TermsPrivacyData processingCookies

Data Processing Agreement

Data Processing Agreement.

Version
2026-07-18
Effective from
July 18, 2026

A binding addendum to the Terms for customers that process personal data about clients, guests, suppliers or team members in Kruspin.

The Czech version of this Agreement is controlling. Translations are provided to aid understanding; if there is a conflict, the Czech version prevails.

Contents

  1. 1. Agreement and roles of the parties
  2. 2. Subject matter, duration, nature and purpose
  3. 3. Data subjects and categories of data
  4. 4. Customer instructions and obligations
  5. 5. Operator obligations as processor
  6. 6. Subprocessors and external services
  7. 7. International data transfers
  8. 8. Technical and organisational measures
  9. 9. Data-subject rights, incidents and assistance
  10. 10. Return, deletion, audit and order of precedence
Operator details
Company
Necktip s.r.o.
Registered office
Hořejší 59, 252 26 Třebotov
Company ID
17420211
VAT number
CZ17420211
Commercial Register
Commercial Register maintained by the Municipal Court in Prague, Section C, File No. 371468
Date of registration
12 August 2022
Contact
[email protected]

1. Agreement and roles of the parties

This Data Processing Agreement forms part of the Terms and Conditions and applies whenever the customer, as a controller or processor, uses Kruspin to process another person's personal data. By accepting the Terms and Conditions, the customer enters into this Agreement with Necktip s.r.o.

For data that the customer enters into a workspace or event about its clients, guests, suppliers, team members and other participants, the customer is typically the controller and Necktip s.r.o., the company operating Kruspin, is the processor. If the customer is itself a processor for its client, it confirms that it is authorised to engage Kruspin as a subprocessor.

Necktip s.r.o. may be an independent controller for data needed for its own account administration, sign-in, billing, security, abuse prevention, legal communications and its own operational monitoring. To the extent that monitoring or session recording processes customer data solely to provide, secure or support the service under the customer's instructions, this Agreement applies. A masked recording may still contain personal data.

2. Subject matter, duration, nature and purpose

The subject matter is the processing of personal data necessary to operate workspaces, events, RSVPs, guest websites, accommodation, seating plans, timelines, tasks, files, suppliers, working financial overviews, communications, client-facing and operational outputs, and support.

Processing continues for the duration of the customer account or agreed service and for the period necessary to return or delete the data. The nature of the processing includes storage, structuring, retrieval, display, transmission, backup, export, correction, restriction and deletion in accordance with the service features and the customer's instructions.

The purpose is to provide and secure the selected Kruspin function and carry out the customer's documented instruction. Identifiable Customer Content is not used to train models or create reusable evaluation datasets. Any future voluntary data-contribution programme would be separate, off by default and require its own terms and legal basis. The operator may use genuinely anonymised and aggregated information under the Terms and Conditions.

3. Data subjects and categories of data

3. Data subjects and categories of data
AreaExamples
Data subjectsCustomers and their users, clients and couples, guests and households, children and plus-ones, suppliers, venue staff, external collaborators and other event participants.
Identification and contact dataName, email, phone number, address, language, role, organisation, membership, invitations and technical access identifiers.
Event and logisticsRSVPs, households and relationships, programme, tasks, accommodation, transport, seating plans, menus, suppliers, forms, comments, files and photographs.
Higher-sensitivity dataAllergies, dietary requirements, health or accessibility needs, data about children, private family notes and other data entered by the customer. This data must be minimised and restricted to the people for whom access is necessary.
Commercial and financial dataSupplier contacts, prices, deposits, payments, billing data, internal costs, margins, and contractual and negotiation notes.
Technical and audit dataTimes, changes, access, IP addresses or derived security signals, device and browser data, email delivery, error and audit records, PostHog identifiers and operational events. When session recording is enabled, this also includes the internal user and workspace IDs, name, email and a masked recording of interactions.

4. Customer instructions and obligations

  • The customer is responsible for the lawfulness of its instructions, the legal basis, obligations to provide information, data accuracy and the authorisation of people it invites to the service.
  • Feature settings, imports, publication, sharing, export, deletion and a request submitted by an authorised person of the customer are documented instructions within the scope of this Agreement and the Terms.
  • The customer must minimise allergies, health and accessibility needs, data about children, family notes and other sensitive data and enter it only where necessary for a specific purpose.
  • The customer must configure roles, permissions, public pages, RSVP links and exports so that data is visible only to the intended recipients.
  • The customer must not instruct the operator to carry out unlawful processing. If the operator reasonably considers an instruction to infringe data protection law, it will inform the customer and may suspend the instruction until the matter is clarified.
  • If the customer processes data on behalf of another controller, it must obtain the necessary authorisation to engage Kruspin and pass on any stricter instructions that apply to the processing.

5. Operator obligations as processor

  • Process personal data only in accordance with this Agreement, the service settings and the customer's other documented instructions, unless processing is required by EU or Member State law; in that case, inform the customer in advance unless the law prohibits this.
  • Ensure that people authorised to process the data are bound by confidentiality and have access only to the extent required by their role.
  • Adopt and maintain the appropriate technical and organisational measures set out below and adapt them to the risk, the state of the art and the nature of the service.
  • Engage subprocessors only in accordance with this Agreement and impose substantially the same personal data protection obligations on them.
  • Taking into account the nature of the processing, reasonably assist the customer with data-subject requests, security, incidents, data protection impact assessments and consultation with a supervisory authority.
  • At the end of the service, return or delete all customer personal data and existing copies at the customer's choice unless continued retention is required by EU or Czech law.
  • Provide the information needed to demonstrate compliance with Article 28 GDPR and permit a reasonable audit subject to the terms below.
  • Inform the customer without undue delay if the operator becomes aware of a personal data breach affecting data processed on the customer's behalf.

6. Subprocessors and external services

The customer grants general written authorisation to engage the subprocessors listed below for the purposes described. Depending on the specific function, some services also act as independent controllers; their own terms are presented when the service is used or on the hosted page.

The operator will give at least 15 days' notice through the account or by email of an intended addition or replacement of a subprocessor that will materially process customer personal data, unless an urgent security or legal need requires a shorter period. The customer may raise a reasoned data-protection objection within 10 days. If the objection cannot reasonably be resolved, the parties may disable the affected optional feature or stop using it.

The operator will impose substantially the same data protection obligations on each subprocessor and remains responsible to the customer for the subprocessor's performance of its obligations to the extent required by GDPR.

6. Subprocessors and external services
ServiceWhen it is usedPurpose and scope
Railway / PostgreSQLCore production infrastructureApplication hosting, database, network traffic and operational infrastructure for account data and customer data.
S3-compatible object storage, including Cloudflare R2 where configuredWhen storing files, photographs, backups or support attachmentsObject storage of customer files, galleries, images, exports, locked backups and any support screenshots.
ResendWhen email delivery is enabledVerification, one-time codes, resets, invitations, comments, guest messages, forms, support and other user-initiated emails; processes the recipient, subject, content, delivery status and any attachment.
Google Maps / Places / FontsWhen a map, address completion or a configured font on a public page is loadedFor maps, address and place search, completion and verification; the search text, place identifier and technical data are sent to the provider. When a font is loaded, Google may receive the IP address and technical browser data.
Vercel AI Gateway and the configured model provider, currently OpenAIOnly when AI translation or another enabled AI feature is startedPerforms the User-initiated operation on the necessary input, for example translation, a text suggestion, a summary or import cleanup. The entire workspace is not sent automatically, and Kruspin does not instruct the provider to use identifiable Customer Content for model training.
Quiver AIOnly when SVG generation is startedProcesses the text prompt, visual instructions and technical parameters to create an SVG. The feature must not receive guests' personal data or non-public project content.
PostHogFor error and operational monitoring; session recording when enabled in the signed-in applicationError and operational events and technical identifiers. Session recording masks text, inputs and attributes and excludes console data, request headers and bodies, heatmaps and cross-origin iframes, but may be linked to the internal user ID, name, email and workspace.
Google AnalyticsOnly on the public website after visitor consentPseudonymous measurement of visits and primary actions on allowlisted public pages with advertising storage disabled. It is not used on non-public project, RSVP or shared tokenised pages.
StripeFor an online payment, storing a payment method or opening the payment portalPayment and billing identifiers, amount, currency, payment status and technical data. Card details are entered by the user directly in Stripe's environment.
iÚčtoWhen invoicing and the accounting transfer are enabledCustomer identity and address, IČO/DIČ, invoice, line items, amounts, VAT, payment reference and payment status for issuing and recording accounting documents.
PinterestOnly when the user connects Pinterest and selects contentOAuth access, profile, selected boards and pins, images and metadata needed to import inspiration. Access tokens are stored encrypted.
Cal.euWhen the user opens the hosted link to book an introductory callBooking data entered by the user directly on Cal.eu, such as name, email, language, time slot and a note. Kruspin does not copy the booking through an API or track its status.
DailyOnly when an instant video call is startedPrivate room, display name, audio, video, screen sharing and technical connection data. Kruspin does not record the call or store short-lived access tokens for the meeting.
PushoverOnly when the instant introductory call is enabledAn internal notification to the operator containing the call language and a link to an internal detail page. It does not send the caller's name or email and is not loaded in the caller's browser.
Upstash RedisOnly when shared request rate limiting is enabledShort-lived technical keys and counters derived from the request to protect sign-in, forms and APIs against abuse.
Cloudflare Custom Hostnames / edge servicesWhen connecting a custom domain or serving the public website at the network edgeDomain, DNS and TLS status, target hostname and technical request data needed to route and secure public pages.
WEDOSWhen checking, registering or managing DNS for a domain through KruspinDomain name, availability, technical and registration identifiers, and the registration contact of Necktip s.r.o. as the domain registrant.
CanvaOnly when the user connects Canva and uses the integrationAccount and team identifiers, granted permissions, design metadata and previews, and exported pages for browsing, importing and updating content. OAuth access and refresh tokens are stored encrypted; imported images are stored in Kruspin.

7. International data transfers

The operator selects a European region or European endpoints where available. Some providers may nevertheless use global infrastructure or permit support access from outside the EU/EEA.

If personal data is transferred to a country without an adequacy decision, the operator will use an applicable mechanism under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, and supplementary measures according to the risk. Information about the current mechanism for a specific provider will be supplied to the customer on request.

The customer instructs transfers to the extent necessary for the feature it has enabled and the approved providers listed above. This does not restrict the customer's right to object to a new subprocessor.

8. Technical and organisational measures

  • Sign-in using a verified email address and short-lived one-time codes, secure HTTP-only sessions and server-side identity checks.
  • Roles, memberships, permissions and separate outputs for client and public views that restrict access by workspace, event and output purpose.
  • Encrypted transmission using HTTPS/TLS; encryption of stored data according to the capabilities and configuration of the database and object-storage providers; encrypted storage of selected integration tokens.
  • Separation of production and development environments, server secrets kept out of the client, restricted support and administrator access, and auditing of security-significant actions.
  • Input validation, same-origin protection, request rate limiting, short-lived tokens, session revocation and protection against common web application abuse.
  • Minimisation of logs, analytics, monitoring and support artefacts; masking of text, inputs and attributes in session recordings and exclusion of console data, request headers and bodies, heatmaps and cross-origin iframes. The recording may nevertheless remain identifiable personal data.
  • Backup and recovery procedures appropriate to the infrastructure provided, controlled database changes and restrictions on destructive production operations.
  • A process to classify, contain, remediate and document security incidents and inform affected customers.
  • Regular reassessment of the measures according to the nature of the data, the state of the art, costs and risk. No system can guarantee absolute security.

9. Data-subject rights, incidents and assistance

If the operator receives a request from an individual concerning customer personal data, it will not respond substantively without the customer's instructions unless required by law. It will forward the request to the customer or help identify the relevant controller and, where possible, provide the tools or information needed to respond.

In the event of a personal data breach, the operator will inform the customer without undue delay after becoming aware of it. Based on the information available, it will describe the nature of the incident, the categories affected, the likely consequences, the measures taken or proposed, and a contact for further assistance. The notice itself is not an admission of liability.

Taking into account the nature of the processing and the information available to it, the operator will reasonably assist with data protection impact assessments, prior consultations, security, notification duties and demonstrating compliance. Exceptional assistance beyond the ordinary scope of the service may be charged for unless the need was caused by the operator's breach of this Agreement.

10. Return, deletion, audit and order of precedence

At the end of the service, the operator will, at the customer's choice, return customer personal data in a reasonably available format or delete it unless continued retention is required by law. Export and deletion are currently handled through support; complete self-service export and account deletion are not available for all accounts.

After deletion from operational systems, copies may remain only in isolated technical backups for the time needed to complete a documented deletion cycle, no longer than 180 days, or where retention is required by EU or Czech law. During that period they are not used for ordinary operations; the Operator deletes them when the applicable period ends. Monitoring data processed on the customer's behalf is subject to the same rule; data for which Necktip s.r.o. is an independent controller is governed by the Privacy Notice.

The customer may request information reasonably necessary to verify this Agreement no more than once a year and also after a serious incident. If the materials are insufficient, the customer may, on at least 30 days' notice, conduct an audit itself or through an independent professional bound by confidentiality, during business hours and without access to other customers' data. This notice period does not apply where a shorter procedure is necessary because of an urgent incident or a supervisory authority's request. The customer bears the reasonable costs of the audit unless it demonstrates a material breach by the operator.

If documents conflict, this Agreement prevails for the processing of personal data on behalf of the customer; the Terms and Conditions prevail on other matters. A stricter individual written agreement prevails to the extent that it expressly varies this Agreement.

Questions, instructions, objections to a new subprocessor and requests for assistance should be sent to [email protected].

A workspace for planning weddings and events. The legal texts describe the current operation of the service.

Operator: Necktip s.r.o., Company ID 17420211, VAT number CZ17420211.

TermsPrivacyData processingCookies