This Data Processing Agreement forms part of the Terms and Conditions and applies whenever the customer, as a controller or processor, uses Kruspin to process another person's personal data. By accepting the Terms and Conditions, the customer enters into this Agreement with Necktip s.r.o.
For data that the customer enters into a workspace or event about its clients, guests, suppliers, team members and other participants, the customer is typically the controller and Necktip s.r.o., the company operating Kruspin, is the processor. If the customer is itself a processor for its client, it confirms that it is authorised to engage Kruspin as a subprocessor.
Necktip s.r.o. may be an independent controller for data needed for its own account administration, sign-in, billing, security, abuse prevention, legal communications and its own operational monitoring. To the extent that monitoring or session recording processes customer data solely to provide, secure or support the service under the customer's instructions, this Agreement applies. A masked recording may still contain personal data.
The subject matter is the processing of personal data necessary to operate workspaces, events, RSVPs, guest websites, accommodation, seating plans, timelines, tasks, files, suppliers, working financial overviews, communications, client-facing and operational outputs, and support.
Processing continues for the duration of the customer account or agreed service and for the period necessary to return or delete the data. The nature of the processing includes storage, structuring, retrieval, display, transmission, backup, export, correction, restriction and deletion in accordance with the service features and the customer's instructions.
The purpose is to provide and secure the selected Kruspin function and carry out the customer's documented instruction. Identifiable Customer Content is not used to train models or create reusable evaluation datasets. Any future voluntary data-contribution programme would be separate, off by default and require its own terms and legal basis. The operator may use genuinely anonymised and aggregated information under the Terms and Conditions.
| Area | Examples |
|---|---|
| Data subjects | Customers and their users, clients and couples, guests and households, children and plus-ones, suppliers, venue staff, external collaborators and other event participants. |
| Identification and contact data | Name, email, phone number, address, language, role, organisation, membership, invitations and technical access identifiers. |
| Event and logistics | RSVPs, households and relationships, programme, tasks, accommodation, transport, seating plans, menus, suppliers, forms, comments, files and photographs. |
| Higher-sensitivity data | Allergies, dietary requirements, health or accessibility needs, data about children, private family notes and other data entered by the customer. This data must be minimised and restricted to the people for whom access is necessary. |
| Commercial and financial data | Supplier contacts, prices, deposits, payments, billing data, internal costs, margins, and contractual and negotiation notes. |
| Technical and audit data | Times, changes, access, IP addresses or derived security signals, device and browser data, email delivery, error and audit records, PostHog identifiers and operational events. When session recording is enabled, this also includes the internal user and workspace IDs, name, email and a masked recording of interactions. |
- The customer is responsible for the lawfulness of its instructions, the legal basis, obligations to provide information, data accuracy and the authorisation of people it invites to the service.
- Feature settings, imports, publication, sharing, export, deletion and a request submitted by an authorised person of the customer are documented instructions within the scope of this Agreement and the Terms.
- The customer must minimise allergies, health and accessibility needs, data about children, family notes and other sensitive data and enter it only where necessary for a specific purpose.
- The customer must configure roles, permissions, public pages, RSVP links and exports so that data is visible only to the intended recipients.
- The customer must not instruct the operator to carry out unlawful processing. If the operator reasonably considers an instruction to infringe data protection law, it will inform the customer and may suspend the instruction until the matter is clarified.
- If the customer processes data on behalf of another controller, it must obtain the necessary authorisation to engage Kruspin and pass on any stricter instructions that apply to the processing.
- Process personal data only in accordance with this Agreement, the service settings and the customer's other documented instructions, unless processing is required by EU or Member State law; in that case, inform the customer in advance unless the law prohibits this.
- Ensure that people authorised to process the data are bound by confidentiality and have access only to the extent required by their role.
- Adopt and maintain the appropriate technical and organisational measures set out below and adapt them to the risk, the state of the art and the nature of the service.
- Engage subprocessors only in accordance with this Agreement and impose substantially the same personal data protection obligations on them.
- Taking into account the nature of the processing, reasonably assist the customer with data-subject requests, security, incidents, data protection impact assessments and consultation with a supervisory authority.
- At the end of the service, return or delete all customer personal data and existing copies at the customer's choice unless continued retention is required by EU or Czech law.
- Provide the information needed to demonstrate compliance with Article 28 GDPR and permit a reasonable audit subject to the terms below.
- Inform the customer without undue delay if the operator becomes aware of a personal data breach affecting data processed on the customer's behalf.
The customer grants general written authorisation to engage the subprocessors listed below for the purposes described. Depending on the specific function, some services also act as independent controllers; their own terms are presented when the service is used or on the hosted page.
The operator will give at least 15 days' notice through the account or by email of an intended addition or replacement of a subprocessor that will materially process customer personal data, unless an urgent security or legal need requires a shorter period. The customer may raise a reasoned data-protection objection within 10 days. If the objection cannot reasonably be resolved, the parties may disable the affected optional feature or stop using it.
The operator will impose substantially the same data protection obligations on each subprocessor and remains responsible to the customer for the subprocessor's performance of its obligations to the extent required by GDPR.
| Service | When it is used | Purpose and scope |
|---|---|---|
| Railway / PostgreSQL | Core production infrastructure | Application hosting, database, network traffic and operational infrastructure for account data and customer data. |
| S3-compatible object storage, including Cloudflare R2 where configured | When storing files, photographs, backups or support attachments | Object storage of customer files, galleries, images, exports, locked backups and any support screenshots. |
| Resend | When email delivery is enabled | Verification, one-time codes, resets, invitations, comments, guest messages, forms, support and other user-initiated emails; processes the recipient, subject, content, delivery status and any attachment. |
| Google Maps / Places / Fonts | When a map, address completion or a configured font on a public page is loaded | For maps, address and place search, completion and verification; the search text, place identifier and technical data are sent to the provider. When a font is loaded, Google may receive the IP address and technical browser data. |
| Vercel AI Gateway and the configured model provider, currently OpenAI | Only when AI translation or another enabled AI feature is started | Performs the User-initiated operation on the necessary input, for example translation, a text suggestion, a summary or import cleanup. The entire workspace is not sent automatically, and Kruspin does not instruct the provider to use identifiable Customer Content for model training. |
| Quiver AI | Only when SVG generation is started | Processes the text prompt, visual instructions and technical parameters to create an SVG. The feature must not receive guests' personal data or non-public project content. |
| PostHog | For error and operational monitoring; session recording when enabled in the signed-in application | Error and operational events and technical identifiers. Session recording masks text, inputs and attributes and excludes console data, request headers and bodies, heatmaps and cross-origin iframes, but may be linked to the internal user ID, name, email and workspace. |
| Google Analytics | Only on the public website after visitor consent | Pseudonymous measurement of visits and primary actions on allowlisted public pages with advertising storage disabled. It is not used on non-public project, RSVP or shared tokenised pages. |
| Stripe | For an online payment, storing a payment method or opening the payment portal | Payment and billing identifiers, amount, currency, payment status and technical data. Card details are entered by the user directly in Stripe's environment. |
| iÚčto | When invoicing and the accounting transfer are enabled | Customer identity and address, IČO/DIČ, invoice, line items, amounts, VAT, payment reference and payment status for issuing and recording accounting documents. |
| Only when the user connects Pinterest and selects content | OAuth access, profile, selected boards and pins, images and metadata needed to import inspiration. Access tokens are stored encrypted. | |
| Upstash Redis | Only when shared request rate limiting is enabled | Short-lived technical keys and counters derived from the request to protect sign-in, forms and APIs against abuse. |
| Cloudflare Custom Hostnames / edge services | When connecting a custom domain or serving the public website at the network edge | Domain, DNS and TLS status, target hostname and technical request data needed to route and secure public pages. |
| WEDOS | When checking, registering or managing DNS for a domain through Kruspin | Domain name, availability, technical and registration identifiers, and the registration contact of Necktip s.r.o. as the domain registrant. |
| Canva | Only when the user connects Canva and uses the integration | Account and team identifiers, granted permissions, design metadata and previews, and exported pages for browsing, importing and updating content. OAuth access and refresh tokens are stored encrypted; imported images are stored in Kruspin. |
The operator selects a European region or European endpoints where available. Some providers may nevertheless use global infrastructure or permit support access from outside the EU/EEA.
If personal data is transferred to a country without an adequacy decision, the operator will use an applicable mechanism under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, and supplementary measures according to the risk. Information about the current mechanism for a specific provider will be supplied to the customer on request.
The customer instructs transfers to the extent necessary for the feature it has enabled and the approved providers listed above. This does not restrict the customer's right to object to a new subprocessor.
- Sign-in using a verified email address and short-lived one-time codes, secure HTTP-only sessions and server-side identity checks.
- Roles, memberships, permissions and separate outputs for client and public views that restrict access by workspace, event and output purpose.
- Encrypted transmission using HTTPS/TLS; encryption of stored data according to the capabilities and configuration of the database and object-storage providers; encrypted storage of selected integration tokens.
- Separation of production and development environments, server secrets kept out of the client, restricted support and administrator access, and auditing of security-significant actions.
- Input validation, same-origin protection, request rate limiting, short-lived tokens, session revocation and protection against common web application abuse.
- Minimisation of logs, analytics, monitoring and support artefacts; masking of text, inputs and attributes in session recordings and exclusion of console data, request headers and bodies, heatmaps and cross-origin iframes. The recording may nevertheless remain identifiable personal data.
- Backup and recovery procedures appropriate to the infrastructure provided, controlled database changes and restrictions on destructive production operations.
- A process to classify, contain, remediate and document security incidents and inform affected customers.
- Regular reassessment of the measures according to the nature of the data, the state of the art, costs and risk. No system can guarantee absolute security.
If the operator receives a request from an individual concerning customer personal data, it will not respond substantively without the customer's instructions unless required by law. It will forward the request to the customer or help identify the relevant controller and, where possible, provide the tools or information needed to respond.
In the event of a personal data breach, the operator will inform the customer without undue delay after becoming aware of it. Based on the information available, it will describe the nature of the incident, the categories affected, the likely consequences, the measures taken or proposed, and a contact for further assistance. The notice itself is not an admission of liability.
Taking into account the nature of the processing and the information available to it, the operator will reasonably assist with data protection impact assessments, prior consultations, security, notification duties and demonstrating compliance. Exceptional assistance beyond the ordinary scope of the service may be charged for unless the need was caused by the operator's breach of this Agreement.
At the end of the service, the operator will, at the customer's choice, return customer personal data in a reasonably available format or delete it unless continued retention is required by law. Export and deletion are currently handled through support; complete self-service export and account deletion are not available for all accounts.
After deletion from operational systems, copies may remain only in isolated technical backups for the time needed to complete a documented deletion cycle, no longer than 180 days, or where retention is required by EU or Czech law. During that period they are not used for ordinary operations; the Operator deletes them when the applicable period ends. Monitoring data processed on the customer's behalf is subject to the same rule; data for which Necktip s.r.o. is an independent controller is governed by the Privacy Notice.
The customer may request information reasonably necessary to verify this Agreement no more than once a year and also after a serious incident. If the materials are insufficient, the customer may, on at least 30 days' notice, conduct an audit itself or through an independent professional bound by confidentiality, during business hours and without access to other customers' data. This notice period does not apply where a shorter procedure is necessary because of an urgent incident or a supervisory authority's request. The customer bears the reasonable costs of the audit unless it demonstrates a material breach by the operator.
If documents conflict, this Agreement prevails for the processing of personal data on behalf of the customer; the Terms and Conditions prevail on other matters. A stricter individual written agreement prevails to the extent that it expressly varies this Agreement.
Questions, instructions, objections to a new subprocessor and requests for assistance should be sent to [email protected].