Skip to main contentMain content
Glenthea

Data Processing Agreement

Last updated: 24 August 2026

This Data Processing Agreement (the "DPA") applies when Glenthea processes personal data about your Guests on your behalf. It forms part of the Terms of Service and takes effect when you accept them. Where it conflicts with the rest of the Terms on the processing of Guest personal data, this DPA prevails.

1. Who is responsible for what

You decide what your Guests are asked, who may see the answers, and what happens to that information. In data-protection terms you are the controller of it, and Glenthea is your processor: we handle it on your behalf and on your instructions.

Glenthea is separately a controller, not your processor, for the limited processing it does for its own purposes: running and securing the Platform, preventing fraud and abuse, billing you, and meeting its own legal obligations. That processing is described in our Privacy Policy and is not governed by this DPA.

"Data protection law" here means the Swiss Federal Act on Data Protection and, where they apply, the EU and UK General Data Protection Regulations.

2. Your instructions

We process Guest personal data only on your documented instructions, including about transfers to other countries, unless the law requires otherwise. Your instructions are: these Terms, this DPA, and the choices you make in the Platform, such as what you ask your Guests, what you publish, who you invite and what you export.

We will tell you if, in our view, an instruction breaks data protection law. We may refuse to act on an instruction that we believe would do so, and we are not obliged to give legal advice about your own use of the Platform.

3. Confidentiality

Everyone we allow to process Guest personal data is bound by a duty of confidence, and only people who need access for the purposes above are given it.

4. Security

We apply appropriate technical and organisational measures to protect Guest personal data, taking account of the state of the art, the cost of implementation, and the risk to the people concerned. These include encryption in transit and at rest, access control, tenant isolation at the database layer, audit logging of administrative access, and encrypted backups.

Security measures change as threats and technology change. We may replace a measure with one that is at least as protective; we will not reduce the overall level of security during the term of this DPA.

5. Subprocessors

You give us general authorisation to engage subprocessors to help provide the service. The subprocessors we use are listed in our Privacy Policy, together with what each one processes and where.

Before a subprocessor processes Guest personal data we impose on it, by contract, data-protection obligations that are equivalent in substance to those in this DPA. We remain fully liable to you for a subprocessor's performance of its data-protection obligations.

We will give you reasonable notice before adding or replacing a subprocessor that processes Guest personal data. If you object on reasonable data-protection grounds, tell us at support@glenthea.com; if we cannot offer you a reasonable alternative, you may end the affected part of the service and ask for a refund of the part you have not used.

6. Helping you answer your Guests

Guests may ask to see, correct, delete, restrict, object to or receive a copy of their information. Those requests are yours to answer, because you decide what happens to that information. The Platform gives you the tools to do it, and we will help you where you cannot do it yourself, at no charge for a reasonable volume of requests.

If a Guest contacts us directly, we will not answer on your behalf beyond telling them to contact you, unless the law requires us to act or you ask us to.

7. Breaches, assessments and prior consultation

If we become aware of a personal data breach affecting Guest personal data, we will tell you without undue delay and give you the information you reasonably need to meet your own notification duties. We will not notify a supervisory authority or your Guests on your behalf unless you ask us to or the law requires it of us.

Taking account of the nature of the processing and the information available to us, we will give you reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority.

8. Where the data goes

Guest personal data is hosted in Switzerland, the European Economic Area, or the United States, depending on the subprocessor. Where a transfer leaves Switzerland or the EEA, it relies on an adequacy decision or on the Standard Contractual Clauses, together with any additional safeguards those require. Our Privacy Policy names the location for each subprocessor.

9. Deletion and return

You can export your Content and your guest list from the Platform at any time while your account is open. When you delete a wedding or your account, or when this DPA ends, we delete the Guest personal data we hold as processor.

Deletion removes the data from active use immediately. Copies remain in encrypted disaster-recovery backups until those backups expire, which is within twelve months at the latest, and they are not restored into active use except to recover from a failure. We may keep data for longer only where the law requires it, and then only for as long as that requirement lasts.

10. Information and audits

We will give you the information you reasonably need to show that we are meeting our obligations under this DPA, and will allow and contribute to audits, including inspections, carried out by you or an auditor you appoint.

Audits are limited to what data protection law requires. Give us reasonable notice, keep what you learn confidential, and do not disrupt the service or the privacy of other customers. We may satisfy an audit request with an up-to-date third-party report or certification where one answers your question. We may charge our reasonable costs for an audit that goes beyond one per year, unless the audit follows a personal data breach.

11. What is processed, and for how long

Subject matter and purpose: providing the Glenthea platform to you so that you can invite your Guests, collect their answers and organise your wedding.

Duration: for as long as your account and the relevant wedding exist, plus the backup period described in Section 9.

Nature of the processing: collecting, storing, organising, displaying, transmitting, exporting and deleting the data, and sending the emails you ask us to send.

Categories of personal data: names; contact details you hold for your Guests; their answers to your invitation, including answers given for others in their party; any dietary requirements or allergies they choose to enter, which may reveal information about health; messages, photographs and other Content they submit; and technical data such as access times generated when they use the wedding card.

Categories of data subject: the people you invite and anyone whose details you or they enter, which may include children where you use features intended for them.

12. Term, changes and liability

This DPA applies for as long as we process Guest personal data on your behalf. Sections 3, 9 and 10 survive its end for as long as they need to.

We may update this DPA where data protection law, a supervisory authority or a change to the service requires it. If a change materially and negatively affects you, Section 7 of the Terms applies.

Section 9 of the Terms limits our liability under this DPA, except where data protection law does not permit that limit.

13. Contact

Questions about this DPA, or a request under it, go to support@glenthea.com.