Guest Data Agreement

Last updated 29 July 2026

Your guests never signed up with us — you collected their details. That makes you responsible for them and us your processor. This addendum sets out what each of us must do, and forms part of our Terms of Service.

1. Who is responsible for what

When you add guests to wed.cards — typing them in, importing a spreadsheet, or using your phone's contact picker — you decide whose details go in and what they're used for. That makes the split simple:

WhoRole
YouIn charge of your guests’ details. You decide what is collected and why.
wed.cardsWe hold and process those details for you, and only ever on your instructions.
Your guestsThe people the information is about. Their rights are exercised through you.

For your own account information — your name, email, payments — it works the other way round: there we are in charge, and our Privacy Policy applies.

2. Scope of the processing

ItemDetail
Subject matterHosting a digital wedding invitation and managing the associated guest list
DurationWhile your account is active, then per our Data Retention Policy
Nature and purposeStorage, display, RSVP collection, invitation delivery, and printing where ordered
Types of personal dataGuest names, phone numbers, email addresses, postal addresses, RSVP status, meal and dietary preferences, personalised messages, guestbook entries and photos
Categories of data subjectYour wedding guests and anyone who signs your guestbook
Special category dataNone requested. Dietary preferences may imply religious belief or health — please do not record more than you need.

3. What we undertake

These are the promises we make to you about how we handle your guests' details. We apply them for every customer, everywhere, without exception.

  • Only on your instructions. We process guest data only to provide the service, and never for our own purposes, our own analytics, AI training, or marketing of any kind.
  • Confidentiality. Everyone with access is bound by confidentiality obligations.
  • Security. We apply appropriate technical and organisational measures — encryption in transit and at rest, hashed passwords, HTTP-only Secure SameSite session cookies, and least-privilege access to production.
  • Sub-processors. You give general authorisation for the providers listed on our Service Providers. We give 30 days' notice before adding a new one, and you may object.
  • Helping you answer your guests. If a guest exercises a right against you, we will help you respond. If a guest contacts us directly, we will not action it ourselves — we will tell them to contact you and let you know.
  • If something goes wrong. If your guest data is ever caught up in a security incident, we will tell you within 48 hours of finding out. That is deliberately quicker than the deadline you yourself may have to report it, so you have time to act rather than being caught out.
  • Deletion and return. On request, or when your account closes, we delete guest data or return it to you. Our export gives you a complete copy in JSON at any time.
  • Proof. If you need to satisfy yourself that we are doing all of the above, ask and we will show you.
  • International transfers. Guest data is covered by Standard Contractual Clauses wherever it moves between countries — we apply them as our baseline, not only where an EEA or UK origin makes them mandatory.

4. What you undertake

Since you decide whose data goes in, some things only you can do. By uploading guest data you confirm that:

  • You have a lawful basis for sharing each guest's details with us — normally your own relationship with them. Inviting people you know to your wedding is exactly the situation the law contemplates here.
  • You will tell your guests who has their data if they ask, and point them to this page and our Privacy Policy.
  • You will action their requests — if a guest asks to be removed, delete them from your guest list. You can do that yourself at any time.
  • You will not upload special category data (health, religion, biometrics) beyond what a meal preference implies, and not more than you need.
  • Where a guest is a child, you have their parent or guardian's agreement to share their details.
  • You will keep your account credentials secure. Most guest-data exposure comes from a shared password, not from a platform failure.

5. Deletion

Guest data is deleted 12 months after your wedding date, when you delete your account, or whenever you ask — whichever comes first. See the How long we keep things for the full schedule and the advance notice you receive.

6. Acceptance and changes

This addendum takes effect when you create an account or upload guest data, and it forms part of the Terms of Service. If you need a countersigned copy for your own records — some corporate and destination-wedding planners do — email support@wed.cards and we will arrange one.

Where this addendum conflicts with the Terms of Service on the processing of guest data, this addendum wins.