Subprocessors and recipients
Effective: 28 August 2026Version: 1.1
On this page
This page lists, item by item, who receives personal data while the Service operates, in what role, where they store it, and on what legal basis anything leaves the European Economic Area. A generic reference to "third parties" is not enough under Hungarian supervisory practice: every provider must be named with its address and its concrete activity. Purposes and legal bases of processing are set out in the Privacy Policy.
The In short summaries are informational and are there to help you follow the section. The full text always prevails legally.
This document is available in Hungarian and English. In case of any discrepancy, the Hungarian version prevails.
1. Why the roles differ
Recipients fall into three groups, and the difference is substantive:
- Processor
- May process data only on the documented instructions of the Provider, under an Article 28 GDPR agreement, and never for its own purposes. Supabase, Vercel, OpenAI, PostHog, Google Ireland, Resend and Formspree fall here.
- Independent controller
- Also decides its own purposes and acts under its own privacy policy, over which the Provider has no control. The merchant of record and Google LLC at sign-in fall here.
- Joint controller
- Jointly determines purposes and means with the Provider for the collection and transmission step (Article 26 GDPR). Meta falls here for the advertising pixel.
2. The list of providers
| Provider | Role | What it does | Where data is stored | Transfer basis |
|---|---|---|---|---|
| Supabase, Inc. 970 Toa Payoh North, Singapore 318992 supabase.com/privacy | Processor | Database and authentication infrastructure: the account, wedding profile, guest list and all uploaded content live here. | European Union, Frankfurt (Germany) | SCCs (2021/914/EU) |
| Vercel Inc. 340 Pine Street, Suite 701, San Francisco, CA 94104, USA vercel.com/legal/privacy-policy | Processor | Application runtime, content delivery and technical logging. | European Union, fra1 region | SCCs (2021/914/EU) |
| OpenAI, LLC 3180 18th Street, San Francisco, CA 94110, USA openai.com/policies/privacy-policy | Processor | Language processing behind the AI features. Only the text you supply for a given request is sent (for the cultural advisor, with your explicit consent, also the couple's cultural and religious background). Under its own API policy OpenAI does not use API customer data for model training; requests are retained for abuse monitoring for up to 30 days and then deleted. | United States | SCCs (2021/914/EU) |
| PostHog, Inc. 2261 Market Street #4008, San Francisco, CA 94114, USA posthog.com/privacy | Processor | Product analytics: which features are used and where people get stuck. Runs in identified mode only and does not track anonymous visitors. | European Union, Frankfurt (Germany) | SCCs (2021/914/EU) |
| Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland policies.google.com/privacy | Processor | Google Analytics 4 web analytics. Loads only after marketing consent. Pages whose URL carries an invitation or upload token are excluded from measurement. | European Union and United States | EU-US Data Privacy Framework and SCCs |
| Resend, Inc. 2261 Market Street #5039, San Francisco, CA 94114, USA resend.com/legal/privacy-policy | Processor | Delivery of transactional email (sign-up confirmation, password reset, account notices). It receives the recipient address and the message body; no newsletters are sent through it. | United States | SCCs (2021/914/EU) |
| Formspree, Inc. United States formspree.io/legal/privacy-policy | Processor | Delivery of the contact form by email. If you prefer not to use it, you can email the address shown on the Contact page directly. | United States (AWS) | SCCs (2021/914/EU) |
| Sold through Link, LLC (formerly Lemon Squeezy, LLC) United States lemonsqueezy.com/privacy | Independent controller | Merchant of record: it concludes the purchase in its own name, issues the invoice and handles card data under PCI-DSS. The Provider only receives subscription status and identifiers. | United States | SCCs (2021/914/EU) |
| Google LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA policies.google.com/privacy | Independent controller | Google sign-in (OAuth). The Provider stores only the returned identifier and email address. This route is optional: email and password work too. | United States | EU-US Data Privacy Framework |
| Meta Platforms Ireland Limited Merrion Road, Dublin 4, D04 X2K5, Ireland facebook.com/privacy/policy | Joint controller (Article 26 GDPR) | Advertising pixel measuring Facebook and Instagram campaigns. Loads only after marketing consent; without consent no request reaches Meta at all. | European Union and United States | EU-US Data Privacy Framework and SCCs |
- ProviderRoleProcessorWhat it doesDatabase and authentication infrastructure: the account, wedding profile, guest list and all uploaded content live here.Where data is storedEuropean Union, Frankfurt (Germany)Transfer basisSCCs (2021/914/EU)
- ProviderRoleProcessorWhat it doesApplication runtime, content delivery and technical logging.Where data is storedEuropean Union, fra1 regionTransfer basisSCCs (2021/914/EU)
- ProviderRoleProcessorWhat it doesLanguage processing behind the AI features. Only the text you supply for a given request is sent (for the cultural advisor, with your explicit consent, also the couple's cultural and religious background). Under its own API policy OpenAI does not use API customer data for model training; requests are retained for abuse monitoring for up to 30 days and then deleted.Where data is storedUnited StatesTransfer basisSCCs (2021/914/EU)
- ProviderRoleProcessorWhat it doesProduct analytics: which features are used and where people get stuck. Runs in identified mode only and does not track anonymous visitors.Where data is storedEuropean Union, Frankfurt (Germany)Transfer basisSCCs (2021/914/EU)
- ProviderRoleProcessorWhat it doesGoogle Analytics 4 web analytics. Loads only after marketing consent. Pages whose URL carries an invitation or upload token are excluded from measurement.Where data is storedEuropean Union and United StatesTransfer basisEU-US Data Privacy Framework and SCCs
- ProviderRoleProcessorWhat it doesDelivery of transactional email (sign-up confirmation, password reset, account notices). It receives the recipient address and the message body; no newsletters are sent through it.Where data is storedUnited StatesTransfer basisSCCs (2021/914/EU)
- ProviderRoleProcessorWhat it doesDelivery of the contact form by email. If you prefer not to use it, you can email the address shown on the Contact page directly.Where data is storedUnited States (AWS)Transfer basisSCCs (2021/914/EU)
- ProviderRoleIndependent controllerWhat it doesMerchant of record: it concludes the purchase in its own name, issues the invoice and handles card data under PCI-DSS. The Provider only receives subscription status and identifiers.Where data is storedUnited StatesTransfer basisSCCs (2021/914/EU)
- ProviderRoleIndependent controllerWhat it doesGoogle sign-in (OAuth). The Provider stores only the returned identifier and email address. This route is optional: email and password work too.Where data is storedUnited StatesTransfer basisEU-US Data Privacy Framework
- ProviderRoleJoint controller (Article 26 GDPR)What it doesAdvertising pixel measuring Facebook and Instagram campaigns. Loads only after marketing consent; without consent no request reaches Meta at all.Where data is storedEuropean Union and United StatesTransfer basisEU-US Data Privacy Framework and SCCs
No external QR code generator appears on this list: QR codes for share links are produced by the Service on its own endpoint, so tokenised URLs never leave the server. No error tracking service (such as Sentry) is in use either.
3. Transfers outside the EEA
Several recipients above are established in the United States or can access data from there. Primary storage is in the European Union (Supabase and PostHog: Frankfurt; Vercel: EU region), but access from the US is itself a transfer, so a legal basis is stated for each.
- Standard Contractual Clauses (SCCs). The primary basis is the set of clauses adopted by Commission Implementing Decision (EU) 2021/914, together with the supplementary measures expected by the European Data Protection Board: encryption in transit and at rest, EU storage, and minimisation of the data transferred.
- EU-US Data Privacy Framework. Where the recipient is certified, the Commission adequacy decision (EU) 2023/1795 applies in addition. We deliberately do not rely on it alone: the SCCs run in parallel, so a transfer stays lawful even if the adequacy decision were annulled or suspended.
- Explicit consent (Article 49(1)(a) GDPR) for the marketing tools, which do not load at all until consent is given.
A transfer impact assessment has been carried out for each recipient. Its main finding: with one exception the transferred data contains no special category data under Article 9 GDPR; the exception is the cultural advisor, which, with your explicit and separate consent, also sends the couple's cultural and religious background to OpenAI (Privacy Policy 2.2). For that transfer, explicit consent under Article 49(1)(a) GDPR applies alongside the SCCs, and OpenAI retains it for no more than 30 days. Otherwise storage is in the European Union wherever technically possible, and access is limited to what running the service requires. If a transfer became unlawful we suspend it and inform users.
4. Changes to this list
Under Article 28(2) GDPR, if the Provider engages a new processor or replaces an existing one, users are notified at least 15 days before the change takes effect, by in-app message or email, and this page is updated.
If you object to the change, use the contact details in the notice. Where the objection is well founded but the engagement is nonetheless necessary to provide the Service, you may terminate free of charge before the effective date and export your data under Section 20 of the Terms.