Privacy Policy
Last updated: 3 October 2026
This Privacy Policy explains what personal data we collect, how we use it, with whom we share it and what rights you have. It is drawn up in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Croatian Act on the Implementation of the General Data Protection Regulation (NN 42/2018) and the rules on privacy in electronic communications.
1. Controller
The controller of your personal data is Svatovi, [upišite naziv i adresu sjedišta], VAT ID (OIB): [upišite OIB] (“we”).
For questions about data protection and to exercise your rights, contact us at privatnost@svatovi.app.
When a wedding organiser enters data about their guests through the Service, the organiser is the controller of that data and we process it on their behalf as a processor.
2. What data we collect
Depending on how you use the Service, we process the following categories of data:
- account data: e-mail, name, encrypted password record, passwordless login data (passkey/WebAuthn) and session security data;
- wedding data: the couple’s names, dates, locations and public page settings;
- guest data: names, contact details (e-mail, phone), guest type, companion composition, invitation responses and notes;
- organisational data: table arrangements, budget items and expenses, gift list and to-do list;
- payment data: transaction identifier, amount, currency, status and date of the Premium upgrade purchase; card data is processed by Paddle and we do not store it;
- content: invitations and the photos and videos you or your guests upload;
- technical data: IP address, device and browser type, and necessary cookie data;
- notification data: the push notification subscription identifier, if you enable them.
3. Purposes and legal bases of processing
We process data for the following purposes and on the following legal bases under Article 6 of the GDPR:
- providing the Service and performing the contract — performance of a contract (Art. 6(1)(b));
- security, abuse prevention and technical maintenance — legitimate interest (Art. 6(1)(f));
- sending push notifications — your consent (Art. 6(1)(a)), which you can withdraw at any time;
- processing payments and meeting tax and accounting obligations — performance of a contract and legal obligation (Art. 6(1)(b) and (c));
- meeting legal obligations (e.g. accounting and tax) — legal obligation (Art. 6(1)(c)).
4. Photo gallery and guest content
Photos and videos uploaded by guests are stored for display in the gallery and may be visible to other guests and the organiser, depending on the settings of the individual wedding.
The organiser can review, hide or delete content. We recommend that the organiser and guests obtain the necessary consents of the persons shown in the recordings before uploading.
5. Cookies and local storage
We use necessary cookies required for the Service to work, for example the session cookie for login and the NEXT_LOCALE cookie that remembers the chosen language. Without them the Service cannot function.
We also use a cookie-free analytics service that collects anonymised, aggregated visit data to improve the Service. We do not use advertising or cross-site tracking cookies.
You can block or delete cookies in your browser settings, but the necessary cookies are required for login and the operation of the Service.
6. Recipients and processors
We do not sell data. We treat it confidentially and share it only with trusted processors that provide the necessary infrastructure for us, under appropriate processing agreements:
- hosting and database provider (Supabase) — data storage;
- cloud storage provider (Cloudflare R2, an S3-compatible service) — storage of photos and videos;
- payment service provider (Paddle) — processing payments, taxes and invoices and refunds;
- e-mail service provider (Resend) — sending transactional e-mails (confirmations and notices);
- web application hosting provider (Vercel) — serving the application and cookie-free analytics;
- individual browser push providers — delivery of notifications if you enable them.
7. Transfers of data outside the EEA
We strive to process personal data within the European Economic Area. If data is transferred to providers outside the EEA, we carry out such a transfer on the basis of appropriate safeguards in accordance with the GDPR, for example the European Commission’s standard contractual clauses or an adequacy decision.
8. Data retention period
We keep personal data only for as long as necessary to achieve the purposes set out in this Policy:
We notify you by e-mail 30 and 7 days before a Free gallery’s retention period ends.
- account data — while the account is active, and after deletion for no more than 30 days for backups and legal obligations;
- wedding and guest data — until the account is deleted or you request deletion;
- photos and videos — on the Free tier 6 months from the wedding date, followed by 30 days read-only and then permanent deletion; on the Premium tier 5 years, after which the gallery becomes read-only and is not deleted automatically;
- payment data — for as long as accounting and tax rules require;
- data needed to meet legal obligations — for as long as the individual rule requires.
9. Your rights
With regard to your personal data you have the right of access, rectification, erasure (the “right to be forgotten”), restriction of processing, data portability and objection to processing, as well as the right to withdraw consent at any time and the right not to be subject to solely automated decision-making.
You can send a request to privatnost@svatovi.app. We will respond within one month, with the possibility of an extension in accordance with the GDPR where justified by the complexity of the request.
If you believe we process your data contrary to the rules, you have the right to lodge a complaint with a supervisory authority.
10. Right to lodge a complaint (AZOP)
The supervisory authority in the Republic of Croatia is the Agency for Personal Data Protection (AZOP), Selska cesta 136, 10000 Zagreb, e-mail: azop@azop.hr, web: www.azop.hr.
If you live in another EU member state, you can lodge a complaint with the supervisory authority in your country.
11. Data security
We apply technical and organisational safeguards appropriate to the risk, including encryption of transmission (HTTPS), encrypted storage of passwords and access control over data.
No system is completely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will inform you and the competent body in accordance with the GDPR.
12. Data of minors
The Service is intended for adults. We do not knowingly collect personal data of children under 16 without the consent of a parent or guardian. If you learn that such data has been entered, contact us to delete it.
13. Automated decision-making and profiling
We do not carry out automated decision-making or profiling that would produce legal or other significant effects on you.
14. Changes to the Privacy Policy
We may amend the Privacy Policy from time to time. We will publish the new version on this page with the date of the last update, and we will notify you of material changes in an appropriate way.
15. Contact
For any questions about the processing of personal data and the exercise of your rights, contact us at privatnost@svatovi.app.