1. What this document covers
This document describes the processing of personal data in Kruspin accounts, workspaces, projects, RSVPs, guest websites and related modules.
For data the customer enters into a project about its clients, guests, suppliers or team, the customer is typically the controller and Kruspin is the processor. For account, security, support and service operation data, Kruspin may be the controller.
2. Categories of personal data
3. Where data comes from
- From users who register, sign in or manage a workspace.
- From coordinators and customers who import or manually enter guests, clients, suppliers, team members and project data.
- From guests or clients who submit an RSVP or guest form, or use client access.
- From technical operation of the application, such as logs, sign-in cookies, email delivery, files or monitoring.
- From external services when a user uses them, such as a map service for an address, a translation provider, a payment service, Cal.eu for booking or Daily for a video call.
4. Why we process data
- Creating and securing accounts, sign-in and access management.
- Operating the coordinator workspace, project, RSVP, accommodation, seating plan, timeline, tasks, files and supplier modules.
- Sending transactional emails, for example for account verification, sign-in and invitations.
- Publishing the guest website and processing RSVP when the customer enables it or sends the link.
- Managing the commercial relationship, self-service card payments through a payment provider, invoicing and individual payment arrangements.
- Security, abuse prevention, audit, support and bug fixes, including restricted operational monitoring and, when enabled, session recording in the signed-in application.
- Meeting legal, contractual or accounting obligations where they apply.
- Measuring performance, reliability, use and capacity, fixing errors and developing new features. For our own product development, we use restricted operational events, or information that has been aggregated or anonymised so that it cannot reasonably identify a person, customer, workspace or specific event.
- User-initiated AI and automation features, such as translations, text suggestions, summaries, search or import cleanup. Only the input needed for the selected operation is transmitted; the entire workspace is not sent automatically.
- Kruspin does not use identifiable Customer Content to train models or create reusable evaluation datasets. For development, it may use genuinely anonymised or aggregated information that no longer permits identification of a person, customer, workspace or event. Any future voluntary data-contribution programme would be separate, off by default and subject to its own terms and legal basis.
- To check delivery, we record the recipient, notification type, send attempts and outcomes from Resend. Ordinary email notifications measure image loading and link requests; mail clients and security scanners can also produce these signals. Authentication emails, invitations and guest e-cards do not use this engagement tracking. For push notifications, we distinguish display receipts, clicks and viewing the source message in the app. Only authorized Kruspin administrators can access this operational report.
5. Legal bases
For account, access, support, billing and security data, processing may rely mainly on contract performance or steps before entering into a contract, legitimate interest in secure and functional service operation, legal obligations and consent where a specific feature is consent-based.
For project data about clients, guests, suppliers and other people entered by the customer, the customer typically determines the legal basis as controller. Kruspin processes this data as processor under the contract, documented instructions and service operation needs.
Security, error detection, technical support and restricted operational monitoring may rely on the legitimate interest in a secure and functional product, after assessing necessity and the impact on individuals. This does not replace consent where cookie rules require it for storing or accessing data on a device, nor does it authorise the use of customer data outside the contract and documented instructions.
We use consent only where a specific feature genuinely requires it, for example optional public website analytics. Consent may be withdrawn without affecting the lawfulness of processing carried out before withdrawal. Accepting the Terms or acknowledging this document is not consent to every processing purpose.
6. Private data vs. shared content
Private project data is not intended for the public. Access is governed by the role in the workspace or project.
Public or shared content exists only when the customer publishes the guest website, sends an RSVP link, invites a client or exports and shares data outside the application. Such content may include selected information about the wedding/event, programme, address, contacts, accommodation or RSVP.
7. Recipients and processors
External services are listed in the Data Processing Agreement. We use PostHog for error and operational monitoring and, when enabled, session recording in the signed-in application. The recording masks text, inputs and attributes, but it may be linked to the internal user ID, name, email and workspace, and is therefore not anonymous. We use Google Analytics on the public website only after consent. We do not sell personal data or provide it to advertising networks.
We engage external AI services only for a feature initiated by the User and transmit only the necessary input. Kruspin does not instruct them to use identifiable Customer Content for model training; the specific provider and scope are listed in the Data Processing Agreement.
If you connect Canva, Kruspin processes Canva account and team identifiers, granted permissions, encrypted access and refresh tokens, design metadata and previews, and exported images to browse designs and import or update their content. Preparing an import exports all pages of the selected design so you can choose which pages to insert. Imported images remain part of the project after disconnecting. Disconnecting removes active tokens; an encrypted token may temporarily remain in a queue for retrying access revocation. You can request broader deletion at [email protected].
8. Retention, export and deletion
We retain project data while the service is used or as agreed with the Customer. We retain account, contractual, accounting, security, audit, support and monitoring records for as long as required by law or appropriate to their purpose, risk and the relevant provider's settings; not every category has a fixed automated period in the current product.
Export, correction or deletion may be requested through support; complete self-service export and account deletion are not yet available everywhere. After deletion from operational systems, copies may remain in backups, logs, audit records or statutory records for the relevant technical or legal reason. Selected object backups may be protected from modification or deletion for 180 days; expiry of that protection does not itself mean that the object is automatically deleted.
An unfinished standalone RSVP form remains in the browser's local storage without automatic expiry; it is removed after completion and can be deleted by clearing the site's data. Retention by PostHog, Cal.eu and Daily is also governed by the current settings of their services. Kruspin does not record Daily video calls.
In the notification ledger, we delete email address snapshots after 90 days, individual events after 180 days and delivery metadata after 365 days. Deletion runs in scheduled batches. Unfinished or recently retried deliveries may remain longer. This ledger does not store message content, access tokens or visited links. Recipient identifiers and fingerprints are pseudonymous data; retention in Resend and backups follows separate settings.
9. Rights of individuals
- An account user may request access to, correction, restriction, deletion or portability of their account data.
- A guest, client or supplier should first contact the planner or organisation that entered their data into the project. That organisation is usually the controller for project data.
- If a request comes directly to the processor, Kruspin will help identify the relevant customer-controller or forward the request where possible and contractually appropriate.
- Requests are usually answered without undue delay and at the latest within one month; complex or numerous requests may be extended under GDPR.
- If a request concerns the operation of Kruspin, support can be contacted at [email protected].
- The data subject also has the right to lodge a complaint with the Czech Office for Personal Data Protection.
- We respond to legal requests under GDPR and according to Kruspin's role as controller or processor.
- Where processing is based on legitimate interests, the individual may object. Where consent is the legal basis, it may be withdrawn at any time.
- Users have the right to know whether providing data is a contractual or statutory requirement and the possible consequences of not providing it; an account cannot be created securely without the required email address and verification.
10. Security
We use access roles, sign-in cookies, server checks, database access controls and separate environments. Files are stored in object storage.
No service can guarantee absolute security. Kruspin uses appropriate technical and organisational measures based on the nature of the data and operation of the service.