Legal
Privacy Policy
How The Snap Shot handles your personal information — including the iris photographs we take.
1. Who we are
The Snap Shot is the trading name of Snap Media Ltd, a company registered in England and Wales (company number 16390638). We operate an iris photography studio at the Dolphin Centre in Poole, Dorset, and provide mobile iris photography at events.
Snap Media Ltd is the “data controller” for the personal information described in this policy. That means we’re legally responsible for how it’s collected, used, and protected.
Registered office: Poole, Dorset, United Kingdom.
Contact for privacy queries: privacy@thesnapshot.co.uk
We are registered with the Information Commissioner’s Office (ICO) under reference ZC132905.
2. The most important thing: iris photographs are biometric data
The pattern of your iris is unique to you. Under the UK GDPR (Article 9), iris photographs are classified as “special category” biometric data when used or capable of being used to uniquely identify an individual. This is the same legal category as health records or fingerprints.
We do not use iris photographs for identification or matching purposes. We use them solely as the source material for a piece of art that you commission from us. However, because the law treats the underlying data as sensitive regardless of our intended use, we apply additional protections:
- We process iris photographs only with your explicit consent, captured in writing at check-in.
- You can withdraw consent at any time by emailing us. We will then delete the photographs and any artwork derived from them, subject to legal exemptions described in section 6.
- We do not share iris photographs with third parties except as strictly required to deliver your prints or digital files.
3. What information we collect
3.1 When you visit our studio or mobile setup
- Contact details: name, email address, mobile number.
- People being photographed: name, whether under 18, any known light sensitivity or medical conditions you choose to disclose.
- Iris photographs: close-up photographs of the iris(es) of consenting subjects.
- Consent and signature records: the time and IP address at which you completed our check-in form, and which consents you ticked.
- Order and payment details: what you bought, how much you paid, payment method, payment date. We do not store full card numbers.
3.2 When you submit our preview lookup form
- The photo number you entered.
- Any name you entered.
- The time of submission and your IP address.
3.3 When you visit our website
- Standard server logs (IP address, browser type, pages visited, referrer).
- Cookies and similar technologies — see section 9.
- Anonymous analytics data via Microsoft Clarity to help us improve the site.
4. Why we collect it — our legal bases
Under the UK GDPR we must have a lawful basis for each thing we do with your information:
- Iris photographs (special category data): processed on the basis of your explicit consent, given when you complete the check-in form.
- Contact details and order information: processed on the basis of contract performance — we need them to deliver the service you’ve requested.
- Health information you choose to disclose (e.g. light sensitivity): processed on the basis of explicit consent, used solely to keep you safe during the session.
- Accounting and tax records: processed on the basis of legal obligation — HMRC requires us to keep these for at least 6 years.
- Marketing communications: sent only with your explicit opt-in consent, which you can withdraw at any time.
- Website analytics: processed on the basis of our legitimate interest in understanding how visitors use the site, in line with our cookie policy.
5. Who we share your information with
We don’t sell your data. We share it only with the small number of service providers we need to operate the studio:
- Hosting provider: Our website and customer records are held on managed hosting infrastructure based in the EU.
- Payment processors: When you pay by card in person, your transaction is handled by Teya, a regulated payment provider. Bank transfers are processed through our business bank, Monzo Business. We never see or store full card details.
- Print suppliers: Most prints are produced in-house. Where we use an external print partner, they receive only the cropped photograph and your delivery details — never your other personal data. We’ll update this section if we add a print partner whose data handling materially changes how your data is processed.
- Email delivery service: Used to send transactional emails (check-in confirmations, invoices, preview notifications).
- Accountants: Our accountants see invoice records as part of routine bookkeeping.
- Government or law enforcement: Only where legally required — for example, in response to a valid court order.
Where any of these providers process data outside the UK or EU, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses or an adequacy decision).
6. How long we keep your information
- Iris photographs: retained for as long as needed to fulfil your order and provide ongoing customer support (typically 2 years after your last interaction). After that they are deleted unless you ask us to retain them longer (e.g. for re-prints).
- Contact details and order records: retained for 7 years from the end of the financial year in which the transaction occurred, in line with HMRC’s requirements.
- Marketing consent records: retained until you withdraw consent, then for a further 2 years to demonstrate compliance.
- Preview lookup logs: retained for 12 months to detect abuse.
- Server logs: retained for 30 days.
If you ask us to delete iris photographs of you, we will do so promptly — but we may need to retain a record of the deletion request itself, and certain invoice records, to meet our legal obligations.
7. Children’s data — our strict policy on under-18s
We take child safeguarding seriously. Anyone under the age of 18 must be accompanied by a parent or legal guardian in order to take part in an iris session. The parent or guardian must:
- Be physically present for the entire session.
- Provide explicit consent on behalf of the minor, in writing, via the check-in form.
- Confirm they have disclosed any relevant medical conditions.
We will not photograph an unaccompanied minor under any circumstances, even if they ask us to.
If you believe we hold iris photographs of a child without proper consent, please contact us immediately at privacy@thesnapshot.co.uk and we will investigate and act promptly.
8. Your rights
Under the UK GDPR you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: have us correct any inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): have your data deleted, subject to certain legal exceptions.
- Right to restrict processing: ask us to pause certain types of processing.
- Right to object: particularly to processing based on legitimate interests, and to direct marketing.
- Right to data portability: receive a copy of your data in a structured, machine-readable format.
- Right to withdraw consent: for any processing based on consent, including for the iris photographs themselves.
To exercise any of these rights, email privacy@thesnapshot.co.uk. We will respond within one calendar month.
If you’re not happy with how we’ve handled your data, you have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113. We’d appreciate the chance to put things right ourselves first, but you don’t have to come to us before going to the ICO.
9. Cookies and tracking
Our website uses a small number of cookies to function correctly and to help us understand how the site is used. Essential cookies are set by default. Non-essential cookies (analytics) are only set with your consent via the cookie banner.
You can change your cookie preferences at any time by clicking the cookie icon in the bottom corner of the site.
10. Security
We take reasonable steps to protect your information:
- All data is transmitted over encrypted connections (HTTPS).
- Customer records are held in a database protected by industry-standard security controls.
- Iris photograph files are stored on access-controlled systems.
- Access to customer data is limited to Eric and to service providers with a contractual need.
No system is perfectly secure, and we cannot guarantee absolute protection. If we ever became aware of a personal data breach affecting you, we would notify you and the ICO in accordance with the law.
11. Changes to this policy
We may update this policy from time to time — for example, when we add new services or when the law changes. The “last updated” date at the top of the page shows when it was last revised. If we make material changes, we’ll let existing customers know by email.
12. Contact us
If you have any questions about this policy or about how we use your information, please get in touch:
Snap Media Ltd (trading as The Snap Shot)
Email: privacy@thesnapshot.co.uk
General enquiries: hello@thesnapshot.co.uk
Studio: 110 Dolphin Centre, Poole BH15 1SZ