PRIVACY & COMPLIANCE

Built for the person in front of the camera

A Manifest Mirror sits in public space and points a camera at guests. That is a privacy question before it is a product question. This page is written for data protection officers, works councils and legal teams: what is captured, what is kept, for how long, and on what legal basis.

7 daysRecording retention
30 daysEmail delivery retention
90 sSession length
NoneBiometric templates

PRINCIPLES

Six commitments that shape the product

These are not policy statements bolted on after the fact. Each one is a constraint the platform was designed around, and each one has a visible consequence in the guest experience.

01

Consent before the camera

The attract loop shows no live image. The camera feed starts when a guest actively begins a session — by touch or by pairing a phone — and after the notice has been shown. Walking past a mirror leaves no trace.

02

Ephemeral by default

The live stream is processed for the length of the session and not archived. Only the recording the guest asked for survives the session, and only for a fixed window.

03

No biometric templates

Identity lock keeps a face looking like itself inside one live session. It does not compute, store or compare a face template. Nothing in the system can recognise a returning guest.

04

No ad-tech in the room

No third-party trackers, no advertising pixels, no analytics SDKs embedded in the kiosk. Operational telemetry exists to keep units running, not to profile the people using them.

05

Processed in the EU

Session processing and delivery run on EU infrastructure. Manifest Media is the brand of BAISE Systems, based in the Mediapark, Cologne, and operates under German and European law.

06

Visibly artificial

Guests are told that what they see is AI-generated, in the interface and in the delivery email. A transformation that hides what it is would fail the product, not only the regulation.

DATA LIFECYCLE

Everything the platform touches, and how long it stays

One table, no footnotes. If a category of data is not listed here, the platform does not collect it.

Live camera streamProcessed in real time to generate the mirror image. Not written to disk, not archived, discarded as the session ends.
Generated videoDisplayed continuously on the mirror during the session. Only the segments a guest chooses to keep are assembled into a recording.
Session recordingStored to allow delivery and re-delivery. Automatically deleted after 7 days, with no manual step required.
Email addressEntered by the guest to receive the recording. Used for that delivery only. Deleted together with the delivery record after 30 days.
Delivery recordProof that a recording was sent, retained for support and dispute handling. Automatically deleted after 30 days.
Pairing dataThe short-lived link between a phone and a mirror created by the QR code. Expires with the session lease.
Operational telemetryUnit health, uptime, session counts, error traces. Aggregate and technical; no guest imagery, no guest identifiers.
Training dataNone. Guest footage is never used to train, fine-tune or evaluate models.

Retention windows are platform defaults and apply to every venue on the network. Venues cannot extend them unilaterally.

ONE SESSION, STEP BY STEP

Follow a single guest's data from first glance to deletion

The clock below starts when a guest decides to take part, not when they enter the room.

  1. Attract mode

    The mirror shows a rendered attract loop. The camera is not streaming, nothing is processed, and no image of a passer-by exists at any point in the system.

  2. Notice and consent

    The guest starts the session by touch or by scanning the QR code. They are shown what happens, that the image is AI-generated, and what will be stored if they ask for a recording.

  3. Session lease opens

    A short-lived lease binds one mirror to one session — and, if used, to one paired phone. The camera stream begins here and nowhere earlier.

  4. Live transformation

    Frames are processed continuously with identity lock applied. The guest switches moments and outfits freely. Nothing is written to persistent storage during this phase.

  5. Session closes

    The lease expires, the camera stream stops, the working buffers are released. A guest who wants no recording leaves no residual data at all.

  6. Optional delivery

    If the guest asked for a recording, the chosen segments are assembled and sent to the address they entered. The email states clearly that the content is AI-generated.

  7. Recording deleted

    The stored recording is removed automatically. Re-delivery is possible only inside this window.

  8. Delivery record deleted

    The email address and the delivery record are removed. At this point nothing in the platform connects that session to a person.

GDPR MAPPING

Where the regulation lands in the architecture

A short map for a first review. It is not a substitute for your own assessment, but it shows which article each design decision answers to.

RequirementHow the platform answers it
Art. 6Lawful basis for processingConsent for the camera session and the recording; legitimate interest limited to operating and securing the units.
Art. 7Conditions for consentConsent is given by an affirmative act at the mirror, separated from any other step, and can be withdrawn by ending the session or by writing to us.
Art. 13Information at collectionPurpose, retention and the AI nature of the output are shown on screen before the camera starts, and repeated in the delivery email.
Art. 17ErasureAutomatic after 7 and 30 days. Earlier deletion on request, handled through the address below.
Art. 25Data protection by design and by defaultNo attract-mode capture, no template extraction, no training on guest footage, fixed retention windows enforced centrally.
Art. 28Processor obligationsManifest Media acts as processor for the venue. A processor agreement with documented instructions and sub-processors is available on request.
Art. 32Security of processingEncrypted transport, origin allow-lists, rate limits per address, session leases, password-protected configuration, kiosk lock on the unit.
Art. 35Impact assessmentWe supply the processing description, data flows and retention model venues need to complete a DPIA for a public installation.

We make no certification claims. Where a venue requires independent assurance, we support that review with documentation rather than badges.

A guest sees herself transformed in the mirror, her own face preserved Identity lock preserves the face; the world around it changes.

AI TRANSPARENCY

Nobody should have to guess that it is generated

The EU AI Act asks providers of systems that generate or manipulate image and video content to make that manipulation clear to the people affected. We treat that as a floor, not a target.

  • Notice before the camera. The start screen states that the mirror generates an artificial image of the guest in real time.
  • Notice in the artefact. The delivery email says the recording is AI-generated, so the disclosure travels with the file.
  • Human review before publication. Every brand world and every moment is reviewed in Manifest Studio before it can be published to a venue.
  • Guardrails on output. Worlds are constrained to their brief; the engine renders wardrobe, setting and lighting, not claims about the person.
  • No covert use. The platform is not offered for hidden capture, surveillance or identification of any kind.

THE SHORT VERSION

What we hold, and what we never will

IN

Inside the system

  • A recording. Only if the guest asked for one, only for seven days.
  • An email address. Only to send that recording, only for thirty days.
  • A session lease. Short-lived, technical, expires with the session.
  • Unit telemetry. Health, uptime and error traces from the hardware.
  • Venue configuration. Session length, format, look and published worlds.
NO

Outside the system

  • No face templates. No biometric vector is computed, stored or matched.
  • No recognition. A returning guest is a new guest every time.
  • No training on guests. Footage never enters a model training or evaluation set.
  • No advertising identifiers. No cross-site tracking, no data brokers, no resale.
  • No silent capture. No processing outside an explicitly started session.

WORKING WITH YOUR DPO

Documents, roles and a single address

In almost every deployment the venue is the controller and Manifest Media is the processor. We prepare the paperwork that follows from that split before an installation goes live.

01

Processor agreement

An Art. 28 agreement with documented instructions, the list of sub-processors, retention commitments and the technical and organisational measures behind them.

Request the pack
02

DPIA support

Processing description, data-flow diagram, retention model and the on-screen notice texts, so your assessment for a public installation starts from evidence rather than assumption.

See the architecture
03

Requests and erasure

Access, erasure and objection requests reach us at hello@manifestmirror.com. Because retention is short and identifiers are minimal, most requests resolve in days rather than weeks.

Write to the team

DPO QUESTIONS

The questions reviewers ask first

Biometric data in the regulatory sense is created when features are extracted to identify or verify a person. That step does not happen here. The camera feed is transformed frame by frame and discarded; no template is derived, stored or compared, and the platform has no way to tell whether two sessions involve the same person.

Nothing. In attract mode the mirror plays a rendered loop and the camera is not streaming. Processing begins only when a guest starts a session by touch or by pairing a phone, and stops when the session ends.

Yes. A guest can end a session at any moment, in which case no recording is created. If a recording was already delivered, it can be deleted on request inside the seven-day window; after that it is removed automatically, and the delivery record follows after thirty days.

Children take part only with a guardian present and consenting, and the venue's own safeguarding rules apply on top. The same retention and deletion windows apply, and venues in sensitive settings can restrict a mirror to supervised operation.

No. Guest footage is never used for training, fine-tuning or evaluation. Brand worlds are built in Manifest Studio from commissioned and licensed reference material, not from what happens in front of a mirror.

Session processing and email delivery run on EU infrastructure, operated from Cologne. The processor agreement names the sub-processors involved and the safeguards that apply to each of them.

Sign the processor agreement, display the notice supplied with the unit, name the installation in its own records of processing, and complete an impact assessment where the placement calls for one. Session length, retention and the AI notice are enforced centrally, so there is no configuration a venue can get wrong.

We make no certification claims on this page. We would rather show the architecture, the retention model and the measures behind them, and support your review directly, than point at a badge.

RELATED

Read on

PL

Platform architecture

The six layers, the data flow from camera to mirror, and the security posture behind a public installation.

Explore the platform
ID

Identity & AI

Why the face must stay the face, how the prompt stack pins identity, and what the model may and may not change.

Read the deep dive
LG

Legal notices

The privacy notice, the terms of use, the AI transparency statement and the imprint for BAISE Systems in Cologne.

Open the legal pages

This page describes how the platform is designed and operated. It is a technical description, not legal advice, and it does not replace a venue's own data protection assessment.

Next step

See yourself in it. Then decide.

Ninety seconds in front of the mirror explains more than any deck. Book a live session in Cologne or run the browser demo now.