Privacy policy
This document explains how we collect, use, store, and protect personal data processed through Nozzio.
1. Controller and policy purpose
This policy describes practices that apply to platform users, guests who interact with public pages, and collaborators who receive access to planning workspaces.
Our goal is to provide transparency about the types of data we collect, why we process it, and the rights you have regarding that data.
2. Data we may collect
We may process account data such as name, email address, phone number, platform role, and secured authentication data.
For event planning, we may also process guest data, groups, RSVP status, menu selections, allergies, seating, budgets, events, and content published on the event website.
3. Legal bases and purposes
We process data to provide contracted services, administer accounts, operate RSVP flows, and enable collaboration between authorized users.
In some cases, processing is required for contract execution, legal obligations, our legitimate interest in securing and improving the service, or your consent where applicable.
4. Operational communications
We may send operational emails such as account confirmations, password reset links, collaboration invites, administrative notifications, or account security messages.
These communications are part of service delivery and are not treated as general marketing messages when strictly necessary for platform use.
5. Data disclosure
We do not sell your data. We may use third-party infrastructure, email, storage, analytics, or security providers only as needed to provide the service.
If required by law, we may disclose data to public authorities or other competent entities.
6. Retention and security
Data is kept for as long as needed for the purposes for which it was collected, for the duration of the active account, or for periods required by applicable legal obligations.
We apply reasonable technical and organizational measures to protect data from unauthorized access, disclosure, alteration, or loss.
7. Data subject rights
You have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where processing is based on consent.
You may also submit a complaint to the competent data protection authority if you believe your rights have been violated.
8. Guest data and user responsibility
The user managing the wedding is responsible for how guest data is entered and managed and for having a legitimate basis to use that data.
The platform provides technical infrastructure, but the user operating the event remains responsible for the content and accuracy of third-party information uploaded to the platform.
9. Policy updates
We may update this policy to reflect product, legal, or operational changes. The current version will remain published on this page.
We encourage you to review this document periodically to stay informed about how we protect processed data.