Data Processing Agreement & Sub-processors
Effective date: 14 July 2026 · Version: 1.2
Part A is a Data Processing Agreement (DPA) our customers accept; Part B is our public sub-processor list.
Operator / Processor: Maciej Besler, sole proprietor (jednoosobowa działalność gospodarcza / JDG) established in Poland, trading as "Wedder" — Poznań, Poland. NIP/VAT: PL7772880973. Contact: admin@wedder.eu.
Part A — Data Processing Agreement
1. Scope and roles
This Data Processing Agreement ("DPA") is between you, the customer — the couple (or a person acting for the couple) who has redeemed a Wedder unlock code — as data controller, and Maciej Besler, trading as "Wedder" as data processor. It governs only the personal data of your wedding guests that we process on your behalf to provide the service. Your own account data is covered by our Privacy Policy, where Wedder is the controller. This DPA forms part of the Terms of Service and is concluded in electronic form (Article 28(9) GDPR). You accept it when you redeem your unlock code.
2. Subject matter and data
- Purpose: hosting a wedding website; collecting and managing RSVPs; storing a guest list; seating planning; running a gift registry; and sending emails to guests — on your instructions.
- Duration: for the term of your unlock code. We delete guest data at the end of the service or on your instruction, unless the law requires us to keep it.
- Data subjects: your wedding guests and their plus-ones.
- Personal data: names, email addresses, phone numbers, language/locale, RSVP status, plus-one details.
- Special-category data (Article 9 GDPR): guests' dietary and allergy information, collected only with the guest's explicit consent, entered by the guest at RSVP, and never bulk-uploaded by you.
3. Our obligations (Article 28(3))
- We process guest personal data only on your documented instructions — this DPA, the Terms of Service, and your use of the features and settings within the app — unless required otherwise by EU or Polish law. We do not sell guest data and do not use it for our own advertising or profiling.
- We ensure that anyone authorised to process the data is bound by an appropriate obligation of confidentiality.
- We implement appropriate technical and organisational measures (Article 32): encryption in transit and at rest, access controls, EU data residency, pseudonymous guest access via signed links, and consent-gated handling of Article 9 data.
- We assist you, so far as possible, in responding to guests exercising their rights; the app provides tools to view, edit and delete guest records.
- We assist you with your obligations under Articles 32–36 (security, breach notification, DPIAs) and will inform you without undue delay of a personal data breach affecting guest data.
- At the end of the provision of the service we delete or return guest data at your choice, and delete existing copies, unless EU or Polish law requires retention; routine backups are overwritten on our standard cycle.
- We make available the information reasonably necessary to demonstrate compliance with Article 28.
4. Sub-processors
You give us your general written authorisation to engage the sub-processors listed in Part B. We keep that list up to date and will give reasonable notice before adding or replacing one, so you may object on reasonable data-protection grounds by writing to admin@wedder.eu. We impose on each sub-processor, by contract, data-protection obligations that are in substance the same as those in this DPA, and we remain responsible to you for their performance.
5. International transfers
Guest personal data is hosted in the EU. Some sub-processors are US-parented companies operating in EU regions; where they are, we rely on their existing safeguards (their Standard Contractual Clauses / Data Processing Agreement and, where applicable, EU-U.S. Data Privacy Framework certification). We do not claim that no US-headquartered company is ever involved. As controller, you should weigh this residual transfer risk.
6. General
This DPA takes effect when you redeem your unlock code and remains in force for as long as we process guest personal data on your behalf. If it conflicts with the Terms of Service on data-protection matters, this DPA prevails. It is governed by Polish law, without prejudice to guests' rights under the GDPR.
Part B — Sub-processor list
Each provider below processes personal data only on our documented instructions and under a written data-protection agreement (Article 28 GDPR). Guest personal data is hosted in the EU; where a provider is US-parented, it operates in an EU region under appropriate safeguards.
| # | Sub-processor | Purpose / service | Location / residency |
|---|---|---|---|
| 1 | Vercel | Application hosting / CDN | EU (Frankfurt); US-parented, EU region |
| 2 | Supabase | Database, authentication, file storage | EU (Frankfurt); US-parented, EU region |
| 3 | Lettermint | Email delivery to guests | EU (Netherlands) |
| 4 | PostHog | Product analytics (how the app is used) | EU Cloud (Frankfurt) |
| 5 | MapTiler | Maps and geocoding | EU / Switzerland (adequacy) |
| 6 | Lemon Squeezy (a Stripe company) | Payments / Merchant of Record | Buyer payment data only, not guest data; US-parented, safeguards via SCCs / DPA + DPF |
| 7 | Sentry | Server-side error monitoring | EU region (Frankfurt); US-parented, EU region |
Error monitoring (Sentry, row 7) runs server-side only — it is not loaded in the browser and sets no cookies or client trackers, so no cookie-consent banner is required for it. Data is sent only to Sentry's EU region.