Skip to content

GDPR Addendum

Version 1 · Effective August 8, 2026

This Addendum consolidates, in one place, the rights available to individuals in the European Economic Area, the United Kingdom, and other jurisdictions with equivalent data protection law. It doesn't replace our Privacy Policy — it summarizes and cross-references the specific GDPR-relevant commitments already made there and in our Data Processing Addendum, for anyone who wants the EEA/UK-specific picture without reading every document in full. Where this Addendum and the Privacy Policy differ in wording, the Privacy Policy's fuller description controls.

Scope note: this Addendum covers the EU/UK General Data Protection Regulation specifically. It does not separately address other regional privacy regimes (for example, Brazil's LGPD) — see our Privacy Policy's California (CCPA/CPRA) section for the one other regional regime we cover today. We may publish further region-specific addenda as we do.

1. Who this applies to

You, if you access the Platform from the EEA, UK, or another jurisdiction where GDPR or an equivalent law applies to how we handle your personal data — whether you're a Couple, Vendor, or Planner account holder, or a guest whose information a Couple or Planner has entered into the Platform.

2. Your data subject rights

Subject to the conditions and exemptions GDPR itself provides, you have the right to:

  • Access — obtain confirmation of whether we process your personal data, and a copy of it.
  • Rectification — correct inaccurate or incomplete personal data. Most account and guest-record fields can be corrected directly in the Platform; anything that can't, we'll correct on request.
  • Erasure ("right to be forgotten") — request deletion of your personal data. Use the deletion request tool in your account settings, which starts a 30-day cancellable grace period before permanent removal — see our Privacy Policy, Section 9, for why that window exists and how retention for legal/tax/accounting purposes can limit erasure in specific cases.
  • Restriction of processing — request that we limit how we use your data while a dispute about its accuracy or our processing is resolved.
  • Data portability — receive personal data you've provided to us in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible. Use the account data export tool in your account settings for a machine-readable copy of your own account data.
  • Object — object to processing based on our legitimate interests, including profiling, on grounds relating to your particular situation.
  • Withdraw consent — where processing is based on your consent (for example, an AI feature, or marketing communications), withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, use the relevant in-account tool where one exists, or contact us through the in-app support system. We respond to verified requests within the timeframe GDPR requires (generally one month, extendable in complex cases with notice to you).

3. Legal bases we rely on

As described in our Privacy Policy, Section 3, we process personal data under one or more of: performance of a contract with you; our legitimate interests, balanced against your rights; your consent; and compliance with a legal obligation. We don't rely on a single blanket legal basis across every processing activity — which basis applies depends on the specific data and purpose, consistent with that section.

4. International transfers

Where personal data is transferred outside the EEA or UK — for example, to a sub-processor located elsewhere — we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Addendum, or another legally recognized transfer mechanism, as detailed in our Data Processing Addendum, Section 8.

5. Automated decision-making

We do not use your personal data to make any fully automated decision that produces a legal or similarly significant effect on you without human involvement, consistent with our Privacy Policy, Section 2. Our AI-assisted features (the concierge and venue reimagination) generate suggestions and images for your own review, not automated decisions about you.

6. Data Processing Addendum

If you're a business customer needing a controller-processor data processing agreement — for example, a Vendor or Planner formalizing how we handle guest data on a Couple's behalf — see our separate Data Processing Addendum, which is the Article 28-structured instrument covering that relationship, sub-processors, security measures, breach notification, and audit rights.

7. Supervisory authority

You have the right to lodge a complaint with the data protection supervisory authority in your EEA member state or, for UK users, the Information Commissioner's Office (ICO), particularly if you believe our processing of your personal data infringes GDPR or UK GDPR. We'd appreciate the chance to address your concern directly first, through the in-app support system, but that isn't a precondition to exercising this right.

8. Contact

Questions about this Addendum, or requests to exercise any right described here, can be submitted through the in-app support system.