Effective 2 September 2026
Privacy notice
This notice explains how DRJS Software & Consulting Ltd handles personal information when you use Laura & David's Whitstable Wedding.
Who is responsible
DRJS Software & Consulting Ltd is the controller for personal information collected through this service. Current operator details are available on the company information page. Use that page for privacy questions and rights requests.
Information collected
Account information
Admin name, email address, password hash, account role, verification status and account timestamps.
Content and service data
RSVP details, party size, dietary requirements, song requests, guest messages and admin notes.
Security and technical data
The service and its hosting providers may process IP address, request time, requested route, response status, browser details and diagnostic events to deliver, protect and troubleshoot the service. An accepted terms version and acceptance time are recorded when an account is requested or created.
Do not enter special-category, regulated or confidential information unless the operator has expressly confirmed that the service is suitable for it.
Purposes and lawful bases
- Provide requested accounts and application features, based on contract or steps requested before entering a contract.
- Authenticate users, prevent misuse, investigate faults and keep the service secure, based on legitimate interests and legal security duties.
- Administer subscriptions or purchases where enabled, based on contract and legal accounting obligations.
- Respond to enquiries and rights requests, based on legitimate interests and applicable legal obligations.
- Establish, exercise or defend legal claims where necessary and proportionate.
The operator does not use account or uploaded content to make automated decisions about a person that produce legal or similarly significant effects.
Sharing and international processing
Personal information is not sold. It may be processed by Railway for application hosting, databases, storage and operational logs. Configured email, billing or support providers process only the information needed when those features are active. Information may also be disclosed to professional advisers, regulators or public authorities where lawfully required.
A provider may process information outside the United Kingdom. Where required, the operator relies on an applicable adequacy regulation or approved contractual safeguards and relevant transfer assessment.
Retention
Account and application data is retained while the account is active and then for the period configured by the operator's retention policy. Security and diagnostic records are retained only for an appropriate operational period.
Password-reset tokens expire after approximately one hour and email-verification tokens after approximately 24 hours. A browser access token may remain in local storage until sign-out or removal, but the server rejects it after its configured validity period.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction or transfer of your information, and may object to processing based on legitimate interests. You can complain to the UK Information Commissioner's Office. The operator may need to verify identity before completing a request.
Security, children and changes
Reasonable technical and organisational measures are used, but no internet service can promise absolute security. This business service is not directed to children and should not be used by anyone under 18. This notice will be updated before a material change to data use; the effective date identifies the current version.