Data processing agreement
The moment you put guest details into Wedding Overview, those details are yours to decide about and ours to look after. This agreement writes down what we may do with them, what we may not do, and what you can hold us to.
1. Two legal frameworks, named on purpose
We are a European company serving couples in the United States, so two vocabularies meet in this document and we would rather name both than quietly pick one.
- Under European law (the GDPR), you are the controller for your guest data and we are your processor. That is the vocabulary this document is built on, because it is the law our company sits under.
- Under United States state privacy laws, the closest equivalents arebusiness or controller for you and service provider orprocessor for us. Where those laws apply to a wedding, read the promises below as service provider commitments: we process your guest data only to provide the service to you, we do not sell or share it, we do not keep or use it outside our relationship with you, and we do not combine it with data from anywhere else.
Whichever of those frameworks reaches you, the standard we apply is the same for everyone: the GDPR, wherever you live. The privacy policy says that too, and it is not a form of words. We do not run a lighter regime per market: how long we keep your data and how quickly we answer a request about it are single settings that do not know where you live. The United States terms are in this document so that you recognize the split of roles, not to lower the standard. Where a privacy law of your own state gives you or your guests more than this agreement does, that law applies on top of it; nothing here takes it away.
2. Who is who
- Processor or service provider: Miron Digital, trading as Wedding Overview
- Company number: 0793239175
- VAT number: BE0793239175
- Address: Deken Darraslaan 5 bus 101, 8700 Tielt, Belgium
- Contact for privacy questions: hallo@weddingoverview.com
- Controller or business: the account holder, meaning the couple who create the wedding
This agreement belongs with the terms of service and theprivacy policy. Where the three texts differ on the handling of guest data, this agreement comes first.
3. Who is responsible for what
The split of roles is not a formality: it decides who has to report a data breach, and to whom. So it is written out here, per kind of data.
- Guest data and wedding data (names, contact details, RSVP answers, dietary needs, allergies, accessibility notes, photos, documents, seating): you are the controller, we are the processor. We handle this data only on your instructions.
- Account, payment, and security data (your email address, your logins, the payment for one-time access, our logs and audit trails): here we are the controller ourselves, because we need this to run the service and to meet our own legal duties.
For the data where we are the controller, the supervisory authority is the Belgian Data Protection Authority. For the data where you are the controller, the authority is the one for the place where you live, and which authority that is differs per state. This section names no authority for you, because we cannot establish that from where we sit.
4. What we may use the data for
Only to make Wedding Overview work for you. Concretely:
- storing and showing the guest list, the groups you put your guests in, and the RSVP answers
- sending invitations, reminders, and messages that you tell us to send
- publishing your wedding website and running the personal RSVP links
- producing the exports you ask for yourself, such as a dietary needs list for your caterer
- securing the environment, preventing abuse, and keeping audit trails
- making backups and recovering after an outage
We do not use guest data for our own marketing, we do not sell it, we do not rent it out, and we do not use it to train models. We do not combine it with data from other weddings.
5. Your instructions
You decide what happens to the guest data. In practice that means you can change or delete data at any time, download an export, set the wedding website to private, revoke an RSVP link, and give or withdraw access for a helper or a planner.
If we receive an instruction that we believe breaks the law, we say so and we do not carry it out. We do not process the data for a purpose of our own that you did not ask for.
6. Confidentiality and access
Everyone on our side who can reach guest data is bound to confidentiality. We keep that access as small as possible: reaching sensitive guest data runs through a separate, extra limited route and is written into an audit trail that you can read yourself.
7. Security
We take appropriate technical and organizational measures. The main ones are:
- encrypted connections to the app, the wedding websites, and the database
- encrypted storage of the database and of the uploaded files
- separation per wedding in the database itself, not only in the screens
- masked display and export of sensitive guest data, with an audit trail per viewing
- a second barrier on the public wedding website: an access code, short lived sessions, and a block after too many attempts
- limiting and reviewing who on our side can reach the production environment
- backups, monitored availability, and a written incident procedure
- when the backup service is activated, a daily copy of the uploaded files at a second provider, encrypted with a key that is not held there, and read back monthly to check that it really works
No system is completely secure, and we will not pretend otherwise. We promise no absolute safety, but we do promise that you can hold us to the measures above.
8. Data breaches: what we do, and by when
If personal data is breached, we tell the couples involved without delay and in any case within 24 hours of establishing it, even when the picture is not complete yet. Those 24 hours are deliberately shorter than the law gives us: as the controller you have your own reporting deadline to meet, and you can only meet it if we do not wait until we understand everything.
With that notice we always give you:
- what happened and when, and whether it is still going on
- which kinds of data and how many guests are involved, or the best estimate we can make
- the likely consequences and what we have already done to limit them
- a named contact on our side
Where the data is data we are the controller for, we report within 72 hours to the Belgian Data Protection Authority. Our full internal procedure, including the decision tree and the notice templates, lives in the file docs/DATALEK-PROCEDURE.md in our own documentation. Ask for it athallo@weddingoverview.com if you want to read it.
United States breach notification law is written per state, with its own deadlines and its own addressees, and this agreement does not try to summarize fifty statutes. The 24 hour promise above is ours to you: it is there to leave you time for whatever your own state requires of you, and it does not replace that.
9. Help with requests from guests
If a guest comes to us with a request about their data, we point them to you and let you know. We do not answer such a request ourselves, because the data is not ours.
If you need help carrying out a request, we help within a reasonable time and at no extra cost: access, correction, deletion, restriction, or an export of that one guest's data. A guest can also withdraw consent for sensitive details through their own RSVP link, and that withdrawal shows up in your environment straight away.
10. Subprocessors
These are the companies that handle your guest data on our instructions, with what they do it for, where they sit, and what crosses a border. We use these companies and no others. This is the full list.
- Supabase (Supabase Inc.)
Purpose: Database, user accounts, file storage, and server functions
Location: Data center in the European Union, region eu-central-1 (Frankfurt, Germany)
Transfer: The data sits in the EU. Supabase Inc. is established in the United States and may have access for support; that access rests on the European Commission standard contractual clauses, where they apply. - Resend (Resend Inc.)
Purpose: Sending email: invitations and reminders to guests, and service messages to the couple
Location: United States
Transfer: This is a transfer outside the European Union. Guest names and email addresses travel with it, along with the content of the message. The transfer rests on the European Commission standard contractual clauses, where they apply. - Mollie (Mollie B.V.)
Purpose: Handling the one-time payment for full access
Location: Amsterdam, the Netherlands
Transfer: No transfer outside the European Union. Mollie receives no guest data. For the payment transaction itself Mollie acts in part as an independent controller, with its own privacy statement. - Cloudflare (Cloudflare, Inc.)
Purpose: Encrypted backup copy of the uploaded files, when the backup service is activated: documents, wedding website photos, and vendor attachments
Location: Storage under EU jurisdiction: the files stay in data centers in the European Union
Transfer: The copy is encrypted before it leaves the Supabase data center, and Cloudflare does not hold the key. Cloudflare, Inc. is established in the United States and may have access to the storage for support; that access rests on the European Commission standard contractual clauses, where they apply. - Vercel (Vercel Inc.)
Purpose: Hosting and delivery of the website, the web app, and the wedding websites
Location: United States, with delivery through servers in the European Union
Transfer: Vercel processes technical data such as IP address and requested page. This is a transfer outside the European Union on the basis of the European Commission standard contractual clauses, where they apply.
If we want to add or replace a subprocessor, we tell you by email at least thirty days beforehand. If you object, you can tell us within those thirty days that you want to end this agreement; we then refund the remaining part of the one-time access, reasonably calculated.
Not on this list: error monitoring. Theprivacy policy mentions optional error diagnosis by Sentry. It is switched off, and it is deliberately not a subprocessor here: before we switch it on we publish a new version of this agreement that names it, and we tell you thirty days beforehand, the way the paragraph above describes.
Other recipients, not subprocessors. Two services see only a technical request when someone searches for a place or looks at a map, and do not work on our instructions with your data. A venue search goes to komoot GmbH (Photon, Germany), which receives the search term and the visitor's IP address. Map tiles come from OpenFreeMap, which sees the IP address and the tile requested. No names, guest details, or account data go to either.
Not subprocessors either are the vendors you appoint yourself, such as the caterer who receives a dietary needs list or the planner you give access to. They receive data on your instruction and you stay the controller for that. We only supply the button.
11. Term, deletion, and return
This agreement runs for as long as you use Wedding Overview. After that we delete the guest data and the wedding data on the deadlines in the privacy policy: no later than twelve months after the wedding date, or twelve months after your last login when no wedding date has been filled in. We warn you by email beforehand, so you can download an export first.
Deleting means the files themselves too, so the uploaded documents and photos, and not only the references to them.
Two things stay longer, and that is not our choice: payment and invoice records fall under the tax retention duty, and data we have to keep on another legal ground. We keep those shielded and use them for nothing else.
12. Checking up on us
If you want to establish that we keep to this agreement, we give you an explanation on request and access to the measures in section 7 and to the audit trails of your own wedding. We are a small company without external certification, and we do not suggest otherwise.
13. Acceptance, version, and time
This agreement applies in the version that stood on this page at the moment you agreed. You give that agreement when you create your account and again when you buy full access. We record which version you accepted and at what time, so it can be established later which text applies to you.
The current version is 1.0 of September 18, 2026. When we change the agreement we raise the version number, tell you beforehand by email, and ask for your agreement again on a material change.
14. Governing law
This agreement is governed by Belgian law, with the General Data Protection Regulation as its framework. Disputes go to the competent court in Belgium, without prejudice to your right as a consumer to go to your own court. Mandatory consumer and privacy protections of the country or state where you live remain yours; nothing here takes them away.