Huskox

Legal

Privacy Policy

Last updated: August 10, 2026

This privacy policy describes how Huskox collects, uses, and protects personal data in connection with the huskox.com site (and its temporary technical address huskox.vercel.app) and the Huskox service (hereinafter the "Service"). It is drafted in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).

One essential point for understanding this document: Huskox acts in two distinct capacities. For certain data (your contact requests, your client account), Huskox is the data controller. For other data (the photos and videos uploaded by an event's guests), Huskox acts solely as the processor of the event organizer, who is the data controller for that data. This distinction structures the rest of this document.

This document is provided in English for informational purposes only. Only the French version is legally binding, and it is governed by French law.

Article 1: Data Controller

The controller for the processing activities described in Articles 2 to 5 is:

John Houzi, sole proprietor (micro-entrepreneur), registered under number 337927834, whose registered office is located at 49 Abarbanel, Tel Aviv. Huskox is a studjoow service (studjoow.com).

Contact for any question relating to personal data: hello@huskox.com

No data protection officer (DPO) has been appointed, as this appointment is not mandatory for Huskox's activity. The contact address above is the single point of entry for any question relating to personal data.

Article 2: Data We Collect as Data Controller

We deliberately limit collection to what is strictly necessary. Below is the exhaustive list of processing activities for which Huskox acts as data controller.

2.1 Contact and Quote Requests (Leads)

When you fill in the contact form or one of the short forms on the site's landing pages, we collect, depending on the form: your name, your email address, the type of event, its date, its location, the number of guests, the desired package, and your message. Only your name and email address are required. No phone number is requested.

Each form submission triggers three operations: recording your request in our database (Supabase), sending a notification email to the publisher, and sending an automatic acknowledgment to the email address provided, via our provider Resend (see Article 6).

This data is used solely to respond to your request and to prepare a possible commercial proposal. The fields marked as required on the form are necessary to process your request: without them, we will not be able to respond to you.

Legal basis: performance of pre-contractual measures taken at your request (article 6(1)(b) GDPR).

2.2 Client Area Account

Creating an account on the client area requires only one piece of data: your email address. The events you have entrusted to us, as well as the progress of your timeline (see 2.3), are then linked to your account.

Sign-in takes place via a magic link: a single-use sign-in link is sent to you by email. No password is created, requested, or stored. This is a deliberate data minimization measure: the less information we hold, the less you are exposed in the event of an incident. In particular, it removes any risk of password leakage or reuse.

Legal basis: performance of the contract binding us (article 6(1)(b) GDPR).

2.3 Checklist Check-Marks and Timelines

Two situations coexist and should not be confused:

2.4 Transactional Emails

We send you emails strictly related to the operation of the Service: sign-in magic link, confirmations, and notifications relating to your event. These are sent via our provider Resend (see Article 6). These are not marketing emails.

Legal basis: performance of the contract, or pre-contractual measures for exchanges prior to subscription (article 6(1)(b) GDPR).

2.5 Online Payment (Coming Soon)

Online payment is not yet available. Once activated, it will be operated by Stripe, our payment provider. Your banking details would then be collected and processed directly by Stripe: Huskox would never have access to your card number. Huskox would retain only the information necessary for billing and proof of payment (amount, date, transaction status). This policy will be updated when this service is activated.

Anticipated legal basis: performance of the contract (article 6(1)(b) GDPR) and, for the retention of accounting records, legal obligation (article 6(1)(c) GDPR).

Article 3: Event Media, Huskox Acts as Processor

This is the most important point of this policy.

The Service allows an event's guests (wedding, celebration, or other) to upload photos and videos to a shared album. For this media, and the data that accompanies it:

In practical terms, this means that:

The media is hosted on servers located in Europe, on infrastructure separate from that of the site. It remains online for the duration of the gallery provided under the chosen package: 12 months (Photo package) or 24 months (Photo + Video package and Go storage tiers), extensions possible. After the gallery expires, an additional 30-day period allows everything to be retrieved, after which the media is deleted (see Article 4).

Article 4: Retention Periods

DataRetention Period
Event photos and videosGallery duration according to the package: 12 months (Photo) or 24 months (Photo + Video and Go storage tiers), extensions possible; then an additional 30-day retrieval period, then deletion
Contact and quote requests (leads)3 years from the last contact
Client area account (email address, linked events, timeline check-marks)Duration of the contractual relationship
Billing data (once online payment is activated)Legal retention period for accounting records (10 years, article L123-22 of the French Commercial Code)

At the end of these periods, the data is deleted.

The additional 30-day period runs from the expiration of the gallery; the client is notified before this expiration. If an extension is agreed between the organizer and Huskox (see the general terms and conditions of sale), these periods run from the end of the extended period. Throughout the duration of the gallery, the client may download all of their content, in its original quality and without watermark.

Article 5: No Profiling or Targeted Advertising

Huskox carries out no profiling, no decision based solely on automated processing that produces legal effects, no targeted advertising, and no resale of data. Your data is never sold or rented to third parties for commercial purposes.

As of today, the site uses no advertising cookies, no third-party audience measurement tools, and no tracker subject to consent. Only technical session cookies (client area and administration) and browser local storage (public checklist and timelines) are used. Details are set out on the site's "Cookies and Local Storage" page.

Article 6: Processors and Transfers Outside the European Union

To provide the Service, Huskox uses the following providers, which access data only to the extent necessary for their task:

ProviderRoleLocation and Safeguards
VercelSite hosting and deliveryUnited States; transfer governed by the European Commission's standard contractual clauses
SupabaseDatabase (leads, accounts, events)European Union: project hosted on AWS, eu-west-3 region (Paris, France)
ResendSending of transactional emailsUS company; transfers outside the EU governed by its data processing agreement (DPA) and the European Commission's standard contractual clauses
Stripe (coming soon)Online payment, once activatedApplicable transfer safeguards will be specified in this policy upon activation

Event photos and videos, meanwhile, are hosted on servers located in Europe, on infrastructure separate from that of the site (see Article 3).

Apart from these providers, no data is transmitted to third parties, except where legally required.

Article 7: Security

Huskox implements appropriate technical and organizational measures to protect data: passwordless sign-in via a single-use magic link, collection reduced to what is strictly necessary, and access limited to only those who need it. In the event of a data breach presenting a risk to your rights and freedoms, we will inform the CNIL and, where applicable, the individuals concerned or the relevant data controller, under the conditions set out by the GDPR.

Article 8: Your Rights

In accordance with the GDPR, you have the following rights over data concerning you:

To exercise these rights, write to the contact address given in Article 1. We will respond within one month, extendable by two months for complex requests, in which case you will be informed. If there is reasonable doubt as to your identity, proof of identity may be requested.

Important reminder: for an event's photos and videos, the data controller is the event organizer (see Article 3). You may nevertheless write to us: we will forward your request to the organizer and help them respond to it.

Article 9: Complaint to the CNIL

If, after contacting us, you believe your rights are not being respected, you may file a complaint with the Commission nationale de l'informatique et des libertés (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at www.cnil.fr.

Article 10: Changes to This Policy

This policy may be updated, in particular upon activation of online payment or as the Service evolves. The date of the last update appears at the top of this document. In the event of a material change, users with an account will be notified by email.

Privacy Policy | Huskox