Privacy policy of the Luxevent portal and the LXVNT planner
Translation and the Bulgarian text. This is an English translation of the privacy policy, which is originally written in Bulgarian. If there is any difference or inconsistency between the English text and the Bulgarian text, the Bulgarian text prevails.
This policy explains how Luxevent Studio LTD (Луксевент Студио ЕООД) processes personal data in the client portal and the digital planner at mywedding.luxevent.bg (and, once the planner has moved, at my.lxvnt.bg), including personal invitations, event websites and shared albums. It applies to:
- clients (couples and event hosts) and their partners with access to the planner – both clients of the Luxevent agency and those who have signed up on their own and use the planner with a trial or a paid plan;
- buyers of gift vouchers;
- guests of events: the people whom hosts invite through the portal;
- visitors to an event website, authors of wishes and people who upload photos to a shared album;
- suppliers of the event (photographers, musicians and others) whose details are entered in the planner;
- people who have joined the LXVNT waiting list.
1. Who processes your data
Luxevent Studio LTD (Луксевент Студио ЕООД), UIC (ЕИК) 205889153, VAT No BG205889153, registered office and address of management: гр. Русе, ул. Ради Иванов 1, manager Ayredin Ayriev, telephone +359 883493842.
Luxevent and LXVNT are brands of the same company. Wherever this policy says “LXVNT”, the controller of the data is the same company.
For any question about personal data, write to info@luxevent.bg or to the address above.
For the data in the portal we are the controller within the meaning of Regulation (EU) 2016/679 (GDPR). Guests’ data is provided to us by the hosts of the event: they decide whom to invite. The portal, the storage, the sending of invitations and the retention periods, however, are ours. We are therefore responsible for this data and for your rights in relation to it.
If you are a client of another agency that uses the planner under its own brand or at its own address, the controller of your data is that agency. We process your data only on its instructions (as a processor) and this policy does not apply to you – please read the agency’s policy.
2. What data we process, why and on what basis
2.1. Clients and partners
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, password (only a cryptographic hash is stored) | account and sign-in | contract or steps taken before entering into it (Article 6(1)(b) GDPR) |
| Data from the enquiry: names, date, venue, number of guests, contact person, telephone, email, wishes, colours, sample photos | preparing a proposal | Article 6(1)(b) |
| Proposals and their electronic acceptance: names as a signature, date and time, IP address; when you opened the proposal | entering into and proving the contract | Article 6(1)(b) and (f) (legitimate interest in proving acceptance in a dispute) |
| Payments: amounts, dates, method of payment | performance of the contract, accounting | Article 6(1)(b) and (c) (legal obligation) |
| Data in the planner: event, budget, tasks, meetings, ideas, questionnaires, messages, documents, suppliers, day schedule, invitation, website | the “digital planner” service | Article 6(1)(b) |
| Email notifications and reminders (payments, meetings, weekly overview) | performance of the service | Article 6(1)(b); the weekly overview can be switched off in the “Event” section |
| Request for feedback after the event | improving our services | legitimate interest (Article 6(1)(f)); you may decline at any time |
| Technical records: who changed what and when; limiting of sign-in attempts | security | Article 6(1)(f) and Article 32 GDPR |
If you sent an enquiry through the LXVNT website (photo booths), it is passed to the portal. An account with your email address is created there automatically so that you can see and accept your proposal.
2.2. Guests
The hosts of the event provide us with: your name, the form of address used in the invitation, the side (the bride’s or the groom’s), group, email and telephone (if they have entered them), the number of people coming with you, and notes.
When you reply to the invitation, we record: whether you will attend, the number of adults and children, the names and menu choices of the people coming with you and of the children that you have stated, your chosen menu, your message and when you replied. We also record whether and when the invitation was sent and opened, so that the hosts know who has seen it. If the hosts assign guests to tables, we also keep your table.
- Purpose: organising the event to which you are invited: invitation, confirmation, menu, seating, thank-you messages after the event.
- Basis: the legitimate interest of the hosts and of ourselves in organising the event to which you have been invited (Article 6(1)(f) GDPR). We do not use your data for advertising and we do not disclose it to other persons for their own purposes.
Health information (e.g. allergies). This is data concerning health. The portal does not ask for it and does not collect it. The menus in the invitation (for example vegetarian, vegan, children’s) are simply a choice of dish and we do not use them for anything else. If you have an allergy or another dietary requirement, please contact the hosts directly. Please do not write it in your message. We also ask the hosts not to enter health information about guests in the notes.
When the hosts’ plan ends. If the hosts do not pay for their plan, the invitation, the website and the album show a neutral page without names, dates and photos, and your data is deleted together with the event (section 8). From 14 days before to 14 days after the date of the event, the invitation remains active.
2.3. Event website, wishes and shared album
- The event website contains what the hosts have published: names, date, venue, programme, photos, texts. It may include the names of the kum and kuma (the couple’s witnesses and wedding sponsors) and of the bridesmaids and groomsmen, and a bank account for gifts. It is accessible to anyone with the address, unless the hosts have set a password. Invited guests open it from their personal invitation without a password. By default the website is hidden from search engines.
- Wishes: your name and text. They are shown on the website after the hosts approve them.
- Shared album: the photos you upload and your name, if you enter it. The name is shown next to the photo. They are shown to everyone with the link to the album (or the QR code), after approval by the hosts if approval is switched on. To limit excessive uploading, we keep a cryptographic fingerprint of your IP address, not the address itself.
- Basis: the legitimate interest of the hosts and guests in sharing memories of the event (Article 6(1)(f)).
If you appear in a photo in the album and do not want it to be shown, write to us at info@luxevent.bg or ask the hosts to hide it. We will hide it immediately and then review it. Please upload only photos that the people in them would not object to, especially when children are in them.
Link preview when sharing. When a link to the website, the invitation or the album is sent in a messaging app or on a social network (Viber, WhatsApp, Facebook and others), the app shows a short preview: the hosts’ names and the date of the event and, for a website without a password, also the city (and the cover photo, only if the hosts have chosen it). The preview with the names is shown only if the event website is published without a password. It never contains data about guests, the venue, the time or a bank account. The apps keep the preview on their side, and it may remain in chats even after the event has been deleted.
2.4. Suppliers of the event
Company name, contact person, telephone, email, arrival time, amounts. They are entered by the client or by our team. The purpose is coordination on the day of the event, and the basis is legitimate interest (Article 6(1)(f)).
The name, arrival time and telephone are also visible to the people with whom the hosts have shared the “The Day” link.
2.6. Sign-up and trial period
| Data | Purpose | Legal basis |
|---|---|---|
| Email, names, password (hash), type and date of the event | creating the account and the event, start of the trial | Article 6(1)(b) |
| Record of acceptance of the General Terms: which version, a fingerprint of the exact text of the tick box, date and time, IP address (at the time of ticking) | proof that and when you accepted the terms | Article 6(1)(b) and (f) (legitimate interest in proving the conclusion of the contract in a dispute) |
| Email confirmation code (a hash is stored) | to make sure the email address is yours | Article 6(1)(b) |
| IP address and time of sign-up | limiting mass sign-ups and abuse | legitimate interest – security (Article 6(1)(f)) |
| Email fingerprint (HMAC-SHA256 of the normalised email address with a secret key), date of the trial | one free trial per person – so that a trial is not used again with a new account | legitimate interest in preventing abuse of the free trial (Article 6(1)(f)) |
| Use during the trial: number of invitations sent, photos, requests to the AI, start and end of the trial, extensions | applying the trial limits, reminders | Article 6(1)(b) |
| Trial emails (on day 5 and day 7, at the end, before deletion) | performance of the contract and warning before deletion | Article 6(1)(b) |
About the email fingerprint. Your email address cannot be recovered from it. We can only check whether an email address entered again at sign-up has already used a trial. It remains after your account is deleted – otherwise every deletion followed by a new sign-up would give a new free trial. We keep it for 24 months from the start of the trial and then delete it (section 8). You may object (Article 21 GDPR) – we will assess the objection, but as a rule we cannot uphold it without opening the trial to repeated use.
About the IP address in the record of acceptance. We keep it in clear form for 6 months and then delete it. We keep the rest of the record (without the IP address) as set out in section 8.
2.7. Subscription, payments and invoices
| Data | Purpose | Legal basis |
|---|---|---|
| Plan, event, period, status (trial, active, suspended), dates, history of changes, discounts applied | performance of the subscription | Article 6(1)(b) |
| Consents given when ordering: the request for the service to start immediately, consent to automatic renewal, the version of the terms accepted, a fingerprint of the exact text, date and time, IP address (6 months) | proof of the conclusion of the contract and of the consents under the Consumer Protection Act | Article 6(1)(c) and (f) |
| Invoice details: name, email, optionally an address; for a company – name, UIC, VAT number, address, representative; result of the check of the VAT number in the EC’s VIES system | issuing an invoice, accounting, taxes | legal obligation (Article 6(1)(c)) under the VAT Act and the Accountancy Act |
Payments: amount, VAT, date, method (transfer or card), reference LX-…, invoice number; for a transfer – the name of the payer and the account from the statement | accounting, linking the payment to the order | Article 6(1)(b) and (c) |
| Emails about renewal (7 days before), failed payment, suspension, change of price | performance of the contract and obligations towards consumers | Article 6(1)(b) and (c) |
| Withdrawal from the contract (date and time, the name and email you gave, the amount to be refunded), complaints and our replies | performance of obligations under the Consumer Protection Act, protection in a dispute | Article 6(1)(c) and (f) |
These emails are part of the service and are not advertising. You cannot unsubscribe from them while you have a subscription.
2.8. Vouchers and benefits for Luxevent clients
- Buyer of a voucher: name, email, invoice details, payment – for the sale and for accounting (Article 6(1)(b) and (c)). We keep only a cryptographic fingerprint of the code and its last 4 characters. We record who used the code and for which event – so that it cannot be used twice.
- Benefits for Luxevent clients: if you have accepted a Luxevent proposal for the event, the total of the accepted proposals determines a discount or a free plan in the planner. This is calculated automatically by the same company, from the same data, only so that you receive the benefit (Article 6(1)(b)). The data from the proposal is not shown elsewhere in the planner.
2.9. Support access to the planner
By default our team does not see the content of the planner of clients who signed up on their own (guests, messages, files), only the data about the plan, the dates, the number of guests and the payments.
If you press “Allow support access”, the team may open the event’s planner for 7 days to help you. You can stop the access earlier. Every opening is recorded (who, when). Basis: your request and performance of the contract (Article 6(1)(b)).
2.10. Waiting list
Email and, optionally, the date of the event and the city. The entry becomes active once you confirm it from the email. We will email you once – when the planner launches. The email confirming your sign-up is a service message. Basis: your consent (Article 6(1)(a)), which you withdraw with the unsubscribe link. We keep the data for up to 3 months after we open.
For invitations to the closed beta, we keep only a cryptographic fingerprint of the email address, so that we do not send you a second invitation. The email address itself exists only in the message.
2.11. News and offers
We send news and offers only if you have agreed by means of a separate tick box that is not ticked by default – this also applies to our existing clients. We record when and with what wording you gave consent (and the IP address – for 6 months), so that we can prove it (Article 7(1) GDPR). You may withdraw your consent at any time – with the link in every such email or by writing to info@luxevent.bg.
3. Is providing the data mandatory
- An email address is needed for the account.
- The contact in the enquiry is needed so that we can prepare a proposal for you.
- Invoice details are needed to buy a plan (a legal requirement). For an individual we do not ask for a personal identification number (ЕГН).
- A guest is not obliged to reply to the invitation or to state a menu.
- A name in the album is optional; for a wish it is required.
4. Who receives the data
- Our team (the portal administrators and your coordinator). They work only on our instructions and are bound to confidentiality. For clients who signed up on their own, the team sees the content of the planner only as set out in section 2.9.
- The hosts and their partners in the planner: they see the data of the guests of their event.
- Guests: they see only their own invitation and what is published on the website and in the album.
- Processors acting on our behalf:
- JetHost – hosting, database, sending of emails, backups, Bulgaria;
- our external accountant – accounting processing of invoices and payments.
- Banks – yours and ours – for bank transfers and refunds.
- Independent controllers to which limited data reaches:
- OpenStreetMap Foundation (United Kingdom): address search and map tiles. Your browser loads the map directly from them and they receive your IP address.
- Restaurant, venue and other contractors, when the hosts or we provide them with a list (for example to the restaurant – only the numbers by menu and by table, without names).
- Public authorities, when the law requires it (for example the National Revenue Agency in a tax inspection, the Consumer Protection Commission in an inspection following a complaint).
When the hosts send the invitation through WhatsApp, Viber or their own email, this is done from their devices and accounts, under the rules of those services.
5. Transfers outside the European Union
- United Kingdom (OpenStreetMap Foundation): on the basis of a European Commission adequacy decision.
6. Automated decisions
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
Some steps in the subscription happen automatically, under the contract rules that you have accepted: the end of the trial, suspension for non-payment, deletion after the warnings, refusal of a second free trial, calculation of the benefit based on the proposal. If you think a mistake has been made, write to us – a person will review the case.
7. How we protect the data
The connection is over HTTPS only. Passwords are stored as a hash. Files are kept in the database, not in a public folder. Personal links use long random codes. Team access is role-based and changes are recorded. We make backups. In the event of a personal data breach we follow an internal procedure: we notify the Commission for Personal Data Protection within 72 hours (Article 33 GDPR) and the affected people without undue delay when the risk to them is high (Article 34 GDPR).
8. How long we keep the data
We will introduce the periods below in the next version of the portal. Until then, data is not deleted automatically, but you can ask for deletion at any time at info@luxevent.bg.
| Data | Planned period |
|---|---|
| Email, telephone, form of address, notes, menu, message and history of replies of guests, names and menu choices of the people coming with them and of children | up to 3 months after the date of the event, then deleted. The personal link to the invitation stops working |
| The planner: event, tasks, budget, guests (names), tables, invitation, website, shared album, wishes, messages, documents, questionnaires | 12 months after the date of the event. A month before that we will write to you so that you can download the data and photos. We delete no earlier than 30 days after that email |
| “Download everything” archive | 24 hours after it is created; the link can be opened at most 3 times. It is always deleted before the event is deleted |
| Enquiries and proposals without acceptance | up to 12 months after the date of the event or the last change (whichever is later) |
| Accepted proposals, data on acceptance and payments | 5 years after the end of the year of the event (limitation period for claims). Accounting documents are kept for up to 10 years under Article 12 of the Accountancy Act. If you ask for earlier deletion, from accepted proposals we keep only the number, dates, amounts, status and services; names, contacts, address, IP address and photos are deleted |
| Payments for plans and vouchers, invoice details, invoice number | 10 years from 1 January of the year after the payment (Article 12 of the Accountancy Act). They remain after the event and the account are deleted, but without the content of the planner |
| Records of consents (at sign-up, at ordering and for news), withdrawals from the contract, complaints | 5 years after the end of the contract or after the account is deleted (limitation period). The IP address in them – 6 months, then deleted |
| Email fingerprint for the trial | 24 months from the start of the trial; it remains after the account is deleted (section 2.6) |
| IP address at sign-up | in the email confirmation link – up to 1 day after it expires; in the record of acceptance of the terms – 6 months |
| Email fingerprint for beta invitations | 12 months from the invitation |
| Waiting list | up to 3 months after we open, or until you unsubscribe |
| Client account | as long as you have an event, enquiry, proposal or subscription with us. After that, if you have not signed in to the account for 24 months, we delete it at the annual review. You can delete the account earlier from “My data” or by email |
| Data of a guest who has asked for deletion | up to 14 days after the request |
| The emails we send | the text of the email is deleted as soon as the server’s mail system accepts it (if the email does not go out – after the last attempt, at the latest within 7 days). The address, subject, type, status, dates and reason for failure (without addresses) we keep for 30 days for emails sent and 90 days for emails not sent – to check whether the email went out |
| Notifications in the portal | 12 months |
| Technical security records (including openings by support) | 24 months; sign-in attempts – 24 hours |
| Backups | nightly copies are kept for 7 days; weekly copies off the server and the hosting provider’s copies – up to 30 days. Deleted data remains in them until they expire and is not used, except for restoring after a failure. In that case the deletions are applied again |
If there is a dispute, or if you ask for more time to download your data, we may hold the planner for 12 months at most. If there is a dispute, we keep the necessary data until it is resolved. A hold does not stop guests’ deletion requests.
9. Your rights
You have the right:
- of access to your data and to a copy of it (Article 15);
- to rectification (Article 16);
- to erasure (“to be forgotten”, Article 17), except where the law obliges us to keep the data;
- to restriction of processing (Article 18);
- to data portability: to receive your data in a machine-readable form (Article 20);
- to object to processing based on legitimate interest (Article 21). If you are a guest, this means you can ask us not to write to you and to delete your data;
- to withdraw your consent at any time, without affecting processing carried out until then (Article 7(3)).
How:
- Clients and partners: from the account menu, “My data”, you can download all your data (a ZIP with JSON files and your documents), including orders, the history of the plan and the recorded consents, and ask for deletion of the account. For each event there is also “Download everything” – one archive with the guests and replies (Excel), tables, budget, tasks, suppliers, invitation, programme, photos from the album, wishes and documents. It always works, including when the plan is suspended. We carry out a deletion request within 30 days after we check contracts and payments. You can also write to us at info@luxevent.bg or call +359 883493842.
- Guests: from your personal invitation, “Your data”, you can see the main data we keep about you, ask for deletion and unsubscribe from emails. For a full copy of your data (for example the hosts’ notes or the table assignment), write to us at info@luxevent.bg.
We will reply within 1 month (for complex requests this period may be extended by a further 2 months, and we will tell you, Article 12(3)). We may ask you to confirm your identity. If we cannot comply with your request, we will tell you why, and that you can lodge a complaint with the CPDP or seek a judicial remedy (Article 12(4)).
Complaint: you can lodge a complaint with the Commission for Personal Data Protection (Комисия за защита на личните данни, КЗЛД / CPDP), 2 Prof. Tsvetan Lazarov Blvd, Sofia 1592, Bulgaria, kzld@cpdp.bg, https://cpdp.bg. We ask you to contact us first: we will do our best to resolve the matter quickly.
10. Cookies
We use only strictly necessary cookies and browser storage. We do not use advertising, analytics or tracking cookies, so we do not ask for your consent with a banner.
- luxevent_session keeps you signed in to your account and protects forms against forged requests. In the invitation, the website and the album it is needed to send a reply, a wish or a photo, and it remembers whether you have unlocked a password-protected website. It is deleted when you close the browser; sign-in expires after 1 hour of inactivity.
- luxevent_device is set only if you tick “Remember this computer” at two-step sign-in: on that computer you can sign in without a code from your phone (7 days for administrators, 30 for others). We keep only a fingerprint of the random code, with no IP address or browser data. It is cancelled by “Forget all devices”, by changing your password or by deleting the cookie.
- Browser storage (localStorage / sessionStorage) keeps conveniences on your device: the code of your personal invitation, your name in the album, liked photos, the last event opened and views. It is not sent to us automatically.
- If you install the portal as an app, the browser keeps a copy of the files so that it works without internet as well. On “Sign out” the copy containing data is deleted.
You can delete cookies and storage in your browser settings. If you delete luxevent_session, you will have to sign in again.
11. Children
The portal is for adult clients. A plan can be bought only by a person over 18. Data about children (the number of children, names of child guests, photos in the album) is entered by their parents, the hosts or the guests. We ask you to share photos of children only with their parents’ consent.
12. Changes
For material changes we will notify you in the portal and by email at least 14 days in advance. The current version is always on this page.
