Privacy Policy
Last updated: July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation
(GDPR) is:
giant Computer Systems, Marc Breuer
Am Altengraben 23
90768 Fürth
Germany
Phone: +49 (0) 911 976912-0
Email: [email protected]
2. General information
The protection of your personal data is important to us. We process your data exclusively on the basis of the statutory provisions (GDPR, German Federal Data Protection Act, TDDDG). wedoro is a wedding planning platform: wedding planners and couples use it to organise their wedding (including guest list, RSVPs, budget, seating plan, tasks and photos) and can publish a public wedding website on their own subdomain. In this privacy policy we inform you about the most important aspects of data processing within this platform.
3. Your rights
You generally have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
- Right to withdraw a given consent (Art. 7 (3) GDPR)
If you believe that the processing of your data violates data protection law or that your data protection rights have otherwise been infringed, you may lodge a complaint with the competent supervisory authority (Art. 77 GDPR).
4. Hosting and storage
Our platform is operated on servers located in Germany. All personal data collected on the platform and all uploaded files (e.g. photos) are stored there. Where service providers are involved, data processing agreements pursuant to Art. 28 GDPR are in place. The legal basis is our legitimate interest in the secure and efficient provision of our offer (Art. 6 (1) (f) GDPR).
5. SSL / TLS encryption
For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://".
6. Server log files
The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: browser type and version, operating system used, referrer URL, host name of the accessing computer, time of the server request and the IP address. This data is not merged with other data sources. The collection is carried out on the basis of Art. 6 (1) (f) GDPR for the technically error-free presentation and optimisation of the website and to ensure system security. Server log files are deleted automatically once they are more than 90 days old. They are kept for longer only where this is necessary to investigate a specific security incident; in that case the data concerned is retained until the investigation has been concluded.
7. Cookies
We use only technically necessary cookies that are required for the operation of the platform (e.g. session cookie, CSRF protection, storage of the chosen language, and the unlocking of password-protected wedding websites). These cookies contain no advertising or tracking functions. The legal basis is § 25 (2) TDDDG and Art. 6 (1) (f) GDPR.
8. Registration and accounts
When you create an account as a wedding planner or as a couple, we process the data you provide (name, email address, password in encrypted form, optionally billing and company details) to provide the account and to perform the contractual relationship. The legal basis is Art. 6 (1) (b) GDPR (performance of a contract). The data is deleted as soon as the account is closed and no statutory retention obligations conflict with this.
9. Wedding projects and guest data
The core of our service is organising weddings. Planners and couples enter data into their projects that may also contain personal data of third parties – in particular guest data (e.g. names, contact details, dietary preferences and intolerances, seating arrangements) as well as photos. We process this data on behalf of the respective users (Art. 28 GDPR); the users who enter this content are the party responsible for it under data protection law. Please only enter data you are entitled to process.
10. RSVPs, wedding websites and gift registry
Guests can submit their response to a wedding via a personal link (e.g. acceptance or decline, accompanying persons, menu choice, intolerances, message). This information is processed solely to organise the respective wedding and is visible only to the couple and their wedding planner (Art. 6 (1) (b) and (f) GDPR). Couples can also publish a public wedding website on their own subdomain; the respective couple is responsible for its content, and every wedding website has its own privacy notice. When reserving gifts via the registry of a wedding website, the data provided (name, optionally an email address) is processed to handle the reservation.
11. Emails
The platform sends emails, e.g. invitation and reminder emails to guests on behalf of the couple or planner, as well as notifications about accounts, projects and billing to registered users. The legal basis is Art. 6 (1) (b) and (f) GDPR.
12. Push notifications
Registered users can optionally enable browser push notifications. For this purpose, a delivery endpoint provided by the browser is stored; delivery takes place via the push service of the respective browser vendor. The legal basis is your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time in the settings.
13. Payment processing (Stripe)
For paid plans and licences we offer payment via the payment service provider Stripe and – where offered – by bank transfer. When paying via Stripe, the data required for processing is transmitted to Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe's privacy policy applies. When paying by bank transfer, we process the information required to allocate the payment. The legal basis is Art. 6 (1) (b) GDPR. Tax and commercial retention periods remain unaffected.
14. Fonts and external services
All fonts and other resources of this platform and of the wedding websites are loaded locally from our servers. When pages are called up, no connections to third-party providers (e.g. Google Fonts or analytics services) are established.
15. Storage period and deletion
We store personal data only for as long as is necessary for the respective purposes. Wedding projects including guest data, photos and the wedding website are kept available for the duration of active use and are deleted after the end of the contract or upon deletion, subject to statutory retention obligations.
16. Changes to this privacy policy
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or in order to implement changes to our services. The new privacy policy will then apply to your next visit.