Data Processing Terms (guest data)
Effective: 28 August 2026Version: 1.1
On this page
When you enter your own data, the Provider is the controller. When you enter data about your guests and other third parties - names, contact details, dietary needs, accommodation, photos - the roles reverse: the decision about whose data goes into the system and why is yours. In that case you are the controller and the Provider is the processor.
Article 28(3) GDPR requires that relationship to be set out in writing. This document serves that purpose: by accepting the Terms you and the Provider enter into a data processing agreement on the terms below. No separately signed instrument is needed, but the Provider will issue a signed copy on request.
The In short summaries are informational and are there to help you follow the section. The full text always prevails legally.
This document is available in Hungarian and English. In case of any discrepancy, the Hungarian version prevails.
1. Subject matter and duration
- Subject matter
- Storage and processing of personal data of guests and other third parties in order to operate the wedding planning features.
- Duration
- For as long as the user account exists, or until you delete the data. Deleting the account deletes the guest data with it.
- Nature and purpose
- Storage, organisation, display, search, export, AI analysis you request, and serving the shared guest page and RSVP flow.
- Categories of data subjects
- Guests and their companions, contact persons (witness, master of ceremonies, relative), vendor contacts, and people who upload or appear in guest photos.
- Types of personal data
- Name, email address, phone number, relationship, RSVP status, dietary requirements, seating and accommodation assignment, travel and transfer details, photographs, the token assigned to a guest, and anything else you enter in a free-text field.
The Service neither requests nor expects special category data under Article 9 GDPR about guests; the dietary field is requested as a dietary preference, not as a medical diagnosis, and guests are reminded of this on the RSVP page. (The couple's OWN cultural and religious background is not guest data: it is governed by your explicit consent and Section 2.2 of the Privacy Policy.)
2. Your obligations as controller
As controller you undertake that:
- you enter only personal data for which you have an appropriate legal basis - typically the data subject's consent, or a legitimate interest in organising the wedding;
- you inform the data subjects that their data goes into a wedding planning application, and who they can turn to in order to exercise their rights;
- you publish a phone number, address or other contact detail on a published guest page only with that person's knowledge;
- you do not distribute personal invitation and upload links in a circle where the data could reach unauthorised recipients;
- you handle data subject requests (access, rectification, erasure) yourself through the interface wherever it allows you to.
The Provider has no visibility into any of this, and should not have: it does not inspect the content of guest data.
3. Provider obligations as processor
As processor the Provider undertakes that it will:
- process guest data only on your documented instructions. Using the Service together with this document constitutes such instructions. If an instruction would in the Provider's view breach the law, it will tell you;
- not use guest data for its own purposes - including marketing, profiling or training AI models;
- bind everyone with access to confidentiality and limit access to what the task requires;
- apply the technical and organisational measures required by Article 32 GDPR - encryption in transit and at rest, row-level access control, server-side validation of sharing tokens - as described in Section 7 of the Privacy Policy;
- assist you to a reasonable extent in meeting data subject requests, and in any data protection impact assessment or prior consultation;
- notify you without undue delay after becoming aware of a personal data breach, so that you can meet the 72-hour deadline in Article 33 GDPR;
- delete guest data together with the account when the contract ends, unless retention is required by law.
4. Sub-processors
The Provider engages sub-processors to perform the service. You give general authorisation for this under Article 28(2) GDPR. The full list of engaged sub-processors - with their addresses, activities, storage locations and transfer bases - is on the Subprocessors and recipients page.
The Provider concludes an agreement with each sub-processor that is materially equivalent to this document, and remains liable for their performance as for its own.
Before engaging a new sub-processor or replacing an existing one, the Provider gives at least 15 days notice and you may object; how objections are handled is described in Section 4 of the subprocessor page.
5. Audit and liability
On request the Provider makes available all information necessary to demonstrate compliance with these obligations - a description of the security measures applied, the sub-processor list, and the transfer bases.
The Provider is a sole trader and cannot host an on-site audit. Instead it answers audit questions in writing within a reasonable time. If you are a business and law or your own compliance obligations require a more detailed audit, the parties will agree separately on how to conduct it.
Liability follows Article 82 GDPR: each party is liable for breaches arising from its own role. The limitation of liability in Section 13 of the Terms does not extend to administrative fines under the GDPR or to compensation claims by data subjects.