Legal · Natali Kornata

Privacy Policy

Last updated: 2026-09-06

What data we collect

We collect only what's needed to run the site and, with your consent, to see how it's used:

  • Analytics (page views, interactions), only if you consent.
  • A session token when you open a private gallery via a magic link.
  • Your language preference and your cookie choice (first-party cookies).
  • Your name when you leave feedback in a private gallery (hearts, lists, photo notes, reviews), and an email if you choose to add one. Browsing and downloading do not ask for them.
  • A record of the feedback you leave in a private gallery (which photos you hearted or added to lists, note edits, reviews), shown only to the photographer.
  • A download count when you use the full-resolution download on a public gallery (if enabled), with no personal identifier attached.
  • Details you submit in a services inquiry (name, email, optional phone or WhatsApp, preferred date, how you prefer to be contacted, number of people, wedding guest count where asked, location, budget where asked, your message, plus the language and page you sent it from), used only to reply. It does not create a booking.
  • A review you choose to leave on a gallery (a star rating, optional text, and the name you type), used as feedback for the photographer and not shown to other visitors.
  • Standard web-server logs. Like any website, our server records each request with its time, the page asked for, the browser and the network address it came from, so the site keeps running and abuse can be spotted. They rotate automatically, are never used for analytics and are never joined to anything else on this page.

Analytics & consent

Analytics is off by default and runs only if you click Accept on the consent banner.

When on, each page view records the page, an approximate location (country, region, city, derived on our server, never your IP), your device, browser, screen size and pixel density, light or dark mode preference, connection type and speed hints, device memory and processor cores, touch support, the referrer and any campaign (UTM) tags in the link you arrived by, language and time zone, tied only to a random ID, never your name or email. In galleries, where you zoom into a photo is recorded as an anonymous heat map with no identifier at all. Deleted after 24 months.

Decline, and no analytics identifier or event is stored. The only thing kept is your choice itself, so we do not ask again on every page.

Change your choice anytime via Cookie settings in the footer. We remember it for up to 12 months, then ask again.

Opening a private gallery via a magic link sets a strictly-necessary session cookie so the gallery works. It expires after 30 days or when you close your browser, and is never used for ads or analytics.

The photographer can also write a name against a link, so she can tell her links apart ("Nora and Tom"). It is optional and does not change what the link gives access to. When the gallery asks for your name, that label may be offered as an editable suggestion. Your email address is used to send the invite and is not stored with the link.

Face grouping in private galleries

If we switch it on for a particular private gallery, the photos in that gallery are analysed to group the people who appear in them, so you can filter the gallery down to one person. It is off by default and is enabled one gallery at a time.

Grouping faces this way creates biometric data, a special category of personal data under Article 9 GDPR. We are responsible for obtaining the consent of the people photographed before enabling it for a shoot.

The analysis runs entirely on our own server. No photo, face crop or facial measurement is sent to any third-party service, and none of it is used to train anything.

Grouping never crosses galleries. A person grouped in one shoot is never matched against another gallery, and there is no search across the site.

Face data lives and dies with its gallery. Deleting the gallery, or the 24-month retention sweep, removes the measurements and the face crops together and switches that gallery back off.

You can ask us to remove your face group, or to switch the feature off for a gallery entirely. Contact us below.

Cookies and local storage

Everything this site stores in your browser, and whether it needs consent:

Cookies and local storage used by natalikornata.com
NamePurposeDurationCategory
locale-overrideRemembers your language.1 yearFunctional (no consent required)
consentRecords your analytics choice. Needed for the consent gate, not an analytics cookie.12 monthsStrictly necessary
nk_anonlocal storageA random analytics ID (no personal data), set only after you consent and removed if you withdraw.Until you withdraw consentAnalytics (consent required)
nk_viewed_<gallery>session storageRemembers that this tab already counted a gallery view, so one visit counts once.Until the tab closesAnalytics (consent required)
photo_sessionAuthenticates your private gallery session. httpOnly, strictly necessary.30 daysStrictly necessary
admin_sessionKeeps the photographer signed in to the admin area. Set only for her, never for a visitor. httpOnly, strictly necessary.12 hoursStrictly necessary

A few more cookies exist for the photographer alone: two that carry her through the sign-in steps, and one that protects connecting a backup account. They last minutes, they are never set for a visitor, and none of them is used for analytics.

Data retention & your rights

We keep personal data only as long as needed:

  • Analytics events (views, downloads, shares): up to 24 months, then anonymised or deleted.
  • Magic-link session tokens: 30 days.
  • Admin sessions: 12 hours.
  • Aggregated zoom-attention data (no identifiers): kept indefinitely.
  • Deleting a gallery or visitor deletes all its events.
  • Services inquiries (everything you typed into the form): 24 months, then deleted.
  • Gallery reviews (rating, text, name): 24 months, then deleted.
  • Private-gallery feedback activity (hearts, lists, notes, reviews): up to 24 months, then deleted.
  • Face groups and crops in private galleries: deleted with the gallery, and in any case within 24 months.
  • Private names the photographer wrote against a link: 24 months.
  • Offsite backup copies, when the photographer has switched them on: kept for the window she sets, then deleted.

These limits are applied by a job that runs every day, not by remembering to do it.

You can ask us to access, correct, or erase your personal data. Contact us below.

Third-party processors

We share limited data with:

  • Contabo (Germany), hosts the server this site runs on. The site, its database and the photo files all live on one machine rented from them, so everything described above passes through it. No content delivery network sits in front of it: pages and photos are served straight from that server.
  • Anthropic (US), translates and refines site text written by us: the About page, gallery titles and descriptions, service and FAQ copy, interface strings, and SEO metadata. Only our own text is sent, never visitor data and never your photos.
  • Resend (US), sends our emails (magic-link invites, admin password reset, inquiry notifications and confirmations). Inquiry emails include what you submitted; others carry only an email address.
  • Google Drive (Google, US), stores our offsite backups when the site owner has switched them on. A backup copies the database and the media files, so it can include the personal data described above. Backups are encrypted in transit and kept for a limited retention window.
  • Telegram (Telegram Messenger Inc., outside the EU), receives an activity summary for the site owner when that option is switched on: the display name you gave when leaving feedback in a private gallery, together with counts and any star rating. Never the text of a note or review, never a photo or a link. Telegram keeps those messages in the chat history under its own retention rules.

Contact & erasure requests

For privacy questions or to access, correct, or erase your data, email us at ceo@wolfsteno.com.

We handle erasure requests within 30 days, removing all linked event and session records.