Who this is for
This Data Processing Addendum (“DPA”) is between you (the host, “Customer”) and Vytley (“Provider”). It forms part of the Terms of Use when you use Vytley to process your guests’ information (invitations, RSVPs, guestbook, photos).
It is adapted from a standard processor DPA. It is not a wet-ink contract until you and we both sign a paid agreement. Until then it states how we process Customer Data on your documented instructions: provide the Service as described on the Site.
Vytley is not a HIPAA business associate. Do not submit protected health information as if this were a medical record system.
Roles
You are the controller (or “business”) of guest-list and event data you submit. We are the processor (or “service provider”) of that Customer Data. We are the controller of waitlist signups, cookie choices, and staff accounts.
We will process Customer Data only to provide the Service and as the law requires. We will not sell it or use it to market to your guests.
Your instructions and your duties
You instruct us to store and display Customer Data so invitations, RSVPs, guestbook entries and photos work as the product does today.
You are responsible for notices and consents to your guests, including children you list, and for any special-category data you include (for example a blessing that reveals religion, or dietary notes).
Do not submit government ID numbers, payment-card data, biometric templates, or medical records. Optional allergy notes are for the host’s catering, not a health file we mine.
Security and incidents
We use private object storage, access tokens on named invitations, HTTPS, and staff sessions behind a login. We may improve these measures if overall protection does not drop.
If we become aware of a breach of Customer Data we will notify you without undue delay with the facts we then have. You remain responsible for notifying your guests and regulators where the law puts that on the controller.
Assistance, subprocessors, deletion
We will help with guest rights requests that concern Customer Data we hold, within the product’s limits. Public requests can use /privacy-request or hello@vytley.com; we may point the person to you where you are the controller.
Subprocessors today: Vercel (hosting and storage); Open-Meteo (venue coordinates only); Apple and Google (wallet pass content when passes are issued). We will post material additions. If you object on reasonable data-protection grounds we will discuss a resolution; if we cannot agree you may stop using the Service.
After an event we delete Customer Data 12 months after the last ceremony, or sooner if you ask us to remove the invitation (which also deletes RSVPs, guestbook files and photos for that code).
AI
We do not use Customer Data (guest lists, RSVPs, guestbook) to train AI models. Staff Studio tools may use AI on staff marketing notes only.
International transfers
We operate from the United Kingdom. Vercel and Google may process data in the United States. [transfer mechanism: SCCs / UK addendum — confirm].
Annex — processing details
Provider: Vytley. Contact: hello@vytley.com. Role: processor of Customer Data.
Customer: the host using the Service. Role: controller.
Data subjects: guests and household members the host includes, including children where the host lists them.
Data: names, optional contact details, tokens, RSVPs, meals, optional dietary or access notes, guestbook text/audio/image, venue details.
Purpose and nature: hosting and delivering the invitation and related guest features. Duration: as in the retention section of the Privacy Policy.
About this DPA
Adapted from General Legal’s CC0 templates. This is not legal advice, and using these pages does not create a lawyer–client relationship with General Legal or with Vytley.