Legal

Data Processing Agreement

Last updated: 2026-06-03

Available in English only

This legal document is available in English only and applies as such. We are working on reviewed translations.

Save your signed copy as a PDF

File → Print → Save as PDF in any modern browser. Send the signed copy to privacy@festela.app and we'll counter-sign within 5 business days.

1. Parties

This Data Processing Agreement (the "DPA") supplements the Festela Terms of Service between Festela SAS, organized in France (the "Processor"), and you, the customer (the "Controller"). By signing this DPA, both parties agree to process Personal Data of guests and end users per GDPR Article 28 and equivalent laws.

2. Subject matter and duration

The Processor processes Personal Data submitted by the Controller through the Festela platform (guest contact details, RSVP responses, dietary needs, messages to the couple, uploaded photos) for the sole purpose of delivering the service. Processing continues for the term of the underlying account and ends with account deletion. Backups are purged within thirty (30) days of deletion.

3. Nature and purpose of processing

  • Storing guest lists, events, invitation groups, families, RSVPs, and expenses.
  • Serving the Controller's guest-facing wedding website via signed invitation URLs.
  • Recording RSVP responses, dietary needs, and messages submitted by guests.
  • Hosting uploaded photos and event imagery.
  • Sending transactional email tied to the Controller's account (no marketing).

4. Categories of data subjects

Wedding guests, the couple, and any contacts the Controller chooses to import.

5. Categories of Personal Data

  • Identifiers: first and last name, phone number (E.164), email.
  • Wedding-specific data: RSVP status, dietary needs, postal address, family relationships, adult/child flag.
  • Free-text messages submitted by guests through the RSVP form.
  • Uploaded photos referenced on the public wedding website.
  • Audit-log entries: who did what, when.

6. Controller's instructions

The Processor processes Personal Data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required by EU or Member State law. The Processor notifies the Controller of any such legal requirement before processing, unless the law prohibits notification.

7. Confidentiality

The Processor ensures persons authorized to process Personal Data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.

8. Security measures (Art. 32)

  • TLS 1.2+ on every public endpoint; HMAC-signed invitation tokens.
  • Encrypted-at-rest databases (Neon) and object storage (Cloudflare R2).
  • Per-wedding access scoping on every read and write.
  • Token-gated public media access (signed short-TTL R2 URLs).
  • Daily backups; point-in-time restore via Neon branch.
  • Least-privilege access controls and quarterly secret rotation.
  • Internal audit-log for material data writes.

9. Sub-processors

The Controller authorizes the engagement of the following sub-processors, each bound by a DPA materially equivalent to this one:

Sub-processorPurposeLocation
NeonManaged PostgresEU (Frankfurt)
VercelWeb app hosting + edge functionsMulti-region
Cloudflare R2Object storage (photos and event media)Multi-region
StripeBilling + payment processingEU + US
ResendTransactional emailEU + US

We notify the Controller at least 30 days before adding a new sub-processor. The Controller may object in writing; absent objection, consent is deemed granted.

10. International transfers

Where a sub-processor stores data outside the EEA, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs) and supplementary measures. The Controller may request copies of the active SCCs at any time.

11. Data subject rights

The Processor assists the Controller in fulfilling data-subject requests (access, rectification, erasure, portability, restriction, objection). Couple-level data exports are self-serve from Account → Danger zone. Other requests are served within 30 days of receipt at privacy@festela.app.

12. Breach notification

The Processor notifies the Controller of any Personal Data breach without undue delay, and in any event within 72 hours of becoming aware of it. The notice includes the nature of the breach, categories and approximate number of data subjects, likely consequences, and remediation steps.

13. Audit rights

The Processor makes available all information necessary to demonstrate compliance with this DPA. The Controller may audit no more than once per twelve months on 30 days' written notice; an external SOC-2 or ISO-27001 report (when available) satisfies this obligation by mutual agreement.

14. Return or deletion of data

On termination, the Controller may export all Personal Data via the self-serve export flow. After 30 days, the Processor permanently deletes the Personal Data from active systems and backups, unless EU or Member State law requires retention.

15. Signature

By accepting Festela's Terms of Service, the Controller is deemed to have signed this DPA. A counter-signed PDF copy is available on request at privacy@festela.app.

Template provided for transparency. Large customers may request a negotiated DPA.