Skip to content

GDPR & Data Handling

Last updated 5 July 2026

This page gives a practical summary of how Newborn Photography Art handles privacy requests, retention and deletion. Please also read the full Privacy Policy.

Privacy Requests

Use the Contact Us page if you want to:

  • ask what data we hold about you;
  • correct your details;
  • export a copy of your client/account data;
  • delete or anonymise client data where possible;
  • withdraw marketing, testimonial or image consent;
  • object to processing or restrict how data is used.

We usually respond within one month. We may need to verify your identity before sharing or changing personal data.

What The App Can Export

Where you have a client account, the app can help export data such as:

  • account details and contact details;
  • connected Apple/Facebook/Google social-login providers;
  • passkey/account security records that can safely be disclosed;
  • consent history and privacy requests;
  • login activity and customer-app token records;
  • bookings, packages, add-ons, vouchers, discounts and payments;
  • contracts, agreements, typed signature names and signed document records;
  • portal messages, emails and customer requests;
  • gallery records, selection choices, committed selections, reset selections, unedited requests and download records;
  • child/session details, questionnaire answers and inspiration uploads.

Some exports may summarise sensitive technical/security data rather than exposing secrets, tokens, hashes, private keys or information that would compromise another person.

What The App Can Delete Or Anonymise

Where deletion is appropriate, the app can remove or anonymise account details, social-login links, passkeys, app tokens, login activity, private messages, lead details, galleries, child/session notes and uploaded inspiration images.

Some records cannot simply be erased on request because we may need them for tax, accounting, contract, insurance, safeguarding, fraud prevention, legal claim or dispute reasons. In those cases we keep only what is necessary and, where possible, reduce or anonymise personal details.

Retention Schedule

Data type Typical retention
Visitor analytics up to 14 months
Heatmaps up to 6 months
Session recordings up to 30 days
Customer activity logs up to 24 months
Security/login logs up to 12 months
Audit logs up to 24 months
Email logs up to 24 months
Import logs up to 24 months
Expired website sessions normally cleared after 7 days
Customer app/API tokens until revoked, replaced or expired
One-time links until used or expired
Selection galleries normally 1 month live
Gallery/archive folders normally purgeable after around 6 months
Financial, payment, booking and signed-contract records normally up to 7 years, reviewed before manual deletion

Galleries, Dropbox Folders And Delivered Files

Galleries and client folders may be provided through Dropbox or another configured file provider. Gallery folders are designed to expire and be purged after the archive period. Financial records, invoices, audit logs and core booking records may be kept separately for legal/accounting purposes.

Consent Records

We keep a history of consent choices, including cookie choices, marketing consent and image/testimonial consent where relevant. This helps us prove what was agreed, respect withdrawals and avoid accidentally using images after consent has changed.

Security Measures

The app uses role-based staff/admin access, customer-only social login, secure authentication, passkey support, audit logs, private storage for client uploads, limited public address sharing, customer API tokens, encrypted/configured third-party credentials and payment providers that handle card data directly.

We do not store full card details. We do not log social-login tokens, Apple private keys, passwords, passkey secrets, payment card details or private API secrets.

Data Minimisation

Please do not upload or send more personal, medical or family information than is needed for the session. If extra sensitive information is needed for safety, comfort or accessibility, we use it only for that purpose.

Limits On Deletion

A privacy request cannot be used to remove records that we reasonably need for accounting, legal obligations, fraud prevention, safeguarding, insurance, dispute handling, enforcing terms, defending legal claims or respecting another person's rights. Where possible, we will restrict, redact or anonymise instead.