Our Core Privacy Commitment to Studios
AuraPix AI operates strictly on a Zero-Data-Monetization model. We never sell, license, or monetize your photographs, client databases, or studio revenues. You retain 100% intellectual property ownership of every pixel uploaded to our cloud.
1. Scope & Studio Data Sovereignty
This Privacy Policy describes the policies and practices of AuraPix AI ("we", "us", or "our", operated by SB Photo Art Technologies) regarding the collection, processing, storage, and transfer of information through the AuraPix AI web platform, mobile Progressive Web Applications (PWAs), client galleries, and associated APIs.
This policy applies to all registered photography studios, cinematographers, freelance crew members, and guests accessing galleries hosted on our domains (aurapix.ai and branded custom domains).
2. Information We Collect
We collect information strictly necessary to provide and operate our studio operating system:
- Studio Account Data: Studio name, primary contact name, phone/WhatsApp number, email address, physical studio address, GSTIN (for Indian tax invoicing), and login credentials.
- Client & Event Metadata: Couple names, ceremony dates, event titles (Haldi, Mehendi, Wedding, Reception), event PIN codes, and client contact information entered by the studio for automated gallery links.
- Media Files: Photographs, digital album spreads, and video highlights uploaded by the studio for processing, client shortlisting, and delivery.
- Technical Telemetry: Browser type, device IP address, operating system, and access timestamps for security logging, DDoS prevention, and performance diagnostics.
3. Treatment of Facial Recognition & Biometric Data
AuraPix AI utilizes proprietary deep neural network computer vision to facilitate instant guest photo discovery ("Selfie Search"):
How AI Face Recognition Operates Without Storing Raw Biometrics:
1. When a guest uploads a selfie to find their wedding photos, our system transforms the facial landmarks into a non-reversible mathematical vector hash (128-dimensional embedding).
2. The raw selfie photograph is processed in volatile memory and deleted immediately after the search session.
3. Vector hashes are strictly sandboxed per event. An embedding from Wedding A cannot match, scan, or access Wedding B.
4. We strictly never train public or third-party foundational AI models using studio photographs.
4. Cloud Security, Storage & Encryption Standards
We enforce enterprise defense-in-depth measures to protect your digital assets:
- Data at Rest: Encrypted with Advanced Encryption Standard (AES-256) on AWS S3 and DynamoDB data stores situated in the AWS Asia Pacific (Mumbai) region.
- Data in Transit: Enforced Transport Layer Security (TLS 1.3 / SSL) for all web, mobile, and API communications.
- Watermark Protection: Automatic real-time watermarking protects client galleries from unauthorized downloads until the studio marks an event fully paid.
- Access Control: Multi-tenant architecture with role-based access control (RBAC), multi-factor authentication (MFA), and session timeout locks.
5. Data Sharing & Third-Party Services
We do not share your private data with marketing agencies or data brokers. Third-party disclosures are restricted strictly to infrastructure partners under strict non-disclosure contracts:
- Cloud Infrastructure: Amazon Web Services (AWS) Mumbai for high-speed local hosting and data replication.
- WhatsApp Cloud API: Official Meta Business Cloud API for automated studio quotations, event notifications, and anniversary greetings configured by the studio.
- Legal Authorities: Disclosures only when compelled by valid legal summons under applicable Indian statutory laws.
6. Data Retention, Portability & Deletion
Studios maintain full control over asset lifecycles:
- Active Subscriptions: Events remain hosted as long as your storage quota and subscription remain active.
- Export & Portability: Studios can download full-resolution ZIP archives and CSV client databases anytime with a single click.
- Account Cancellation: Upon cancellation or written deletion request, all photographs, database records, and face embeddings are permanently wiped from primary storage within 30 calendar days.
7. Payment Processing & PCI-DSS Compliance
AuraPix AI does not store credit card, debit card, CVV, or bank net-banking passwords on our infrastructure. All subscription transactions are routed through RBI-licensed payment aggregators (Razorpay, Cashfree, or Stripe) utilizing PCI-DSS Level 1 certified tokenization.
8. Studio & Client Rights (DPDP Act 2023)
Under the Digital Personal Data Protection Act 2023 of India, studios and their clients enjoy the following statutory rights:
- Right to Access: Inspect the exact data stored under your studio workspace.
- Right to Correction: Update inaccurate client, billing, or event records.
- Right to Erasure: Request immediate deletion of specific event albums, guest selfies, or full accounts.
- Right of Grievance Redressal: Direct access to our designated Indian Grievance Officer.
9. Grievance Redressal & Data Protection Officer (DPO)
In accordance with the Information Technology Act 2000 and DPDP Act 2023, the details of our Grievance Officer are published below:
Grievance Officer: Data Protection & Legal Compliance
Entity: AuraPix AI (SB Photo Art Technologies)
Registered Location: Vill-Jaisalmer, State-Rajasthan 345001, India
Email: aurapixpro@gmail.com · Helpline: +91 89552 34292