Data Processing Agreement

Last updated: 9 June 2026

Plain-English summary

When you use Essentially Events to manage guest lists, RSVPs, communications, or photos, you are the data controller and Essentially Events acts as your data processor under UK GDPR Article 28.

Parties and scope

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and Essentially Events (“Processor”).

It applies to personal data processed on behalf of the Controller through the Essentially Events platform, including guest contact details, RSVP responses, photos, and communications metadata.

Processing instructions

The Processor will process personal data only on documented instructions from the Controller, including configuration of events, communications, and retention settings within the dashboard.

Confidentiality and personnel

The Processor ensures that persons authorised to process personal data are bound by confidentiality obligations.

Security measures

The Processor implements appropriate technical and organisational measures, including:

  • Row Level Security and tenant isolation at the database layer.
  • Hashed guest magic-link tokens and server-side authorisation checks.
  • Encrypted transport, access-controlled media storage, and rate limiting on communications endpoints.

Subprocessors

The Controller authorises the Processor to engage subprocessors listed on our Subprocessors page. The Processor will notify Controllers of material changes before new subprocessors process personal data, where required by law or contract.

Data subject requests

The Processor will assist the Controller in responding to data subject requests using available platform tools and reasonable technical measures.

Personal data breaches

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting Controller data, and provide information reasonably required for regulatory notification.

Deletion and return

Upon termination or expiry of retention settings, the Processor will delete or return personal data in accordance with the Controller’s instructions and documented retention policy, subject to legal retention requirements.

How to execute this DPA

By creating an agency or planner account and using the service to process guest data, you agree to this DPA on behalf of your organisation.

Enterprise customers requiring a countersigned copy may request one at hello@essentiallyevents.com.