Data Processing Addendum

Last updated: June 29, 2026

This addendum explains how we handle the personal data you and your couples place in Sera Agency Ops. It applies to every agency that uses the Service and forms part of our Terms of Service.

1. Parties and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Sera Weddings, LLC, a Wyoming limited liability company ("Processor", "we"), and the agency that uses Sera Agency Ops ("Controller", "you"). It applies whenever we process personal data on your behalf. For the personal data of your couples and their wedding guests, you are the controller and we are your processor. Each party is independently responsible for complying with the data-protection laws that apply to it.

2. Subject matter and duration

We process personal data only to provide the Service described in the Terms: managing room blocks, rooming lists, guest booking pages, couple dashboards, payment tracking, and the emails you trigger. Processing lasts for as long as your account is active and through the return-or-deletion window described in section 9.

3. Nature and purpose of processing

Collection, storage, organization, display, transmission of transactional email, and deletion of personal data, carried out by automated means, for the sole purpose of operating the Service on your instructions. We do not sell personal data, do not use it for advertising, and do not train machine-learning models on it.

4. Categories of data and data subjects

Data subjects: your staff, the couples you serve, and their wedding guests. Personal data: names, email addresses, phone numbers, wedding and travel dates, room and reservation details, payment status, and the content you and your couples publish to guest pages. We do not store payment card numbers; card data is collected on Stripe-hosted pages under Stripe's own terms.

5. Your instructions

We process personal data only on your documented instructions, including those given through the Service's features and settings, unless law requires otherwise (in which case we will tell you, unless that law forbids it). You confirm you have a lawful basis and any required consents to provide the personal data you upload, and that your instructions comply with applicable law.

6. Confidentiality and access

Access to your personal data in production is limited to the operator of the Service and is granted only as needed to run and support it. Personnel and contractors with access are bound by confidentiality obligations.

7. Security measures

We maintain technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and encryption at rest with our hosting providers; tenant isolation enforced at the database layer by row-level security, so no agency can read another's data; scoped administrative access; and reliance on SOC 2-type infrastructure providers. You are responsible for safeguarding your own account credentials and for the bearer links (couple dashboard and website-editor links) you choose to share.

8. Subprocessors

You authorize us to engage the subprocessors listed below to help deliver the Service. Each is bound by data-protection terms no less protective than this DPA, and we remain responsible for their performance. We will give notice before adding or replacing a subprocessor that handles personal data, so you have a chance to object on reasonable data-protection grounds.

SubprocessorPurposeLocation
Vercel Inc.Application hosting and content deliveryUnited States
Supabase, Inc.Database, authentication, and file storageUnited States / EU
Stripe, Inc.Payment processing on the agency's own connected accountUnited States
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited States

9. Return and deletion

On termination, or on your earlier written request, you may export your data through the Service. We will delete personal data within 90 days, except where retention is required by law or for legitimate accounting records, in which case we isolate and protect it until deletion is permitted.

10. Assistance with data-subject and compliance requests

Taking into account the nature of the processing, we will provide reasonable assistance so you can respond to data-subject requests (access, correction, deletion, portability, objection) and meet your security, breach-notification, and data-protection-assessment obligations. Where a request reaches us directly about a wedding you manage, we will route it to you rather than act on it ourselves.

11. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide the information reasonably available to help you meet your own notification duties.

12. International transfers

Our subprocessors are located primarily in the United States and the European Union. Where personal data is transferred across borders, the transfer relies on an appropriate safeguard recognized under applicable law, such as the EU Standard Contractual Clauses, which are incorporated by reference where they apply.

13. Audits

On reasonable written request, and no more than once a year unless required by a regulator or following a breach, we will make available the information necessary to demonstrate compliance with this DPA, including relevant third-party reports from our infrastructure providers, subject to confidentiality.

14. Liability, governing law, and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the State of Wyoming, United States. If there is a conflict between this DPA and the Terms on the subject of personal-data processing, this DPA controls. This DPA is provided in English, which is the controlling language. Contact: hello@seraweddings.com.