Skip to content

Data processing agreement

Last updated: August 2026

The short version

When you create a wedding site, you decide what to ask your guests and why: who gets invited, what the RSVP form collects, whether photos and messages are allowed. Because you make those decisions, you are the data controller for your guests' data, and we are your processor — we only hold and handle that data to run the site for you.

There is one exception. For your own account — your name, email, and profile image from the sign-in provider you choose, plus billing data if you buy a paid plan — we are a separate controller in our own right. That part is covered by our Privacy Policy, not by this agreement.

This page is that processor agreement, as required by Article 28 of the GDPR. It is between you (the controller) and Ruben Cipriano, Rua André Vidal de Negreiros, 1950-024 Lisboa, Portugal (the processor).

What we process for you

Subject matter: running your wedding site. Duration: for as long as your site exists. Nature and purpose: storing, displaying, and emailing the content your site collects. Data subjects: your guests and anyone who appears in what they upload. Categories of data: names, email addresses, RSVP answers, guest counts, dietary notes and messages, photos and videos, quiz answers and scores, and technical data such as IP address and browser user-agent used for security and abuse prevention.

Please do not use the site to collect special-category data (health, religion, and similar). Free-text fields like dietary notes can attract it, so keep the question narrow and tell your guests what you need it for.

Our instructions come from you

We process guest data only on your documented instructions. Your instructions are the settings you choose in the admin area, the features you switch on, and any written request you send us. If we are ever required by law to process the data some other way, we will tell you first unless the law forbids it. If we think an instruction breaks data-protection law, we will say so.

Confidentiality

Everyone who can access guest data is bound by a duty of confidentiality and only gets access where they need it to operate or support the service.

Security measures

Under Article 32 we keep appropriate technical and organisational measures in place. Concretely, today that means:

  • All traffic is encrypted in transit over HTTPS/TLS.
  • Sign-in is OAuth-only, with an HttpOnly session cookie; there are no passwords for us to lose.
  • Role-based access control — site owners and the admins they add can only reach their own site's data.
  • Uploads are scanned for malware and rejected if they fail.
  • EXIF and GPS metadata are stripped from stored images, so a guest photo does not carry a location.
  • Rate limiting and hCaptcha on public forms.
  • Audit logging of administrative actions, retained for up to 180 days.
  • Off-site backups on a 30-day rotation, encrypted at rest by the storage provider. We do not add a separate layer of encryption before upload.

We review these as the product changes. We do not currently hold an external security certification, and we do not claim one.

Sub-processors

You give us general authorisation to use the sub-processors below. If we add or replace one, we will post the change on this page and email site owners at least 30 days beforehand, so you have time to object. If you object on reasonable data-protection grounds and we cannot offer an alternative, you may close your site and we will delete the data.

Sub-processors engaged to help run your wedding site
Sub-processorPurposeLocation
CloudflareCDN, DNS, and bot protection in front of the siteUnited States (global edge network; EU transfers under SCCs)
hCaptcha (Intuition Machines)Spam and bot prevention on RSVP and other public formsUnited States (EU transfers under SCCs)
BrevoTransactional email, such as RSVP confirmations and notificationsFrance (EU)
Google / Facebook / GitHubSign-in — only the one provider each person chooses is contactedIreland (EU) or United States, depending on the provider (SCCs)
Hetzner Online GmbHHosting for the application, database and cache, and storage for photos and videosGermany (EU)
StripePayment processing. Not engaged today — it only becomes active once paid plans go live.Ireland (EU) and United States (SCCs)

Each sub-processor is bound by data-protection terms no less protective than these. Where a provider processes data outside the EEA, transfers rely on that provider's published Standard Contractual Clauses or an adequacy decision.

Helping with guest requests

If a guest asks you for access, correction, deletion, a copy of their data, or objects to how it is used, most of it you can do yourself in the admin area — view and edit RSVPs, remove photos, delete a guest's entries. Where the tools do not cover it, email [email protected] and we will help you answer within 2 business days. If a guest contacts us directly about your site, we will not answer for you — we will pass the request on to you.

Breaches, DPIAs, and prior consultation

If we become aware of a personal-data breach affecting your site, we will tell you without undue delay and within 72 hours of becoming aware, with what we know: what happened, who is likely affected, the likely consequences, and what we are doing about it. You are the one who decides whether to notify the supervisory authority or your guests, since you are the controller. We will also give you the information you reasonably need for a data-protection impact assessment or a prior consultation under Articles 35 and 36.

Deletion and return

When you delete your site or close your account, we delete the guest data we hold for you. You can export your data before you do — see your account page. Backups still holding a copy age out on their 30-day rotation, and audit-log entries are kept for up to 180 days where we need them as a record of security-relevant actions. We keep nothing else, unless the law requires us to.

Showing our work

We will give you the information you need to show you meet Article 28 — that is this page, our security measures, and the sub-processor list above, kept current. If you need more for an audit or inspection, write to [email protected] and we will answer in writing, or arrange an audit at a reasonable time and frequency, at your cost, with 30 days' notice. We do not have an independent audit report to hand you today.

Accepting this agreement

You accept this agreement when you create a wedding site. It applies for as long as that site exists and forms part of our Terms of Service. If we change it, we will update the date at the top and email site owners. Questions go to [email protected], or by post to Ruben Cipriano, Rua André Vidal de Negreiros, 1950-024 Lisboa, Portugal.

← Back home·Privacy Policy·Terms of Service