Skip to main content

Data Processing Agreement

GDPR Article 28 Compliant

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Biraea ("Processor") and the user ("Controller") who creates sites and collects personal data from visitors through the Biraea platform.

To request a countersigned copy of this DPA, contact privacy@hearthsites.com.

1

Parties

Controller: The user who has created an account on Biraea and uses the Service to create sites that collect personal data from visitors and guests.

Processor: Biraea, the operator of the Biraea platform, which processes personal data on behalf of the Controller.

2

Subject Matter and Duration

Subject matter: The processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Biraea platform services.

Duration: This DPA is effective for the duration of the Controller's use of the Service and terminates upon deletion of the Controller's account, subject to any data retention obligations described in the Privacy Policy.

3

Nature and Purpose of Processing

The Processor processes personal data for the purpose of providing the Biraea platform, including:

  • Hosting and displaying visitor sites created by the Controller
  • Processing RSVPs, messages, name suggestions, guesses, and other visitor submissions
  • Managing guest lists and guest authentication
  • Sending email and SMS notifications on behalf of the Controller
  • Processing cash fund contributions through Stripe
  • Running interactive games and storing game session data
4

Types of Personal Data

  • Names (full name, first name, last name)
  • Email addresses
  • Phone numbers
  • Mailing addresses
  • Dietary restrictions and preferences
  • RSVP responses and event attendance data
  • Messages and guest book entries
  • Payment information (processed by Stripe; Biraea does not store card numbers)
  • IP addresses and browser metadata (for security and rate limiting)
5

Categories of Data Subjects

  • Site owners (Controllers): Users who create accounts and build sites on Biraea
  • Visitors and guests: Individuals who visit published sites and interact with site features (RSVPs, messages, guesses, meal train sign-ups, game participation, cash fund contributions)
6

Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller, unless required by law
  • Ensure that persons authorized to process personal data are subject to confidentiality obligations
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
  • Not engage another processor (sub-processor) without prior specific or general written authorization of the Controller
  • Assist the Controller in responding to data subject access requests, erasure requests, and other rights under GDPR
  • Delete or return all personal data to the Controller upon termination of services, and delete existing copies unless storage is required by law
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28
  • Allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller
  • Immediately inform the Controller if, in the Processor's opinion, an instruction infringes GDPR or other data protection provisions
7

Authorized Sub-Processors

The following sub-processors are authorized to process personal data on behalf of Biraea:

Sub-ProcessorPurposeLocation
Vercel Inc.Hosting, CDN, serverless computeUnited States
Brevo (Sendinblue)Transactional email and SMS deliveryEuropean Union
Stripe Inc.Payment processing for cash fund contributions and shop purchasesUnited States

The Controller generally authorizes Biraea to engage the above sub-processors. Biraea will notify the Controller of any intended changes to this list, giving the Controller the opportunity to object.

8

Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach. The notification shall include:

  • A description of the nature of the breach, including categories and approximate number of data subjects and records concerned
  • Contact details for obtaining more information
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach
9

International Data Transfers

Where personal data is transferred outside the European Economic Area, the Processor shall ensure that appropriate safeguards are in place, including:

  • EU-U.S. Data Privacy Framework certification (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission

Request a Countersigned Copy

To request a countersigned copy of this DPA, contact our privacy team.

privacy@hearthsites.com