1. Data controller
Photo247 (Oslo, Norway) is the data controller for personal data processed through this website. Contact: privacy@photo247.com.
Photo247 · Legal
Last updated: 2026-05-23
This Privacy Policy explains what personal data Photo247 processes, why we process it, and what choices you have. For GDPR-specific information, see our GDPR page.
Photo247 (Oslo, Norway) is the data controller for personal data processed through this website. Contact: privacy@photo247.com.
Account data: name, email, username, password hash, profile details, location fields, avatar, and work interests. Content data: photos, titles, descriptions, EXIF/GPS metadata you choose to store, comments, likes, follows, and messages. Technical data: session cookies, IP address, browser type, and server logs used for security and troubleshooting.
We process data to create and manage accounts, display profiles and photos, operate search and maps, deliver messages, prevent abuse, improve the service, and comply with legal obligations. Legal bases under GDPR include contract (providing the service), legitimate interests (security and product improvement), and consent where required (non-essential cookies).
Essential cookies keep you signed in and protect forms (CSRF). Optional cookies may be used later for analytics. You can accept or reject non-essential cookies via the cookie banner. See also our GDPR page for details on storage duration and withdrawal of consent.
We do not sell personal data. Public profile and photo information is visible to other users and search engines according to your settings and page visibility. Data is kept while your account is active and for a reasonable period afterward for backups, legal compliance, and dispute resolution.
Depending on your location, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent at any time. Contact privacy@photo247.com or use account settings where available. You may also lodge a complaint with your local supervisory authority.
If data is processed outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses where required.