor's choice.

8. Marketing

We send optional newsletters or unrelated promotions only where a valid legal basis applies. You may unsubscribe through the message link or by emailing Eidos. This does not stop necessary messages about an inquiry, booking, payment or gallery.

9. Your GDPR rights

Subject to applicable conditions, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time for future processing.

Send requests to hello@eidosphotography.com. We may request reasonable proof of identity and normally respond within one month, subject to permitted extensions.

You may also complain to the Italian supervisory authority:

Garante per la protezione dei dati personali https://www.garanteprivacy.it

Deletion is not absolute; data may be retained for tax, fraud-prevention, consent records, legal claims or another lawful purpose.

10. Security and galleries

We use reasonable technical and organisational measures, access controls and reputable service providers. No internet or storage system is completely risk-free.

The Client must protect gallery links and passwords and download files before expiry. Eidos cannot control access resulting from the Client sharing a link or password.

11. Children and third-party services

Bookings are intended for adults. Children may be photographed when a parent or authorised adult arranges and supervises the session.

Our site may link to marketplaces, payment providers, maps, galleries, social media and other third-party services. Their own privacy policies apply to their processing.

12. Changes and contact

We may update this Policy to reflect changes in law, services or technology. The current version and date will appear on this page. A change will not retrospectively create a new consent.

Privacy questions and requests may be sent to:

Eidos Photography hello@eidosphotography.com +39 351 881 1978 Via Raffaele Stasi 36B, int. 14, 00189 Rome (RM), Italy