Enlázate
Privacy Policy
This privacy policy describes how Enlázate ("the service") handles the personal data of the people who use it: the couples who build their wedding invitation and the guests who RSVP. Enlázate is operated from Spain and complies with the EU General Data Protection Regulation (GDPR, Regulation EU 2016/679) and the Spanish Organic Law 3/2018 (LOPDGDD).
1. Data controller
The service operator runs Enlázate from Spain. For any question about this policy or about your data, write to alvaro.lazaro.g@gmail.com.
Important: for guest data (RSVP responses), the couple who created the invitation is the data controller and Enlázate acts as a data processor, processing that data only to provide the service to the couple. If you are a guest and want to exercise your rights over your response, please contact the couple who invited you first; you may also write to us and we will forward your request.
2. What data we process
- Couple's account: your email address, used for magic-link login (there are no passwords).
- Wedding details: the couple's names, date, venue, texts, day schedule and any other content you add to the invitation.
- Guest responses (RSVP): name, attendance, plus-one, dietary restrictions or other form answers the couple has enabled. Dietary restrictions may reveal sensitive information (e.g. religious beliefs or health); they are processed solely to organise the reception and are visible only to the couple.
- Gallery images: the photos the couple uploads to their invitation.
- Payment data: the payment for publishing the invitation is processed by Stripe. Enlázate does not store card numbers; it only receives confirmation of the payment and its amount from Stripe. If the couple enables the gift section, the payment details they choose to provide (IBAN, Bizum number or PayPal link) are displayed on their invitation to their guests; Enlázate does not process or take part in those payments.
- Technical data: IP address, used transiently for rate limiting and to keep the service secure.
3. Purposes and legal bases
- Providing the service (creating, publishing and managing the invitation and its responses): performance of a contract (Art. 6(1)(b) GDPR).
- Sending transactional emails (login link, RSVP notifications if the couple enables them): performance of a contract. We do not send marketing emails.
- Processing payments through Stripe: performance of a contract and legal obligations (invoicing and accounting, Art. 6(1)(c) GDPR).
- Security and abuse prevention (per-IP limits, anti-spam protection): legitimate interest (Art. 6(1)(f) GDPR).
4. Cookies and analytics
Enlázate only uses strictly necessary technical cookies: a session cookie to keep the couple logged in and, when an invitation is protected by an access code, a cookie remembering that a guest entered the correct code. We use no advertising or tracking cookies.
On our public pages (the main site, the legal pages and the blog) we use first-party analytics with OpenPanel, hosted on our own server (stats.lkd.es): neither the data nor the script goes to any third party. It is cookieless —it identifies visits with a daily hash of the IP and browser, with no persistent identifiers— so this basic, anonymous analytics runs on the basis of our legitimate interest (Art. 6(1)(f) GDPR) without consent; we honour «Do Not Track» and «Global Privacy Control» signals, in which case we load nothing. We do not enable it on the couple dashboard; on guests' invitations we only measure page views anonymously, without cookies and without session replay.
Session replay (recording your browsing, with form fields masked) is more intrusive, so we only enable it with your consent: a notice lets you accept or reject it. Your choice is stored in your browser (local storage) and you can withdraw it by clearing the site's data.
5. Who we share data with
We do not sell personal data. We share data only with the providers needed to run the service, acting as processors or independent controllers as applicable:
- Cloudflare (hosting and infrastructure: Workers, the D1 database and R2 storage for images).
- Stripe (payment processing).
- Google (Gmail) (transactional email delivery over SMTP).
Some of these providers may process data outside the European Economic Area; where they do, transfers rely on Standard Contractual Clauses or other valid GDPR mechanisms.
6. Invitation visibility
Published invitations are private by link: we explicitly ask search engines not to index them, so only people who receive the address can access them. Optionally, the couple can protect the invitation with an access code.
7. Retention
We keep data while the account and the wedding are active. The couple can delete responses, images or the whole wedding from their dashboard at any time. Records linked to payments are kept for as long as Spanish tax and accounting law requires.
8. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to alvaro.lazaro.g@gmail.com. We will reply within one month. You also have the right to lodge a complaint with the Spanish data protection authority, the Agencia Española de Protección de Datos (www.aepd.es).
9. Security
We apply reasonable technical measures: access tokens are stored hashed (SHA-256), sessions use HttpOnly cookies, all traffic is encrypted (HTTPS) and each wedding's data is isolated per account.
10. Changes to this policy
If we change this policy, we will publish the new version on this page with its update date. Substantial changes will be communicated to couples by email.