For your data protection officer
What a DPO or procurement team usually asks before a company buys headshots for its staff, answered in one place. It restates our data protection impact assessment. If you need something that is not here, write to privacy@staffshots.com.
Last updated 25 September 2026
Who is responsible for what
Erik Finans AB (company number 559495-5063, Sweden), trading as Staffshots, is the controller for each person's photograph, for the check that a result looks like them, and for the headshots made from it.
Each colleague signs in with their own account, uploads their own photograph and gives their own consent. There is no way for a team owner to upload photographs for anyone else.
Your company is a separate controller for the headshots it receives. We are not your processor, so there is no Article 28 agreement between us, and you do not need one to use Staffshots.
What your company receives
The headshots each colleague unlocks with the team's credits, and the colleague's name, or the part of their email address before the @ if they have not given one. The team's owners can see and download them. Every colleague is told this in the invitation, before they join.
A headshot a colleague buys with their own card reaches you only if they choose to share that one image with the team. They can take it back whenever they like, and there is deliberately no way for an owner to ask for it.
Your company never receives the photograph a colleague uploaded, or anything derived from their face other than the finished headshots.
Legal bases
| Purpose | Basis |
|---|---|
| Making headshots from a photograph | Explicit consent, Article 9(2)(a), for the biometric check. Contract, Article 6(1)(b), for the rest. |
| Giving your company the headshots it bought | Contract, Article 6(1)(b). It is what the company bought, and the colleague is told before accepting the invitation. |
| Showing the team a headshot a colleague bought privately | Consent, Article 6(1)(a), given by the colleague for each image and withdrawable at any time. |
| Inviting the colleagues your organiser names | Legitimate interests, Article 6(1)(f). The colleague decides by accepting or not. |
| Keeping order records | Legal obligation, Article 6(1)(c): Swedish bookkeeping law, 7 years. |
Biometric data
To check that a generated headshot still looks like the person, we compute a numeric template of their face from the photograph and from each result, and compare the two. This is special category data under Article 9. It is processed only with the person's explicit consent, given in its own tick box before upload, and that consent is recorded with the exact wording they saw. The template is deleted after 30 days, or sooner if the photograph is erased, even when the headshot is kept. It is never used to recognise anyone, and there is no face database.
Processors and other recipients
| Service | What it does | Where | Safeguard |
|---|---|---|---|
| Google Cloud | Hosting, database and storage | Stockholm, Sweden | Google Cloud Data Processing Addendum |
| Google Vertex AI | Generates the headshots from the photograph | Google's global endpoint, which may be outside the EEA | Data Processing Addendum with Standard Contractual Clauses |
| Stripe | Payments, invoices and VAT | EU and US | Stripe DPA with Standard Contractual Clauses |
| Resend | Every email we send | Stored in the US, sent from Ireland | Resend DPA with Standard Contractual Clauses, and the Data Privacy Framework between the EU and the US |
| Lovable | Hosts this website. Photographs and account data go straight to our servers in Stockholm, not through it | Website only | Lovable DPA |
| Google Analytics | Visit statistics, only for visitors who accept them | EU and US | Data Privacy Framework between the EU and the US |
| Google or Microsoft | Sign-in, only for a person who chooses that button | Their own services | Independent controllers. They learn only that the person is signing in to Staffshots |
Transfers outside the EEA
Besides payment details, which Stripe processes in the EU and the US, two things routinely leave the EEA. Photographs go to Google's image model, which has no EU-only endpoint for this work yet. They go with the prompt and nothing else: no name, email address, account identifier or filename, and all metadata is stripped first. Email is stored by Resend in the US. These transfers rest on Standard Contractual Clauses in the providers' data processing terms, and Resend is also certified under the Data Privacy Framework. Everything else, including photographs and headshots at rest, the database and its backups, stays in Google Cloud's Stockholm region.
How long things are kept
| What | Kept for |
|---|---|
| The uploaded photograph, the biometric template, and any preview nobody bought | 30 days, then deleted automatically |
| Headshots someone bought | While their account exists. After two years without a sign-in we email a warning, and delete 30 days later |
| An invitation nobody answered, with the address and any name on it | 30 days after it expires |
| Order records and the credit ledger | 7 years, as Swedish bookkeeping law requires |
| Records of administrator access to personal data | 365 days |
Each person can erase a set, a photograph or their whole account from their account page at any time, and erasure reports what was actually deleted.
Security
- Customer images are never public. Every link to one is signed and expires within minutes.
- Photographs, headshots and the database live in Google Cloud's Stockholm region, encrypted at rest.
- Metadata, including location data, is stripped from every upload before it is stored or sent anywhere, and files are stored under random identifiers.
- Keys and passwords live only in Google Secret Manager. Our services authenticate as service accounts, not with keys in code.
- Every time an administrator reads a customer's email address, IP address or photographs, it is recorded. Only a super administrator can read that record, and their reads are recorded too.
- A written breach procedure is in place, built around the 72 hour deadline for notifying the Swedish authority, IMY.
- We do not hold SOC 2 or ISO 27001 certification ourselves. Our infrastructure runs on Google Cloud, which is certified to ISO/IEC 27001 and audited under SOC 2, and payments go through Stripe, a PCI DSS Level 1 service provider.
Our impact assessment
Because the service processes biometric data, we carried out a data protection impact assessment under Article 35 before launch. It was adopted on 22 August 2026, and it is reviewed whenever the model, the transfers, the retention periods or the kinds of data change, and at least once a year. It assesses every remaining risk as medium or lower, so prior consultation with IMY under Article 36 is not required. For questions about it, write to privacy@staffshots.com.
Requests from your staff
Each person can erase their own data from their account page. For a copy of their data, a correction, or anything else, they write to privacy@staffshots.com, and we answer within a month. Requests about headshots your company has already received are yours to answer, as their controller. The supervisory authority is Integritetsskyddsmyndigheten (IMY).
Who you're buying from
Erik Finans AB
Öljersjö 212
371 94 Lyckeby
Sweden
Company registration number 559495-5063
VAT ID SE559495506301