PhotoCrew.co.uk — Privacy Policy / Privacy Notice
Effective date: 5 August 2026 Version: 1.0
This Privacy Policy / Privacy Notice (“Privacy Notice”) explains how PhotoCrew.co.uk (“PhotoCrew”, “we”, “us” or “our”) collects, uses, stores, shares, protects and otherwise processes personal data when a person visits or uses photocrew.co.uk and any related profiles, listings, directories, dashboards, forms, messaging tools, reviews, applications, paid features and associated services (the “Platform”).
PhotoCrew.co.uk is operated as a sole trader business under the trading name PhotoCrew.co.uk.
For privacy, data-protection and personal-data enquiries or complaints, contact:
hello@photocrew.co.uk
This Notice should be read with the Terms and Conditions and Cookie Policy.
1. Important public-profile notice
PhotoCrew is a user-generated-content and professional-discovery Platform.
Depending on the Account type and settings:
names, business names, usernames, profile images, biographies, location information, services, pricing, availability, portfolios, team information, reviews and other profile content may be public;
public pages may be accessed without login;
search engines may index, cache and display public pages;
third parties may link to, screenshot, copy, archive or unlawfully scrape public information;
public information may be accessed outside the United Kingdom;
removal from PhotoCrew does not guarantee removal from search engines, browser caches, external archives, social platforms, screenshots, messages, backups or third-party copies;
Users should not publish information that they need to remain confidential.
PhotoCrew prohibits unauthorised scraping and misuse, but cannot guarantee that every third party will obey technical restrictions or law.
2. Data controller
For most processing described in this Notice, PhotoCrew acts as a controller under UK data-protection law.
Users may act as separate and independent controllers when they receive or use personal data for their own purposes, including when they receive enquiries, process applications, communicate outside the Platform, enter contracts, retain Client, candidate or collaborator information, conduct marketing, manage projects or comply with their own accounting, employment or legal duties.
PhotoCrew is not responsible for an independent User’s processing outside PhotoCrew’s control, although we may take action where Platform misuse is reported.
3. Personal data we may collect
The categories below are deliberately broad because the exact data depends on Account type, features used, information voluntarily supplied and legal or security needs.
3.1 Identity and account data
full name;
preferred name;
username;
title;
business or trading name;
account type;
account identifier;
profile photograph;
date of birth or age confirmation where required;
login credentials in protected form;
account creation and status;
role and permissions;
linked Account information;
records of accepted Terms and policies.
3.2 Contact data
email address;
public contact email;
telephone number where provided;
business address;
service area;
website;
social media links;
communication preferences;
support and billing contact details.
3.3 Profile and professional data
biography;
job title;
professional category;
skills;
experience;
qualifications;
awards;
memberships;
licences;
languages;
services;
rates or pricing information;
availability;
working locations;
travel preferences;
equipment;
insurance statements;
team members;
work history;
client names where lawfully supplied;
profile visibility settings.
3.4 Portfolio and media data
photographs;
videos;
audio;
graphics;
thumbnails;
documents;
captions;
alt text;
metadata;
links;
file names;
technical file information;
persons, locations, brands, works or properties depicted in content.
Portfolio media may itself contain personal data about Users, Clients, models, performers, employees, children, guests or other identifiable persons. The uploading User is responsible for having an appropriate legal basis and rights to publish it.
3.5 Services, gigs and jobs
listing title and description;
category;
location;
dates;
budget, compensation or price;
deliverables;
requirements;
contract or employment information;
application instructions;
status and history;
responses and applications;
shortlisting or workflow information where available.
3.6 Messages, enquiries and communications
messages sent through the Platform;
enquiry details;
attachments;
timestamps;
participants;
delivery and read status where supported;
reports of spam, harassment, fraud or abuse;
communications with support;
complaint and appeal correspondence;
survey and feedback responses.
We do not encourage Users to send unnecessary sensitive or highly confidential information through messaging.
3.7 Review and reputation data
review text;
rating;
reviewer and reviewed Account;
date;
response;
report;
moderation history;
evidence of interaction;
fraud or authenticity signals;
appeal information.
3.8 Payment and transaction data
order and subscription identifiers;
product or plan;
amount;
currency;
payment status;
refund, chargeback or cancellation status;
billing name and address where provided;
limited card information such as brand and last digits where supplied by a processor;
tax information;
invoices;
payment-provider customer identifiers;
fraud and risk signals.
Full payment-card data is normally processed by an external payment provider and not stored directly by PhotoCrew.
3.9 Verification and compliance data
Where verification or compliance checks are offered or required, we may process:
identity documents;
business documents;
proof of address;
selfie or likeness checks;
verification result;
document expiry;
reason for verification;
fraud indicators;
sanctions or risk information where lawfully checked;
right-to-work information where a specific service requires it;
records of checks and decisions.
The exact provider, information and retention may be described at the point of collection.
3.10 Technical, device and network data
IP address;
date and time;
browser;
operating system;
device type;
screen and language settings;
referral URL;
pages requested;
response codes;
session identifiers;
cookie and storage identifiers;
login events;
error logs;
security logs;
approximate location inferred from IP;
network and hosting information;
user-agent and technical capability information.
3.11 Usage, analytics and interaction data
pages viewed;
searches;
filters;
clicks;
profile views;
listing views;
interactions;
application events;
sign-up and checkout journeys;
feature use;
time and navigation patterns;
notification interaction;
conversion and attribution information;
aggregated performance information.
3.12 Security, fraud and moderation data
failed logins;
suspicious traffic;
rate-limit events;
account links;
duplicate-account indicators;
spam indicators;
reports;
moderation records;
content classifications;
device and payment risk indicators;
evidence supplied in disputes;
blocked identifiers;
enforcement action;
law-enforcement or regulatory requests.
3.13 Marketing and preference data
subscription status;
consent status;
lawful soft-opt-in status where applicable;
marketing channels;
campaign interaction;
unsubscribe history;
preference centre selections;
audience or attribution information.
3.14 Inferred and derived data
We may derive or infer:
profile completeness;
category relevance;
approximate region;
engagement;
likely spam or fraud risk;
duplicate-account likelihood;
review authenticity signals;
search-ranking signals;
eligibility for features;
account health;
aggregated trends.
3.15 Information about other people
A User may provide information about Clients, team members, employees, models, performers, references, reviewers, collaborators, job applicants or other persons. The User must have authority and a lawful basis to do so and must provide any privacy information required by law.
4. Special-category and criminal-offence data
PhotoCrew does not generally require Users to publish special-category data such as health, disability, race or ethnicity, religion, political opinions, trade-union membership, genetic data, biometric data used for unique identification, sexual orientation or sex-life information.
Such information may nevertheless appear incidentally in photographs or videos, biographies, accessibility requests, messages, reviews, complaints, verification or safety reports.
Users should avoid submitting sensitive information unless necessary.
Where PhotoCrew intentionally processes special-category data, we will identify an Article 9 condition or other lawful basis, which may include explicit consent, legal claims, substantial public interest or another condition available by law.
Criminal allegations may appear in reports, fraud investigations or legal requests. We process such information only where a lawful condition applies.
We may remove unnecessary sensitive information from public content or restrict access.
Public publication of sensitive information carries increased risk. Users are responsible for considering that risk before voluntary publication.
5. How we obtain personal data
We may obtain personal data:
directly from the person;
through Account registration;
through profile editing;
through forms, listings, applications, messages and reviews;
automatically through use of the Platform;
from other Users;
from payment, email, hosting, security, analytics, verification and other service providers;
from public sources, websites and professional profiles where lawful;
from regulators, courts, law enforcement, advisers and complainants;
through cookies and similar technologies;
by creating derived data from other information.
Where data is obtained from another source, we provide privacy information within the period required by law unless an exception applies.
6. Purposes and lawful bases
The table describes common purposes. More than one lawful basis may apply.
Purpose Typical data Lawful basis
Create and manage Accounts Identity, contact, login, profile and technical data Contract; legitimate interests
Publish public profiles, portfolios and services Profile, professional, media and location data Contract; legitimate interests; consent where specifically required
Provide search and discovery Profile, listing, location, usage and ranking data Contract; legitimate interests
Enable messages and enquiries Identity, contact and communication data Contract; legitimate interests
Publish gigs, jobs and applications Profile, listing, application and communication data Contract; legitimate interests
Provide reviews and ratings Review, identity, interaction and moderation data Contract; legitimate interests; legal obligation where applicable
Supply Paid Plans and Paid Features Account, transaction, billing and usage data Contract; legal obligation; legitimate interests
Process payment and prevent payment fraud Transaction, device, identity and risk data Contract; legitimate interests; legal obligation
Provide support Account, communication, technical and transaction data Contract; legitimate interests
Secure the Platform Technical, device, login, risk and moderation data Legitimate interests; legal obligation
Prevent fraud, spam and abuse Account, transaction, technical, communication and risk data Legitimate interests; legal obligation
Moderate content and handle reports User Content, reports, communications and evidence Legitimate interests; legal obligation
Comply with online-safety duties User Content, reports, risk assessments and enforcement data Legal obligation; legitimate interests
Comply with fake-review obligations Review, account, interaction and fraud data Legal obligation; legitimate interests
Enforce Terms and legal rights Account, content, transaction, communication and evidence Legitimate interests; legal obligation; legal claims
Keep tax, accounting and business records Transaction, identity and billing data Legal obligation; legitimate interests
Improve and test the Platform Usage, technical, feedback and aggregated data Legitimate interests; consent where PECR requires
Analytics and measurement Cookie, usage, device and interaction data Consent where required; statutory exception where available; legitimate interests where UK GDPR permits
Send essential service communications Contact and Account data Contract; legitimate interests; legal obligation
Send marketing Contact and preference data Consent; lawful soft opt-in where available; legitimate interests for permitted business communications
Personalise or recommend content Profile, usage and preference data Contract; legitimate interests; consent where required
Business transfer or restructuring Relevant Account, contract and transaction data Legitimate interests; legal obligation
Establish, exercise or defend claims Relevant records and evidence Legitimate interests; legal obligation; legal claims
Our legitimate interests may include operating a sustainable marketplace, providing useful search, protecting Users, preventing fraud, maintaining records, improving services, enforcing contracts, defending claims and promoting PhotoCrew. We balance those interests against individual rights and expectations.
Where consent is the basis, consent may be withdrawn without affecting earlier lawful processing.
7. Contractual and required information
Some information is required to create an Account, authenticate a User, publish a listing, provide a Paid Feature, process a payment, prevent fraud, comply with law or investigate a complaint.
If required information is not provided, we may be unable to supply the feature, process the transaction, maintain the Account or complete a request.
8. Public profiles and search engines
Public profile information may be accessed globally.
Search engines and third parties act independently.
PhotoCrew may use structured data, metadata, snippets, previews, sitemaps and links to make public profiles discoverable.
A User can request removal from PhotoCrew, but external de-indexing is not immediate or guaranteed.
Search engines may retain cached copies.
Third parties may preserve screenshots or archives.
PhotoCrew is not responsible for independent external processing except where law makes us responsible.
Users must contact the relevant external controller where necessary.
We may assist with reasonable information but cannot control another controller’s response.
9. User-to-User sharing
When Users contact one another, personal data may be shared directly.
The recipient may become an independent controller.
Recipients must use data only for lawful and relevant purposes.
Users must not add another User to marketing lists without a lawful basis; sell contact data; scrape or compile databases; conduct unrelated profiling; publish private correspondence without justification; retain applicant data indefinitely without a purpose; or use data for harassment, discrimination or fraud.
PhotoCrew cannot control every use after lawful transmission.
Misuse should be reported.
PhotoCrew may restrict Accounts or disclose information where lawful and necessary to address misuse.
10. Messaging privacy
Messages may be stored to provide the service, maintain security, investigate complaints, prevent fraud and enforce Terms.
We do not promise that messages are end-to-end encrypted.
Authorised personnel and service providers may access messages where reasonably necessary and legally permitted.
Automated systems may scan technical signals, links, spam patterns or content for safety and fraud.
Users should not send passwords, full payment-card details, unnecessary ID documents, medical information or highly confidential material.
Deleting a message from one interface may not remove the recipient’s copy or retained compliance records.
We may preserve messages subject to legal hold, complaint or investigation.
11. Reviews, moderation and online safety
We may process personal data to receive and publish reviews; detect fake, incentivised, coordinated or abusive reviews; request evidence of genuine experience; moderate content; assess illegal-content risk; investigate fraud, threats, abuse, harassment, exploitation or intellectual-property complaints; operate reporting and complaints procedures; restrict or terminate Accounts; make disclosures required by law; and keep evidence of decisions.
Moderation data may include sensitive allegations. Access is restricted according to role and purpose.
We do not guarantee that every harmful, false or illegal item will be detected before publication.
12. Verification
Verification may be provided by PhotoCrew or an external provider.
The point-of-collection notice may describe required data, provider, purpose, whether participation is mandatory, retention, transfer and consequences of refusal.
We may retain a verification result rather than a full document where feasible.
Some records may be retained for fraud, dispute, audit or legal purposes.
Verification does not guarantee future identity, honesty, quality or eligibility.
A Verification Badge is not an endorsement.
13. Payments
External payment providers may process card information, bank information, billing address, authentication, fraud signals and transaction history.
PhotoCrew receives limited information needed for orders, refunds, subscriptions, accounting and fraud prevention.
Payment providers act as controllers or processors depending on the activity.
Users should read the provider’s notice at checkout.
We may disclose evidence to banks, card schemes, fraud-prevention services, advisers or authorities in a chargeback or dispute.
14. Cookies and storage technologies
We use cookies and similar technologies as described in the Cookie Policy.
Optional technologies are used with consent where required.
Some limited-risk technologies may rely on a statutory exception where the legal conditions are met.
Consent records may include device, choice, timestamp and policy version.
Users can manage preferences through the available settings tool.
15. Analytics, ranking and recommendations
We may analyse use to improve the Platform, measure performance, detect abuse and understand demand.
Analytics may be incomplete because of consent choices and technical limitations.
Ranking may use profile, location, category, recency, reviews, plan, engagement, quality, availability, safety and technical signals.
We may infer relevance or risk.
Paid status may influence visibility where described.
We do not use solely automated processing to make a decision producing legal or similarly significant effects unless lawful safeguards apply.
Users may contact us about a significant automated decision where applicable.
16. Marketing and communications
16.1 Service communications
We may send messages necessary for registration, security, password reset, transactions, subscriptions, moderation, complaints, policy updates, enquiries and Platform operation. These are not optional marketing where necessary for the service or legal compliance.
16.2 Marketing
We may send marketing where the person consented, a lawful soft opt-in applies, or another lawful basis and channel rule applies. Marketing may include Platform news, features, plans, promotions, opportunities and surveys.
16.3 Opt-out
A person may unsubscribe through the message link, preference settings or hello@photocrew.co.uk. We may retain a suppression record to respect the choice.
16.4 Business contacts
We may send proportionate business-to-business communications where law permits. Recipients can object.
17. Who we may share personal data with
We may share data with the following categories where necessary and lawful:
hosting and infrastructure providers;
CDN, caching and performance providers;
website, database and software suppliers;
security, anti-spam, fraud and monitoring providers;
email and notification providers;
payment and subscription providers;
analytics and consent-management providers;
map, video, social and embedded-content providers;
verification providers;
customer-support providers;
backup and storage providers;
developers, administrators and contractors under appropriate obligations;
accountants, lawyers, insurers, auditors and professional advisers;
banks, card schemes and fraud-prevention bodies;
regulators, courts, law enforcement and public authorities;
prospective or actual buyers, sellers, investors or restructuring parties;
another User where the User requested or initiated sharing;
persons needed to investigate a complaint, subject to fairness and confidentiality;
any other recipient authorised by the person or required by law.
We require processors to act under appropriate contracts. Some providers act as independent controllers.
We do not sell personal data in the ordinary meaning of selling a customer database for money. We may use advertising or measurement technology only as explained and subject to applicable consent rules.
18. International transfers
Some service providers may process data outside the United Kingdom.
Where a restricted transfer occurs, we may rely on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, binding corporate rules, an applicable statutory derogation or another lawful transfer mechanism.
We may conduct transfer-risk assessments and apply supplementary measures where required.
No transfer mechanism eliminates every foreign-law or cybersecurity risk.
A person may request information about relevant safeguards by contacting hello@photocrew.co.uk, subject to confidentiality and legal limits.
19. Retention
We retain personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting, fraud, security, complaint and dispute needs.
Indicative criteria and periods may include:
Data Indicative approach
Active Account and profile data While the Account is active and for a reasonable period after closure
Public profile content Until removed, Account closure or moderation, subject to backups and legal retention
Login and security logs Usually months rather than indefinitely, unless linked to an incident
Messages and enquiries For the period needed to provide the feature, protect Users and handle disputes
Applications For the Platform workflow and a reasonable dispute/compliance period
Orders, invoices and tax records For the period required by tax, accounting and legal rules
Payment and chargeback records For transaction, fraud, card-scheme and legal limitation periods
Consent and preference records For as long as needed to demonstrate and respect the choice
Reviews and moderation records While the review is relevant and for a reasonable evidence period afterwards
Reports and safety records According to seriousness, legal duties, risk and limitation periods
Verification documents As briefly as reasonably possible for the verification purpose, unless longer retention is justified
Verification result For badge eligibility, fraud prevention, audit and disputes
Support communications For service, quality, evidence and complaint purposes
Backups Until overwritten under the applicable backup cycle
Suppression lists As long as needed to honour opt-out requests
Legal claims and holds Until the claim, investigation or required period ends
We may anonymise data instead of deleting it. Anonymised data that cannot reasonably identify a person is not personal data.
Account deletion does not require deletion where retention is legally required or justified by fraud prevention, safety, claims, accounting or rights of others.
20. Security
We use technical and organisational measures intended to protect personal data.
Measures may include access controls, authentication, encryption in transit where supported, restricted administrative access, backups, logging, security updates, anti-spam and fraud controls, supplier contracts and incident procedures.
No system can be guaranteed completely secure.
Users must protect their own credentials and devices.
A suspected incident should be reported promptly.
We assess personal-data breaches and notify the ICO or affected people where law requires.
Nothing in this Notice limits rights or remedies arising from applicable data-protection law.
21. Personal-data breaches
Where a breach is suspected, we may investigate; contain and remediate; preserve evidence; engage providers and advisers; assess risk; notify regulators; notify affected people; require password resets; restrict Accounts; and cooperate with authorities.
Notifications may be delayed where law or law-enforcement requirements permit or require.
22. Individual rights
Subject to legal conditions and exemptions, a person may have rights to:
be informed;
access personal data;
rectify inaccurate data;
erase data;
restrict processing;
object to processing;
data portability;
withdraw consent;
receive information about automated decision-making;
request safeguards relating to significant automated decisions;
complain to PhotoCrew;
complain to the Information Commissioner’s Office.
Requests may be sent to hello@photocrew.co.uk.
We may verify identity, request clarification, search proportionately, redact third-party information, refuse or charge for manifestly unfounded or excessive requests where law permits, extend the response period for complex or multiple requests where law permits, and retain evidence of the request and response.
Withdrawing consent does not affect processing already carried out lawfully.
Right to object
A person may object to direct marketing at any time. A person may also object to processing based on legitimate interests. We will stop processing unless we demonstrate compelling legitimate grounds or need the information for legal claims, as applicable.
23. Data-protection complaints
A person may make a data-protection complaint by emailing hello@photocrew.co.uk.
The complaint should identify the person, relevant Account or email, the processing complained about, dates, evidence and desired outcome.
We will acknowledge a data-protection complaint within 30 days.
Without undue delay, we will take appropriate steps to investigate, keep the complainant informed where necessary and communicate the outcome.
We may request identity evidence or clarification.
A person may also complain to the Information Commissioner’s Office.
We encourage the person to contact PhotoCrew first so that we have an opportunity to resolve the issue, but this does not remove the right to contact the ICO.
24. Children
The Platform is intended for persons aged 18 or over.
We do not knowingly permit under-18s to create Accounts.
User portfolios may lawfully depict children, but the uploading User must have all required rights, consents and safeguards.
Users must not upload exploitative, sexualised, harmful or unlawful content involving children.
If we believe an under-18 has created an Account, we may suspend it and request information.
A concern involving a child should be reported immediately.
We may report suspected child sexual exploitation or abuse to relevant authorities.
25. Data about people appearing in portfolios
A photograph or video of an identifiable person may be personal data.
The uploading User is responsible for determining a lawful basis, respecting contractual restrictions, providing privacy information where required, protecting children and vulnerable persons, and responding to rights requests as an independent controller where applicable.
PhotoCrew may remove or restrict content following a privacy complaint without deciding every underlying legal issue.
A depicted person may contact hello@photocrew.co.uk with the exact URL and supporting information.
PhotoCrew may ask the uploader for evidence of rights or consent.
26. Third-party links and external services
External websites and providers have their own privacy practices.
PhotoCrew is not responsible for an independent controller’s processing.
Users should read external notices.
Clicking a link or loading an embed may disclose technical information to the provider.
Cookie choices may control some embeds where technically available.
27. Business transfers
If PhotoCrew or relevant assets are sold, transferred, financed, merged, reorganised or acquired, personal data may be disclosed or transferred subject to confidentiality, due diligence, legitimate interests and applicable law. The new controller may continue processing for compatible purposes and will provide required information.
28. Accuracy
Users are responsible for keeping Account and profile data accurate.
PhotoCrew may receive inaccurate information from Users or third parties.
We may correct, restrict or remove information where appropriate.
Publication does not constitute verification.
A person may request correction of their own inaccurate personal data.
29. Automated decision-making and profiling
We may use automated systems to detect spam, fraud, abuse, duplicate Accounts, review manipulation, security threats, eligibility, search relevance or content risk.
These systems may make recommendations or trigger review.
We do not generally make decisions based solely on automated processing that produce legal or similarly significant effects.
If such processing is introduced, we will identify a lawful basis, provide required information and safeguards, and allow human intervention where required.
Automated systems can make errors.
Users may contact us to challenge a significant decision.
30. Artificial intelligence
AI-assisted services may be used for moderation, support, search, classification, summaries, analytics, security, recommendations or technical operations.
Data shared with an AI provider will be limited according to purpose, contract and law.
Users should not submit unnecessary confidential or sensitive information to AI-enabled features.
AI output may be inaccurate or biased.
Users remain responsible for reviewing content before publication.
We may update this Notice if AI processing materially changes.
31. No sale of personal data
PhotoCrew does not ordinarily sell personal data as a standalone customer list. This statement does not prevent disclosure to service providers, business transfers, lawful advertising measurement, disclosure required by law, User-requested sharing or use of aggregated or anonymised information.
Where a particular activity requires consent or an additional notice, we will provide it.
32. Changes to this Notice
We may update this Notice for legal, technical, operational or business changes.
The effective date and version will be changed.
Material changes may be communicated by email, Account notice or Platform notice.
Where a new purpose is incompatible or requires consent, we will take the steps required by law before processing.
Users should review this Notice periodically.
33. Legal character of this Notice
This Notice provides privacy information; it is not a request for blanket consent.
A person does not lose statutory rights by using the Platform.
“Acknowledging” or reading this Notice does not create consent where consent is legally required.
PhotoCrew relies on the lawful basis appropriate to each purpose.
The Terms and Conditions govern the contractual use of the Platform.
This Notice does not create a warranty that no privacy or security incident can occur.
Nothing in this Notice excludes an obligation or remedy that cannot lawfully be excluded.
34. Scope
This Notice may apply to:
visitors;
registered Visitors;
Creators;
Studios;
Clients;
applicants;
reviewers;
support contacts;
persons shown in portfolios;
team members;
representatives of organisations;
website administrators and contractors;
persons reporting content;
persons involved in disputes;
payment contacts;
prospective Users;
persons whose information is supplied by another User.
It applies to public and non-public information processed through or in connection with the Platform.
35. Controller, processor, joint-controller and independent-controller roles
PhotoCrew is generally the controller for operation of Accounts, public profiles, Platform messaging, billing records, security, moderation, search, analytics and support.
A payment, verification, email, analytics or security provider may act as a processor, independent controller or joint controller depending on the activity.
A User receiving an enquiry, application, message or project information normally determines their own subsequent purposes and may be an independent controller.
PhotoCrew is not the controller merely because two Users first met on the Platform if their later processing is independent of PhotoCrew.
Users must provide their own privacy information where required.
PhotoCrew may be required to assist a processor or controller with rights, complaints, security or legal requests.
Legal roles depend on actual facts, not labels alone.
36. Expanded identity and Account information
We may process:
full or preferred name;
title;
username;
business or trading name;
profile image;
date of birth or age confirmation where needed;
country, region and service area;
Account type and role;
user ID;
registration date;
verification and status;
login history;
password hash and security state;
accepted policy versions;
communication preferences;
linked organisation or team;
Account restrictions, warnings and enforcement history.
PhotoCrew does not need every category for every person.
37. Expanded professional, listing and portfolio information
We may process:
biography and professional description;
categories and specialisms;
skills, experience and equipment;
qualifications, awards and memberships;
languages;
prices, rates, packages and service terms;
portfolio images, video, audio and documents;
file metadata, captions and alt text;
availability and dates;
working locations and travel range;
team information;
service listings;
gigs and jobs;
applications and responses;
endorsements, reviews and ratings;
public and private contact information;
profile-completeness and quality indicators.
Information supplied by a User may be inaccurate, outdated or unlawful. Publication does not mean PhotoCrew has verified it.
38. Information about people depicted or mentioned in User Content
Photographs, videos, reviews, messages and portfolio descriptions may identify people who do not hold an Account.
The uploading User is responsible for having an appropriate lawful basis, permission, release or other right.
PhotoCrew may process the information as host and controller of Platform operations.
A depicted person may request review, restriction or removal by providing the exact URL and enough information to identify the issue.
PhotoCrew may ask the uploader for evidence.
Removal is not guaranteed where the request is disputed, a legal exemption applies or evidence is insufficient.
PhotoCrew may remove content without determining final legal ownership.
External copies are outside PhotoCrew’s direct control.
39. Information supplied by other Users
A person may provide information about:
a team member;
a Client;
an applicant;
a referee;
a model or performer;
a collaborator;
a rights holder;
a complainant or reported person;
a person involved in a project or dispute.
The supplying User warrants that they are permitted to do so. PhotoCrew may contact the person, restrict the information or request evidence where appropriate.
40. Special-category data
PhotoCrew does not ordinarily require Users to publish special-category data.
Such data may appear voluntarily or incidentally in images, biographies, accessibility requests, messages, reviews, verification, complaints or moderation evidence.
Users should not disclose health, disability, race, ethnicity, religion, political opinion, trade-union membership, genetic data, biometric identifiers, sex-life or sexual-orientation information unless necessary and lawful.
Where PhotoCrew intentionally processes such data, it must identify an Article 6 basis and an Article 9 condition.
Conditions may include explicit consent, legal claims, employment or social-protection law, substantial public interest or another lawful condition.
PhotoCrew may redact, restrict or remove unnecessary sensitive information.
Public disclosure creates increased risk and should be considered carefully.
A User’s voluntary publication does not remove PhotoCrew’s duties but may affect reasonable expectations and available remedies.
41. Criminal-offence and allegation information
Reports, reviews, fraud investigations, legal requests and safety complaints may contain allegations of crime or unlawful conduct.
Allegations may be false, disputed, unproven or incomplete.
PhotoCrew may process such information where permitted by law for prevention, detection, safeguarding, legal claims, regulatory cooperation or substantial public interest.
Access may be restricted.
PhotoCrew does not publish every allegation.
A moderation action is not a criminal finding.
PhotoCrew may preserve evidence and disclose it where lawfully required.
42. Children and young people
Account use is intended for persons aged 18 or over.
PhotoCrew may process age-confirmation or risk information to enforce this restriction.
User Content may lawfully depict children, for example family, school, event, fashion or commercial photography.
The uploading User is responsible for appropriate rights, safeguarding and lawful publication.
PhotoCrew prohibits exploitative, sexual, abusive or unlawful content involving children.
A suspected under-18 Account may be suspended while investigated.
PhotoCrew may consider the best interests of children where the service is likely to be accessed by them, even where the intended age is 18+.
PhotoCrew may report suspected child exploitation or abuse to relevant authorities.
43. Detailed purpose and lawful-basis matrix
Purpose Typical information Main lawful basis
Register and authenticate Accounts Identity, contact, login, Device and security information Contract; legitimate interests
Provide public profiles Profile, portfolio, location, service and contact information Contract; legitimate interests; consent where specifically required
Search, ranking and recommendations Profile, location, category, activity, plan and quality signals Contract; legitimate interests
Messaging and enquiries Identity, communication, attachment and technical information Contract; legitimate interests
Gigs, jobs and applications Listing, identity, professional, application and communication information Contract; legitimate interests
Reviews and ratings Review, Account, interaction, evidence and fraud information Contract; legitimate interests; legal obligation where applicable
Plans, add-ons and billing Identity, transaction, subscription, billing and technical information Contract; legal obligation; legitimate interests
Payment and chargebacks Transaction, Device, Account, evidence and risk information Contract; legitimate interests; legal obligation
Security and fraud Login, IP, Device, activity, payment and risk information Legitimate interests; legal obligation; recognised legitimate interest where applicable
Moderation and safety User Content, messages, reports, evidence and enforcement information Legitimate interests; legal obligation; legal claims
Support and complaints Account, communication, technical, transaction and evidence information Contract; legitimate interests; legal obligation
Legal compliance Relevant Account, transaction, content and communication information Legal obligation; legitimate interests
Tax and accounting Identity, transaction, invoice and billing information Legal obligation; legitimate interests
Analytics and improvement Usage, Device, technical, feedback and aggregate information Consent where required by PECR; statutory exception where valid; legitimate interests for subsequent processing where lawful
Marketing Contact, preference and campaign information Consent; lawful soft opt-in; legitimate interests for permitted business communications
Business transfer Relevant Account, contract and transaction information Legitimate interests; legal obligation
Legal claims Relevant records, evidence and communications Legitimate interests; legal obligation; legal claims
The basis may vary with context. PhotoCrew will not rely on contract merely because processing is mentioned in Terms if the processing is not objectively necessary for the requested service.
44. Legitimate interests
PhotoCrew’s legitimate interests may include:
operating a sustainable marketplace;
providing relevant search;
preventing fraud, spam and abuse;
protecting Users and the Platform;
securing Accounts and payments;
moderating content;
enforcing Terms;
handling disputes;
measuring and improving functionality;
communicating essential information;
maintaining business and legal records;
preventing misuse of public contact information;
defending legal rights;
understanding demand and performance.
PhotoCrew should assess necessity and balance these interests against rights and reasonable expectations. Legitimate interests do not override PECR consent requirements for Device storage or access.
45. Recognised legitimate interests and legal changes
Current UK law may identify certain recognised legitimate interests for which a balancing test is modified or not required.
PhotoCrew may rely on such a basis only where the actual purpose falls within the statutory category and all other duties are met.
Possible areas may include public security, emergency response, safeguarding or prevention and detection of crime where the legal conditions apply.
Mention of the basis does not mean it is used for every security or moderation activity.
PhotoCrew will review changes to ICO guidance and legislation.
46. Contractual necessity
PhotoCrew may process information necessary to create an Account, publish requested content, provide messaging, manage subscriptions and deliver Paid Features.
Information that is merely useful for advertising or general improvement is not automatically necessary for contract.
If required information is not supplied, PhotoCrew may be unable to provide the requested feature.
A User may choose not to publish optional profile fields.
Some information may be publicly necessary to operate a public professional profile.
47. Consent
Consent may be used for optional cookies, certain marketing, optional sensitive information or another purpose requiring a choice.
Consent must be specific and informed.
Consent may be withdrawn.
Withdrawal does not affect earlier lawful processing.
Refusing optional consent should not prevent unrelated core services unless the information is genuinely necessary.
PhotoCrew may retain a suppression or consent record.
Consent is not valid merely because a person uses the Platform.
48. Search, ranking, recommendation and profiling
PhotoCrew may analyse profile and activity information to organise results, recommend content, identify relevance and protect integrity.
Signals may include category, service, location, completeness, recency, reviews, verification, plan, Boost, availability, engagement, safety and technical factors.
Paid status may influence visibility where described.
Search ranking is not a legal or professional assessment of a person.
Fraud or safety profiling may restrict functionality or trigger review.
Automated signals can be wrong.
PhotoCrew may offer human review where legally required or reasonably appropriate.
The Terms contain further ranking information.
49. Messaging, enquiries and communication monitoring
PhotoCrew may store messages to provide the feature, maintain history, investigate abuse, prevent fraud and enforce Terms.
Messages are not guaranteed to be end-to-end encrypted.
Authorised personnel or providers may access them where necessary and lawful.
Automated systems may inspect links, spam patterns, attachments, fraud signals or prohibited content.
PhotoCrew does not routinely read every message manually.
Users must not send unnecessary sensitive information, passwords or full card details.
Deletion by one User may not delete the recipient’s copy or compliance record.
Communications outside PhotoCrew are controlled by the participants and their providers.
50. Reviews, reports, moderation and online safety
PhotoCrew may process information to:
verify that a review reflects a genuine interaction;
detect fake or incentivised reviews;
investigate reports;
assess illegal content;
protect children and vulnerable persons;
address threats, harassment, fraud, discrimination or exploitation;
make moderation decisions;
maintain risk assessments and records;
respond to appeals;
cooperate with authorities.
A report may contain information about both reporter and reported person. PhotoCrew may limit disclosure to protect safety, confidentiality or investigations.
51. Payment, Stripe and financial information
Stripe or another provider may process full card or bank details directly.
PhotoCrew may receive customer ID, transaction ID, amount, currency, card brand, last digits, billing information, status, risk result and dispute information.
PhotoCrew may retain orders, refunds, chargebacks, invoices and subscription records.
Payment providers may be independent controllers for fraud, regulation and service operation.
Information may be shared with banks, card schemes, advisers and authorities during disputes.
PhotoCrew does not control every provider retention period.
Project payments made directly between Users are not processed under PhotoCrew’s ordinary billing role unless a feature expressly states otherwise.
52. Email, Brevo and communication providers
PhotoCrew may use an email-delivery, transactional, support or newsletter provider.
Providers may process recipient, sender, subject, message content, delivery, bounce, complaint, open and click information.
Service communications may be necessary for Account operation.
Marketing communications follow applicable consent or soft-opt-in rules.
PhotoCrew may maintain suppression records after unsubscribe.
Email transmission is not guaranteed confidential or error-free.
A provider may scan content for abuse, delivery or security.
The specific provider may change.
53. Technical logs, cookies and Device information
PhotoCrew may process IP address, browser, Device, operating system, timestamp, requested URL, referrer, user agent, session, cookie choice, response code and security events.
Such information may be necessary for delivery, security, troubleshooting, fraud prevention, analytics and legal evidence.
Cookie and similar-technology use is explained in the Cookie Policy.
Rejecting optional cookies does not prevent necessary server logs.
Technical information can sometimes identify or single out a person.
PhotoCrew may aggregate or anonymise information.
No method of anonymisation is described as absolute where re-identification remains reasonably possible.
54. Security, fraud and abuse information
PhotoCrew may process:
failed logins;
suspicious IPs;
Device and browser signals;
Account links;
duplicate-account indicators;
payment risk;
rate limits;
bot and scraping indicators;
malicious links;
spam and review-manipulation signals;
reports and enforcement history;
evidence of attempted evasion.
Security decisions may be automated or manual. PhotoCrew may withhold detailed signals to prevent circumvention.
55. Verification information
Verification may involve identity, business, address, selfie, document, expiry or status information.
A third-party provider may perform the check.
The collection screen should explain whether verification is optional or required.
PhotoCrew may retain a result rather than the full document where feasible.
Documents may be retained for a limited fraud, dispute or legal period.
Verification does not guarantee honesty or quality.
A User who refuses required verification may lose access to a feature.
Biometric processing will require a separate lawful assessment where used for unique identification.
56. Support, complaints and evidence
Support communications may include Account, technical, payment, accessibility, privacy, safety and legal information.
PhotoCrew may retain them to resolve issues, improve support, evidence decisions and defend claims.
A complaint may be shared internally or with a relevant provider.
PhotoCrew may request identity verification before disclosing Account information.
Abusive communication may be restricted while maintaining a lawful route for rights or complaints.
PhotoCrew does not guarantee that every requested outcome will be granted.
57. Sources of information
Information may come from:
the person;
another User;
public profiles and websites;
search engines;
payment providers;
hosting and security providers;
email providers;
analytics and consent providers;
verification providers;
regulators, courts or law enforcement;
advisers;
cookies and Device technology;
derived analysis.
Where information is not obtained directly, PhotoCrew will provide required information within the applicable period unless an exemption applies.
58. Recipients and provider categories
PhotoCrew may disclose relevant information to:
hosting and infrastructure providers;
CDN and security providers;
WordPress, plugin and software suppliers;
payment providers;
email and newsletter providers;
consent and analytics providers;
map, video and social providers;
verification providers;
anti-spam and fraud providers;
support and error-monitoring providers;
backup and storage providers;
contractors and administrators;
accountants, lawyers, insurers and auditors;
banks and card schemes;
regulators, courts and law enforcement;
buyers, sellers, investors or restructuring parties;
Users where sharing is requested or necessary for the feature.
Disclosure is limited according to purpose, role, contract, confidentiality and law where applicable.
59. Processors and contracts
A processor should act under a written data-processing contract where required.
Contracts may address instructions, confidentiality, security, subprocessors, assistance, deletion, audits and transfers.
PhotoCrew may rely on standard provider terms where appropriate.
A provider’s contract does not guarantee that no breach or error can occur.
PhotoCrew may replace providers or permit subprocessors subject to applicable requirements.
Current provider details may be supplied where reasonably required, subject to security and confidentiality.
60. Independent controllers
Providers may act independently for:
payment regulation and fraud;
legal compliance;
delivery of external social, map or video services;
their own Account services;
network security;
professional advice;
law-enforcement or regulatory functions.
PhotoCrew is not responsible for every independent purpose, but remains responsible for its own lawful disclosure and transparency duties.
61. Business transfer and succession
Information may be disclosed during investment, sale, merger, restructuring, financing, insolvency or transfer of the Platform.
Disclosure may occur under confidentiality for due diligence.
The receiving party may become controller.
PhotoCrew may transfer contracts and records as permitted by law.
Users will receive required information about material controller changes.
A business transfer does not permit unrelated unlawful use.
62. Legal, regulatory and protective disclosures
PhotoCrew may disclose information where reasonably believed necessary to:
comply with law, court order or regulator;
prevent or investigate fraud or crime;
protect life or safety;
enforce Terms;
establish, exercise or defend legal claims;
protect PhotoCrew, Users or third parties;
respond to rights complaints;
address intellectual-property infringement;
comply with tax, accounting or online-safety duties.
PhotoCrew may challenge, narrow or refuse a request where lawful but does not guarantee that it will do so.
63. International transfers
Providers may process information outside the United Kingdom.
PhotoCrew may rely on UK adequacy regulations.
Where adequacy is unavailable, PhotoCrew may use the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, binding corporate rules or another appropriate safeguard.
PhotoCrew may conduct or rely on transfer-risk assessments and supplementary measures.
An Article 49 exception may be used only where applicable.
No safeguard eliminates every foreign-law, government-access or cybersecurity risk.
A person may request information about relevant safeguards, subject to confidentiality and security.
A third party may independently transfer information under its own notice.
64. Retention principles
Retention is based on:
the purpose;
Account status;
legal and tax requirements;
contract and payment records;
fraud and safety risk;
dispute and limitation periods;
review and content history;
technical backup cycles;
the rights and expectations of others;
the feasibility of deletion or anonymisation.
PhotoCrew does not retain every category for the same period.
65. Indicative retention schedule
Information Indicative approach
Active Account While active and for a reasonable closure period
Public profile and listings Until removed, expiry, closure or moderation, subject to backups and legal holds
Authentication and security logs Usually months, longer if connected to an incident or claim
Messages For service history, safety, dispute and operational needs; not necessarily indefinitely
Applications For the relevant workflow and a reasonable dispute/compliance period
Reviews While published and for evidence after removal where justified
Moderation and reports Based on seriousness, recurrence, safety, legal duties and limitation periods
Orders, invoices and tax records For the applicable accounting and tax period
Payment disputes and chargebacks For provider, fraud and legal limitation periods
Consent and policy acceptance For as long as needed to demonstrate the choice or contract
Marketing suppression As long as needed to respect opt-out
Verification documents As briefly as feasible, unless fraud, dispute or law justifies longer retention
Verification status While relevant to eligibility and for reasonable audit/fraud periods
Support records For resolution, quality, evidence and legal needs
Backups Until overwritten under the relevant cycle
Legal hold Until the matter and required retention end
Exact periods may vary. Criteria are used where a fixed period is not reasonably possible.
66. Account closure, deletion and de-indexing
Account closure may remove public access but does not instantly erase every record.
PhotoCrew may retain transaction, fraud, moderation, complaint, consent, tax and legal records.
Other Users may retain messages, contracts, reviews or applications.
Search engines may retain cached pages.
Backups may retain data until overwritten.
Data may be anonymised or restricted rather than deleted.
A deletion request is assessed under applicable law and exemptions.
Users should save information they need before deletion.
67. Backups, archives and technical deletion
Backups protect service continuity and incident recovery.
Immediate deletion from every backup may be impracticable.
Deleted data may remain isolated until the backup expires.
Restored backups may require deleted records to be removed again.
Access to backups should be restricted.
PhotoCrew does not use isolated backup data for ordinary active purposes.
68. Security measures and limitations
PhotoCrew may use:
access controls;
password hashing;
encryption in transit;
restricted administration;
backups;
logging;
updates;
firewalls and anti-spam;
fraud and rate controls;
provider contracts;
incident procedures;
role-based access.
No online system is completely secure. This statement does not excuse a failure to use appropriate technical and organisational measures.
69. Personal-data breaches
Where an incident is suspected, PhotoCrew may:
investigate;
contain and remediate;
preserve evidence;
involve providers and advisers;
assess risk;
notify the ICO where required;
notify affected people where required;
reset credentials;
restrict functionality;
cooperate with authorities.
Notification may be delayed where law permits or an investigation requires it. Not every security event is a reportable personal-data breach.
70. Rights overview
Subject to conditions and exemptions, a person may have rights to:
information;
access;
rectification;
erasure;
restriction;
objection;
portability;
withdraw consent;
safeguards concerning significant automated decisions;
make a complaint.
Rights differ according to lawful basis and circumstances.
71. Exercising rights
A request may be sent to hello@photocrew.co.uk and should include enough information to identify the person, Account and request.
PhotoCrew may:
verify identity;
request clarification;
conduct reasonable and proportionate searches;
redact another person’s information;
apply exemptions;
refuse or charge for manifestly unfounded or excessive requests where law permits;
extend time for complex or multiple requests where law permits;
preserve evidence of the request and response.
Users must not submit another person’s request without authority.
72. Right of access
A person may request confirmation and a copy of their personal data, subject to law.
The right is not a right to unrestricted copies of software, confidential moderation methods, legal advice or another person’s data.
PhotoCrew may provide data in a commonly used electronic format.
Repeated or broad requests may require clarification.
Reasonable and proportionate searches will be conducted.
Deleted, overwritten or anonymised data may not be recoverable.
73. Rectification
A person may request correction of inaccurate personal data.
Opinion, review and disputed allegation information may not be “inaccurate” merely because it is contested.
PhotoCrew may record a dispute or request evidence.
Users can correct many profile fields directly.
Historical transaction or enforcement records may be retained with a correction note.
74. Erasure and restriction
Erasure is not absolute.
Data may be retained for legal obligations, claims, fraud, safety, freedom of expression, public interest or another lawful reason.
Restriction may be used while accuracy or objection is considered.
Public removal does not control external copies.
An anonymised record may remain.
PhotoCrew may notify relevant recipients where required and feasible.
75. Data portability
Portability applies only to certain data supplied by the person, processed by automated means, on consent or contract.
It does not necessarily cover inferred ranking, moderation, fraud or proprietary data.
A transfer may be refused where it adversely affects others or is technically unsafe.
PhotoCrew may provide a structured, commonly used machine-readable format where the right applies.
76. Right to object
A person has the right to object at any time to direct marketing. PhotoCrew will stop direct marketing to that person, subject to retaining a suppression record.
A person may also object to processing based on legitimate interests. PhotoCrew will consider the objection and stop unless compelling legitimate grounds or legal claims justify continuation, as applicable.
An objection does not automatically require deletion of records needed for contract, law, security or claims.
77. Automated decision-making
PhotoCrew may use automated tools for ranking, spam, fraud, safety, eligibility and moderation support.
PhotoCrew does not generally intend to make solely automated decisions producing legal or similarly significant effects.
If such processing is introduced, PhotoCrew will identify a lawful basis, explain material logic and provide required safeguards.
A person may request human intervention where the right applies.
A recommendation or search rank is not ordinarily a legal decision.
Automated systems can produce false positives and false negatives.
78. Marketing rights and preferences
Marketing may be sent with consent or under a lawful soft opt-in where available.
Essential service communications are not marketing merely because they concern the Account or subscription.
Users can unsubscribe from marketing.
PhotoCrew may retain a suppression record.
An unsubscribe may not stop a campaign already in transmission immediately.
Business-to-business communications may be sent where law permits and recipients can object.
PhotoCrew does not sell a mailing list as an ordinary business activity.
79. Data-protection complaint process
A complaint may be submitted electronically to hello@photocrew.co.uk.
It should identify the processing complained of, relevant dates, Account, evidence and requested outcome.
PhotoCrew will acknowledge a data-protection complaint within 30 days.
PhotoCrew will investigate appropriately and communicate the outcome without undue delay.
PhotoCrew may keep the complainant informed where necessary.
Identity or authority may be verified.
A complaint may overlap with a rights request, moderation appeal, payment dispute or accessibility complaint and may be handled through coordinated processes.
PhotoCrew does not guarantee that the complainant’s requested outcome will be granted.
80. Complaint to the Information Commissioner’s Office
A person may complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. PhotoCrew encourages the person to contact PhotoCrew first so that the matter can be investigated, but this does not remove the right to contact the ICO.
PhotoCrew does not control the ICO’s process, timing or decision.
81. Public-profile risk and personal responsibility
Public profiles are designed to be discovered.
Users decide what optional information to publish, subject to required fields and settings.
Public content can be indexed, copied, screenshotted, archived, linked to, quoted or unlawfully scraped.
A User should not publish a home address, identity document, private email, private telephone number, financial information, confidential Client information or precise availability unless necessary and safe.
Privacy settings reduce but do not eliminate risk.
PhotoCrew prohibits misuse but cannot guarantee that every person obeys the Terms or law.
Users publish public User Content at their own informed risk, subject to their statutory rights and PhotoCrew’s legal duties.
82. Search engines, archives, scraping and AI reuse
Search engines may index public pages.
Archives and caches may persist after removal.
Bots may ignore technical restrictions.
Third parties may use public content in datasets or AI systems without permission.
PhotoCrew may use robots controls, rate limits, contractual prohibitions and enforcement.
PhotoCrew does not guarantee prevention or external deletion.
PhotoCrew may assist with information but cannot command an independent controller.
A User may need to contact the third party directly.
PhotoCrew is not liable for unlawful third-party reuse outside reasonable control except to the extent law makes PhotoCrew responsible.
83. Analytics and accuracy limitations
Analytics may be incomplete because of consent choices, bots, privacy tools, caching, shared Devices, duplicate filtering and technical errors.
Profile-view analytics do not necessarily represent unique people or commercial interest.
PhotoCrew may derive aggregate trends.
Analytics may be delayed or corrected.
Paid Users must not treat analytics as audited evidence, guaranteed exposure or financial advice.
Cookie-related legal treatment is explained in the Cookie Policy.
84. User obligations as independent controllers
A User receiving personal data must:
use it only for relevant lawful purposes;
provide privacy information where required;
secure it;
avoid unrelated marketing without a lawful basis;
respect rights;
delete or retain it according to a lawful schedule;
avoid discrimination or unlawful profiling;
report relevant breaches where required;
not sell, scrape or compile Platform contact data;
comply with employment, recruitment and client-data obligations applicable to them.
PhotoCrew may suspend a User for misuse but does not supervise every independent processing activity.
85. No absolute confidentiality, anonymity or control guarantee
PhotoCrew does not represent that:
public information will remain confined to PhotoCrew;
a message will remain confidential after receipt;
every third party will comply with law;
no security incident will occur;
deletion removes every copy;
a VPN, private browser or alias makes a person anonymous;
all analytics are exact;
all User information is true;
every Provider is located only in the UK;
every future technical change can be described in advance.
These limitations do not remove PhotoCrew’s own mandatory duties.
86. Liability and statutory rights
This Notice does not create a contractual exclusion of UK GDPR or Data Protection Act rights.
PhotoCrew does not accept responsibility for independent User misuse, unlawful scraping, external websites, search-engine caches or provider conduct outside reasonable control except to the extent law makes PhotoCrew responsible.
PhotoCrew does not exclude liability for its own unlawful processing, failure to apply appropriate measures, fraud or another non-excludable matter.
Liability is also subject to the lawful limitations in the Terms and Conditions.
Users should take reasonable steps to protect their information and report concerns promptly.
No privacy notice can provide absolute immunity from regulatory action or civil claims.
87. Operator, controller contact and address for service
PhotoCrew.co.uk is operated by Mr. Martin J., a sole trader trading as PhotoCrew.co.uk.
Address for business correspondence and service of legal documents: 44 Chesterton House, Ingrave Street, London, SW11 2UD, United Kingdom.
Email: hello@photocrew.co.uk
The address above is provided for business correspondence and service of legal documents only. It is not a public office, retail premises, meeting location, collection point, delivery point or location at which in-person customer support is offered. No User or other person is authorised to attend without a prior written appointment expressly confirmed by PhotoCrew. Unsolicited visits, personal approaches, harassment, intimidation, surveillance, photography, filming, publication of unrelated personal information, doxxing, unwanted deliveries and use of the address for unrelated marketing are prohibited to the fullest extent permitted by law.
For the processing described in this Notice, the sole trader operating PhotoCrew.co.uk generally acts as the data controller unless a specific notice or the factual relationship identifies another controller.
Privacy enquiries, rights requests and data-protection complaints should be sent to hello@photocrew.co.uk.
88. Changes to this Notice
PhotoCrew may update this Notice for legal, technical, provider, feature, business or security changes.
The effective date and version should be updated.
Material changes may be notified through email, Account notice or the Platform.
A new incompatible purpose will be assessed and, where required, a new basis or consent obtained.
Earlier versions may be retained for evidence.
Users should review the current version.
89. Contact
Privacy, personal-data, rights and complaint enquiries:
hello@photocrew.co.uk
Schedule 1 — Data-category register
PhotoCrew’s internal data map should record for each category:
source;
purpose;
lawful basis;
system location;
public or private status;
recipient categories;
international transfer;
retention;
security classification;
responsible owner;
rights implications;
deletion method.
Schedule 2 — Rights-request template
Full name:
Account email or user ID:
Right being exercised:
Information or processing concerned:
Date range:
Relevant URLs:
Preferred response format:
Authority document if acting for another person:
Do not send passwords, full card details or unnecessary identity documents unless requested through a secure method.
Schedule 3 — Data-protection complaint template
Name:
Contact details:
Account identifier:
Description of the processing complained about:
Relevant dates:
Evidence:
Previous contact with PhotoCrew:
Requested outcome:
Accessibility or communication needs:
PhotoCrew will acknowledge the complaint within 30 days and investigate without undue delay as required by applicable law.
Schedule 4 — Personal-data incident report
A report should include:
what happened;
date and time;
information affected;
people affected;
whether information was viewed, copied, altered or lost;
containment steps;
evidence;
contact details;
ongoing risk.
Urgent security information should be sent promptly to hello@photocrew.co.uk with a clear subject line.
Schedule 5 — Public-profile safety notice
Before publishing, Users should check that content does not unnecessarily reveal:
home address;
private telephone number;
private login email;
identity documents;
financial information;
children’s identifying details;
confidential Client information;
exact future absence or travel patterns;
building access details;
information prohibited by contract or law.
Schedule 6 — Provider due-diligence checklist
Before using a material provider, PhotoCrew should consider:
role as processor or controller;
contract terms;
security;
subprocessors;
data location;
transfer mechanism;
retention;
deletion;
incident notification;
access controls;
support and audit information;
ability to assist with rights requests.
Schedule 7 — Maximum protection statement
PhotoCrew operates a public, user-generated and technically complex online marketplace. Users and independent providers can create risks that PhotoCrew cannot entirely eliminate. Public information can leave PhotoCrew’s direct control, third-party systems can fail, and no security or deletion process is absolute. PhotoCrew therefore limits warranties and responsibility to the fullest extent permitted by law and requires Users to make informed publication and communication choices.
Nothing in this Schedule waives UK data-protection rights, excuses unlawful processing or excludes liability that cannot lawfully be excluded.