
PRIVACY & COMPLIANCE
Built for the person in front of the camera
A Manifest Mirror sits in public space and points a camera at guests. That is a privacy question before it is a product question. This page is written for data protection officers, works councils and legal teams: what is captured, what is kept, for how long, and on what legal basis.
PRINCIPLES
Six commitments that shape the product
These are not policy statements bolted on after the fact. Each one is a constraint the platform was designed around, and each one has a visible consequence in the guest experience.
Consent before the camera
The attract loop shows no live image. The camera feed starts when a guest actively begins a session — by touch or by pairing a phone — and after the notice has been shown. Walking past a mirror leaves no trace.
Ephemeral by default
The live stream is processed for the length of the session and not archived. Only the recording the guest asked for survives the session, and only for a fixed window.
No biometric templates
Identity lock keeps a face looking like itself inside one live session. It does not compute, store or compare a face template. Nothing in the system can recognise a returning guest.
No ad-tech in the room
No third-party trackers, no advertising pixels, no analytics SDKs embedded in the kiosk. Operational telemetry exists to keep units running, not to profile the people using them.
Processed in the EU
Session processing and delivery run on EU infrastructure. Manifest Media is the brand of BAISE Systems, based in the Mediapark, Cologne, and operates under German and European law.
Visibly artificial
Guests are told that what they see is AI-generated, in the interface and in the delivery email. A transformation that hides what it is would fail the product, not only the regulation.
DATA LIFECYCLE
Everything the platform touches, and how long it stays
One table, no footnotes. If a category of data is not listed here, the platform does not collect it.
| Live camera stream | Processed in real time to generate the mirror image. Not written to disk, not archived, discarded as the session ends. |
|---|---|
| Generated video | Displayed continuously on the mirror during the session. Only the segments a guest chooses to keep are assembled into a recording. |
| Session recording | Stored to allow delivery and re-delivery. Automatically deleted after 7 days, with no manual step required. |
| Email address | Entered by the guest to receive the recording. Used for that delivery only. Deleted together with the delivery record after 30 days. |
| Delivery record | Proof that a recording was sent, retained for support and dispute handling. Automatically deleted after 30 days. |
| Pairing data | The short-lived link between a phone and a mirror created by the QR code. Expires with the session lease. |
| Operational telemetry | Unit health, uptime, session counts, error traces. Aggregate and technical; no guest imagery, no guest identifiers. |
| Training data | None. Guest footage is never used to train, fine-tune or evaluate models. |
Retention windows are platform defaults and apply to every venue on the network. Venues cannot extend them unilaterally.
ONE SESSION, STEP BY STEP
Follow a single guest's data from first glance to deletion
The clock below starts when a guest decides to take part, not when they enter the room.
- Attract mode
The mirror shows a rendered attract loop. The camera is not streaming, nothing is processed, and no image of a passer-by exists at any point in the system.
- Notice and consent
The guest starts the session by touch or by scanning the QR code. They are shown what happens, that the image is AI-generated, and what will be stored if they ask for a recording.
- Session lease opens
A short-lived lease binds one mirror to one session — and, if used, to one paired phone. The camera stream begins here and nowhere earlier.
- Live transformation
Frames are processed continuously with identity lock applied. The guest switches moments and outfits freely. Nothing is written to persistent storage during this phase.
- Session closes
The lease expires, the camera stream stops, the working buffers are released. A guest who wants no recording leaves no residual data at all.
- Optional delivery
If the guest asked for a recording, the chosen segments are assembled and sent to the address they entered. The email states clearly that the content is AI-generated.
- Recording deleted
The stored recording is removed automatically. Re-delivery is possible only inside this window.
- Delivery record deleted
The email address and the delivery record are removed. At this point nothing in the platform connects that session to a person.
GDPR MAPPING
Where the regulation lands in the architecture
A short map for a first review. It is not a substitute for your own assessment, but it shows which article each design decision answers to.
| Requirement | How the platform answers it | |
|---|---|---|
| Art. 6 | Lawful basis for processing | Consent for the camera session and the recording; legitimate interest limited to operating and securing the units. |
| Art. 7 | Conditions for consent | Consent is given by an affirmative act at the mirror, separated from any other step, and can be withdrawn by ending the session or by writing to us. |
| Art. 13 | Information at collection | Purpose, retention and the AI nature of the output are shown on screen before the camera starts, and repeated in the delivery email. |
| Art. 17 | Erasure | Automatic after 7 and 30 days. Earlier deletion on request, handled through the address below. |
| Art. 25 | Data protection by design and by default | No attract-mode capture, no template extraction, no training on guest footage, fixed retention windows enforced centrally. |
| Art. 28 | Processor obligations | Manifest Media acts as processor for the venue. A processor agreement with documented instructions and sub-processors is available on request. |
| Art. 32 | Security of processing | Encrypted transport, origin allow-lists, rate limits per address, session leases, password-protected configuration, kiosk lock on the unit. |
| Art. 35 | Impact assessment | We supply the processing description, data flows and retention model venues need to complete a DPIA for a public installation. |
We make no certification claims. Where a venue requires independent assurance, we support that review with documentation rather than badges.
Identity lock preserves the face; the world around it changes.
AI TRANSPARENCY
Nobody should have to guess that it is generated
The EU AI Act asks providers of systems that generate or manipulate image and video content to make that manipulation clear to the people affected. We treat that as a floor, not a target.
- Notice before the camera. The start screen states that the mirror generates an artificial image of the guest in real time.
- Notice in the artefact. The delivery email says the recording is AI-generated, so the disclosure travels with the file.
- Human review before publication. Every brand world and every moment is reviewed in Manifest Studio before it can be published to a venue.
- Guardrails on output. Worlds are constrained to their brief; the engine renders wardrobe, setting and lighting, not claims about the person.
- No covert use. The platform is not offered for hidden capture, surveillance or identification of any kind.
THE SHORT VERSION
What we hold, and what we never will
Inside the system
- A recording. Only if the guest asked for one, only for seven days.
- An email address. Only to send that recording, only for thirty days.
- A session lease. Short-lived, technical, expires with the session.
- Unit telemetry. Health, uptime and error traces from the hardware.
- Venue configuration. Session length, format, look and published worlds.
Outside the system
- No face templates. No biometric vector is computed, stored or matched.
- No recognition. A returning guest is a new guest every time.
- No training on guests. Footage never enters a model training or evaluation set.
- No advertising identifiers. No cross-site tracking, no data brokers, no resale.
- No silent capture. No processing outside an explicitly started session.
WORKING WITH YOUR DPO
Documents, roles and a single address
In almost every deployment the venue is the controller and Manifest Media is the processor. We prepare the paperwork that follows from that split before an installation goes live.
Processor agreement
An Art. 28 agreement with documented instructions, the list of sub-processors, retention commitments and the technical and organisational measures behind them.
Request the packDPIA support
Processing description, data-flow diagram, retention model and the on-screen notice texts, so your assessment for a public installation starts from evidence rather than assumption.
See the architectureRequests and erasure
Access, erasure and objection requests reach us at hello@manifestmirror.com. Because retention is short and identifiers are minimal, most requests resolve in days rather than weeks.
Write to the teamDPO QUESTIONS
The questions reviewers ask first
Biometric data in the regulatory sense is created when features are extracted to identify or verify a person. That step does not happen here. The camera feed is transformed frame by frame and discarded; no template is derived, stored or compared, and the platform has no way to tell whether two sessions involve the same person.
Nothing. In attract mode the mirror plays a rendered loop and the camera is not streaming. Processing begins only when a guest starts a session by touch or by pairing a phone, and stops when the session ends.
Yes. A guest can end a session at any moment, in which case no recording is created. If a recording was already delivered, it can be deleted on request inside the seven-day window; after that it is removed automatically, and the delivery record follows after thirty days.
Children take part only with a guardian present and consenting, and the venue's own safeguarding rules apply on top. The same retention and deletion windows apply, and venues in sensitive settings can restrict a mirror to supervised operation.
No. Guest footage is never used for training, fine-tuning or evaluation. Brand worlds are built in Manifest Studio from commissioned and licensed reference material, not from what happens in front of a mirror.
Session processing and email delivery run on EU infrastructure, operated from Cologne. The processor agreement names the sub-processors involved and the safeguards that apply to each of them.
Sign the processor agreement, display the notice supplied with the unit, name the installation in its own records of processing, and complete an impact assessment where the placement calls for one. Session length, retention and the AI notice are enforced centrally, so there is no configuration a venue can get wrong.
We make no certification claims on this page. We would rather show the architecture, the retention model and the measures behind them, and support your review directly, than point at a badge.
RELATED
Read on
Platform architecture
The six layers, the data flow from camera to mirror, and the security posture behind a public installation.
Explore the platformIdentity & AI
Why the face must stay the face, how the prompt stack pins identity, and what the model may and may not change.
Read the deep diveLegal notices
The privacy notice, the terms of use, the AI transparency statement and the imprint for BAISE Systems in Cologne.
Open the legal pagesThis page describes how the platform is designed and operated. It is a technical description, not legal advice, and it does not replace a venue's own data protection assessment.