GDPR Compliance
EU Data Processing Information
1. Commitment to GDPR
My Invite Studio is committed to ensuring the protection and security of personal data in accordance with the European Union's General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). By integrating privacy by design throughout our software development cycle, we ensure that personal data is processed lawfully, transparently, and only for specific, explicit, and legitimate purposes.
2. Legal Basis for Processing
Under the GDPR, we rely on the following legal foundations to process your data:
- Performance of a Contract: When you provide your personal details to create a wedding invitation website, we need your data to fulfill our side of the agreement (i.e., hosting the website and managing the RSVP form).
- Consent: For actions like subscribing to non-essential marketing emails or using non-essential cookies. You have the right to withdraw this consent at any time.
- Legitimate Interests: To improve our service functionality, maintain security logs, and prevent fraud, provided these interests are not overridden by your fundamental rights.
3. Your Fundamental Rights
As a European Union denizen (or user protected under equivalent laws like the UK GDPR), you possess extensive rights over your personal data. We are committed to facilitating these rights without undue delay:
- Right to Access: You may request a comprehensive digital copy of all data we currently hold about you.
- Right to Rectification: You may correct inaccurate or incomplete data associated with your profile directly in your Dashboard.
- Right to Erasure ("Right to be Forgotten"): You may request that we purge all traces of your personal data and uploaded User Content from our servers (except where statutory limitations force us to retain billing records).
- Right to Restrict Processing: You may temporarily pause our processing of your data while a dispute about its accuracy or legality is resolved.
- Right to Data Portability: You may request an export of your RSVP lists and guest data in a structured, commonly used framework (e.g., JSON or CSV format).
- Right to Object: You may categorically object to processing predicated upon legitimate interests or direct marketing priorities.
4. International Data Transfers
Some of the software infrastructure and third-party sub-processors we utilize (such as Cloudflare R2 and AWS) run data centers located outside the European Economic Area (EEA), predominantly in the United States.
Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by utilizing specific contracts approved by the European Commission (Standard Contractual Clauses - SCCs) which give personal data the same protection it has in Europe.
5. Data Breach Notification
If a data breach occurs that is likely to result in a high risk to the rights and freedoms of individuals, My Invite Studio will notify the competent supervisory authority within 72 hours of becoming aware of the breach, and will seamlessly communicate the gravity of the breach directly to affected data subjects where mandated.
6. Contacting the Data Protection Officer (DPO)
To exercise your rights, seek clarification on international transfers, or lodge a data-related complaint, please contact our appointed DPO directly at: