Privacy Policy
In effect from 2026-08-10
This notice explains what Latido does with personal data. It is written to meet Articles 13 and 14 of the GDPR and the Hungarian Infotv. (Act CXII of 2011). If anything here is unclear, write to hello@latido.wedding and we will explain it in plain language.
1. Who we are
- Operator: Szénási Dániel e.v. (trading as Latido)
- Registered seat: 6727 Szeged, Érc utca 17.
- Registration number: 62646068 · Tax number: 92262081-1-26
- Email: hello@latido.wedding · Website: https://latido.wedding
- We have not appointed a Data Protection Officer. We are not required to: we are a very small operation, our core activity is not large-scale monitoring, and the special-category data we touch is processed on our customers’ behalf rather than for our own purposes. If that changes we will appoint one and say so here.
2. The most important thing on this page: we wear two hats
Latido handles two very different kinds of data, and our legal role is different for each. This distinction decides who you should contact about what.
a) We are the controller of the account and platform data
For the data that exists because you use Latido — your profile, your login, your vendor business listing, your subscription and invoices, security logs and product analytics — we decide why and how it is processed. We are the data controller. Everything in sections 3–14 below applies.
b) We are only a processor for what is inside a wedding workspace
The guest list, seating plan, budget, timeline, documents, messages, photos and the guest wedding website belong to the couple who created that wedding. They decide what to collect and why. They are the controller; we merely store and display it on their instructions. We do not use that content for our own purposes, we do not sell it, we do not mine it, and we do not train AI models on it.
The same applies to a vendor’s own CRM records about their clients. If you are a guest and want your data corrected or deleted, the fastest route is to ask the couple; you can also write to us and we will pass it on and help them action it. The processing terms that govern this relationship are set out in our Data Processing Terms.
3. What we collect, why, and on what legal basis
Where we act as controller:
| Data | Why | Legal basis (Art. 6) |
|---|---|---|
| Name, email, phone, language, authentication identifiers, terms-acceptance timestamp | To create and run your account, sign you in, and prove you accepted the terms | Contract · legal obligation (accountability) |
| Vendor business profile — business name, category, description, address & coordinates, links, cover and portfolio images, service areas, opening/availability settings | To publish your listing and let couples find you | Contract |
| Vendor tax number and bank account, where you enter them | So the couple you work with can pay you. Never shown to other vendors or to the public | Contract |
| Subscription, invoices, payment status | To bill vendor subscriptions and meet accounting and tax law | Contract · legal obligation |
| Notification and email preferences | To send only what you asked for | Contract · consent (where you opted in) |
| Server logs, IP address, user agent | Security, abuse prevention, debugging | Legitimate interest — running a secure service |
| Error diagnostics (Sentry), with personal data collection disabled | To find and fix crashes | Legitimate interest — a working service |
| Product analytics (OpenPanel, cookieless) — which features are used, keyed to your account ID | To see what to improve. Never guest data or message content | Legitimate interest — improving the service |
| Support and feedback you send us | To answer you and fix problems | Legitimate interest · contract |
| Marketplace listings created from public sources | To give couples a usable directory from day one — see section 8 | Legitimate interest |
| Vendor reviews you write — star ratings, review text, the display name you chose (a first name, both, or initials) and the month of your wedding | To publish them on the vendor’s profile so other couples can read them. Published until you delete them or your account — see the reviews policy | Contract · legitimate interest — an honest marketplace |
| Advertising-measurement identifiers (Google Ads click ID, Meta Pixel cookies) — only if you accepted marketing cookies | To know whether our own ads lead to signups | Consent (Art. 6(1)(a)) — withdrawable any time via “Cookie settings” |
Where we act as processor — guests, seating, budget, timeline, documents, messages, photos, the guest website and vendor CRM records — the legal basis is set by the controller (the couple or the vendor), not by us.
Where we rely on legitimate interest, we have weighed our interest against your rights: the data is limited, it is used only to run and improve the service, we do not profile you, we never use it for advertising, and you can object at any time (section 11). Advertising measurement is the one thing that runs on a different basis — your consent, given (or not) in the cookie banner and withdrawable any time.
4. Guest data and dietary information
A couple’s guest list can contain a guest’s name, email, phone, whether they are a child, RSVP status, dietary flags (vegan, lactose-free, gluten-free), a free-text allergy field, accommodation and room, transport needs, a seat, a gift note, a comment left with the RSVP, and private notes the couple writes.
Allergy and dietary information can amount to health data — a special category under Article 9 of the GDPR. We treat it that way. It reaches us in one of two ways: the couple types it in, or the guest enters it themselves on the couple’s wedding website when they RSVP. In both cases the couple is the controller and is responsible for the Article 9 condition — in practice the guest’s explicit consent, given by choosing to fill the field in, for the single purpose of catering their event.
We have built the product so this data stays narrow:
- Vendors see nothing about guests by default. A couple must switch on each category of sharing per vendor, and those switches are enforced in the database itself, not just in the interface.
- Guest names and free-text allergy details are separate switches. A caterer can be given “number of vegans and how many have an allergy” without ever seeing a name, and the seating view then shows anonymous occupied seats with dietary markers.
- The free-text allergy field is in no default sharing preset. It is only ever released by an explicit, purpose-stating confirmation.
- Every grant and withdrawal is logged, and the couple can see at any time exactly what each vendor can read — including a preview rendered through the same database rules the vendor’s own account uses.
- A couple can permanently purge all dietary data and the RSVP audit log after the wedding, from the website editor.
Guests reach their RSVP page through a personal link containing a random token. Anyone holding that link can see and edit that household’s RSVP, so treat it like a key. The token never appears in search engines; guest websites are excluded from indexing.
5. Who we share data with
We do not sell personal data and we do not share it for anyone else’s marketing. Data is shared only with:
- The people you share it with inside the product — your co-owner, collaborators, and any vendor you have explicitly granted access to.
- The service providers listed below, which act on our instructions.
- Authorities, courts, or our legal advisers, where the law requires it or to establish or defend legal claims.
- A successor, if the business is ever transferred — you would be told beforehand.
6. Service providers (sub-processors)
We use the following providers to run Latido. Each processes personal data only on our instructions under a data-processing agreement, except where marked as an independent controller.
| Provider | Purpose | Location & role |
|---|---|---|
| Supabase | Database, authentication, file storage — all wedding and account data lives here | EU (Frankfurt, eu-central-1) · processor |
| Render | Application hosting | US company, EU hosting (Frankfurt) · processor |
| Resend | Transactional email — sign-in links, invitations, notifications, guest emails | US · processor |
| Anthropic (Claude) | Optional “Latido AI” drafting. Only used when you press the AI button | US · processor |
| OpenAI | Optional “Print studio” card design — the pictures you choose as inspiration and the words you type for a card are sent to generate and check the design. Only when you press Design it | US · processor (EU data residency where available) |
| Google Maps Platform | Maps, geocoding, address autocomplete. Loads only on pages showing a map or address search | US / global · independent controller for its own telemetry |
| Sentry | Error and performance monitoring. Configured with personal data collection switched off | US company, EU data residency (Germany) · processor |
| OpenPanel | Cookieless product analytics — which features are used, keyed to an account ID | EU (Sweden) · processor |
| Stripe | Vendor subscription payments. We never see or store card details | Ireland / EU · independent controller |
| Számlázz.hu / Billingo | Invoicing and statutory NAV reporting | EU (Hungary) · processor |
| Google Ads | Measuring our own advertising — loads only after you accept marketing cookies in the banner | US / global · independent controller for ad measurement · EU–US DPF |
| Meta Platforms (Facebook/Instagram) | Measuring our own advertising (Meta Pixel) — loads only after you accept marketing cookies in the banner | Ireland / US · independent controller for ad measurement · EU–US DPF |
We will update this list before adding or replacing a provider, so that controllers using Latido have a chance to object.
7. International transfers
Your wedding data is stored in the EU (Frankfurt). Some providers in the table are US companies. Where personal data reaches a country outside the EEA, we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework. You can ask us for details of the mechanism used for any provider.
8. Marketplace listings created from public sources
We no longer do this. Until August 2026, to make the directory useful from the start, some venue and vendor listings were compiled from publicly available business information, including OpenStreetMap (© OpenStreetMap contributors, ODbL) — the situation Article 14 of the GDPR covers, where the data comes from a source other than the business itself.
Those listings were deleted in August 2026 and the practice was discontinued. Every business in the marketplace today is there because it registered itself and published its own profile. We hold no listing that its subject did not create. This section is kept rather than removed so that anyone who read the earlier policy can see what happened to that data.
9. Latido AI
Latido AI is optional and never runs on its own. When you press an AI button, the relevant context — the vendor’s business details, the wedding’s basic facts, and for a reply draft the message thread — is sent to Anthropic to generate a draft you then review before anything is saved. We do not send guest lists or dietary data to the AI. We do not train models on your data, and we have contracted for the provider not to train on it either. If the feature is switched off for the service, the button does not appear.
The Print studio’s card design uses OpenAI’s image models in the same way: when you press Design it, the inspiration pictures you selected and the exact words you typed for the card (a menu, a table number, a guest’s name) are sent to draw the card and to read it back for checking. Pictures you upload as inspiration should not show people; we use them for style only and say so in the request, but they are still transmitted. Generated cards are stored privately in your wedding and deleted with it.
AI assistants you connect yourself (MCP)
Latido also speaks the Model Context Protocol, so an AI assistant you use (Claude, ChatGPT, Claude Code and others) can search the public vendor directory and use our free tools from inside a conversation. Without signing in, such an assistant can read only what any visitor to the marketplace can read: the vendor storefronts their owners chose to publish, plus the budget benchmarks and the checklist. Nothing about you is sent. When we later let you connect a signed-in account, the assistant will receive only the data you grant it on a consent screen, and that data then goes to the assistant’s provider under their terms — connecting one is your choice, like exporting a file.
10. How long we keep things
| Data | Retention |
|---|---|
| Account and wedding content | While the account exists. Deleted or anonymised within 30 days of a deletion request |
| Accounts with no sign-in for 3 years | Deleted after notice to the email on file |
| Invoices and accounting records | 8 years — Hungarian Accounting Act (2000. évi C. tv.) § 169 |
| Terms-acceptance record | For the life of the account plus 5 years (limitation period) |
| Server and security logs | 90 days |
| Error diagnostics (Sentry) | 90 days |
| Product analytics | 24 months, pseudonymous |
| Guest data, seating, messages, documents, photos | Set by the couple. Deleted when they delete the wedding or their account |
| Inspiration board images and links | Until the couple removes them or deletes the wedding. Visible only to the vendors they engage and share it with |
| RSVP audit log and dietary data | Until the couple purges it — available to them in one click after the wedding |
| Sign-in tokens | Minutes to hours (they expire) |
11. Your rights
You can ask us to give you access to your data, correct it, delete it, restrict how we use it, or hand it to you in a portable format. You can object to processing based on legitimate interest. Where processing is based on consent you can withdraw it at any time, without affecting what happened before.
- Self-service: Settings → Privacy & your data lets you export everything we hold about you as a JSON file, and request deletion of your account.
- By email: hello@latido.wedding. We answer within 30 days, extendable once by two months for complex requests — we will tell you if that happens.
- If you are a wedding guest, ask the couple first — they control that data. We will help either way.
- Requests are free unless they are manifestly unfounded or excessive.
12. Security
What we actually do, rather than what sounds good:
- Access control is enforced in the database with row-level security, not only in the application. Every query runs as the signed-in user, so a bug in the interface cannot expose another wedding’s data.
- We store no passwords. Sign-in is by one-time email link, Google, or passkey, handled by our authentication provider.
- All traffic is encrypted with TLS. Data is stored in the EU.
- Error monitoring is configured not to send personal data.
- What each vendor can see is enforced by database rules derived from the couple’s sharing switches.
- We keep backups, and we test restores.
No system is perfect. If a breach occurs that is likely to risk your rights, we will notify the NAIH within 72 hours as Article 33 requires, and tell affected users directly where Article 34 requires it.
13. Children
Latido accounts are for adults; you must be able to enter a contract. Guest lists may include children — a couple can mark a guest as a child — and that data is processed on the couple’s instructions and responsibility. We do not knowingly create accounts for minors, and if we learn we have, we delete them.
14. Cookies
We use strictly necessary cookies, plus Google Maps on pages that show a map. Our analytics sets no cookies at all. Marketing cookies (Google Ads, Meta) exist only if you expressly accept them in the cookie banner, and you can withdraw that any time via “Cookie settings” in the footer. Full detail is in the Cookie Policy.
15. Complaints
Please try us first — hello@latido.wedding. You also have the right to complain to the supervisory authority, or to go to court.
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- 1055 Budapest, Falk Miksa utca 9–11. · Postal: 1363 Budapest, Pf. 9.
- Phone: +36 1 391 1400 · Email: ugyfelszolgalat@naih.hu · naih.hu
16. Changes
We will update this notice as the product changes and update the date at the top. If a change is significant, we will tell registered users by email before it takes effect.