Privacy Policy
Effective: 30 August 2026Version: 2.2
On this page
- 1. Data controller
- 2. Personal data we collect and why
- 3. Processors, recipients and international transfers
- 4. Retention periods
- 5. Your rights under the GDPR
- 6. Cookies and local storage
- 7. Data security
- 8. Personal data breach
- 9. Data about children
- 10. Rights of visitors in the United States
- 11. Complaints to the supervisory authority
- 12. Amendments to this Policy
This Privacy Policy explains how Parais Gergely, a Hungarian sole trader (we, us, our), collects, uses and protects your personal data when you use Wedding Co-Pilot (the Service), in accordance with the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.
Two parts live on their own pages because they change most often: the itemised list of processors and recipients and the cookie and local storage notice. The Article 28 GDPR agreement covering guest data is in the Data Processing Terms. All three form part of this Policy.
The In short summaries are informational and are there to help you follow the section. The full text always prevails legally.
This document is available in Hungarian and English. In case of any discrepancy, the Hungarian version prevails.
1. Data controller
Name: Parais Gergely
Legal form: egyéni vállalkozó
Registered address: 8045 Isztimér, Jókai utca 3.
Registration number: 62671981
Tax number: 92279441-1-27
Phone: +36 30 303 4020
Email: weddingcopilot@outlook.com
Website: www.yourweddingcopilot.com
We are the data controller within the meaning of GDPR Article 4(7) - we determine the purposes and means of processing your personal data.
2. Personal data we collect and why
2.1. Account and identity data
Data: email address, password (stored only as a bcrypt hash), Google account identifier (if using Google OAuth), registration timestamp, last login timestamp.
Purpose: creating and authenticating your account; providing secure access to the Service. Confirmation and password-reset emails are delivered by Resend, Inc. as a processor (Section 3).
Legal basis: GDPR Art. 6(1)(b) - performance of a contract.
2.2. Wedding profile data
Data: names of the couple, planned wedding date and venue, estimated guest count, budget, and other planning details you voluntarily provide.
Purpose: powering personalised AI-assisted planning features.
Legal basis: GDPR Art. 6(1)(b) - performance of a contract.
Cultural background and religious note - special category data. You may optionally state the couple's cultural background (which can indicate ethnic origin) and a religious note. These are special categories of data under GDPR Article 9. The only legal basis for processing them is your explicit consent (Art. 9(2)(a) together with Art. 6(1)(a)), which the interface asks for through a separate, unticked checkbox before the fields can be edited. The consent also covers sending these details, together with your names, to OpenAI (United States) when you use the cultural advisor; the transfer basis is described in Section 3 of the Subprocessors page. You can withdraw consent at any time on the Settings page by unticking the box and saving: both fields are erased immediately and the advisor answers in general terms. The fact and time of consent are logged against your account. Without consent the Service is fully usable; only the personalisation of the advisor is unavailable.
2.3. Guest and third-party data
Data: names of guests you add to the guest list, optionally dietary requirements, seating assignments, and other details you enter.
Purpose: powering the seating chart optimizer and guest management features.
Who plays which role: for this data you are the controller and we are the processor: you decide whose data goes into the system and why. The Article 28 GDPR agreement is set out in the Data Processing Terms.
Legal basis: on your side as controller, typically the consent of the data subject or a legitimate interest in organising the wedding (GDPR Art. 6(1)(a) or (f)). You are responsible for ensuring that you enter guest data with those people's knowledge and in compliance with applicable data protection law.
2.4. Vendor data
Data: names, categories, quotes, contract status and notes for wedding vendors you add. These are typically business data but may include personal data where the vendor is a natural person.
Purpose: powering vendor tracking and AI quote analysis features.
Legal basis: GDPR Art. 6(1)(b) - performance of a contract.
2.5. Subscription and payment data
Data: subscription plan type, subscription status (active, expired, cancelled), order and subscription identifiers issued by the merchant of record, payment date and amount.
Purpose: managing paid subscriptions, unlocking plan features, fulfilling statutory accounting obligations.
Legal basis: GDPR Art. 6(1)(b) - performance of a contract; GDPR Art. 6(1)(c) - compliance with a legal obligation (accounting law).
Actual payment card details are handled exclusively by the merchant of record; we never see or store them.
2.6. AI usage data
Data: timestamps of AI feature use, feature type (e.g. vendor, budget, seating), and your account identifier.
Purpose: preventing abuse, enforcing plan-based rate limits, ensuring Service quality.
Legal basis: GDPR Art. 6(1)(f) - legitimate interests. A legitimate interest assessment has been carried out; a summary is available on request at weddingcopilot@outlook.com.
2.7. Technical and log data
Data: IP address, browser type, operating system, access timestamps and pages visited. This data is automatically collected by Supabase and Vercel infrastructure.
Purpose: system security, troubleshooting, abuse prevention.
Legal basis: GDPR Art. 6(1)(f) - legitimate interests.
Error alerts. On a server-side error the operator receives an immediate alert on a messaging channel (Telegram). The alert contains the error text and the name of the operation; the user and wedding identifiers appear only as an irreversible 8-character digest, never as names, email addresses or tokenised links. The channel therefore receives no personal data; the full identifier remains only in Vercel's contracted logs.
2.8. Guest page and guest photo collection
Guest page. If you create a guest page, the details you put on it (your names, the wedding date, the schedule, the venue and address, the menu, and any notes or cover photo you add) become readable by anyone who has the link, once you publish the page. The page is never listed in search engines: it is served with a noindex instruction and is excluded in our robots.txt. You decide what goes on the page and when to publish it, and you can unpublish it at any time.
Contacts. You may add up to five contact people (name, role and phone number) for guests to call on the day. These details are visible on the published guest page to anyone who has the link. They are the personal data of third parties: you decide whether to add and publish them, and you act as controller in this respect. It is your responsibility to obtain the person's consent beforehand; the interface warns about this at the moment of entry. The person concerned may request removal from you or directly from us.
Stay and travel. If you enable the relevant section, accommodation and transfer details (name, address, phone number, departure time) appear on the guest page. These are typically supplier details. A guest's own room and transfer assignment is only available through their personal invitation link; the guest page never shows where other guests sleep or which trip they are on.
Personal invitation link. You may share a unique, token-bearing link per guest. The token identifies the guest: whoever receives the link can see that guest's RSVP page and, if any, their own assignment. We therefore recommend that you send the link personally and that guests do not share it publicly. Such addresses are excluded from search engines.
Guest photo collection. If you open a photo collection, your guests can upload photos through a link or QR code, without creating an account.
Data collected from guests: the photographs they choose to upload, the name they optionally provide, a random identifier stored in their browser (used only to enforce the per-guest upload limit; it is stored in hashed form and is not used for tracking), and a hashed IP address for abuse protection.
Purpose: collecting the couple's wedding photographs in one place.
Legal basis: GDPR Art. 6(1)(a) - consent. Guests upload voluntarily: nobody is required to send photographs, and the upload page states before uploading what happens to the pictures. For the hashed IP address the legal basis is Art. 6(1)(f) - legitimate interests (protecting the service from abuse).
Storage and access: uploaded photographs are stored in a private storage bucket. They are not publicly accessible: the couple views them through short-lived signed links. If a reveal time is set, the photographs stay hidden until then. The couple can hide or delete any uploaded photograph.
Important - who is responsible: the couple decides who is invited to upload, what is displayed on the guest page, and how long the collection stays open. In respect of these decisions the couple acts as the controller and we act as a processor. Guests can ask the couple, or us at weddingcopilot@outlook.com, to have a photograph removed; we act on such requests without undue delay.
2.9. Further data flows you initiate
Each of the activities below is started by you, and each moves data into or out of the system that the categories above do not cover.
- Contact form
- Name, email address, subject, message. Purpose: answering your enquiry. Complaints are accepted by email under Section 17 of the Terms; should a complaint nevertheless arrive through the form, the same rules apply to it. Legal basis: Art. 6(1)(f) (legitimate interest); for complaints Art. 6(1)(c) (statutory duty under the Hungarian Consumer Protection Act). The form is delivered by Formspree, Inc.; if you prefer not to use it, write directly to the email address in Section 1.
- Inviting a co-planner
- The invitee's email address and the access token assigned to it. Purpose: enabling shared planning. Legal basis: Art. 6(1)(b). The invitee gets access on your decision, and you can revoke it at any time.
- Responses entered directly by guests
- On the RSVP page a guest enters their own reply, companion name, dietary preference and message. We store these on your behalf as controller (Section 2.3); the guest may ask you or us for rectification or erasure. The dietary field is requested as a preference, not as health data.
- Contract and quote analysis
- The full text of a vendor document you paste or upload is sent to OpenAI for AI analysis (Section 3). The document may contain the vendor's contact person's details; for those you are the controller. The Provider does not retain the document beyond the analysis.
- Spreadsheet import (Excel, Google Sheets)
- The Service reads the uploaded file or the Google Sheets link you provide and moves its content into the guest list, budget or vendor register. To recognise the columns the AI receives only the headers and up to five masked sample rows (letters and digits substituted), so no real guest data leaves the system. The source file is not kept after import; only the file name, row count and column mapping remain as a log.
2.10. Product usage measurement until the cookie decision (legitimate interest)
A few named product events (for example: sign-up completed, first vendor added) are measured without consent until you make your choice on the cookie banner. The data processed: the event name and time, the User's internal identifier (UUID) and the page URL stripped of invitation tokens. No email address, name or profile data enters the measurement.
This measurement writes nothing to and reads nothing from your device (no cookie, no local storage), fingerprint-like attributes (screen size, exact versions, timezone) are filtered out, the IP address is discarded by the analytics tool, and storage is in the EU (Frankfurt). Purpose: understanding where users get stuck before their first real use. Legal basis: Article 6(1)(f) GDPR (legitimate interest); the balancing test is available on request.
Choosing Only the necessary on the cookie banner counts as an objection to this measurement (Article 21 GDPR) and stops it immediately and permanently. After consent is given, measurement continues in the consent-based mode described in Section 6. Page view measurement, automatic behaviour capture and any persistent identifier continue to run only with consent.
3. Processors, recipients and international transfers
Recipients fall into three groups. Processors may process personal data only on our documented instructions, under an Article 28 GDPR agreement. Independent controllers also set their own purposes and act under their own policies. For the advertising pixel there is joint controllership in respect of collection and transmission.
The full list - every provider's name, address, concrete activity, storage location and the legal basis for any transfer outside the EEA - is maintained on its own page:
It sits on a separate page because this list changes most often, and Article 28(2) GDPR requires us to notify you before a change. We give at least 15 days notice before engaging a new provider, and you may object.
Primary storage is in the European Union (Supabase and PostHog: Frankfurt; Vercel: EU region). Access from the United States rests primarily on the Standard Contractual Clauses adopted by Commission Decision (EU) 2021/914; we deliberately do not rely on the adequacy decision alone.
4. Retention periods
| Data category | Retention period | Why |
|---|---|---|
| User account and wedding profile | While the account is active, or until a deletion request is fulfilled; for an inactive account, at most 3 years from the last sign-in. | Performance of the contract |
| Guest and vendor data | While the user account exists, or until you delete it. | Instruction of the user as controller |
| Subscription and billing data | 8 years from the invoice date. | Section 169 of Act C of 2000 on accounting |
| Guest page content | While the user account exists. The page becomes unreachable the moment publication is revoked. | Performance of the contract |
| Guest photos and uploader names | While the user account exists, or until the photo or the collection is deleted. An upload link expires automatically one year after it is created. | Performance of the contract and consent of the data subject |
| AI usage logs | At most 90 days. | Legitimate interest in abuse and cost prevention |
| Technical logs (IP address, access log) | At most 90 days. | Legitimate interest in system security |
| Enquiries through the contact form or by email | Until the matter is closed, plus 1 year. | Legitimate interest in handling follow-up questions |
| Consumer complaint and the reply on the merits | 3 years. | Section 17/A of Act CLV of 1997 on consumer protection |
- Data categoryUser account and wedding profileRetention periodWhile the account is active, or until a deletion request is fulfilled; for an inactive account, at most 3 years from the last sign-in.WhyPerformance of the contract
- Data categoryGuest and vendor dataRetention periodWhile the user account exists, or until you delete it.WhyInstruction of the user as controller
- Data categorySubscription and billing dataRetention period8 years from the invoice date.WhySection 169 of Act C of 2000 on accounting
- Data categoryGuest page contentRetention periodWhile the user account exists. The page becomes unreachable the moment publication is revoked.WhyPerformance of the contract
- Data categoryGuest photos and uploader namesRetention periodWhile the user account exists, or until the photo or the collection is deleted. An upload link expires automatically one year after it is created.WhyPerformance of the contract and consent of the data subject
- Data categoryAI usage logsRetention periodAt most 90 days.WhyLegitimate interest in abuse and cost prevention
- Data categoryTechnical logs (IP address, access log)Retention periodAt most 90 days.WhyLegitimate interest in system security
- Data categoryEnquiries through the contact form or by emailRetention periodUntil the matter is closed, plus 1 year.WhyLegitimate interest in handling follow-up questions
- Data categoryConsumer complaint and the reply on the meritsRetention period3 years.WhySection 17/A of Act CLV of 1997 on consumer protection
After account deletion we erase your data without delay, except what the table above requires us to retain by law. Copies that temporarily remain in backups are erased when the backup cycle expires.
5. Your rights under the GDPR
Under GDPR Chapter III you have the rights below. To exercise them, email us at weddingcopilot@outlook.com. We respond within one month of receipt; taking into account the complexity and number of requests, this may be extended by a further two months, of which we inform you within the first month. Handling a request is free of charge; for manifestly unfounded or repetitive requests we may charge a reasonable fee or refuse to act.
5.1. Right of access (Art. 15)
You may request confirmation of whether we process your personal data and, if so, receive a copy of it along with information about the purposes, legal bases, retention periods and processors involved.
5.2. Right to rectification (Art. 16)
You may request correction of inaccurate data or completion of incomplete data. You can also update most of your wedding profile data directly in your account settings.
5.3. Right to erasure (Art. 17)
You may request deletion of your personal data where it is no longer necessary for the original purpose, you withdraw consent, or you object to processing with no overriding legitimate interest. Erasure cannot be fulfilled where retention is legally required.
5.4. Right to restriction of processing (Art. 18)
You may request that we restrict processing - for example while the accuracy of data is disputed, or while an objection is being assessed. During restriction, data may only be stored, not otherwise used.
5.5. Right to data portability (Art. 20)
You may receive your personal data in a structured, commonly used, machine-readable format (such as JSON or CSV) and transmit it to another controller, where processing is based on consent or contract and carried out by automated means. Separately, Section 20 of the Terms grants a broader contractual right to data extraction and switching. The export is available from the privacy card on the Settings page, as a full JSON file and as a guest-list CSV.
5.6. Right to object (Art. 21)
You may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
5.7. Rights related to automated decision-making (Art. 22)
The Service uses automated logic only to determine AI access based on your subscription plan. This is necessary for contract performance. You may request human review of such decisions, express your views and contest the outcome at any time. AI output is a suggestion, not a decision: the Service attaches no automatic legal consequence to it.
6. Cookies and local storage
The Service uses cookies and local storage on your device. The governing rule covers not only cookies but any information stored on terminal equipment, which is why the notice itemises local storage as well.
Cookie and local storage notice
In short: strictly necessary items require no consent but are named. Full statistics measurement (PostHog page views, automatic event capture, persistent identifiers) and marketing tools (Google Analytics 4, Meta pixel) run only after consent is given. Until your decision a single, narrow exception applies: the storage-free product event measurement described in Section 2.10, which the Only the necessary choice stops immediately.
Consent can be withdrawn at any time through the Cookie settings link in the footer, and while signed in through the privacy card on the Settings page. Withdrawal takes effect immediately.
7. Data security
We and our processors apply appropriate technical and organisational measures under GDPR Article 32, taking into account the nature, scope and risks of the processing. In particular:
- Encryption: all data in transit is protected by HTTPS/TLS; passwords are stored as bcrypt hashes.
- Access control: Row Level Security (RLS) policies in Supabase ensure you can only access your own data.
- Protection of shared tokens: tokens for the guest page, RSVP and photo upload are validated server-side; a token is never passed to an external provider we have no agreement with, and QR codes are generated on our own endpoint.
- Limiting measurement: pages whose URL carries an invitation or upload token are excluded from web analytics, and page titles are transmitted with the token stripped.
- Infrastructure security: database and application run in managed data centres holding ISO 27001 and SOC 2 Type II certifications.
- SSRF protection: the Moodboard scraper component blocks private network IP ranges via DNS resolution checks.
8. Personal data breach
A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
In such a case we will:
- investigate without delay and take the measures needed to mitigate the consequences;
- notify the supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk (Article 33 GDPR);
- where the breach is likely to result in a high risk to the rights of data subjects, also inform them without undue delay and in clear language (Article 34 GDPR);
- maintain an internal register of breaches recording the circumstances, effects and measures taken.
Where a breach affects guest data for which you are the controller and we act as processor, we notify you without undue delay so that you can meet your own 72-hour deadline. Details are in the Data Processing Terms.
Anyone can report a security flaw to weddingcopilot@outlook.com. We will not take action against a good-faith, responsible disclosure.
9. Data about children
Only people aged 18 or over may register for the Service. We do not knowingly collect personal data from users under 18. If we learn that an account was created by a minor, we delete the account and its data.
A separate case is where you enter data about a child as a guest - typically a name, and possibly a dietary requirement or seating assignment. For that data you are the controller and must ensure an appropriate legal basis, which for a minor is usually the consent of the holder of parental responsibility. We apply the same security measures to it as to any other guest data.
Particular care is needed on a published guest page and in a photo collection: publishing a photograph of a child requires parental consent. The interface warns about this, but the decision and the responsibility are yours.
10. Rights of visitors in the United States
The Service is also available to visitors in the United States. The controller does not meet the applicability thresholds of the California Consumer Privacy Act (CCPA, as amended by the CPRA); the following rights are therefore offered as a voluntary commitment, modelled on that Act, to every resident of the United States:
- Right to know: request disclosure of the categories and specific pieces of personal information collected, their sources, business purposes, and any third parties with whom they were shared.
- Right to delete: request deletion of personal information we collected from you, subject to exceptions.
- Right to opt out of sale or sharing: we do not sell personal information and do not share it for cross-context behavioural advertising.
- Right to non-discrimination: we will not discriminate against you for exercising these rights.
To submit a request, email weddingcopilot@outlook.com. We respond within 45 days.
11. Complaints to the supervisory authority
If you believe we are processing your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
- NAIH (Nemzeti Adatvédelmi és Információszabadság Hatóság - Hungarian National Authority for Data Protection and Freedom of Information)
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Postal address: 1363 Budapest, Pf. 9., Hungary
- Phone: +36 1 391 1400
- Email: ugyfelszolgalat@naih.hu
- Website: naih.hu
You may also complain to the supervisory authority in your EU member state of habitual residence. In parallel, you may bring court proceedings before a competent court, including the court for your place of residence.
For consumer and contractual disputes, the further redress forums are listed in Section 17 of the Terms.
12. Amendments to this Policy
We reserve the right to amend this Privacy Policy. In case of material changes we notify you by email at least 15 days before the effective date. Continued use of the Service after the effective date constitutes acknowledgment of the updated Policy.
The current version is always available at /en/privacy, and previous versions can be followed in the change log on the legal documents overview page.