Privacy Policy
Last updated: July 13, 2026
EnQube SMPC ("Company", "we", "us"), a company incorporated in Greece with its registered office in Patras, Greece, operates the Agapaé platform (the "Platform"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our Platform, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Greek data protection law.
1. Data Controller
The data controller for the personal data processed through the Platform is:
- Company: EnQube SMPC
- Registered office: Patras, Greece
- Email: privacy@agapae.gr
For processing where a Couple (Event Owner) determines the purposes and means of processing Guest data, the Couple acts as the data controller and EnQube SMPC acts as the data processor. See Section 6 for further details.
2. Data We Collect
We collect the following categories of personal data:
Account Data
When you create an account as a Couple, we collect your email address and password (stored as a cryptographic hash, never in plain text). We also collect your event name and date to set up your event.
Event Data
Information you provide about your wedding or event, including: partner names (first and last), phone numbers, event date and location, venue and church details (including map links), wedding schedule (times, titles, descriptions), love story narratives, family member names, best men and maids of honour, and gift preferences (including IBAN, account holder name, and gift registry URL if provided).
Guest Data
When Guests join an event, we collect their display name and, if required by the Couple, their email address. Each Guest is assigned an opaque per-event identifier (for example, "guest-" followed by a random string), which lets us attribute uploads without exposing real identities to other users. We also record when they joined the event.
Guest List Data (entered by the Couple)
Couples may build a guest list within the Platform. For each invited Guest, the Couple may enter contact details (name, email, phone), party composition, RSVP status, and, optionally, dietary requirements (for example, vegetarian, gluten-free) and accessibility or special-assistance notes — purely to help the Couple coordinate catering and hospitality. The Couple is the data controller for this information; we process it on the Couple's behalf as a data processor (see Section 6 and Section 7).
Couples on eligible plans may also arrange Guests into seating tables for the reception and, optionally, enable a guest-facing seat lookup that lets a Guest find their own table — and, where the Couple permits, see who else is seated with them. These seating arrangements form part of the Guest List Data above and follow the same controller/processor roles and retention rules.
Media Data
Photographs and videos uploaded by Couples or Guests, along with associated metadata including original filename, file size, content type (MIME), image dimensions, video duration, and processing status.
Financial Data
For paid Service Plans, we store your Stripe customer ID, subscription ID, payment intent ID, plan type, subscription status, and payment dates. We do not store your payment card details — all card processing is handled directly by Stripe, a PCI-DSS compliant payment processor.
Communication Data
If you use our contact form, we collect your first name, last name, email address, subject, and message content. If you subscribe to our newsletter, we collect your email address.
Technical Data
We collect IP addresses as part of our audit logging system, which records upload activities, storage quota events, and media deletions. We also collect standard server logs necessary for security and service operation.
AI Assistant Data
On eligible plans (Heirloom), Couples may use Éros, our optional AI planning assistant. When you interact with Éros, we process the messages you send it, together with the Event Data and Guest List Data it needs to respond — for example your guest list, tasks, vendors, payments, budget, seating arrangements, schedule, and invitation details — solely to generate the assistant's responses within your own event. See Section 5 for the AI providers involved.
3. Legal Bases for Processing
We process your personal data on the following legal bases under Article 6 of the GDPR:
Performance of Contract (Art. 6(1)(b))
We process Account Data, Event Data, Guest Data, and Media Data as necessary to perform our contract with you — namely, to provide the Agapaé service, manage your event, host your media, and deliver the features of your Service Plan.
Legitimate Interest (Art. 6(1)(f))
We process Technical Data (IP addresses and audit logs) for security monitoring, fraud prevention, abuse detection, and service integrity. We also use aggregated, non-identifiable data to improve our service. Our legitimate interests do not override your fundamental rights and freedoms.
Consent (Art. 6(1)(a))
We process your email address for newsletter communications based on your explicit consent, obtained through our double opt-in process. You may withdraw consent at any time. Where applicable, we obtain consent for non-essential cookies as described in our Cookie Policy.
Legal Obligation (Art. 6(1)(c))
We may process Financial Data to comply with tax, accounting, and regulatory obligations under Greek and EU law.
4. How We Use Your Data
We use your personal data for the following specific purposes:
- To create and manage your account and authenticate your access;
- To provide and maintain the wedding event management service;
- To host, process, and deliver your photographs and videos (including generating thumbnails and transcoding videos);
- To enable Guests to view event information and contribute media;
- To process payments and manage your Service Plan;
- To send transactional emails (account verification, password resets, payment confirmations);
- To send newsletter communications (with your consent);
- To respond to your contact form enquiries;
- To provide the optional AI planning assistant (Éros) on eligible plans;
- To monitor and ensure the security and integrity of our service;
- To comply with legal obligations.
The Éros AI assistant provides suggestions that you choose whether to act on; it does not carry out automated decision-making that produces legal or similarly significant effects concerning any individual within the meaning of Article 22 GDPR, nor profiling. We do not sell your personal data to third parties.
5. Data Sharing and Third-Party Processors
We share your personal data with the following third-party service providers (sub-processors), each of whom processes data on our behalf and under our instructions:
| Service Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe | Payment processing | Email, event ID, plan details | USA (EU SCCs / Data Privacy Framework) |
| Amazon Web Services (S3) | Media file storage | Photos, videos, thumbnails | EU (Frankfurt, eu-central-1) |
| Amazon Web Services (MediaConvert, Lambda) | Video transcoding and image processing | Video and image files | EU (Frankfurt, eu-central-1) |
| MongoDB Atlas | Database hosting | All application data | EU |
| Resend | Transactional email delivery | Email addresses, email content | USA (EU SCCs / Data Privacy Framework) |
| Google Cloud Run | API hosting | Request data in transit | EU (Belgium, europe-west1) |
| Google Fonts | Font delivery | IP address (standard web request) | Global CDN |
| Sentry (Functional Software, Inc.) | Application error monitoring | IP address, error context, authenticated user ID and email when signed in | USA (EU SCCs) |
| Cloudflare Turnstile | Bot protection on signup, RSVP, and contact forms | IP address, browser fingerprint signals | Global CDN (EU SCCs) |
| Anthropic, PBC (Claude) | AI planning-assistant responses (Heirloom) | Event and planning data you submit to the assistant | USA (EU SCCs) |
| Google (Gemini API / Google AI Studio) | AI planning-assistant responses (Heirloom) | Event and planning data you submit to the assistant | USA (EU SCCs / Data Privacy Framework) |
We require all sub-processors to implement appropriate technical and organisational measures to protect your data, in accordance with Article 28 of the GDPR. Our use of each sub-processor is governed by their respective data processing terms.
The AI providers listed above (Anthropic and Google) process the data you submit to the assistant solely to generate its responses. Under the data processing terms applicable to their business and API services, they do not use this data to train their models, and we maintain data processing terms with each of them.
We do not share your personal data with any other third parties except where required by law or with your explicit consent.
6. Guest Privacy and Data Roles
Our Platform has a unique data relationship structure that we want to explain clearly.
When the Couple is the Controller
When a Couple inputs personal data about their Guests (such as names and email addresses), the Couple acts as the data controller for that Guest data. The Couple determines why and how that data is processed. EnQube SMPC acts as the data processor, processing Guest data solely to provide the Service on the Couple's behalf.
When EnQube SMPC is the Controller
For Guest data that we collect directly — such as when a Guest joins an event and provides their display name and email, or uploads media — EnQube SMPC acts as the data controller.
Guest Rights
Guests, whether or not they hold registered accounts, have the same data protection rights as any data subject under the GDPR (see Section 10). Guests may exercise their rights by contacting us at privacy@agapae.gr, or by contacting the Couple who invited them where the Couple is the controller.
Guests may upload Content to an event's shared gallery. This Content is subject to the same storage, retention, and deletion policies as all Event Data.
7. Special Category Data
The Platform is designed to minimise the collection of special categories of personal data as defined in Article 9 of the GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation).
Dietary Requirements and Special-Assistance Notes
Couples may, at their discretion, enter dietary requirements (for example, vegetarian, gluten-free, halal, kosher) and special-assistance or accessibility notes for individual Guests in their guest list. Some of this information may indirectly reveal religious belief or health condition and therefore qualifies as special category data under Article 9 GDPR.
For this category of data, the Couple acts as the data controller and EnQube SMPC acts as the data processor (see Section 6). The Couple is responsible for obtaining the Guest's explicit consent (Art. 9(2)(a) GDPR) where required by law before entering such information into the Platform. We process this data solely to display it to the Couple and their authorised collaborators for the purpose of coordinating catering and hospitality at the event. We do not use it for any other purpose.
Where a Guest's dietary or special-assistance notes form part of the information the Éros AI assistant reads to answer a Couple's request, that data may be transmitted to the AI providers identified in Section 5, under the same controller/processor roles and the same limited terms — solely to generate the requested response, and never to train any model.
Guests may at any time request the correction or deletion of dietary or special-assistance notes about them, either by contacting the Couple directly or by writing to us at privacy@agapae.gr (see Section 10).
If future features of the Platform require the direct collection of any other special category data, we will obtain your explicit consent (Art. 9(2)(a) GDPR) before processing such data and will clearly explain the purpose and scope of that processing.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of your account, plus 30 days after deletion request |
| Event Data and Media | Per Service Plan: Blossom 15 days, Bouquet 60 days, Heirloom 90 days after your event date |
| Audit Logs | Retained with associated Event Data, deleted on the same schedule |
| Financial Data | As required by Greek tax law (currently up to 5 years) |
| Newsletter Subscriptions | Until you unsubscribe or withdraw consent |
| Contact Form Messages | 12 months after submission |
| Cookie Consent Preferences | 1 year (stored in your browser cookie) |
After the applicable retention period, data is permanently deleted from our systems, including cloud storage. This process is irreversible.
9. International Data Transfers
The majority of your data is processed within the European Union:
- Media storage and processing: AWS eu-central-1 (Frankfurt, Germany)
- API hosting: Google Cloud europe-west1 (Belgium)
- Database: MongoDB Atlas (EU region)
Some of our sub-processors are based in the United States:
- Stripe: Certified under the EU-US Data Privacy Framework; additionally covered by Standard Contractual Clauses (SCCs) adopted by the European Commission;
- Resend: Transfers governed by Standard Contractual Clauses (SCCs) adopted by the European Commission;
- Sentry: Transfers governed by Standard Contractual Clauses (SCCs) adopted by the European Commission;
- Cloudflare Turnstile: Global CDN routing; transfers governed by Standard Contractual Clauses (SCCs) adopted by the European Commission;
- Anthropic (Claude AI-assistant provider): Transfers governed by Standard Contractual Clauses (SCCs) adopted by the European Commission;
- Google (Gemini AI-assistant provider): Certified under the EU-US Data Privacy Framework; additionally covered by Standard Contractual Clauses (SCCs) adopted by the European Commission.
Where data is transferred outside the EU/EEA, we ensure that adequate safeguards are in place in accordance with Article 46 of the GDPR, including Standard Contractual Clauses adopted by the European Commission.
10. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): You may request a copy of your personal data that we hold.
- Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You may request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction (Art. 18): You may request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): You may request to receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): You may object to processing based on legitimate interest.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
How to Exercise Your Rights
To exercise any of these rights, please contact us at privacy@agapae.gr. We will respond to your request within one (1) month, as required by the GDPR. This period may be extended by a further two months for complex requests, in which case we will inform you of the extension.
We will not charge a fee for processing your request unless it is manifestly unfounded or excessive.
Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
- Hellenic Data Protection Authority (HDPA)
- Address: Kifisias 1-3, 115 23 Athens, Greece
- Website: www.dpa.gr
- Phone: +30 210 6475600
- Email: contact@dpa.gr
11. Controller–Processor Relationship
Where EnQube SMPC acts as a processor on behalf of Couples (as data controllers) in relation to Guest data and Event Data, our obligations are governed by Sections 6 and 7 of this Policy, by our Terms of Service, and by the requirements of Article 28 of the GDPR.
Those obligations include, among others, processing personal data only on the documented instructions of the Couple, ensuring confidentiality, implementing appropriate technical and organisational security measures, assisting the controller in fulfilling its obligations to data subjects, and deleting or returning the data at the end of the provision of the Service.
If you are a Couple and wish to enter into a separate, bespoke Data Processing Agreement (DPA), or if you have questions about data processing arrangements, please contact us at privacy@agapae.gr.
12. Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: Media files stored in AWS S3 and data in MongoDB Atlas are encrypted at rest.
- Password security: User passwords are hashed using bcrypt with salt rounds, never stored in plain text.
- Authentication: Short-lived access tokens (15 minutes) with secure refresh token rotation.
- Access controls: Role-based access ensuring Guests can only access events they are invited to; presigned URLs for media access with 5-minute expiry.
- Rate limiting: Per-endpoint request limits sized to each endpoint's risk profile (for example, stricter limits on authentication and contact endpoints than on read-only routes) to protect against brute force, scraping, and abuse.
- Audit logging: Comprehensive logging of security-relevant events for monitoring and incident response.
- Infrastructure security: AWS and Google Cloud enterprise-grade security, including network isolation, monitoring, and incident response.
While we implement robust security measures, no system is entirely immune to risk. We encourage you to use strong, unique passwords and to keep your account credentials confidential.
13. Children's Privacy
The Platform is not directed at children under the age of fifteen (15). Pursuant to Article 21 of Greek Law 4624/2019, read together with Article 8 of the GDPR, Greece has set the age threshold for a child to consent to the processing of personal data in connection with information society services at fifteen (15) years. We do not knowingly collect personal data from children below that age. If you become aware that a child under fifteen (15) has provided us with personal data, please contact us at privacy@agapae.gr, and we will take steps to delete such data promptly.
Note: The minimum age of fifteen (15) referenced here concerns the lawful processing of personal data and is distinct from the contractual age of eighteen (18) required to register an account and enter into our Terms of Service.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service features. When we make material changes:
- We will update the "Effective date" shown at the top of this policy;
- We will notify registered users by email or through the Platform;
- Material changes will take effect thirty (30) days after notification.
We encourage you to review this Privacy Policy periodically.
15. Contact Us
If you have questions about this Privacy Policy, your personal data, or wish to exercise your rights, please contact us:
- Email: privacy@agapae.gr
- Company: EnQube SMPC
- Registered office: Patras, Greece