Data processing agreement
Last updated 19 August 2026
If you run an event on Twirl, you are the data controller for your guests' data and we are the processor. The law requires a written agreement covering that, and this is it. Most people will never need to read this page.
Na tej stronie
01Parties and scope
1.1The parties
| Role | Party |
|---|---|
| Controller | The Organizer. The person or organisation that creates an event on Twirl and determines what personal data is collected in it and why. Identified by the account holder's name and email address on record. |
| Processor | Ciceroni VOF, trading as Twirl. A vennootschap onder firma registered in the Netherlands, KVK 76619176, registered at Franklinstraat 161, 2562 CD Den Haag. |
1.2What this agreement covers
This agreement governs Twirl's processing of personal data on the Organizer's behalf in connection with an event. That is principally guest data: names, RSVP responses, uploaded photographs, videos and voice memos, and the personal data of people depicted in that content.
It does not cover personal data for which Twirl is itself the controller, which is the Organizer's own account, billing and support data. That processing is governed by the Privacy Policy, not by this agreement.
1.3How it takes effect
This agreement forms part of the Terms of Service and takes effect when the Organizer accepts them. No separate signature is required. An Organizer who needs a signed counterpart, for example a wedding planner acting for a business client, can request one from hello@twirl.photos.
1.4Order of precedence
If this agreement conflicts with the Terms of Service on a matter of personal data processing, this agreement governs. If it conflicts with the Standard Contractual Clauses where those apply, the Standard Contractual Clauses govern.
02Definitions
Personal data, processing, controller, processor, subprocessor, data subject, personal data breach and supervisory authority have the meanings given in Article 4 of the GDPR.
GDPR means Regulation (EU) 2016/679, and where the Organizer or the data subjects are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 as applicable.
Applicable Data Protection Law means the GDPR and any national implementing law that applies, including the Dutch Uitvoeringswet AVG.
Services means the Twirl platform as described in the Terms of Service.
Subprocessor means a third party engaged by Twirl to process personal data on the Organizer's behalf.
03Roles and responsibilities
- The Organizer is the controller. They determine the purposes and means of processing guest data: who is invited, what questions are asked, what content is kept, when the event ends.
- Twirl is the processor. It processes that data only to provide the Services and only on the Organizer's instructions.
- The Organizer warrants that it has a lawful basis for the processing it instructs, that it has provided any notices and obtained any consents required, and that its instructions do not require Twirl to breach Applicable Data Protection Law.
- The Organizer acknowledges that RSVP answers concerning meals and dietary requirements may constitute special category data under Article 9 of the GDPR, and is responsible for having a valid Article 9 condition where that is the case. Twirl's recommendation, recorded here so that it is on the record, is that dietary questions are never made mandatory.
- The Organizer acknowledges that content uploaded to an event will contain personal data of people who are not the uploader, including children, and is responsible for the lawfulness of that processing.
04Subject matter and details of processing
Required by Article 28(3). The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex 1.
05Processing on documented instructions
Article 28(3)(a).
- Twirl processes personal data only on the Organizer's documented instructions, including on transfers to third countries, unless required to do otherwise by Union or member state law. Where such a legal requirement applies, Twirl will inform the Organizer before processing unless the law prohibits that notification on important grounds of public interest.
- The Terms of Service, this agreement, the configuration the Organizer sets in the dashboard, and the ordinary use of the Services constitute the Organizer's documented instructions. Additional instructions must be agreed in writing and may attract a reasonable charge if they require work outside the Services.
- Twirl will inform the Organizer if, in its opinion, an instruction infringes Applicable Data Protection Law. Twirl may suspend the affected processing until the instruction is withdrawn or amended.
- Twirl does not use personal data processed under this agreement for its own purposes. Specifically, it does not sell it, does not use it for marketing, and does not use it to develop or train machine learning or artificial intelligence models. Standing exception, disclosed for transparency. Twirl may act without waiting for the Organizer's instruction where content is manifestly unlawful, where it appears to have been uploaded without the consent of a person depicted, or where a takedown is legally required. Twirl will inform the Organizer when it does this. The Organizer accepts this as a term of the Services, and it is recorded here so that it is not later characterised as processing outside instructions.
06Confidentiality
Article 28(3)(b). Twirl ensures that anyone authorised to process personal data under this agreement is bound by an obligation of confidentiality, whether contractual or statutory, and that access is limited to those who need it to provide the Services or to meet a legal obligation. Access to production data is limited to the founders and is used for operational and support purposes only.
07Subprocessors
Article 28(2) and 28(4).
7.1General authorisation
The Organizer gives Twirl general written authorisation to engage subprocessors. The subprocessors engaged at the date of this agreement are listed in Annex 3 and maintained at where your photos live, which is the authoritative and current version.
7.2Terms imposed on subprocessors
Twirl imposes on each subprocessor, by written contract, data protection obligations no less protective than those in this agreement, and in particular the obligations required by Article 28(3). Twirl remains fully liable to the Organizer for the performance of each subprocessor's obligations.
7.3Notice of changes
Twirl will give at least 30 days' notice before adding or replacing a subprocessor. Notice is given by email to the Organizer's registered address and by updating where your photos live. Organizers can subscribe to change notifications from that page.
7.4Objection
- The Organizer may object to a new subprocessor on reasonable data protection grounds, in writing to privacy@twirl.photos, within 30 days of the notice.
- Twirl will work in good faith to address the objection, which may mean explaining safeguards, applying additional measures, or where practicable offering an alternative configuration.
- If no resolution is reached within 30 days of the objection, the Organizer may terminate the affected event or the account, and Twirl will refund the unused portion of any window already paid for on a pro rata basis.
- Twirl acknowledges that at its scale it cannot always offer an alternative provider, and that termination with a pro rata refund will sometimes be the only available remedy. Saying so plainly here is preferable to promising flexibility that does not exist.
- Where a change is urgent and necessary for security, Twirl may implement it before the notice period expires, and will inform the Organizer as soon as possible. The objection right still applies afterwards.
08International transfers
Article 28(3)(a) and Chapter V.
- Media storage and the database are both located in Frankfurt, Germany. Neither involves a transfer outside the European Economic Area and neither requires a transfer mechanism. The current locations are stated in Annex 3.
- Twirl commits not to move media storage outside the European Economic Area. Any change of storage provider will remain within the EEA and will be notified under section 7.3.
- Where a subprocessor with a parent company outside the EEA may access data, Twirl relies on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, and on the provider's certification under the EU-US Data Privacy Framework where held.
- For Organizers or data subjects in the United Kingdom, the UK International Data Transfer Addendum applies to those Standard Contractual Clauses.
- Twirl will assist the Organizer in carrying out a transfer impact assessment where one is required, and will provide the information reasonably needed to complete it.
- Copies of the relevant transfer mechanisms are available on request to privacy@twirl.photos. Commercial terms may be redacted.
09Security
Article 28(3)(c) and Article 32. Twirl implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Those measures are described in Annex 2.
Twirl may update the measures over time provided the level of protection is not reduced.
10Personal data breaches
Article 28(3)(f) and Article 33(2).
- Twirl will notify the Organizer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed under this agreement.
- The notification will describe, so far as known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, Twirl will provide information in phases rather than waiting.
- Twirl will assist the Organizer in meeting its own obligations under Articles 33 and 34, including any notification to a supervisory authority or to affected data subjects.
- Twirl will not notify a supervisory authority or data subjects on the Organizer's behalf unless the Organizer instructs it to, or unless Twirl is independently required to do so as a controller in its own right.
- Twirl maintains an internal record of breaches, including those not requiring notification.
11Assistance and audits
11.1Data subject rights
Article 28(3)(e). Twirl will assist the Organizer, by appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise data subject rights. In practice:
- The dashboard allows the Organizer to search, view, correct, export and delete guest data directly, which resolves most requests without involving Twirl at all.
- Where a data subject contacts Twirl instead of the Organizer, Twirl will not respond substantively on the Organizer's behalf. It will pass the request to the Organizer without undue delay and support them in answering it, subject to the standing exception in section 5.
- Twirl does not charge for this assistance at ordinary volumes.
11.2Data protection impact assessments
Article 28(3)(f). Twirl will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, taking into account the nature of the processing and the information available to it.
11.3Audits
Article 28(3)(h). Twirl will make available to the Organizer all information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits.
- In the first instance Twirl will satisfy this by providing documentation: this agreement, the subprocessor list, Annex 2, the Privacy Policy, and written answers to a reasonable security questionnaire.
- Where that is genuinely insufficient for the Organizer to meet a regulatory obligation, an audit may be carried out no more than once in any 12 month period, on 30 days' written notice, during business hours, subject to confidentiality, and in a manner that does not disrupt the Services or compromise other customers' data.
- The Organizer bears its own audit costs and Twirl's reasonable costs of participation, unless the audit reveals a material breach by Twirl.
- Twirl notes plainly that it is a two person company, that it does not hold ISO 27001 or SOC 2 certification, and that it does not intend to claim otherwise. Organizers with formal certification requirements should factor that in before purchasing.
12Deletion and return
Article 28(3)(g).
- At any time during the event window, the Organizer can export guest and RSVP data as a spreadsheet and download all content in bulk, without needing to ask.
- On expiry or termination of the event window, Twirl deletes all personal data processed under this agreement, in accordance with the window and end-of-window paths described in the Terms of Service.
- Deletion covers media objects at the storage provider and the corresponding database records. Encrypted backups may retain residual copies until they rotate out, currently within 30 days, during which they are not accessed except for disaster recovery.
- Twirl retains no personal data after that point except where Union or member state law requires retention, principally billing records under Dutch tax law, which are Twirl's own controller data rather than guest data.
- Twirl will confirm deletion in writing on request.
13Term
This agreement takes effect when the Organizer accepts the Terms of Service and continues for as long as Twirl processes personal data on the Organizer's behalf. Sections 6, 10, 12 and 14 survive termination for as long as is necessary to give them effect.
14Liability
- Each party's liability under this agreement is subject to the limitations in the Terms of Service, except where those limitations are not permitted by law.
- Nothing in this agreement limits either party's liability to a data subject under Article 82 of the GDPR, which cannot be contracted away.
- Where both parties are responsible for damage caused by processing, liability is apportioned according to each party's responsibility, as provided in Article 82(5).
- Nothing here limits liability for intent or deliberate recklessness, or for anything else that cannot lawfully be limited.
15Governing law
This agreement is governed by the law of the Netherlands. Disputes are subject to the jurisdiction provisions in the Terms of Service. Where the Standard Contractual Clauses apply to a particular transfer, their own governing law and jurisdiction provisions govern that transfer.
16Contact
Data protection matters, including subprocessor objections and audit requests: privacy@twirl.photos.
Annex 1details of processing
Required by Article 28(3).
| Item | Detail |
|---|---|
| Subject matter | Provision of an event photo sharing and RSVP service, comprising a password-protected gallery for guest uploads, an RSVP system, a programme, guest management, moderation tools and bulk download |
| Duration | The event window: two months from the first upload under the base package, plus any extensions purchased. Followed by deletion in accordance with section 12. |
| Nature of processing | Collection, recording, organisation, structuring, storage, adaptation (including thumbnail generation, resizing and transcoding), retrieval, consultation, use, transmission to the Organizer and to other guests as configured, restriction, erasure and destruction |
| Purpose | Enabling guests to contribute photographs, videos and voice memos to a private event gallery; enabling guests to RSVP and answer questions set by the Organizer; enabling the Organizer to manage, moderate, download and delete that content |
| Categories of data subjects | Guests invited to the event; people depicted or recorded in uploaded content, including people who are not guests; children present at the event; co-hosts appointed by the Organizer |
| Types of personal data | Names entered at upload or RSVP; email addresses and other contact details where the Organizer enters them; photographs, videos and voice memos, including embedded metadata such as timestamps, device information and, where present, location data; RSVP responses including attendance, plus-one details and answers to custom questions; content flags and any reason given; technical data including IP address, browser and device type and timestamps |
| Special categories of personal data | Not intentionally collected. May arise incidentally, in particular through dietary or meal-choice answers that reveal religious belief or health information, and through images that reveal racial or ethnic origin, religious belief or health information. The Organizer is responsible for identifying and lawfully handling these. Twirl applies the same access controls as to all other data and processes them for no purpose other than displaying them to the Organizer. |
| Voice memos | Unlike photographs and videos, a voice memo recorded through the in-app recorder exists nowhere other than in Twirl and cannot be re-collected from a guest device. This is reflected in section 15.3 of the Terms of Service. |
| Data concerning children | Photographs and recordings of children present at the event are expected. The Organizer is responsible for the basis on which they are collected and displayed. Twirl performs no facial recognition, biometric matching or age estimation on any content. |
| Frequency of transfer | Continuous, for the duration of the event window |
Annex 2technical and organisational measures
Article 32. A summary rather than an exhaustive description, since a complete description of security measures is itself a security risk.
| Area | Measures |
|---|---|
| Encryption in transit | TLS on all connections to the application, the database, the storage provider and all subprocessor APIs |
| Encryption at rest | Database and object storage encrypted at rest by the respective providers, both located in Frankfurt, Germany |
| Access control, organizers | Password authentication with hashed credentials. Passwords are never stored in recoverable form and are not visible to Twirl. |
| Access control, guests | Event-level shared password. Galleries are unlisted, excluded from search engine indexing, and inaccessible without the event link and password. |
| Access control, media | Media is served through time-limited signed URLs rather than permanently public addresses |
| Data isolation | Row-level security policies in the database restrict access to data within the scope of a single event |
| Internal access | Restricted to the two founders. Multi-factor authentication on all administrative accounts. Access is used for operations and support, not for routine review of customer content. |
| Logging and monitoring | Authentication events and security-relevant access logged and retained for 90 days. Error and crash monitoring through Sentry, configured to exclude media content. |
| Resilience and recovery | Database backups maintained by Supabase with point-in-time recovery. Object storage redundancy per OVHcloud's standard offering. Backups rotate fully within 30 days. |
| Vulnerability management | Dependencies monitored for known vulnerabilities and patched. Security updates applied promptly. |
| Abuse prevention | Rate limiting on authentication, upload and API endpoints. Guest flagging with escalation to the Organizer. |
| Deletion | Automated deletion at the end of the event window, covering both storage objects and database records, with confirmation available on request |
| Subprocessor management | Written Article 28 agreements with every subprocessor. Published subprocessor list with 30 day change notice. |
| Personnel | Access limited to the founders, who are bound by confidentiality as partners in the firm. No external staff have production access. |
| Testing and review | Measures reviewed when the architecture changes and at least annually. |
Annex 3authorised subprocessors
Current as at 19 August 2026. The authoritative and current version is maintained at where your photos live, and the full standalone list carries additional detail.
| Subprocessor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Vercel Inc. / Vercel EU | Application hosting, content delivery, serverless execution | EU regions. US parent company. | EEA processing. SCCs and Data Privacy Framework for any US access. |
| Supabase Inc. | Database and organizer authentication | EU, Germany (eu-central-1) | EEA processing. SCCs for any US access. |
| OVH SAS | Object storage for photographs, videos and voice memos | EU, Germany (Frankfurt) | EEA processing. No transfer mechanism required. |
| Stripe Payments Europe Ltd | Payment processing, tax calculation, invoicing | Ireland, with group entities elsewhere | EEA processing. SCCs and Data Privacy Framework for onward transfers. |
| Sendinblue SAS (Brevo) | Transactional and lifecycle email. Open and click tracking disabled. | EU, France | EEA processing |
| Functional Software Inc. (Sentry) | Error and crash diagnostics. Configured to exclude media content. Session Replay disabled. | EU region (confirmed). US parent company. | SCCs and Data Privacy Framework |
| [Analytics provider] | Traffic counting on public marketing pages only. Not used inside the product. | EU | EEA processing |
| Google Ireland Ltd | Business email for hello@ and privacy@twirl.photos | EU, with group entities elsewhere | SCCs and Data Privacy Framework |
Media and database are both in Frankfurt, Germany. Any future change of subprocessor will be notified under section 7.3 with the full 30 day notice period, and the published list will be updated before the change takes effect. Media storage will not be moved outside the European Economic Area.
