The agreement
Data Processing Terms
How we handle your guests’ details on your behalf
Last updated: September 26, 2026 · Version 2026-09-26
These Data Processing Terms are part of our Terms & Conditions. They apply whenever you, as a host, give us personal information about other people — your guests, the people in their households, your vendors and the people working your door — or ask us to collect it from them. Where these terms and the Terms & Conditions differ on the protection of that information, these terms apply. How we handle everyone’s information, including yours, is in our Privacy Policy.
If you booked under an earlier version of our Terms, our commitments to you in sections 3 and 5 to 12 below apply to your events from 26 September 2026 as well. They only add to what you already have; nothing in them narrows it.
1. Who is who
You are the host: the client who bought the plan and every person you give access to your event. We are Evorrah, operated by Innovatech Brazil LLC, a Delaware limited liability company with its principal office in Florida, 40 SW 13th St, Suite 204, Miami, FL 33130, USA.
For your guests’ details, you decide who is invited and why, so you are the controller (LGPD art. 5 VI; GDPR art. 4(7)). We process them for you, as your operator under the LGPD (art. 5 VII) and your processor under the GDPR (art. 4(8)). The few things we do with guests’ details for our own reasons — keeping the service secure, keeping the record of a guest’s consent or of their request not to be contacted, answering a guest who writes to us, and the “By Evorrah” tap — are set out in our Privacy Policy, and for those we are responsible ourselves.
2. What we process, why, and for how long
- Whose details. Your guests and their plus-ones; the people in their households, children included; people you propose or keep on Your People; your vendors and door staff.
- Which details. Names and how to address them; email addresses, phone numbers and postal addresses; replies and attendance; dietary needs and allergies, and accessibility needs; transport and arrival details; notes you or they write; guestbook messages; photos and videos added to your event album; and the messages we send them and they send back.
- Why. Only to provide the services of your plan: your guest list, invitations and replies, reminders by email, text message and WhatsApp, your event website, seating, check-in at the door, your album and your recap.
- For how long. For as long as we run your events, and then for the periods in the retention section of our Privacy Policy: guest details are deleted 5 years after your most recent event.
3. We act only on your instructions
We process your guests’ details only on your instructions and only for the purposes in section 2. Your instructions are these terms, the plan you bought, and what you set in your portal — who is on your list, what is sent, and when. If we believe an instruction would break data protection law, we tell you and do not follow it until it is resolved. If a law ever requires us to process your guests’ details in some other way, we tell you first, unless that law forbids it.
4. What you promise us
- You are allowed to share them. You have a lawful reason to give us your guests’ details and to have us contact them about your event, as section 9 of our Terms & Conditions already says.
- You tell your guests. You let your guests know that you use Evorrah to run your event and that their details are handled as our Privacy Policy describes. Every reply page we send carries a short privacy note and a link to that policy; it helps, but it does not replace telling them yourself.
- Consent where it is needed. You tick a guest’s text-message consent box only when that guest has agreed to be texted at that number. You do not enter a guest’s allergy or medical detail unless they have told it to you for that purpose, and you add children’s details only with a parent’s or guardian’s knowledge.
- Only what the event needs. You do not use the notes, labels or fields in your portal to record anything about a guest that your event does not need.
5. Confidentiality
Everyone at Evorrah who can see your guests’ details is bound to keep them confidential, and sees them only where their work on your event needs it. Only the owner of Evorrah can open a host’s portal as the host; the rest of our team works from our internal system, where what each person may do is set by their role and recorded.
6. Security
We protect your guests’ details with measures suited to what they are, including:
- HTTPS on every page and every connection to the services we use;
- a personal link for each guest that opens only that guest’s own reply, and roles for the people you invite to help you (co-host, planner, or someone who can only look);
- encrypted passwords, access rules in our database, and limits on how fast any address can try our forms;
- a record of what our team changes, and of who signed in;
- location data removed from photos and videos guests add to your album;
- daily backups kept for a limited time, used only to restore the service after a failure;
- a written procedure for security incidents (section 10).
7. The services we use, and how we tell you about changes
You authorise us to use the following services to process your guests’ details, each for the job named and under its own data protection terms:
- Supabase — our database and file storage, hosted in the United States.
- Vercel — hosting for the website, your portal and every guest page.
- Resend — sending emails to your guests.
- Twilio — sending text messages, and WhatsApp messages to guests who said yes to them.
- WhatsApp (run by Meta) — delivering WhatsApp messages to guests who said yes to them.
- Anthropic — reading seating notes against your guest list to suggest who should sit together, and reading a guest’s reply to a text or email to record whether they are coming. It receives names and the text being read, never guests’ phone numbers or email addresses.
- Recraft, fal.ai and Google Gemini — making artwork elements; they receive only wording that is to appear on a design, such as names.
- Stripe — card payments; it receives a guest’s details only if that guest pays for something connected with your event.
Changes. Before we add or replace a service that will receive your guests’ details, we update this list and tell you by email at least 30 days in advance. If you object on reasonable data-protection grounds, tell us; if we cannot meet your concern, you may stop using the affected feature, or end the service for your event, and we delete that event’s guest details as section 11 describes.
8. Transfers to other countries
The services in section 7 are based in the United States and our team works from Brazil, so your guests’ details are transferred to and stored in the United States. You authorise those transfers for the purposes in section 2. From Brazil, we are putting in place the standard contractual clauses approved by the ANPD (Resolution CD/ANPD nº 19/2024) with each of those services; until each is signed, a transfer relies on the protections in that service’s own data protection terms. Between the European Union and Brazil, each recognises the other’s data protection as adequate (EU decision 2026/179; ANPD Resolution 32/2026). The transfers section of our Privacy Policy gives the detail.
9. Helping you with your guests’ requests
Your guests can see, correct and stop messages about their own details from their personal link. When a guest writes to us instead about their details on your event, we tell you, answer the guest, and carry out what you decide — or, where it is a request we must honour ourselves, such as a request to stop being contacted, we honour it and tell you. We help you answer any request within the time the law allows (in Brazil, 15 days for a full answer under LGPD art. 19), including by preparing a copy of a guest’s details or deleting them.
10. If something goes wrong
If we become aware of a security incident that affects your guests’ details, we tell you without undue delay, so that you can meet any deadline you have yourself, including the ANPD’s three working days (Resolution CD/ANPD nº 15/2024) and, where the GDPR applies, 72 hours. We tell you what happened, which details and which people are affected, what it may mean for them and what we are doing about it, and we keep you updated as we learn more. We keep a record of every incident, help you notify the authority and your guests where that is needed, and take the steps needed to contain it.
11. At the end
Your guests’ details are deleted 5 years after your most recent event, or sooner if you ask. Before anything is deleted at your request, we give you a copy of your guest list if you want one. Copies in our backups are replaced on their rolling schedule, within 6 months. Two things are kept after a deletion, as our Privacy Policy explains: the record of a guest’s consent or of their request not to be contacted, and records the law requires us to keep.
12. Records and checks
We keep a record of the processing we carry out for you. We answer your reasonable questions about how your guests’ details are handled, and give you the information you need to show that these terms are being kept, or to carry out an impact assessment. Where the law gives you the right to an audit or inspection, we allow it on reasonable notice, at your cost, and in a way that protects our other clients’ information.
13. Hosts in the European Union and the United Kingdom
Where the GDPR or the UK GDPR applies to you, these terms are the contract article 28 of that law requires between a controller and a processor: section 2 sets out the subject matter, duration, nature and purpose, and the kinds of personal data and people; section 3 the instructions; section 5 confidentiality; section 6 the security article 32 requires; section 7 our use of other processors, which you authorise in general with notice of changes; sections 9 and 10 our help with requests and with articles 32 to 36; section 11 deletion or return at the end; and section 12 information and audits.
14. Liability, changes and contact
Section 10 of our Terms & Conditions applies to these terms too, and nothing in either limits liability that cannot lawfully be limited. If we change these terms, we update the date and version above and tell you by email before a change that affects you takes effect. These terms are written and published in English, and the English text is the binding version.
Questions about these terms, or about your guests’ details: our data protection officer, Bryan Buch, at hello@evorrah.com (subject line “Data protection”).
Anything unclear
A contract you can
actually ask about.
If a clause here matters to your event and does not read plainly, write to us before you buy — a person replies.
Talk to us →