FOTURA

Privacy Policy

Last updated: September 30, 2026

This Policy describes how Fotura processes personal data in accordance with Brazil's General Data Protection Law (Law No. 13,709/2018 — LGPD).

1. Data we process

Photographers: authentication data, studio name, logo, photos, gallery settings, and data needed for the platform to operate securely.

Clients added by photographers: name and, optionally, email address and phone number, plus links to galleries. On a public link, clients do not need to provide this data to Fotura to view the gallery. Selections and comments made in a gallery are also processed to provide the service.

2. Roles in processing client data

When a photographer adds personal data about clients, the photographer determines the purpose and essential means of that processing and acts as controller. Fotura processes that data to provide the contracted features and acts as processor within the photographer's instructions and applicable law.

3. Purposes and legal bases

Account data is processed for authentication, security, service delivery and improvement, and platform-related communications under applicable legal bases, including performance of a contract and other bases available under the LGPD. Photographers are responsible for establishing and maintaining an appropriate legal basis for third-party data they add to Fotura.

4. Sharing

We do not sell personal data. To operate the service, data may be processed by infrastructure providers including Supabase (database and storage) and Vercel (hosting), subject to applicable contractual and security measures.

5. Security

Photos are stored in a private bucket and made available through temporary signed links. Communications use HTTPS, and access controls and account isolation measures are applied.

6. Retention, export, and account closure

Account data is kept while needed to provide the service and for periods required by legal obligations. Photographers can edit or delete client records they created. If a client record is deleted, its galleries may remain but without the registered link to that client. Data may be retained when a legal obligation or another basis permitted by the LGPD applies.

Account holders can request a structured export of their data in Settings. They can also start account closure. Closure includes a safety period and a confirmation step before account access and public content are blocked; final physical deletion is handled separately to reduce accidental data-loss risk and respect legally required retention.

7. Data-subject rights

Where applicable, the LGPD provides rights including confirmation, access, correction, anonymization, blocking, deletion, portability, information, and withdrawal of consent. For Fotura account holders, export and closure tools available in Settings support access, portability, and deletion requests without limiting the direct contact described in this Policy.

For client data entered by a photographer, requests concerning that data should first be directed to the responsible photographer, who is the controller. Fotura will provide technically appropriate assistance to the photographer. Data subjects may also use the contact below for questions related to processing carried out by Fotura.

8. Cookies

Fotura uses essential cookies for authentication and session operation. It does not use advertising cookies in the currently available flow.

9. Changes

This Policy may be updated to reflect changes to the service or legal requirements. Material changes may be communicated through available channels.

10. Contact

Privacy questions and requests can be sent to izaqueandrade384@gmail.com.

Terms of Use•Back to sign in