Data Processing Agreement (DPA)

Version 1.0 - April 2026

This Data Processing Agreement ("Agreement") supplements the Terms and Conditions of Folio and describes how Folio processes personal data on behalf of the User within the meaning of Article 28 GDPR.

1. Parties

Clarification per scenario

Couples using Folio directly: the couple is the Controller for the data of their guests, vendors, and team members. Folio processes this data solely on the couple's instructions.

Wedding planners using Folio on behalf of couples: the wedding planner is the Controller for the data in the wedding environments they manage. The planner is responsible for informing the couple about the use of Folio and the processing of personal data. Folio processes data on the planner's instructions.

2. Subject matter and duration

Folio processes personal data on behalf of the Controller for the purpose of providing the wedding planning platform. The processing lasts for as long as the Controller uses the Service, including the retention period after deletion (30 days) as described in the Privacy Policy.

3. Nature and purpose of processing

The processing takes place for the following purposes:

4. Types of personal data

CategoryData
Guest dataNames, email addresses, dietary requirements, RSVP status, plus-one details, household grouping
Couple contact dataNames, email addresses
Vendor dataBusiness name, contact person, email, phone, agreements
Financial dataBudget amounts, expenses, installment payments

5. Categories of data subjects

6. Obligations of the Processor

Folio commits to the following:

7. Sub-processors

Folio uses the following sub-processors. The Controller consents to these by accepting this Agreement:

Sub-processorPurposeLocation
Hetzner Online GmbHHosting and server infrastructureGermany (EU)
Brevo (Sendinblue)Sending transactional emails (RSVP invitations, password resets)France (EU)
Stripe Inc. (future)Payment processingEU/US under SCCs

Folio will notify the Controller by email of any changes to the sub-processor list. The Controller has 30 days to object. In case of objection, the Controller may terminate the Service.

8. Security measures

Folio implements the following measures to protect personal data (Article 32 GDPR):

9. International transfers

All data is stored and processed within the EU/EEA. No personal data is transferred to countries outside the EU/EEA, with the exception of Stripe (when active), for which Standard Contractual Clauses (SCCs) apply.

10. Data breaches

In the event of a data breach affecting the Controller's personal data, Folio will inform the Controller within 48 hours of discovery, providing:

The Controller is responsible for notifying the relevant supervisory authority if required (within 72 hours).

11. Termination

Upon termination of the Service, Folio will delete all personal data in accordance with the retention periods in the Privacy Policy (30 days after confirmed deletion). The Controller may export all data via the platform's download feature prior to termination.

12. Contact

Questions about this Data Processing Agreement: