Skip to content

GDPR / CCPA Data Processing Addendum

Version 3 · Effective August 8, 2026

Version 3 — see the end of this document for what changed since Version 2.

1. Purpose and scope

This Data Processing Addendum ("DPA") forms part of the agreement between you and Vows & Volts and applies to personal data processed through the Platform's core features (accounts, guest management, marketplace, payments, AI-assisted features, support) for as long as your account is active, plus any retention period described in the Privacy Policy. It is intended to reflect the structure of GDPR Article 28 for users to whom that regulation applies, and equivalent obligations elsewhere.

2. Roles

For data you submit as a Couple, Vendor, or Planner operating your own account (account details, your own content), Vows & Volts generally acts as an independent data controller. For guest data a Couple or Planner manages in connection with an event, Vows & Volts generally acts as a data processor on that Couple's behalf, processing it only on their documented instructions (as expressed through their use of the Platform's features) except where required otherwise by law.

3. Categories of data and data subjects

Data subjects include: account holders (Couples, Vendors, Planners, staff) and, indirectly, wedding guests — including children, subject to the COPPA-driven protections described in the Privacy Policy (no direct contact-detail collection for guests marked as children). Categories of data include contact details, event and guest information (RSVP status, dietary needs, seating), payment references, communications content, and usage data.

4. Sub-processors

We use a limited set of sub-processors to operate the Platform, selected to actually power specific features rather than general-purpose data brokering:

| Sub-processor category | Purpose | |---|---| | Payment processor | Payments, subscription billing, tax calculation | | Email delivery provider | Transactional email and guest email messaging | | SMS delivery provider | Guest text messaging (only for accounts with SMS enabled) | | AI provider(s) | The concierge and venue-visualization features (only when actively used) | | Cloud file storage provider | Uploaded photos and files | | Application and database hosting providers | Running and storing the Platform itself |

Not every category above is necessarily active for every account or at every point in time — some features, and their underlying sub-processor, activate only once configured. We will provide notice of a material change in sub-processors (such as adding a new category of processing) through the Platform or by other reasonable means, and you may object on reasonable data-protection grounds through our support system.

5. Security measures

Sub-processors and our own infrastructure implement the protections described on our public Security page, including field-level encryption of sensitive guest contact data at rest, role-based access control enforced independently at the page and API layers, rate limiting, and audit logging of sensitive administrative actions — reported with real, current test status, not as an unconditional guarantee.

6. Data subject rights assistance

We'll assist you, as controller, in responding to data subject requests (access, deletion, correction, portability) to the extent required by applicable law, consistent with the deletion-request workflow described in the Privacy Policy — including the 30-day cancellable grace period before a deletion request is finalized.

7. Breach notification

We'll notify affected account holders of a confirmed personal data breach without undue delay, consistent with applicable legal requirements, and provide the information reasonably necessary for you to meet your own notification obligations as controller where relevant.

8. International transfers

Where personal data is transferred internationally (for example, to a sub-processor located outside your region), we rely on appropriate safeguards — such as the EU Standard Contractual Clauses or an equivalent recognized mechanism — consistent with applicable law.

9. Audit

On reasonable request, and no more than once per year absent a specific security concern, we will provide information reasonably necessary to demonstrate compliance with this DPA, which may take the form of this document, our public Security page, and relevant sub-processor certifications, in lieu of an on-site audit.

10. Deletion or return of data

On termination of your account, data is handled per the deletion-request and retention terms described in the Privacy Policy.

What changed in Version 3: removed the AI-drafted/attorney-review notice that previously appeared at the end of this document.

What changed in Version 2: restructured sub-processors into a labeled table by category, added an audit section, a more explicit breach-notification commitment, and clarified the controller/processor split as it actually maps to Couple/Vendor/Planner account data versus guest data.