Data protection
Privacy Policy
1. Data controller
| Controller | Nicolás Federico Sánchez |
|---|---|
| Tax identification | Codice Fiscale SNCNLS93M11Z600T · Partita IVA 02136650385 (Italy) |
| Address | Via Foro Boario, 48 — 44122 Ferrara (FE), Italy |
| Privacy contact | contact@matrimonio.pro |
| Data Protection Officer (DPO) | Not appointed, as it is not mandatory under art. 37 GDPR given the nature and volume of the processing. |
| EU representative | Not applicable: the controller is established in the European Union (Italy). |
2. Our two roles
Depending on the activity, we process data in different roles:
- As controller: when we process the data of the couples using the service (those creating the invitation) and browsing and billing data.
- As processor: when the couple collects data about their guests through the RSVP. In that case, the couple is the controller and we process that data solely on their behalf and instructions, to provide the Service. The relationship is governed by these terms, which serve as the data processing agreement (art. 28 GDPR / art. 39 LGPD).
3. Data we process
| Category | Examples | Source |
|---|---|---|
| Couple's data | Names, email, event date and venue, texts, photographs, music, gift registry details (IBAN/account/alias) | Provided by the user |
| Purchase and payment data | Amount, date, country, transaction identifier. Card details are processed directly by the payment provider; we do not store them. | User / payment provider |
| Guest data (RSVP) | Name, email, number and names of plus-ones, dedicated song and, where applicable, food intolerances or allergies | Provided by guests to the couple |
| Technical and usage data | IP address, browser and device type, first-party usage events (internal analytics), identifiers stored in the browser | Automatic |
| Communications | Content of the emails or messages you send us | User |
4. Purposes and legal bases
| Purpose | Legal basis (GDPR / LGPD / Law 25.326) |
|---|---|
| Create, host, publish and maintain the invitation | Performance of the contract (art. 6.1.b GDPR) |
| Process the payment and comply with tax/accounting obligations | Performance of the contract and legal obligation (art. 6.1.b and 6.1.c) |
| Manage the RSVP and notify confirmations to the couple | Performance of the contract / legitimate interest; with respect to guests, on behalf of the couple as controller |
| User support | Performance of the contract and legitimate interest (art. 6.1.f) |
| Security, fraud prevention and Service improvement (internal analytics) | Legitimate interest (art. 6.1.f) |
| Sending commercial communications | Consent (art. 6.1.a) or legitimate interest for existing customers, with an opt-out option |
| Non-essential cookies | Consent (art. 6.1.a) — see the Cookie Policy |
5. Sensitive data (intolerances and allergies)
The RSVP form may include a field for food intolerances or allergies. This information may be considered health-related data and, therefore, a special category (art. 9 GDPR / sensitive data under the LGPD and Law 25.326). We recommend the couple use this field only if necessary and obtain the guest's explicit consent. The guest provides this data voluntarily; by entering it, they consent to its processing for the sole purpose of organizing the event's catering. This data is not used for any other purpose or shared with third parties outside the Service.
6. Communications and email marketing
We distinguish two types of messages:
- Transactional or operational communications (payment confirmation, invitation link, RSVP notices, expiry notices): necessary to provide the Service; sent on the basis of the performance of the contract.
- Commercial or promotional communications: sent only if the user has given consent or, for existing customers, on the basis of legitimate interest for similar products, always with the option to unsubscribe in every message.
U.S. · CAN-SPAM All commercial emails include an identifiable sender, a non-misleading subject line, a physical postal address and an unsubscribe mechanism that is honored promptly. EU · ePrivacy Commercial sending requires prior consent, except for the existing-customer exception for similar products. You can revoke your consent or unsubscribe at any time by writing to contact@matrimonio.pro or via the unsubscribe link.
7. Recipients and data processors
We do not sell personal data. We share data only with providers that render services to us as data processors, under contract and with appropriate safeguards:
| Provider | Purpose | Location |
|---|---|---|
| Hostinger | Web hosting and email | European Union |
| Stripe | Payment processing | EU / U.S. |
| Google (Fonts, Maps, YouTube) | Typefaces, maps and music playback on the invitations | EU / U.S. |
| Operational email (SMTP) | Sending transactional emails (confirmations, RSVP notices). No email marketing provider is currently used. | European Union |
We may also disclose data to public authorities where a legal obligation exists.
8. International transfers
Some providers may process data outside the European Economic Area or the user's country (for example, in the U.S.). In such cases, transfers rely on valid mechanisms such as the European Commission's Standard Contractual Clauses, the EU-U.S. Data Privacy Framework (where the provider is certified) or adequacy decisions. You can request information about the applicable safeguards by writing to contact@matrimonio.pro.
9. Retention periods
- Unpublished/unpaid invitations: deleted after a short period, as indicated on the Platform.
- Published invitations: while the invitation is active and for 12 months after the event.
- Billing data: for the applicable legal tax and commercial periods (usually between 5 and 10 years depending on the country).
- Guest data (RSVP): for as long as the couple, as controller, needs it and does not request its deletion.
- Marketing data: until you revoke your consent or unsubscribe.
10. Your rights
You may exercise, free of charge, the rights of access, rectification, erasure, objection, restriction of processing, portability and the right not to be subject to automated decisions, as well as withdraw consent at any time. To exercise them, write to contact@matrimonio.pro indicating the right you wish to exercise; we may request proof of identity.
If you believe we have not handled your request correctly, you can lodge a complaint with the competent supervisory authority: the AEPD (Spain, aepd.es) or another EU authority, the ANPD (Brazil), the AAIP (Argentina) or your country's authority.
11. Specific rights in the U.S. (CCPA/CPRA)
Residents of California and other states with equivalent laws have the right to know, access, correct and delete their personal information, as well as not to be subject to the "sale" or "sharing" of their data. We do not sell personal information within the meaning of the CCPA/CPRA. You can exercise your rights at contact@matrimonio.pro without discrimination for doing so.
12. Specific rights in Brazil (LGPD)
Under the LGPD, the data subject has the right to confirmation and access, correction, anonymization or deletion, portability, information about sharing and revocation of consent (art. 18). The processor (operador) and the controller (controlador) are liable under the terms of the LGPD. Contact: contact@matrimonio.pro.
13. Specific rights in Argentina (Law 25.326)
The data subject may exercise the rights of access, rectification, updating and deletion (habeas data). The Agency for Access to Public Information (AAIP), the enforcement body of Law 25.326, is competent to handle complaints. The data subject has the right to access their data free of charge at intervals of no less than six months, unless a legitimate interest exists.
14. Security
We apply appropriate technical and organizational measures to protect the data (encryption in transit via HTTPS, access control, data minimization and isolation of sensitive information such as the gift registry details). No system is infallible; in the event of a security breach affecting your rights, we will act in accordance with applicable regulations, notifying the authority and those affected where appropriate.
15. Minors
The Service is not intended for anyone under 18 and we do not knowingly collect data from anyone under 16. If we detect that we have processed a minor's data without proper authorization, we will delete it.
16. Cookies
We use cookies and similar technologies as described in the Cookie Policy. Non-essential cookies are only turned on with your consent.
17. Changes and contact
We may update this Policy to reflect legal or Service changes. We will publish the current version with its date. For any privacy matters: contact@matrimonio.pro.