Data Processing Terms
In effect from 2026-08-01
These terms are the agreement required by Article 28(3) of the GDPR between you (the controller) and us (the processor). They form part of the Terms of Service and the Partner Terms — you do not need to send us a separate data-processing agreement, though we will sign one if your own circumstances require it.
1. When these terms apply
They apply to the personal data you put into Latido about other people: for a couple, the guest list and everything in the wedding workspace; for a vendor, the client records you keep. They do not apply to your own account data, for which we are the controller — see the Privacy Policy, section 2.
2. Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Hosting and processing personal data so you can plan a wedding or manage your client work in Latido |
| Duration | For as long as your account exists, plus the deletion period in section 9 |
| Nature and purpose | Storage, organisation, display to people you authorise, transmission of email you trigger, backup, and deletion |
| Types of personal data | Names, contact details, RSVP status, relationships and households, seating, dietary requirements and allergies (health data), accommodation, messages, documents, photographs, notes, and for vendors: client contact and enquiry records |
| Categories of data subject | Wedding guests, your collaborators, vendor contacts, and — for vendors — clients and prospects |
3. Our obligations
- We process the data only on your documented instructions. Your use of the product is your instruction; these terms and the Terms of Service are the rest of it. If the law requires us to process it otherwise, we will tell you first unless the law forbids that.
- We will tell you if we think an instruction breaches data-protection law.
- Everyone with access is bound by confidentiality, and access is limited to what is needed to run and support the service.
- We implement the technical and organisational measures described in the Privacy Policy, section 12, and keep them appropriate to the risk.
- We assist you in responding to data-subject requests, taking into account the nature of the processing — the product’s own export, edit and delete tools are the primary means.
- We assist you with security, breach notification, impact assessments and prior consultation (GDPR Articles 32–36), taking into account the information available to us.
- We notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own 72-hour obligation.
- We make available the information needed to demonstrate compliance with Article 28 and allow for audits — normally by answering your questions and providing our documentation; on-site audits only where a supervisory authority requires it, at your cost, and with reasonable notice.
4. Your obligations
- You must have a lawful basis for everything you enter, and meet an Article 9 condition for dietary and allergy data — in practice the guest’s explicit consent.
- You must give the people concerned the information Articles 13 and 14 require, and answer their requests.
- Share data with vendors only where you have a basis to. Use the per-category sharing controls rather than sending files outside the product.
- Keep guest personal links confidential and distribute them to the household concerned.
5. Sub-processors
You give us general authorisation to engage the sub-processors listed in the Privacy Policy, section 6. We impose the same data-protection obligations on each and remain fully liable to you for their performance. We will update that list before adding or replacing one; if you object on reasonable data-protection grounds you may terminate your account, and we will help you export your data first.
6. International transfers
Data is stored in the EU. Where a sub-processor transfers data outside the EEA, we rely on Standard Contractual Clauses or an adequacy decision, as described in the Privacy Policy, section 7.
7. Security
The measures in Privacy Policy section 12 are the agreed technical and organisational measures for the purposes of Article 32. The central one is that access is enforced by row-level security in the database, and that what each vendor can see is derived from your sharing settings and enforced there — not in the interface.
8. Confidentiality
We treat your data as confidential and do not use it for our own purposes, disclose it, sell it, mine it or train AI models on it.
9. Deletion and return
You can export your data at any time from the product. When you delete a wedding or your account, we delete or anonymise the personal data within 30 days, and backups age out within a further 90 days. We keep only what the law requires us to keep — principally invoicing records.
10. Liability and changes
Liability under these terms follows the liability provisions of the agreement they form part of, and Article 82 of the GDPR. We may update these terms; where a change materially affects your rights we give at least 15 days’ notice, as under the corresponding terms of service.