Compliance & security

A product architecture designed for trust.

Bloom® builds consent, retention, and deletion requirements in from the start to guarantee a defensible operational framework.

Explicit, specific, and traceable consent before any selfie.

A non-biometric alternative active by default.

Per-event retention settings with automatic purge.

On-demand guest deletion with an audit trail.

Facial collections isolated per event (no global database).

Continuous monitoring of errors and sensitive incidents.

Facial recognition: optional and governed

Bloom® can use facial recognition (AWS Rekognition) so a guest can find their photos via a selfie. It is never imposed: a non-biometric alternative (access code, browse by day) is on by default. A selfie is processed only after explicit, specific, timestamped consent.

Legal basis — GDPR Article 9

Biometric data falls under Article 9 of the GDPR. Processing relies on the person's explicit consent, collected before any selfie and logged (date, IP, user-agent). Consent can be withdrawn at any time.

Kid-safe — protecting minors

For events where minors may appear, biometrics are disabled and faces estimated as minors are excluded from facial indexing. Access is then by code, with no biometric processing.

Hosting and data location

Photos are stored on CDN infrastructure (Cloudflare R2) and facial recognition runs on AWS Rekognition in a European region. Each event has its own isolated facial collection: there is no global biometric database.

Retention and deletion

Retention is configured per event, with automatic purge at expiry (photos, facial collection, and personal data deleted). A guest can request deletion of their data at any time, executed within 72 hours, with an audit trail.

Your rights

Access, rectification, erasure, objection: write to contact@seidoprotocol.com. You may also lodge a complaint with the CNIL (www.cnil.fr), the French data protection authority.