Data protection
Privacy policy
Cachet handles two very different kinds of data: that of the hosts preparing an event, and that of the guests replying to an invitation. This document explains, for each of them, what we collect, why, for how long, and how to take back control.
Last updated — 12 août 2026
Who is responsible
Unless stated otherwise below, the controller is:
- Registered name
- GMC Information Technology SRL
- Registered office
- Gordelstraat 87, 3401 Waasmont (Landen), Belgique
- Data protection contact
- [[EMAIL_RGPD]]
- Data protection officer
- [[DPO]]
Two roles, depending on the data
For the data of our customers — the hosts who open an account, prepare an invitation and order a plan — we are the controller: we decide what is collected and why.
For guest data, it is the host who chooses the list, the questions asked and the moment of deletion. The host is the controller; we act solely as a processor, on the host’s instructions. The mutual undertakings are set out in the terms and conditions of sale.
Host data
- Account
- Display name, email address, and a password kept only as a non-reversible hash; or the identifier of your Google account if you sign in that way.
- Event
- Title, date, venue, texts, images, schedule and guest list that you enter.
- Order
- Plan and options chosen, amount, date, payment status and transaction reference. Card numbers never pass through our servers: they are entered directly with our payment provider.
- Support
- The content of the messages you send us and our reply.
- Technical logs
- IP address, timestamp, browser type and pages viewed, strictly necessary for security and for diagnosing incidents.
Guest data
A guest has no account and enters nothing beyond what the host asks for. Depending on how the form is configured, this may include:
- their name and, where applicable, the names of the people accompanying them;
- their email address or telephone number, where the host wishes to be able to reach them;
- their reply to the invitation and their attendance at the various moments of the programme;
- their menu choice, allergies or dietary requirements;
- a free-text message to the hosts;
- the photos and voice messages they choose to share in the big-day gallery, when the host has enabled it — technical photo metadata, including location, is stripped on arrival;
- the language detected by their browser, so that the invitation can be shown to them in their own language.
The invitation link is shared by the household: anyone holding it can view the replies already sent from that same link. Each household receives its own link, never anyone else’s.
An allergy or a dietary requirement may reveal health data or a personal conviction. These questions are only asked if the host enables them, answering remains optional, the answer is visible to the host alone, and it is used solely to organise the meal. A guest who would rather not say can reply to the invitation without filling anything in.
Purposes and legal bases
- Providing the service ordered
- Performance of the contract concluded with the host — creating the invitation, publishing it, collecting the responses.
- Ordering, payment and invoicing
- Performance of the contract, then the legal obligation to retain accounting records.
- Account and support
- Performance of the contract and our legitimate interest in answering your requests properly.
- Collecting a guest’s reply
- The legitimate interest of the host, on whose behalf we act, in organising their event. Replying always remains optional.
- Allergies, diets and other sensitive data
- The guest’s explicit consent, given by filling in the field, and revocable at any time.
- Sending invitations and reminders
- The host’s legitimate interest, and only where the sending option has been purchased. Every message allows the recipient to opt out of reminders.
- Security and fraud prevention
- Our legitimate interest in protecting the service, its hosts and their guests.
Who has access to this data
Your data is never sold, rented or exchanged, and never serves any advertising purpose. It is accessible:
- to the host of the event, for the replies of their guests;
- to authorised staff of the publisher, strictly within what their duties require;
- to the processors listed below, bound by contract and held to the same obligations;
- to an administrative or judicial authority, on a duly issued request.
- Stripe
- Collection of payments and invoicing. Receives only the data required for the transaction; card details are entered with Stripe, never with us.
- [[HEBERGEUR]]
- Hosting of the application servers, the database and the backups, within the European Union.
- Brevo (Sendinblue SAS, France) — envoi des e-mails transactionnels
- Delivery of the service emails — account confirmation, order receipt, and invitations where the sending option has been purchased.
- Brevo (Sendinblue SAS, France) — envoi des SMS transactionnels
- Delivery of text messages, only where the host purchases the SMS sending option.
Retention periods
- Host account
- For as long as the account exists, then three months after its deletion, so that any complaint can be handled.
- Invitation content
- Until deleted at the host’s request, and in any event no later than the closure of the event.
- Guest responses
- 12 mois after the date of the event — big-day photos and messages included — or immediately, as soon as the host asks for it.
- Drafts never activated
- Deleted after six months of inactivity — the host is notified by email thirty days beforehand, and any modification keeps the draft.
- Invoices and accounting records
- Ten years, in accordance with accounting and tax obligations.
- Technical logs
- Twelve months at most.
- Support messages
- Three years after the last exchange.
A host may at any time ask for their guests’ responses to be deleted immediately, from their own area or by a simple email. Deletion is final and propagates to the backups within thirty days.
Transfers outside the European Union
The servers, the database and the backups are located in the European Union. In the normal operation of the service, no host or guest data is transferred outside the Union.
Our payment provider may, in order to combat fraud and to meet its own regulatory obligations, process certain transaction data from a third country. Such transfers are then covered by the European Commission’s standard contractual clauses. They never concern your guests’ responses.
Security
Exchanges with the service are encrypted in transit, passwords are never stored in clear text, internal access is named and restricted, and the backups are encrypted. The link to an invitation contains a personal code that acts as an access key: it should only be passed on to the people concerned.
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw consent at any time — without affecting the lawfulness of what was done beforehand.
To exercise them, write to[[EMAIL_RGPD]]. We reply within one month. Proof of identity may be requested where there is reasonable doubt as to the identity of the person making the request.
If you are a guest and would like your reply corrected or erased, please contact the host who invited you first: it is the host who decides what happens to that data. Write to us if you cannot reach them — we will pass your request on and, if the host does not act, we will deal with it ourselves.
Lastly, you may lodge a complaint with the competent supervisory authority: l’Autorité de protection des données (APD), Rue de la Presse 35, 1000 Bruxelles — www.autoriteprotectiondonnees.be.
Cookies
The site uses only cookies that are strictly necessary for it to work. It sets no advertising cookie, no third-party analytics tracker, no social network button and no profiling.
cachet.auth- Session cookie for the hosts’ area. Set when you sign in, it keeps the session authenticated. It is encrypted, inaccessible to JavaScript, limited to our own domain, and expires at the end of the session — or after thirty days if you ask to stay signed in.
cachet.consent.v1- Your answer to the audience-measurement question, kept in your browser (local storage) for six months. It is never sent to us: it only serves to avoid asking you again, and to load nothing if you declined.
_ga,_ga_*- Google Analytics 4 (Google Ireland Limited) — audience measurement. These cookies are set only after your explicit consent : as long as you have not answered, or if you declined, Google's script is not even loaded and no request leaves for its servers. The IP address is anonymised, advertising signals and personalisation are switched off. Duration: up to two years.
The session cookie is strictly necessary to provide a service you expressly request: it is exempt from prior consent. Audience measurement is not — which is why you are asked, and why declining is as simple as accepting.
You can change your mind at any time through the “Cookies” link in the footer: it reopens the question, and declining removes the measurement for later visits.
No audience measurement follows the guests. An invitation opened from a personal link loads no third-party tool and shows no banner: it is the couple's mail, not a page of our site.
Changes to this document
This document may change along with the service or the applicable regulation. The date of the last update appears at the top of the page. Where a change is substantial, hosts holding an account are informed by email before it takes effect.