milía is a wedding-planning studio. Weddings are made of people, so we handle personal data with the same care we ask of the couples who use us. This policy explains what we collect, why, and what rights you have — whether you are a couple planning a wedding, a guest invited to one, or a visitor to this website. It is written to comply with Regulation (EU) 2016/679 (the GDPR) and Cyprus Law 125(I)/2018.
[LEGAL ENTITY NAME], registration no. [HE NUMBER], of [REGISTERED ADDRESS, CYPRUS] ("milía", "we", "us"). For anything in this policy, write to privacy@milia.app.
For couples: when you create an account, pay, or message us, we decide how that data is used — we are the controller.
For guests: your names, phone numbers, RSVPs, photos and messages are put into milía by the couple who invited you, for their wedding. For that data the couple is the controller and milía is their processor — we handle it only on their instructions, under the data-processing terms in our Terms of Service (§13).
To see which parts of the studio help and which get stuck, we record anonymous product statistics — for example that a wedding website was published, how many guests were added (a count, never the names), which design was chosen, or that an invitation was opened and replied to.
Within the couple's own planning studio we may also record anonymised session replays — a reconstruction of how the screen was used, so we can see where the product is confusing. All text and every field value is masked before it leaves the browser, so a replay shows which buttons were pressed and how someone moved through a screen, never the names, numbers, budgets or notes on it. Guest-facing pages such as RSVP links and the photo guestbook are never recorded.
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the studio: accounts, guest lists, RSVP, seating, websites, guestbook, print files | Performance of a contract (6(1)(b)) |
| Sending wedding SMS on the couple's instruction, with delivery receipts | Contract (6(1)(b)); the couple is responsible for its lawful contact of guests |
| Payments, receipts, VAT records | Contract (6(1)(b)) and legal obligation (6(1)(c)) — tax law requires us to keep records |
| Security, fraud and abuse prevention, service logs | Legitimate interests (6(1)(f)) — keeping the service safe |
| Answering your messages | Legitimate interests (6(1)(f)) / contract |
| Anonymous usage statistics, to understand what helps couples and improve the studio | Legitimate interests (6(1)(f)) — no wedding or guest content is included, and no one is profiled or identified |
| Anything we might one day ask separately (e.g. a testimonial) | Consent (6(1)(a)) — always asked, never assumed |
We share data only with the service providers below, each bound by a data-processing agreement, and only as needed to run the studio:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | EU region hosting; US entity under EU–US Data Privacy Framework / SCCs |
| Stripe | Card payments and receipts | EU (Stripe Payments Europe) with DPF/SCC-covered transfers |
| Twilio | Delivering wedding SMS | US, under EU–US Data Privacy Framework / SCCs |
| Resend | Transactional email | US, under SCCs |
| Vercel | Website hosting / delivery | US, under EU–US Data Privacy Framework / SCCs |
| PostHog | Anonymous product usage statistics (no wedding or guest content) | EU (Frankfurt) — data stays in the EU |
| Optional "Sign in with Google" | EU/US, under EU–US Data Privacy Framework |
Where a provider processes data outside the EEA, transfers rest on an EU adequacy decision (including the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses. We may also disclose data where the law requires it (e.g. to tax authorities or courts).
Under the GDPR you can ask us for access to your data, its correction, erasure, portability (a machine-readable copy), the restriction of processing, and you may object to processing based on legitimate interests. Write to privacy@milia.app — we answer within one month. You also have the right to complain to the Cyprus supervisory authority: the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy, 1 Iasonos Street, 1082 Nicosia, commissioner@dataprotection.gov.cy).
The couple who invited you added your name and number so that milía could carry their invitation and collect your RSVP — the same way a wedding planner would keep a guest list. We use your details only for that couple's wedding: never for marketing, never shared beyond the providers in §5, deleted when the couple's wedding is deleted. To stop receiving texts for a wedding, tell the couple or write to us at privacy@milia.app — we will stop messages to your number for that wedding. To exercise any data right, contact the couple (the controller of their guest list) or write to us directly at privacy@milia.app — we will help either way, and we will pass your request to the couple where the decision is theirs.
All traffic is encrypted in transit (TLS); data is encrypted at rest; access to guest data is enforced row-by-row in the database so each wedding is only ever visible to its own couple and their invited co-planners; payment fulfilment is verified server-side against cryptographically signed notifications from Stripe; passwords are hashed, never stored. No system is perfectly secure — if a breach ever put your rights at risk, we would notify the Commissioner within 72 hours and affected people without undue delay, as the GDPR requires.
milía accounts are for adults (18+). Wedding photos uploaded by couples and guests may incidentally include children of the wedding party; couples are responsible for having the agreement of a parent or guardian where needed, and any parent may ask us or the couple to remove such material at any time.
If we change this policy in any meaningful way we will post the new version here, update the date above, and — for material changes — tell account holders in the app or by email before the change takes effect.
Questions? privacy@milia.app