Last updated: April 2026

Terms & Conditions

This page describes the responsibilities of InvitatiaNoastra platform users with respect to the protection of personal data.

1. GDPR Roles

The User (the client who creates the invitation) is the personal data controller with respect to guest data. InvitatiaNoastra.com acts solely as a data processor, handling data on behalf of the User.

2. User Responsibilities

The User declares and warrants that they: • have the legal right to enter guest data into the platform • will inform guests about the processing of their data • will comply with applicable data protection legislation

3. Permitted Data Types

The User agrees not to enter: • sensitive data (e.g. health, religion, etc.), except where strictly necessary (e.g. dietary preferences) • excessive or irrelevant data for the purpose of the event

4. Data Retention

Guest data is retained for the duration of the account and may be deleted: • manually by the User • automatically after a defined period following the event

5. Liability

InvitatiaNoastra.com is not responsible for: • the legality of data collection by the User • the way in which the User informs guests Responsibility rests solely with the User in their capacity as data controller.

Data Processing Agreement (DPA)

This agreement governs the processing of personal data in accordance with the General Data Protection Regulation.

1. Parties

Controller: The platform user (the Couple) Processor: InvitatiaNoastra.com

2. Subject Matter

The Processor handles guest personal data solely for: • providing the digital invitation service • managing RSVPs

3. Data Types

• name • RSVP response • additional information provided by guests

4. Duration

Data is processed for the duration of the contract and deleted in accordance with the retention policy.

5. Processor Obligations

InvitatiaNoastra: • processes data only in accordance with the controller's instructions • ensures adequate technical and organisational measures • does not use data for its own purposes

6. Sub-processors

The Processor may use third-party providers (e.g. hosting, email), in compliance with GDPR obligations.

7. Security

The Processor implements appropriate security measures (e.g. encryption, access control).

8. Data Subject Rights

The Processor assists the controller to the extent possible in honouring the rights of data subjects.

9. Data Deletion

Upon termination of the service, data will be deleted or anonymised within a reasonable timeframe.

10. Contact

For general inquiries: contact@invitatianoastra.com For legal notices and GDPR rights: legal@invitatianoastra.com

Back to home
Terms & Conditions — InvitatiaNoastra