?where @re you ?
МакедонскиBack to home

Legal

Data Processing Agreement

Last updated: 6 October 2026 · Version 1.2

This agreement is made under the Law on Personal Data Protection (Official Gazette of the Republic of North Macedonia No. 42/2020) and, where applicable, Article 28 of the General Data Protection Regulation (EU) 2016/679 (GDPR). It forms part of the platform's Terms of Service.

This document is published in Macedonian and English. In case of a difference, the Macedonian version prevails.

Contents

  1. Parties
  2. Subject matter and duration
  3. Nature and purpose of processing
  4. Categories of data subjects and data
  5. Venue's obligations
  6. Processor's obligations
  7. Security measures
  8. Sub-processors
  9. Assistance with data subjects' rights
  10. Deletion and return of data
  11. Personal data breach
  12. Audits
  13. Final provisions
  14. Acceptance

1. Parties

  • Controller: the venue that registered an account on the platform and accepted the Terms of Service, with the details entered in the account ("the venue").
  • Processor: GoDevLab Agency (godevlabagency.com), privacy contact: support@kadesi.mk ("the processor").

2. Subject matter and duration

The processor provides the Каде си? platform to the venue and, in doing so, processes the personal data entered by the venue and by its clients through the tools the venue makes available to them as part of its service (guest list, invitation, notes, budget and other planning tools), and the data guests enter through the invitation link. The venue's staff do not see the guest list or the client's planning content in the panel, but the venue can export or erase it.

This agreement applies for as long as the processor provides the service to the venue; the deletion obligations (section "Deletion and return of data") survive termination. Data about the venue's staff accounts, contact-form messages and security records are not covered by this agreement: for those the processor is the controller (see the Privacy Policy).

3. Nature and purpose of processing

  • Nature: storing, displaying, transmitting, backing up, exporting and erasing data in the platform.
  • Purpose: providing the platform's features: events and clients, reservations, table layouts, guest lists, digital invitations and answers through a link, the clients' planning tools (notes, agenda, locations, budget, to-do list), a photo portfolio.
  • The processor does not use the data for its own purposes, does not sell it and does not use it for advertising.

4. Categories of data subjects and data

Data subjectsData
Venue clients (couples, organizers)Names; date, time and type of the event; contact email and phone; total price and deposit paid (a record, no payment processing); username and password (hash only); sign-in session (hash only); notes, agenda, locations (possibly a private address), budget, to-do list; invitation text and photo; table labels.
GuestsFull name; phone (optional); party size; invitation answer; side; notes; time of the last change of the answer through the link and the previous answer.
Reservation customersName; phone; email (optional); date and time; party size; event type; note.
People in event photosPhotos in the venue's portfolio.
Third parties named in free textNames and contact details of vendors, family members and similar.

Special categories: the notes fields may contain data about health or religious beliefs (diet, allergies, access needs). The venue is responsible for these being entered only when needed, with the data subject's explicit consent or on another ground of Art. 9(2) GDPR or the corresponding provision of the Law on Personal Data Protection.

5. Venue's obligations

The venue ensures a legal basis for the processing, informs its clients and guests (and instructs its clients to inform their guests), gives only lawful instructions and uses the tools in the settings for data subjects' requests.

6. Processor's obligations

  • Processes the data only on the venue's documented instructions, including with regard to transfers to third countries, unless required to do so by law; in that case it informs the venue before processing unless the law prohibits it. The instructions are this agreement, the Terms of Service and the venue's actions in the platform. If it believes an instruction infringes the law, it informs the venue immediately.
  • Ensures that the people authorised to process the data are bound by confidentiality.
  • Applies the security measures in this agreement.
  • Engages sub-processors only under this agreement.
  • Assists the venue with data subjects' requests, with the security of processing, with breach notification, with data protection impact assessments and with prior consultation of the supervisory authority.
  • Keeps a record of the processing activities it carries out on the venue's behalf.
  • Deletes the data after termination under this agreement.
  • Gives the venue the information needed to demonstrate compliance and allows audits.

7. Security measures

  • EU hosting: database, sign-in and storage at Supabase in region eu-west-1 (Ireland); server functions at Vercel in region dub1 (Dublin).
  • Encryption in transit: all traffic uses HTTPS.
  • Separation between venues: Row Level Security in the database; every staff request is checked against the staff member's venue. The guest and planning tables have no browser access; they are reached only through the server, scoped to one event.
  • Passwords and sessions: passwords are stored only as a bcrypt hash, at least 10 characters. Client sessions are stored only as a SHA-256 hash and expire 30 days after last use. A client sign-in is locked for 15 minutes after 5 failed attempts.
  • Rate limiting for client sign-ins, sign-up, the contact form, answers and photo uploads; counters contain only a hash and are deleted after 1 day.
  • Append-only audit log of security-relevant actions, without names or contact details.
  • Public photos: listing of the storage is disabled; a photo opens only with its exact address. Photos are deleted when their record is deleted.
  • Error reports (Sentry, if enabled): configured to exclude request content, cookies, user identity and invitation links.
  • Backups: daily copies at Supabase (7 days) and nightly copies in Cloudflare R2 in the EU (35 days, planned), encrypted before upload.
  • Staff access control: only a small number of authorised people can access production data, and the list is reviewed regularly.
  • Data classification: an automated test does not allow a new database column unless it is marked as containing personal data or not.

8. Sub-processors

The venue gives general authorisation for the following sub-processors:

Sub-processorServiceDataLocationStatus
SupabaseDatabase, sign-in, storage, daily backupsAll data in this agreementEU, Ireland (eu-west-1)Active
VercelHosting and server functionsData in transit; request records (IP address, page address (URL), browser)EU, Dublin (dub1) for functionsActive
ResendSending emailRecipient email and message contentEUPlanned
SentryError monitoringTechnical description of the error, configured to exclude personal dataEU, FrankfurtPlanned, only if enabled
Cloudflare R2Off-site backupsAn encrypted copy of the database and the photosEUPlanned
GitHubRunning the nightly backup job (GitHub Actions)Temporarily, while the job runs: a copy of the database and the photos before encryptionDetermined by GitHubPlanned

The processor has a contract with each sub-processor with data protection obligations no less protective than these. It informs the venue of any added or replaced sub-processor in advance; the venue may object and, if no solution is found, may delete its account. The processor remains liable for its sub-processors as for itself.

Transfers outside the EU: the data is stored in the EU. The sub-processors are companies headquartered in the United States; when their staff access data from a country outside the EU, or when the backup job runs outside the EU, the safeguards in their data processing agreements apply (for example standard contractual clauses).

9. Assistance with data subjects' rights

  • In the venue settings: export of all the venue's data (JSON), erasure of an event's personal data (guests, notes, agenda, locations, budget, to-do list, invitation and photos, the client's sign-in data; a record of the event without names, contact details or guest data remains) and account deletion.
  • On the venue's request, the processor provides an export of the data of a single event (for a client's access request).
  • If the processor receives a request directly from a client or guest, it forwards it to the venue without undue delay and does not answer on its own, except on the venue's instructions.

10. Deletion and return of data

  • Before termination, the venue can export all its data.
  • When the service ends for any reason (account deletion, closure by the processor or end of the contract), the venue has 30 days to export its data, after which the processor deletes all personal data processed for the venue. On request the processor confirms the deletion in writing.
  • Account deletion by the venue is immediate and permanent: the venue, all events, clients, guests, reservations, photos and staff accounts are deleted. Only the audit-log entries remain, which contain internal identifiers without names or contact details.
  • Deleted data disappears from backups after 35 days at the latest (Supabase: 7 days; Cloudflare R2: 35 days). After any restore from a backup, the processor re-applies all erasures recorded in the audit log since the backup was made.
  • By default, and unless the venue asks for a different period by email, the venue instructs the processor to erase the personal data of an event's clients and guests automatically 12 months after the event date.
  • The processor keeps no copies unless the law requires it.

11. Personal data breach

The processor notifies the venue without undue delay and no later than 48 hours after becoming aware of a breach, by email to the venue's registered address and to any privacy contact the venue has given. The notice includes, as far as known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken and proposed, and a contact person. If not all information is available, it provides it in phases. The processor keeps a record of all breaches affecting the venue's data and helps the venue notify the Personal Data Protection Agency (Агенција за заштита на личните податоци) and the data subjects when required.

12. Audits

On request, the processor provides the information needed to demonstrate compliance with this agreement (including a description of the measures). The venue, or an auditor bound by confidentiality, may carry out an audit with reasonable prior notice, during business hours and without access to other venues' data. The venue bears the cost of the audit unless it reveals a material breach of this agreement.

13. Final provisions

Liability is governed by the Terms of Service; they do not limit the rights of the data subjects. This agreement is governed by the law of the Republic of North Macedonia, and disputes are decided by the competent court in the Republic of North Macedonia. If this agreement and the Terms of Service conflict on data protection, this agreement prevails.

14. Acceptance

This agreement is accepted electronically together with the Terms of Service at sign-up; the platform records the version and time of acceptance.

Privacy PolicyTerms of ServiceData Processing Agreement
© 2026 Каде си? All rights reserved.Managed by GoDevLab Agency