Data Processing Addendum
Last updated 2026-07-13 · version 2026-07-13-draft
Draft — pending legal review. Not yet binding.
1. Purpose and scope
This Data Processing Addendum ("DPA") describes how Ever processes personal data submitted to the platform (including guest data couples add or that guests submit) when acting as a processor on behalf of the couple's wedding account. [COUNSEL: confirm whether a signed, standalone DPA is required for EU/UK customers and add execution mechanics (order form reference, signature block) if so.]
2. Roles
The couple (wedding account owner and collaborators) is the controller of the guest data they collect and enter. Ever is the processor, acting only on the couple's documented instructions as expressed through the product's normal functionality.
3. Data processed
Categories: guest names, contact details, RSVP responses, dietary/accessibility notes, plus-one and household data, and any free-text the couple or guests enter (messages, notes). No special-category data is intentionally collected; couples should avoid entering it in free-text fields beyond what's needed (e.g. dietary restrictions).
4. Sub-processors
Ever uses the following sub-processors to provide the service. We'll update this list as our infrastructure changes; material additions will be reflected here with an updated "last updated" date. [COUNSEL/PRIVACY: confirm whether advance notice + objection rights are required for EU/UK customers, and add processing-region detail per vendor.]
- Stripe — Payment processing, Stripe Connect payouts, and PCI-scope card handling for registry/cash-fund contributions.
- Resend — Transactional email delivery (RSVP confirmations, invites, receipts, and account notifications).
- Neon — Managed Postgres database hosting for wedding, guest, budget, and account data.
- Clerk — Authentication, session management, and account identity.
- Anthropic — AI concierge, drafting, and contract-summary features (model inference on user-provided context).
- Cloudflare — Hosting, CDN, and edge-network protection for the marketing site (ever.wedding).
- Sentry — Error monitoring and crash diagnostics.
- Upstash — Rate-limiting and short-lived caching (Redis) to protect the API from abuse.
- PostHog — Product analytics (page views, feature usage) — only after consent where required. See the Cookie Policy.
5. Security measures
Encrypted transport (TLS) for all traffic; Stripe-hosted card entry (out of PCI scope for Ever); access-controlled infrastructure; audit logging of sensitive account actions. [COUNSEL: insert the full security-measures annex expected under Art. 28 GDPR / equivalent, and confirm incident-notification timelines.]
6. International transfers
Sub-processors may process data outside your region. [COUNSEL: confirm the transfer mechanism (e.g. SCCs, UK IDTA) required for each sub-processor and region combination.]
7. Your rights and contact
Data-subject requests (access, correction, deletion, portability) can be made per the Privacy Policy. DPA-specific questions: [COUNSEL: insert contact + mailing address.]
Terms of Service·Privacy Policy·Cookie Policy·Data Processing Addendum·Acceptable Use Policy·Vendor Agreement