Your privacy rights
Last updated July 31, 2026 · GDPR rights for EU / EEA & UK residents, self-service for everyone
What you can do with your data, what deleting your account actually removes, and how to ask us for anything you can’t do yourself.
Your rights
If you live in the EU, EEA, or UK, the GDPR gives you clear rights over your personal data. Momeza supports every one of them — and offers the same self-service export and erasure to everyone, wherever they live.
Get a copy of the personal data we hold about you.
Correct information that is inaccurate or incomplete.
Delete your data and be forgotten.
Export your data in a portable, machine-readable format.
Object to processing based on our legitimate interests.
Ask us to pause processing while a concern is resolved.
Legal basis
We process personal data to give you the account and the event you asked for (contract), to keep the service secure and reliable and to prevent abuse (legitimate interest), and to meet obligations such as keeping billing records (legal obligation).
Nothing here rests on consent today, because there is nothing optional to consent to: Momeza runs no analytics and no advertising. If that ever changes we will ask first, and you will be able to withdraw at any time without affecting anything that came before. This works alongside our Privacy Policy.
Export and deletion, yourself
Access, portability and erasure need no request at all. Open Settings → Data: one button downloads everything we hold about you as a JSON file, the other deletes your account.
For the rights that do need us — correction, objection, restriction — get in touch.
Make a requestWhat deletion removes
Deleting your account is immediate and permanent. It removes:
- Your account, sign-in details and sessions.
- Every event you host, and everything inside it — guests, photos, videos, notes, letters, competitions and results.
- The photos, videos, notes and letters you added to other people’s events, and your place on their guest lists.
- The files themselves in our object storage, not merely the database rows that point at them.
Two things do not vanish with it. Copies can survive for a short while in our providers’ automated database backups, until those are overwritten on their own schedule — nothing is ever restored from them except to recover from a failure. And what other guests made — their own photos and notes at an event you hosted — belongs to them; deleting your account deletes the event around it, so nobody else can reach it either.
Hosts: this takes your events down for your guests too. Export what you want to keep first.
Deleting a single event does the same for that event alone: it and everything inside it are erased for everyone, files included. Either way there is nothing to restore afterwards.
Data transfers
Your data is stored in the EU by default. Where a provider sits outside the EEA — as our payment processor does — the transfer runs on Standard Contractual Clauses and the safeguards that go with them.
Every provider that touches your data is named, with what it does and where it is, in the Privacy Policy.
Complaints
If you think we have handled your data badly, tell us first — it is the fastest way to get it fixed, and we would rather know.
You also have the right to complain to your national data protection authority, wherever you live in the EU, EEA or UK, without going through us at all.
How to reach us
Momeza is small enough that there is no separate Data Protection Officer — a rights request reaches the person who runs the service directly.
Stylianos Karydakis. Email support@momeza.com, or write to Afrikis Street, 3052 Limassol, Cyprus. We respond to every rights request within 30 days, and you can also reach us through our contact page.