Data and consent
What happens to a guest's photograph.
A portrait activation collects a face and, usually, a phone number. That is personal information under POPIA, and part of it is sensitive. This page sets out what we collect, what each guest is asked, how long anything is kept, and how it is deleted. It is written to be read by your legal and compliance team, not only your marketing team.
Three separate consents
Bundled consent is not consent.
A guest is asked three distinct questions and can answer yes to one and no to the others. Nothing is pre-ticked, and declining the second and third still gets them their portrait.
- 01
To take and style the photograph
Asked at the station, before the shutter, in plain language: what will be photographed, that it will be styled by an AI model, and that a host will review the result. A guest who declines is not photographed.
Required for the portrait
- 02
To receive the portrait, and how
The guest gives a WhatsApp number or an email address for delivery only. Used for that delivery and nothing else unless the third consent is also given.
Required for delivery
- 03
To be contacted, and for their image to be used
Two separate opt-ins: marketing contact by the brand, and the brand's use of the portrait in its own channels. Both are optional, both are recorded individually, and either can be declined while still receiving the portrait.
Always optional
Electronic direct marketing to someone who is not already a customer requires their prior consent under section 69 of POPIA. That is why the marketing opt-in is separate and never bundled with delivery — a guest who only wanted their picture has not agreed to a newsletter.
The part most suppliers skip
A face is not ordinary personal information.
POPIA treats biometric information as special personal information, with a higher bar for processing. A photograph of a face, captured and processed by a system, sits close enough to that line that we treat it as though it crosses it rather than arguing that it does not.
In practice that means: explicit consent at the point of capture rather than implied consent from attendance; no facial recognition, matching, indexing or identification of any kind; no use of guest images to train or fine-tune any model, ours or a vendor's; and the shortest retention we can operate with.
If a supplier tells you a photo booth does not touch special personal information, ask them to put it in writing.
Where the data goes
Who touches it, and in which country.
Section 72 of POPIA restricts sending personal information outside South Africa. It can be done, but the conditions have to be met and disclosed rather than assumed.
| Stage | Where | Who can access it |
|---|---|---|
| Capture | On the station, in the venue | The host on duty. The station is passcode-locked and its storage is encrypted. |
| Styling | A contracted image-processing provider, which may be outside South Africa | Automated processing only. Covered by a written agreement meeting the section 72 conditions, with no rights for the provider to retain, reuse or train on the image. |
| Delivery and gallery | Hosted in South Africa | The guest, by a private link. Your named team members, if you have taken the gallery option. |
| Lead export | Handed to you, then deleted from our side on the retention schedule below | Your named contact. Transferred over an authenticated channel, never as an unprotected email attachment. |
Where the styling step runs outside South Africa, that is disclosed in the consent wording at the station rather than buried in a policy the guest will not read. If your organisation requires all processing to stay in the country, say so at briefing — it changes the toolchain and the price, and it is a change we can make.
Your own enquiry, separately
The brief you send through this site — your name, your email, and the event details — is delivered by a contracted email provider whose infrastructure is in the European Union. That is a section 72 transfer in its own right, made under a written agreement, and it is separate from anything to do with your guests. The record is kept while we are in a conversation about the event and deleted on request at any point.
Retention
Everything has a delete date, set before the event.
The default schedule is below. It can be shortened for your activation at no cost. Lengthening it needs a documented reason, because keeping personal information longer than necessary is itself a breach of the minimality condition.
| What | Kept for | Then |
|---|---|---|
| Original capture frame | 7 days | Deleted. Held only long enough to re-run a styling failure. |
| Styled portrait | 30 days in the guest gallery | Deleted from our systems. Your own copy is yours to govern from that point. |
| Guest contact details | Until handed to you, and no more than 30 days | Deleted from our systems. You become the responsible party for the copy you hold. |
| Consent records | 3 years | Retained as evidence that consent was given, and for no other purpose. Kept separately from the images. |
| Activation report | Indefinitely | Aggregate counts only. Contains no personal information and no images. |
Who is responsible for what
The handover is the moment the responsibility moves.
For the capture and styling of the portrait, Signal Frame is the responsible party. We decide how the photograph is processed, we take the consent, and we answer for it.
For the marketing data, you are the responsible party and we act as your operator. The guest is consenting to be contacted by your brand, not by us. We collect it on your behalf, hand it over, and delete our copy.
That means the marketing consent wording has to match what your privacy notice says you will do with the data. We will draft it, but you have to approve it before the event, and we will not run an activation where the two contradict each other.
Guest rights
A guest can change their mind, and it has to actually work.
Every delivery message carries a working deletion link. No account, no login, no reply-and-wait.
Deletion
One tap from the delivery message removes the portrait and the capture frame. Actioned within 48 hours, and confirmed back to the guest.
Access and correction
A guest can ask what we hold about them and have it corrected. We respond within 30 days, at no charge.
Objection to marketing
Withdrawing the marketing consent is a single tap and takes effect immediately. We notify you so your own list stays accurate.
Complaints
A guest who is not satisfied with our response may complain to the Information Regulator. We will tell them so rather than waiting for them to find out.
What we need from you
Four things, at briefing.
- 01Your privacy notice, or a link to it, so the consent wording at the station can point at something real.
- 02Confirmation of who the responsible party is for the marketing data, and the name of your Information Officer.
- 03Any retention period shorter than our default that your policy requires.
- 04Whether your organisation requires all processing to remain inside South Africa.
Send this to your compliance team.
If it raises questions, that is the point. We would rather answer them now than discover a disagreement three days before an activation. We will complete a vendor security questionnaire and sign an operator agreement on your paper.
Delivery, throughput and uptime are covered separately. Read the service standards.