Privacy Policy
v2.0·
1. Introduction
This Privacy Policy explains how the personal data of Davetin.app ("Service" or "Platform") users is collected, used, shared, and protected by Bosvara OÜ ("Davetin", "we", "us"). Bosvara OÜ is a company incorporated in Estonia and operates as a data controller under the European Union General Data Protection Regulation ("GDPR").
This Policy applies to Account Holders (B2C users and B2B agency users, team members, and client accounts who open an account on Davetin). The applicable regime for Guest Data uploaded by Account Holders is explained separately in Section 3 below.
2. Data Controller Information
Data Controller: Bosvara OÜ
Address: Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551, Estonia
Contact: info@davetin.app
3. Data Controller / Data Processor Distinction
Davetin acts in two different roles regarding personal data:
3.1 Regarding Account Holder Data — Davetin is the "Data Controller"
Davetin is the Data Controller concerning your (as the Account Holder) first name, last name, email address, password (hashed), billing information, and Service usage data. Sections 4-9 of this Policy apply to this data.
3.2 Regarding Guest Data — Davetin is the "Data Processor"
Regarding the first name, phone number, email address, RSVP status, dietary preferences, and plus-one information ("Guest Data") belonging to your Guests that you upload to the platform for your events, you (the Account Holder) are the Data Controller, and Davetin is solely the Data Processor. Davetin processes Guest Data exclusively in accordance with your instructions to provide the technical infrastructure of the Service (storage, transmission, RSVP recording, etc.); it does not process this data for its own marketing or other purposes.
It is the responsibility of the relevant Account Holder (Data Controller) to fulfill data subject rights requests (access, deletion, etc.) from Guests. Davetin provides technical tools to Account Holders to fulfill these requests and provides support in case of reasonable requests.
4. Information We Collect (Account Holder Data)
a) Information You Provide Directly:
• First name, last name
• Email address
• Password (stored only in hashed/encrypted form)
• Billing information (processed via Stripe; full card numbers are not stored by us)
• For B2B users: company/agency name, team member information
b) Information Collected Automatically:
• Device information (browser type, operating system, IP address)
• Usage analytics (which features are used, session durations)
• Cookies (see Cookie Policy for details)
c) Event Data:
• Details of the events you create (date, venue, invitation design, descriptions)
• Media content you upload (photos, videos)
5. Purposes and Legal Bases for Using Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Account creation and provision of the Service | Performance of a contract (Article 6(1)(b)) |
| Processing payment transactions | Performance of a contract (Article 6(1)(b)) |
| Transactional notifications (RSVP alerts, invoices, account security) | Performance of a contract (Article 6(1)(b)) |
| Service improvement, analytics | Legitimate interests (Article 6(1)(f)) |
| Marketing emails (optional) | Explicit consent (Article 6(1)(a)) |
| Compliance with legal obligations (tax, accounting records) | Legal obligation (Article 6(1)(c)) |
| Prevention of fraud and abuse | Legitimate interests (Article 6(1)(f)) |
6. Data Sharing and Third-Party Processors
We do not sell your personal data. Your data is only shared with the following categories of third parties to the extent necessary to provide the Service:
• Stripe (payment processing — Account Holder billing data)
• AWS (cloud hosting — EU servers, all data categories)
• Resend / AWS SES and other email providers (email delivery)
• SMS gateways and WhatsApp Business API (Guest Data delivery — only upon Account Holder's instruction)
• Legal authorities (in case of a court order or legal obligation)
• In the event of a merger, acquisition, or sale of assets (users will be notified in advance)
Data Processing Agreements ("DPAs") in accordance with GDPR Article 28 have been executed with all third-party data processors.
7. International Data Transfers
Bosvara OÜ is a company incorporated in Estonia, a member state of the European Union. Your data is processed and stored on cloud servers located within the EU (AWS eu-central-1 and/or relevant EU regions).
Since the Service is offered to users in Turkey and worldwide, data of users outside the EU is transferred to the EU. These transfers from outside the EU to the EU constitute a standard data flow within the EU and do not require an additional transfer mechanism.
In exceptional cases where data must be transferred outside the European Economic Area (for instance, due to the infrastructure of a specific WhatsApp/SMS provider), Davetin implements Standard Contractual Clauses ("SCCs") or other appropriate safeguards recognized by the GDPR.
8. Data Retention Periods
• Account Data: Retained as long as your account is active. When you close your account, it is deleted, except for legal retention obligations (e.g., up to 10 years for accounting regulations regarding invoice records).
• Event Data: Archived in your account after the event is completed and remains accessible to you; it is retained unless you delete it or close your account.
• Guest Data: Automatically deleted or anonymized within 90 days from the event date, unless you request early deletion. Account Holders may manually delete Guest Data prior to this period.
• Account Deletion Request: When you delete your account, all User Content and Guest Data associated with your account will be permanently deleted within 30 days, subject to the legal exceptions mentioned above.
9. Data Subject Rights (GDPR Articles 15-22)
All Account Holders, whether located inside or outside the EU, possess the following rights regarding their personal data:
• Right of access: To learn what data of yours is being processed,
• Right to rectification: To request correction of incorrect or incomplete data,
• Right to erasure ("right to be forgotten"): To request the deletion of your data,
• Right to restriction of processing,
• Right to data portability: To receive your data in a structured, machine-readable format,
• Right to object: To object to processing based on legitimate interests,
• Right to withdraw consent: For consent-based processing (e.g., marketing emails).
To exercise these rights, you may use the relevant tools in your account settings or contact us at info@davetin.app. We will respond to your request within 30 days at the latest.
Additionally, you have the right to lodge a complaint with the competent data protection authority in the country where you reside or work (for the EU, the relevant national Data Protection Authority; for Estonia, the Andmekaitse Inspektsioon).
10. Data Security
To protect your data, we implement industry-standard technical and organizational measures, such as encryption of data at rest and in transit, access controls, regular security audits, and the principle of least privilege for staff. However, no system is 100% secure; in the event of a data breach, we will notify the competent authorities and affected users without undue delay, in accordance with applicable legislation.
11. Children's Privacy
The Service is not intended for individuals under the age of 18, and we do not knowingly collect data from such individuals. If we become aware that an individual under 18 has provided us with data, we will delete this data immediately.
12. Policy Changes
We may update this Privacy Policy from time to time. In the event of material changes, the "Last Updated" date will be revised, and we will notify you via email or through the Platform.
13. Contact
For privacy-related questions: info@davetin.app
Bosvara OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551