Data Processing Agreement
Version 2026-09-30. This agreement forms part of the Starvite Terms of Use for every organizer that uses Starvite for an event with guests.
Parties
The organizer that creates or manages an event on Starvite (the "Controller"), and ADS Delivery OOD, a company incorporated in Bulgaria, company number 208549000, 192A Cherni Vrah Blvd., 1407 Sofia, Bulgaria (the "Processor"). Contact: info@shoetracker.ai.
1. Roles
For guest data the organizer adds or collects through its event, the organizer is the controller and ADS is the processor under Article 28 of the GDPR. For the organizer's own account, billing and payment records, ADS is an independent controller, and those records are outside this agreement.
2. Subject matter and duration
ADS processes personal data to provide the event's invitation films, RSVP, optional question, organizer dashboard, report and venue screen. Processing lasts for the life of the event and ends when its data is deleted: automatically 90 days after the event date, or earlier on the organizer's request.
3. Nature and purpose
- storing guest names and, where the organizer provides them, email addresses or phone numbers, to create each guest's personal link;
- recording each guest's answer, party size, vote, and whether they opened their page, made or shared their film;
- storing the organizer's event video in private storage and showing it to people holding the event's links;
- showing first names on the venue screen only for guests who opted in and said they are coming;
- producing the organizer's dashboard, report and exports.
Guests' personal films are rendered on their own devices. ADS does not message guests: invitations are sent by the organizer through its own channels.
4. Categories of personal data
Guest first name or name as provided; email address or phone number where the organizer provides it or the guest asks for reminders; RSVP status, party size and vote; timestamps of opening, answering and sharing; who invited whom through a friend link; the organizer's event video, which may show people who agreed to appear. No special categories of data are intended to be processed, and no face recognition is performed.
5. Data subjects
The organizer's invited guests, employees, attendees and co-organizers, all aged 18 or over.
6. Controller obligations
- have a lawful basis to invite the guests it adds and to share their details with ADS;
- give guests any notice required by law, including that Starvite is used for the event;
- add only the data needed (a name, and an email or phone only when useful);
- hold the rights to its event video, logo and text, and have the consent of everyone who appears in the video;
- send invitations only in ways permitted by applicable law, including anti-spam rules.
7. Processor obligations
In accordance with GDPR Article 28(3), ADS shall:
- process personal data only on the Controller's documented instructions, which are these terms and the organizer's use of the Starvite settings;
- ensure persons authorized to process personal data are bound by confidentiality;
- implement the security measures in section 12;
- assist the Controller with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing;
- notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data;
- make available the information reasonably necessary to demonstrate compliance with this agreement;
- delete personal data at the end of processing as described in section 10.
ADS does not sell personal data, does not use it for advertising, does not build profiles across events, and does not use the Controller's data or videos to train artificial intelligence models.
8. Sub-processors
The Controller gives general authorization to the sub-processors below. ADS binds each to data protection obligations no less protective than this agreement and remains responsible for their performance. ADS will give at least 30 days' notice of a new sub-processor, except where an urgent change is needed for security or continuity; the Controller may object on reasonable data protection grounds.
| Sub-processor | Purpose | Data |
|---|---|---|
| Vercel Inc. | Hosting, application servers, private file storage (event videos stored in Frankfurt, EU) | All event data in transit; event videos at rest |
| Neon Inc. | Managed database | Guest records, answers, votes, activity |
Stripe, Inc. processes the organizer's own billing details as an independent controller for payments and is not a sub-processor for guest data.
9. International transfers
Where personal data is transferred outside the European Economic Area, ADS ensures the transfer is covered by a lawful mechanism, such as an adequacy decision, the EU-US Data Privacy Framework where available, or Standard Contractual Clauses in the sub-processor's terms, and provides information about these safeguards on request.
10. Deletion and return
The organizer can export its guest list and personal links at any time from the dashboard. All event data, including guest records and event videos, is deleted automatically 90 days after the event date, and a guest can delete their own data at any time from their page. Files are deleted from storage before their records. Backups and infrastructure logs held by sub-processors are overwritten on their own retention cycles and are not used for active processing in the meantime.
11. Data subject requests
The Controller answers requests from its guests. ADS assists where it reasonably can and, if it receives a request directly, may refer the guest to the Controller. Guests can remove themselves instantly from their personal page.
12. Security measures
- encryption in transit (HTTPS with HSTS) and at rest by the hosting and database providers;
- unguessable personal links (128 bits or more of randomness) and host keys stored only as digests, compared in constant time;
- private file storage with no public addresses, served only through short-lived signed links after an authorization check;
- request size limits, rate limiting and input validation on every server route;
- a strict content security policy, no third-party scripts, trackers, ad pixels or externally hosted fonts;
- spreadsheet exports neutralize formula injection;
- every code change passes automated tests and code analysis before it reaches production; production changes are logged.
13. Liability and precedence
Liability under this agreement follows the Starvite Terms of Use, except where applicable data protection law does not allow it to be limited. If this agreement conflicts with the Terms on the processing of personal data, this agreement prevails. It is governed by the laws of Bulgaria.