Parties & roles
This DPA applies between you ("Controller") — typically an event host, organisation, or wedding planner using Vowly Event to manage guest data — and CKR Technology Group Ltd ("Processor"). The Controller determines the purposes and means of processing personal data; the Processor processes personal data only on documented instructions from the Controller.
Scope of processing
The Processor will process personal data on behalf of the Controller to provide the Vowly Event service, including but not limited to event creation, invitation distribution, RSVP collection, guest list management, payment processing for events, and platform analytics.
- Categories of data subjects: event guests, plus-ones, vendors, and Controller staff
- Categories of personal data: names, contact details, RSVP responses, photographs (where uploaded by guests), and — only with the guest's separate explicit consent — dietary and allergen information, which may reveal health or religious details (special category data under Article 9)
- Duration: for the lifetime of the Controller's subscription and any data retention period agreed in writing
Processor obligations
In accordance with Article 28(3) of the UK/EU GDPR, the Processor commits to the following obligations regarding personal data processed on behalf of the Controller.
- Process personal data only on documented instructions from the Controller
- Ensure that all personnel authorised to process personal data are bound by confidentiality
- Implement appropriate technical and organisational measures (TOMs) — detailed in our Security page
- Assist the Controller with data-subject rights requests, DPIAs, and prior consultations with supervisory authorities
- Notify the Controller without undue delay of any personal data breach affecting their data
- Make available all information necessary to demonstrate compliance with Article 28
Sub-processors
The Processor uses a curated list of sub-processors to deliver the service. By signing this DPA, you grant general authorisation for the use of sub-processors, subject to a 30-day prior notice of any changes giving you the right to object.
- Google Ireland Limited (Google Cloud / Firebase) — database, file storage and hosting in the EU; sign-in operated from US data centres under SCCs
- Stripe Payments Europe Ltd (Ireland) — payment processing
- Resend Inc. (US) — transactional email delivery, under EU SCCs
- Crisp IM SARL (France) — support chat, when the Controller uses it
- Functional Software, Inc. (Sentry, US) — error monitoring, with personal identifiers switched off
- Cloudflare, Inc. — DNS for our domains
- Apple Inc. & Google LLC — app store distribution and in-app purchase processing
- The always-current list, including any service that receives no personal data, is maintained at vowly.co/subprocessors
International transfers
Where personal data is transferred outside the UK or EEA, the Processor relies on appropriate safeguards as required by Chapter V of the UK/EU GDPR. The primary mechanisms are the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum (IDTA), supplemented by additional technical and organisational measures where necessary.
Audits & inspections
The Processor will, upon reasonable written notice, allow for and contribute to audits conducted by the Controller or a mandated third-party auditor (subject to confidentiality undertakings). To minimise disruption, the Processor will first offer industry-standard audit reports (e.g., SOC 2 Type II reports from infrastructure providers) and security questionnaires.
Return or deletion of data
The Controller can export event data at any time from the platform, and deletes personal data directly by deleting guests, events, or the account itself — deletion takes effect immediately in production systems. Upon written request after termination, the Processor will return or delete any remaining personal data within 30 days, unless retention is required by applicable law. Residual copies on Google Cloud infrastructure are purged in line with Google's documented deletion timelines (up to 180 days).
Liability
The Processor's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party's liability for failures to comply with the UK GDPR or EU GDPR where such liability cannot be excluded by law.
Need a signed DPA?
Business customers can request a counter-signed DPA and our current list of sub-processors at any time.
legal@vowly.co