Skip to content

Data processing agreement

The moment you put guest details into Wedding Overview, those details are yours to decide about and ours to look after. This agreement writes down what we may do with them, what we may not do, and what you can hold us to.

1. Two legal frameworks, named on purpose

We are a European company serving couples in the United States, so two vocabularies meet in this document and we would rather name both than quietly pick one.

Whichever of those frameworks reaches you, the standard we apply is the same for everyone: the GDPR, wherever you live. The privacy policy says that too, and it is not a form of words. We do not run a lighter regime per market: how long we keep your data and how quickly we answer a request about it are single settings that do not know where you live. The United States terms are in this document so that you recognize the split of roles, not to lower the standard. Where a privacy law of your own state gives you or your guests more than this agreement does, that law applies on top of it; nothing here takes it away.

2. Who is who

This agreement belongs with the terms of service and theprivacy policy. Where the three texts differ on the handling of guest data, this agreement comes first.

3. Who is responsible for what

The split of roles is not a formality: it decides who has to report a data breach, and to whom. So it is written out here, per kind of data.

For the data where we are the controller, the supervisory authority is the Belgian Data Protection Authority. For the data where you are the controller, the authority is the one for the place where you live, and which authority that is differs per state. This section names no authority for you, because we cannot establish that from where we sit.

4. What we may use the data for

Only to make Wedding Overview work for you. Concretely:

We do not use guest data for our own marketing, we do not sell it, we do not rent it out, and we do not use it to train models. We do not combine it with data from other weddings.

5. Your instructions

You decide what happens to the guest data. In practice that means you can change or delete data at any time, download an export, set the wedding website to private, revoke an RSVP link, and give or withdraw access for a helper or a planner.

If we receive an instruction that we believe breaks the law, we say so and we do not carry it out. We do not process the data for a purpose of our own that you did not ask for.

6. Confidentiality and access

Everyone on our side who can reach guest data is bound to confidentiality. We keep that access as small as possible: reaching sensitive guest data runs through a separate, extra limited route and is written into an audit trail that you can read yourself.

7. Security

We take appropriate technical and organizational measures. The main ones are:

No system is completely secure, and we will not pretend otherwise. We promise no absolute safety, but we do promise that you can hold us to the measures above.

8. Data breaches: what we do, and by when

If personal data is breached, we tell the couples involved without delay and in any case within 24 hours of establishing it, even when the picture is not complete yet. Those 24 hours are deliberately shorter than the law gives us: as the controller you have your own reporting deadline to meet, and you can only meet it if we do not wait until we understand everything.

With that notice we always give you:

Where the data is data we are the controller for, we report within 72 hours to the Belgian Data Protection Authority. Our full internal procedure, including the decision tree and the notice templates, lives in the file docs/DATALEK-PROCEDURE.md in our own documentation. Ask for it athallo@weddingoverview.com if you want to read it.

United States breach notification law is written per state, with its own deadlines and its own addressees, and this agreement does not try to summarize fifty statutes. The 24 hour promise above is ours to you: it is there to leave you time for whatever your own state requires of you, and it does not replace that.

9. Help with requests from guests

If a guest comes to us with a request about their data, we point them to you and let you know. We do not answer such a request ourselves, because the data is not ours.

If you need help carrying out a request, we help within a reasonable time and at no extra cost: access, correction, deletion, restriction, or an export of that one guest's data. A guest can also withdraw consent for sensitive details through their own RSVP link, and that withdrawal shows up in your environment straight away.

10. Subprocessors

These are the companies that handle your guest data on our instructions, with what they do it for, where they sit, and what crosses a border. We use these companies and no others. This is the full list.

If we want to add or replace a subprocessor, we tell you by email at least thirty days beforehand. If you object, you can tell us within those thirty days that you want to end this agreement; we then refund the remaining part of the one-time access, reasonably calculated.

Not on this list: error monitoring. Theprivacy policy mentions optional error diagnosis by Sentry. It is switched off, and it is deliberately not a subprocessor here: before we switch it on we publish a new version of this agreement that names it, and we tell you thirty days beforehand, the way the paragraph above describes.

Other recipients, not subprocessors. Two services see only a technical request when someone searches for a place or looks at a map, and do not work on our instructions with your data. A venue search goes to komoot GmbH (Photon, Germany), which receives the search term and the visitor's IP address. Map tiles come from OpenFreeMap, which sees the IP address and the tile requested. No names, guest details, or account data go to either.

Not subprocessors either are the vendors you appoint yourself, such as the caterer who receives a dietary needs list or the planner you give access to. They receive data on your instruction and you stay the controller for that. We only supply the button.

11. Term, deletion, and return

This agreement runs for as long as you use Wedding Overview. After that we delete the guest data and the wedding data on the deadlines in the privacy policy: no later than twelve months after the wedding date, or twelve months after your last login when no wedding date has been filled in. We warn you by email beforehand, so you can download an export first.

Deleting means the files themselves too, so the uploaded documents and photos, and not only the references to them.

Two things stay longer, and that is not our choice: payment and invoice records fall under the tax retention duty, and data we have to keep on another legal ground. We keep those shielded and use them for nothing else.

12. Checking up on us

If you want to establish that we keep to this agreement, we give you an explanation on request and access to the measures in section 7 and to the audit trails of your own wedding. We are a small company without external certification, and we do not suggest otherwise.

13. Acceptance, version, and time

This agreement applies in the version that stood on this page at the moment you agreed. You give that agreement when you create your account and again when you buy full access. We record which version you accepted and at what time, so it can be established later which text applies to you.

The current version is 1.0 of September 18, 2026. When we change the agreement we raise the version number, tell you beforehand by email, and ask for your agreement again on a material change.

14. Governing law

This agreement is governed by Belgian law, with the General Data Protection Regulation as its framework. Disputes go to the competent court in Belgium, without prejudice to your right as a consumer to go to your own court. Mandatory consumer and privacy protections of the country or state where you live remain yours; nothing here takes them away.