Document language
Legal

Data Processing Agreement

The Article 28 GDPR agreement between you as controller and us as processor of your guests' data.

Last updated: 17 August 2026

This agreement forms part of the Terms of Service and you accept it together with them. No separate signature is required. In case of discrepancies between the language versions, the German version prevails.

In short

You decide which guest data you enter and what happens to it. We only store and display it, on your instructions.

This document sets out what we may do, what we may not do, and what you are responsible for.

1. Parties and subject matter

The processor is Marko Stjepanović, xtwo.dev, Gerhart-Hauptmann-Straße 3, 78112 St. Georgen im Schwarzwald, Germany (the Processor).

The controller is you, the user who opened an account and created an event (the Controller).

The subject matter of this agreement is the processing of personal data that the Controller or their guests enter into the Platform in the course of using the xtwo.events service. This agreement runs for as long as the contract for use of the Platform.

For the Controller's own data (account, payment, security records, anonymous statistics) the Processor is an independent controller; this agreement does not apply to that processing, the privacy policy does.

2. Nature, purpose, types of data and data subjects

Nature and purpose of processing
Storage, organisation, display and deletion of data in order to maintain a guest list, send and display digital invitations, collect RSVPs, maintain a gift list and song suggestions, build a seating plan, and receive, store and display photos uploaded by guests.
Types of personal data
First and last name, phone number, table and group assignment, accommodation requirement, RSVP status, free-text message stored in the dietary notes field, the name attached to a song suggestion and to a gift reservation, photos and other media uploaded by guests, and technical metadata about uploaded files.
Special categories of data
The dietary notes field may contain health data. Photographs may reveal religious belief or health data. The Controller must ensure an appropriate legal basis under Article 9 GDPR.
Categories of data subjects
The Controller's guests and invitees, persons named as contacts or important people in an invitation, and every person depicted in an uploaded photograph.
Duration of processing
Until the individual content is deleted, until the event is deleted, or until the contract for use of the Platform ends, whichever occurs first.

3. Processing on documented instructions only

The Processor processes personal data only on the Controller's documented instructions, including with regard to transfers to third countries. Actions the Controller takes in the Platform's interface constitute instructions. Further instructions are given by email to the Processor's address.

Where the Processor is required by Union or Member State law to process without an instruction, it will inform the Controller of that legal requirement before processing, unless that law prohibits the notice on important grounds of public interest.

The Processor will inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other data protection law.

4. Confidentiality

Every person authorised to process personal data on the Processor's side is bound to confidentiality, whether by contract or by statute. That obligation survives the end of their engagement. Authorisation is granted only once the undertaking is in place.

Access to the Controller's data is limited to persons who need it to provide the service, resolve faults or deliver support the Controller has requested.

5. Security of processing (Article 32 GDPR)

The Processor applies the technical and organisational measures set out in Annex 2 to this agreement, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of data subjects.

Measures may evolve. The Processor will not reduce the overall level of protection during the term of this agreement.

6. Sub-processors

The Controller gives general authorisation for the engagement of sub-processors. The current list, with names, places of establishment, purposes and transfer bases, is published at /subprocessors.

The Processor gives at least 30 days' notice of an intended change or addition of a sub-processor, by in-app notice or email. The Controller may object on reasoned grounds within 14 days of that notice. If the objection cannot reasonably be resolved, the Controller may terminate the contract for use of the Platform at no cost and request an export of their data.

The Processor imposes on sub-processors data protection obligations no less protective than those in this agreement and remains liable for their performance as for its own.

7. Assistance with data subject rights

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures in fulfilling its obligations under Chapter III GDPR.

A data subject request addressed directly to the Processor will be forwarded to the Controller without undue delay. The Processor does not respond to such a request itself unless instructed by the Controller or required by law.

In practice: the Controller can delete an individual guest, RSVP, song suggestion, reservation or photo in the dashboard. Where that is not possible, the Processor will carry out the deletion on instruction, free of charge.

8. Assistance with security, breaches and impact assessments

The Processor assists the Controller in complying with Articles 32 to 36 GDPR, to the extent proportionate to the nature of the processing and the information available to the Processor.

The Processor notifies the Controller without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting data processed under this agreement. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

Notification to the supervisory authority under Article 33 and communication to data subjects under Article 34 are made by the Controller. The Processor provides the information needed for both.

9. Deletion and return of data

On the end of the provision of services the Processor will, at the Controller's choice, delete or return all personal data processed under this agreement, unless Union or Member State law requires storage.

The Controller can export their data at any time: the guest list and budget as Excel files, the seating plan as a poster, and photos individually or, with an active Premium plan, all at once.

A request to delete all data is sent to kontakt@xtwo.dev. Deletion is carried out within 30 days. There is currently no automated deletion.

Technical backups kept by sub-processors in the ordinary course of operation may contain data for a short period after deletion, until their regular cycles expire.

10. Demonstrating compliance and audits

The Processor makes available to the Controller, on request, all information necessary to demonstrate compliance with Article 28 GDPR, including this agreement with its annexes and the current sub-processor list.

The Controller may audit, itself or through an auditor it mandates. Audits are announced with reasonable notice, take place during business hours, must not unreasonably disrupt operations, and must not compromise the confidentiality of other customers' data. They are ordinarily conducted by providing documentation and written answers to a questionnaire.

11. Transfers to third countries

Transfers outside the European Economic Area take place only to the sub-processors named in the list and only with appropriate safeguards: the European Commission's Standard Contractual Clauses under Implementing Decision (EU) 2021/914, or certification under the EU-US Data Privacy Framework.

The Controller may request a copy of the safeguards in use by email.

12. The Controller's obligations

The Controller is responsible for the lawfulness of the processing towards their guests. That includes establishing a legal basis, informing guests under Article 13 GDPR, and obtaining consent where required, in particular for photographs of people and for health data.

To help with informing guests, the Processor provides a short notice at /datenschutz-gaeste free of charge, which the Controller can share alongside the invitation or the QR code.

The Controller must not enter data into the Platform that is not needed to organise the event, and in particular no data relating to criminal convictions and offences.

Annex 1: Overview of processing operations

AreaDataData subjectsDuration
Guest list and RSVPsFirst name, last name, phone, tags, table, accommodation, status, free textGuestsUntil the guest or the event is deleted
InvitationsInvitation content, names and photographs of important people, contacts with phone numbersGuests, persons named in the invitationUntil the invitation or the event is deleted
Song suggestionsGuest name, song title, artist, linkGuestsUntil the suggestion or the event is deleted
Gift listName of the person reserving, reservation time, action recordGuestsUntil the gift or the event is deleted
Seating planAssignment by guest identifier; names are not stored in the planGuestsUntil the plan or the event is deleted
Guest photographsFile, size, type, upload time; the identity of the uploader is not storedGuests and every person depictedUntil the photo or the event is deleted
Host notificationsGuest name in the notification titleGuestsUntil the event is deleted

Annex 2: Technical and organisational measures

The following measures are in place as at the last update of this agreement.

  • All data in transit is carried over an encrypted connection (TLS).
  • Security headers: framing of the site is denied, content-type sniffing is disabled, referrer disclosure is restricted, and camera, microphone and geolocation access is denied.
  • A Content Security Policy restricting the permitted sources of scripts, styles, images and frames.
  • Every page carrying personal data is excluded from search engine indexing, including for the known AI training crawlers.
  • Server-side validation of file type and size before an upload permission is issued.
  • Storage and file-count quotas per event.
  • Link passwords are compared server-side in constant time and are never sent to a visitor's browser.
  • Proof that a password was entered is held in a cryptographically signed cookie that scripts cannot read and that expires after 12 hours.
  • Ownership checks on privileged server endpoints.
  • Sessions are verified server-side with the authentication provider rather than from the token alone; stale sessions belonging to deleted users are invalidated.
  • Sign-in uses the PKCE flow and post-login redirects are restricted to our own domain.
  • Payment provider webhook signatures are verified before processing.
  • Hidden honeypot fields to detect automated submissions on every public form.
  • Per-IP request rate limiting on public endpoints.
  • Separation of access: the browser client and the session client are subject to database-level access rules; the privileged key is used server-side only.
  • Account passwords are stored by the authentication provider as a cryptographic hash only.

Annex 2, addendum: current limitations

We state these openly because you are the controller and need them for your own risk assessment under Article 32 GDPR.

Link passwords are shared access codes, not user credentials. They are not stored as one-way hashes.

Photographs are held in a store whose file addresses are random and unguessable but are not protected by a login. Anyone holding the link can open the file.

EXIF metadata is not removed from original files. The thumbnails and previews we generate ourselves do not contain it.

Encryption at rest is provided at the platform level by our sub-processors; no additional application-level encryption is applied.

Two-factor authentication, access logging and distributed rate limiting are not currently implemented.

There is no automated deletion on expiry; deletion is carried out on request.

13. Final provisions

In the event of a conflict between this agreement and the Terms of Service, this agreement prevails on data protection matters.

If any provision is invalid, the remainder stays in force. This agreement is governed by the law of the Federal Republic of Germany.

Amendments to this agreement follow the procedure set out for amendments to the Terms of Service.

Need a signed copy?

If your own records need a signed counterpart, ask us for one.

Request a copy