1. Who we are
Ode Events is a trading name of Laramattix Ltd, registered in Scotland (company number SC884319), with a registered office at Office 2/3 48 West George Street, Glasgow, United Kingdom, G2 1BP. We are registered with the Information Commissioner's Office (ICO registration number ZC115769).
For the purpose of UK GDPR, we act as a data controller for account and billing data. When processing guest and event data created by organisers, we act as a data processor on behalf of event organisers, who are the data controllers for their own event data (photos, RSVPs, guestbook messages, music requests and gift registry claims).
Ode Business accounts. Where a business (a venue, planner or other supplier) runs events on an Ode Business account, that business is the data controller for the events on it and we are its processor for the guest and event data those events hold. Everyone the business has on its team can open every event on the account, including guest lists, RSVP replies, seating plans and photo albums. Where a couple is invited onto one of those events as a co-organiser, the business and the couple both control that event’s data. We remain the controller for the business’s own account and billing data. If you are a guest or a couple and want to exercise your rights over an event run by a business, contact that business first.
If you have a question about how your data is used within a specific event, including requests to access, correct, or delete content you uploaded, please contact the event organiser directly. For questions about the platform itself, contact us at hello@ode.events.
We are not required to appoint a Data Protection Officer under UK GDPR and have not done so. For any data protection queries, you can reach us at hello@ode.events.
2. Data we collect
Account holders (organisers):
- Email address and display name (required for signup)
- Payment information (processed by Stripe; we do not store card details)
- Event data you create (pages, settings, content)
- If you buy Set up for you: the details you email us to build your event (your wording, venue and schedule, photos, menus and your guest list). We use these only to build your event, they are held in our email account and entered into your event, and we delete the emails and attachments after handover. Guest names you send us are processed on the same basis as any guest list you enter yourself.
Ode Business accounts:
- The business name you choose, which is shown to its team
- Who is on the team, their role, and the email addresses invited to join it
- Subscription and billing records (plan, status, invoices and photo top-ups; card details are processed by Stripe and are not stored by us)
- A record of each album added to an event from the account’s photo pool, kept as a billing record after the event is deleted
Guests (non-account users):
- Photos you upload, and the name you choose to attach to them (optional)
- RSVP responses (attendance status, meal choices, plus-one names)
- Guestbook messages and music requests, with the name you enter (optional)
- Gift registry claims, with the name you enter where the organiser asks for one
- Access cookie: for password-protected events only, a cookie stored in your browser that remembers you entered the password. It contains no personal data and does not identify you.
- Browser storage: your browser keeps a copy of the RSVP you sent for the current tab only, so the page can show it back to you. It never leaves your device (see Section 7).
Children:
This service is not directed at children under 16. You must be at least 16 years old to create an account or use the service. If we become aware that data from a user under 16 has been collected, we will delete it promptly. To report a concern, email hello@ode.events.
Data we do not collect:
We do not collect IP addresses beyond standard server logs, location data, device fingerprints, or browsing history. We do not use third-party analytics. The only advertising tracker we use is the Meta Pixel, and it is loaded only after you accept optional cookies on our banner (see Section 7); if you decline, no tracking of any kind takes place. Organisers can see how many times their event page was opened each day; that is a single number per event per day, counted on our server with no cookie, IP address or other identifier stored.
3. How we use your data and our lawful basis
We only process personal data where we have a lawful basis to do so under UK GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)): processing organiser account data, event data, and payments to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)): processing guest data (alias, photos, RSVPs) to enable participation in events created by organisers. Our legitimate interest is providing the functionality guests access when joining an event. This processing is limited to what is necessary and guests retain full rights described in Section 6. A Legitimate Interests Assessment (LIA) has been carried out and is available on request.
- Legal obligation (Art. 6(1)(c)): retaining billing records where required by tax or financial regulations.
We may also use the email address you provide at sign-up to send you occasional product updates and promotional offers from Ode Events. This is done on the basis of our legitimate interests (Art. 6(1)(f)) under the UK PECR soft opt-in, as you are an existing customer and the communications relate directly to similar services. You can unsubscribe at any time using the link in any email we send, or by emailing hello@ode.events.
We do not rely on consent as a lawful basis for any other processing activity described in this policy. If you wish to stop your data being processed, your relevant right is the right to erasure or the right to object, both described in Section 6.
We do not carry out automated profiling that produces legal or similarly significant effects on individuals. We do use automated image analysis to detect and remove prohibited content at the point of upload; this is described in Section 4.
We do not sell your data, use it for advertising, or share it with third parties except as required to operate the service (see Section 8).
4. Photos and uploaded content
Event organisers are the data controllers for content uploaded to their events. By uploading photos to an event, you confirm that you have the right to share them. You should not upload photos of identifiable individuals who have not consented to their image being shared with the event's guests.
Photos may incidentally contain special category personal data within the meaning of UK GDPR Article 9: for example, images that reveal health conditions, religion, or ethnicity. We do not process such data for those purposes; it is stored and displayed exactly as uploaded. The uploading guest's act of sharing the photo constitutes their explicit consent to that content being visible to other event guests, and organisers are reminded of their responsibility not to share images of individuals without appropriate consent.
If you are a person who appears in a photo and wish to exercise your data subject rights (including erasure), you should contact the event organiser, who is responsible for responding to such requests. If you cannot reach the organiser or believe your rights are not being respected, you may contact us at hello@ode.events and we will assist in escalating the request.
Photos uploaded to the platform are currently scanned for inappropriate or illegal content using AWS Rekognition, an image analysis service provided by Amazon Web Services, Inc. This scan takes place at the point of upload, before any photo is displayed to event guests. Images identified as containing explicit nudity, graphic violence, visually disturbing content, or hate symbols are automatically removed and are not stored or displayed. Image data is transmitted to AWS Rekognition solely for the purpose of this analysis and is not retained by AWS beyond the duration of the request. This processing is carried out on the basis of our legitimate interest in preventing the distribution of harmful or illegal content through the platform (Art. 6(1)(f) UK GDPR). We may change or disable this scanning at any time; responsibility for the content in an event rests with its organiser, and organisers can hold every photo for their own approval by enabling manual moderation.
Photos are stored securely and are visible only to people who hold the event's link. If the organiser sets a password, viewers must also enter that password. Organisers should treat the link accordingly. Event organisers can delete individual photos or entire events at any time through the dashboard.
5. Data retention
The following rules govern how long we retain event and personal data:
- Event photos: photos and associated files are permanently deleted when the album window for your plan expires. The album window is calculated as the album open date plus the storage period for your plan (from 7 days to 6 months on current plans; some older plans had a 1-year window). Deletion is scheduled automatically and normally completes within a few days of the window closing. We email the organiser before it happens. The event page and all other data are not deleted at that point.
- All other event data (seating plans, guestbook entries, music requests, gift registry claims, and settings) is permanently deleted approximately 1 year after the event date, but only once the album window has also expired. If no album window was set, deletion occurs approximately 1 year after the event date. Unpaid events with no date set are deleted approximately 1 year after creation. Paid events with no date set are not automatically deleted. Events on an Ode Business account follow these rules like any other event; the subscription does not extend them.
- RSVP responses are deleted approximately 90 days after the event start date at the time of submission, regardless of other retention windows. If no event date was set, RSVP responses are deleted when the event itself is deleted under its retention policy.
Retention periods describe when data becomes due for deletion. Deletions are processed automatically in scheduled batches, so data may remain in our systems for a short period after the stated retention period before removal completes.
Organisers can delete their entire event and all associated data at any time from the dashboard, regardless of the retention period. When an organiser deletes an event, all associated data, including guest photos and RSVP responses, is permanently deleted.
Ode Business account records (the business name, its team and their roles, and its subscription history) are kept while the account exists and are deleted when it is closed, apart from billing records, which are kept for the period set out below. Events on the account are not deleted when a subscription ends; they follow the retention rules above like any other event.
Account data (email, display name) is retained until you delete your account. You can delete your account at any time from your account settings, or by emailing hello@ode.events. Deleting your account permanently deletes all events you own and all associated data, including any active paid events. This action is irreversible and no refund will be issued.
Financial and billing records are retained for a minimum of 6 years from the end of the relevant accounting period, as required by UK tax law. This obligation applies independently of account deletion: deleting your account removes your login credentials and personal profile but does not erase billing records that we are legally required to keep.
Organiser responsibilities: where organisers act as data controllers for their event data, they are responsible for providing their own privacy notice to guests. By activating an event on this platform, organisers acknowledge this responsibility.
6. Your rights (UK GDPR)
You have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: ask us to correct inaccurate data
- Erasure: ask us to delete your personal data (“right to be forgotten”)
- Restriction: ask us to limit how we process your data
- Portability: receive your data in a structured, machine-readable format. This right applies to data processed under contract or consent (primarily organiser account data). It does not apply to guest data processed under legitimate interests. However, if you are a guest and cannot exercise the right to portability, you can still request a copy of your data under the right of access above, and we will provide it in a readable format on request.
- Object: object to processing based on legitimate interests
Guests: the organiser of the event can delete any photo, RSVP, guestbook message, music request or gift claim from their dashboard, so the quickest route is to ask them. You can also email us directly.
All requests: email hello@ode.events. If you submitted data as a guest without creating an account, please include the event name, the approximate date of your submission, and the name or alias you used, and we will use these details to locate and verify your data before acting on any request.
We will respond within one calendar month of receiving your request. In complex or high-volume cases, we may extend this by a further two months; we will notify you within the first month if an extension is needed and explain why.
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
8. Third-party services and data processors
We share data with the following third-party processors, each covered by a Data Processing Agreement (DPA) or equivalent contractual safeguard:
- Supabase: database, file storage and organiser sign-in, including the account confirmation and password reset emails. Our primary database and file storage are hosted in the EU (Ireland). Supabase Inc. is a US-based company and may access data for support and infrastructure purposes under Standard Contractual Clauses (SCCs) with a UK Addendum (IDTA).
- Stripe: payment processing (PCI-DSS compliant; card details are not passed to or stored by us). Data may be transferred to the US under the UK-US Data Bridge and SCCs.
- Vercel: hosting and CDN (application code and edge functions). Data may be transferred to the US under the UK-US Data Bridge and SCCs.
- Resend: transactional email to organisers (welcome email, payment confirmations, co-organiser invitations, notices before photos or events are deleted) and occasional marketing broadcasts to account holders. Account confirmation and password reset emails are sent by Supabase Auth (see above). Data may be transferred to the US under Standard Contractual Clauses (SCCs) with a UK Addendum (IDTA).
- Amazon Web Services, Inc. (AWS Rekognition): automated image content moderation. Uploaded photos are transmitted to AWS Rekognition for analysis to detect prohibited content. Images are not stored by AWS beyond the duration of the request. AWS is a US-based company; transfers are made under Standard Contractual Clauses (SCCs) with a UK Addendum (IDTA).
- Meta Platforms Ireland Ltd: advertising attribution and retargeting via the Meta Pixel (Facebook/Instagram), only where you have consented to marketing cookies. Hashed event data (page views, sign-ups) is transmitted to Meta to measure ad effectiveness and build advertising audiences. Data may be transferred to the US under the UK-US Data Bridge and SCCs. Meta's processing of this data is subject to their own privacy policy. This processor is only active for users who have accepted optional cookies.
All international transfers are made in compliance with UK GDPR Chapter V. Where adequacy decisions do not apply, we rely on Standard Contractual Clauses (SCCs) approved under the UK International Data Transfer Agreement (IDTA) or the UK-US Data Bridge, as applicable to each processor.
9. Security and breach notification
We maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure. These include encrypted data storage, access controls, and regular security reviews.
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected individuals without undue delay. We will report notifiable breaches to the ICO within 72 hours of becoming aware of them, as required by UK GDPR Article 33.
To report a suspected security vulnerability, email hello@ode.events.
10. Contact
Questions about this policy? Email us at hello@ode.events.