Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Biraea ("Processor") and the user ("Controller") who creates sites and collects personal data from visitors through the Biraea platform.
To request a countersigned copy of this DPA, contact privacy@hearthsites.com.
Parties
Controller: The user who has created an account on Biraea and uses the Service to create sites that collect personal data from visitors and guests.
Processor: Biraea, the operator of the Biraea platform, which processes personal data on behalf of the Controller.
Subject Matter and Duration
Subject matter: The processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Biraea platform services.
Duration: This DPA is effective for the duration of the Controller's use of the Service and terminates upon deletion of the Controller's account, subject to any data retention obligations described in the Privacy Policy.
Nature and Purpose of Processing
The Processor processes personal data for the purpose of providing the Biraea platform, including:
- Hosting and displaying visitor sites created by the Controller
- Processing RSVPs, messages, name suggestions, guesses, and other visitor submissions
- Managing guest lists and guest authentication
- Sending email and SMS notifications on behalf of the Controller
- Processing cash fund contributions through Stripe
- Running interactive games and storing game session data
Types of Personal Data
- Names (full name, first name, last name)
- Email addresses
- Phone numbers
- Mailing addresses
- Dietary restrictions and preferences
- RSVP responses and event attendance data
- Messages and guest book entries
- Payment information (processed by Stripe; Biraea does not store card numbers)
- IP addresses and browser metadata (for security and rate limiting)
Categories of Data Subjects
- Site owners (Controllers): Users who create accounts and build sites on Biraea
- Visitors and guests: Individuals who visit published sites and interact with site features (RSVPs, messages, guesses, meal train sign-ups, game participation, cash fund contributions)
Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorized to process personal data are subject to confidentiality obligations
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
- Not engage another processor (sub-processor) without prior specific or general written authorization of the Controller
- Assist the Controller in responding to data subject access requests, erasure requests, and other rights under GDPR
- Delete or return all personal data to the Controller upon termination of services, and delete existing copies unless storage is required by law
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in GDPR Article 28
- Allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller
- Immediately inform the Controller if, in the Processor's opinion, an instruction infringes GDPR or other data protection provisions
Authorized Sub-Processors
The following sub-processors are authorized to process personal data on behalf of Biraea:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting, CDN, serverless compute | United States |
| Brevo (Sendinblue) | Transactional email and SMS delivery | European Union |
| Stripe Inc. | Payment processing for cash fund contributions and shop purchases | United States |
The Controller generally authorizes Biraea to engage the above sub-processors. Biraea will notify the Controller of any intended changes to this list, giving the Controller the opportunity to object.
Data Breach Notification
The Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach. The notification shall include:
- A description of the nature of the breach, including categories and approximate number of data subjects and records concerned
- Contact details for obtaining more information
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach
International Data Transfers
Where personal data is transferred outside the European Economic Area, the Processor shall ensure that appropriate safeguards are in place, including:
- EU-U.S. Data Privacy Framework certification (where applicable)
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
Request a Countersigned Copy
To request a countersigned copy of this DPA, contact our privacy team.
privacy@hearthsites.com