For your data protection officer

What a DPO or procurement team usually asks before a company buys headshots for its staff, answered in one place. It restates our data protection impact assessment. If you need something that is not here, write to privacy@staffshots.com.

Last updated 25 September 2026

Who is responsible for what

Erik Finans AB (company number 559495-5063, Sweden), trading as Staffshots, is the controller for each person's photograph, for the check that a result looks like them, and for the headshots made from it.

Each colleague signs in with their own account, uploads their own photograph and gives their own consent. There is no way for a team owner to upload photographs for anyone else.

Your company is a separate controller for the headshots it receives. We are not your processor, so there is no Article 28 agreement between us, and you do not need one to use Staffshots.

What your company receives

The headshots each colleague unlocks with the team's credits, and the colleague's name, or the part of their email address before the @ if they have not given one. The team's owners can see and download them. Every colleague is told this in the invitation, before they join.

A headshot a colleague buys with their own card reaches you only if they choose to share that one image with the team. They can take it back whenever they like, and there is deliberately no way for an owner to ask for it.

Your company never receives the photograph a colleague uploaded, or anything derived from their face other than the finished headshots.

Legal bases

PurposeBasis
Making headshots from a photographExplicit consent, Article 9(2)(a), for the biometric check. Contract, Article 6(1)(b), for the rest.
Giving your company the headshots it boughtContract, Article 6(1)(b). It is what the company bought, and the colleague is told before accepting the invitation.
Showing the team a headshot a colleague bought privatelyConsent, Article 6(1)(a), given by the colleague for each image and withdrawable at any time.
Inviting the colleagues your organiser namesLegitimate interests, Article 6(1)(f). The colleague decides by accepting or not.
Keeping order recordsLegal obligation, Article 6(1)(c): Swedish bookkeeping law, 7 years.

Biometric data

To check that a generated headshot still looks like the person, we compute a numeric template of their face from the photograph and from each result, and compare the two. This is special category data under Article 9. It is processed only with the person's explicit consent, given in its own tick box before upload, and that consent is recorded with the exact wording they saw. The template is deleted after 30 days, or sooner if the photograph is erased, even when the headshot is kept. It is never used to recognise anyone, and there is no face database.

Processors and other recipients

ServiceWhat it doesWhereSafeguard
Google CloudHosting, database and storageStockholm, SwedenGoogle Cloud Data Processing Addendum
Google Vertex AIGenerates the headshots from the photographGoogle's global endpoint, which may be outside the EEAData Processing Addendum with Standard Contractual Clauses
StripePayments, invoices and VATEU and USStripe DPA with Standard Contractual Clauses
ResendEvery email we sendStored in the US, sent from IrelandResend DPA with Standard Contractual Clauses, and the Data Privacy Framework between the EU and the US
LovableHosts this website. Photographs and account data go straight to our servers in Stockholm, not through itWebsite onlyLovable DPA
Google AnalyticsVisit statistics, only for visitors who accept themEU and USData Privacy Framework between the EU and the US
Google or MicrosoftSign-in, only for a person who chooses that buttonTheir own servicesIndependent controllers. They learn only that the person is signing in to Staffshots

Transfers outside the EEA

Besides payment details, which Stripe processes in the EU and the US, two things routinely leave the EEA. Photographs go to Google's image model, which has no EU-only endpoint for this work yet. They go with the prompt and nothing else: no name, email address, account identifier or filename, and all metadata is stripped first. Email is stored by Resend in the US. These transfers rest on Standard Contractual Clauses in the providers' data processing terms, and Resend is also certified under the Data Privacy Framework. Everything else, including photographs and headshots at rest, the database and its backups, stays in Google Cloud's Stockholm region.

How long things are kept

WhatKept for
The uploaded photograph, the biometric template, and any preview nobody bought30 days, then deleted automatically
Headshots someone boughtWhile their account exists. After two years without a sign-in we email a warning, and delete 30 days later
An invitation nobody answered, with the address and any name on it30 days after it expires
Order records and the credit ledger7 years, as Swedish bookkeeping law requires
Records of administrator access to personal data365 days

Each person can erase a set, a photograph or their whole account from their account page at any time, and erasure reports what was actually deleted.

Security

  • Customer images are never public. Every link to one is signed and expires within minutes.
  • Photographs, headshots and the database live in Google Cloud's Stockholm region, encrypted at rest.
  • Metadata, including location data, is stripped from every upload before it is stored or sent anywhere, and files are stored under random identifiers.
  • Keys and passwords live only in Google Secret Manager. Our services authenticate as service accounts, not with keys in code.
  • Every time an administrator reads a customer's email address, IP address or photographs, it is recorded. Only a super administrator can read that record, and their reads are recorded too.
  • A written breach procedure is in place, built around the 72 hour deadline for notifying the Swedish authority, IMY.
  • We do not hold SOC 2 or ISO 27001 certification ourselves. Our infrastructure runs on Google Cloud, which is certified to ISO/IEC 27001 and audited under SOC 2, and payments go through Stripe, a PCI DSS Level 1 service provider.

Our impact assessment

Because the service processes biometric data, we carried out a data protection impact assessment under Article 35 before launch. It was adopted on 22 August 2026, and it is reviewed whenever the model, the transfers, the retention periods or the kinds of data change, and at least once a year. It assesses every remaining risk as medium or lower, so prior consultation with IMY under Article 36 is not required. For questions about it, write to privacy@staffshots.com.

Requests from your staff

Each person can erase their own data from their account page. For a copy of their data, a correction, or anything else, they write to privacy@staffshots.com, and we answer within a month. Requests about headshots your company has already received are yours to answer, as their controller. The supervisory authority is Integritetsskyddsmyndigheten (IMY).

Who you're buying from

Erik Finans AB

Öljersjö 212

371 94 Lyckeby

Sweden

Company registration number 559495-5063

VAT ID SE559495506301

Questions and billing: hello@staffshots.com

Privacy requests: privacy@staffshots.com

privacy@staffshots.com