Controller
The controller is Wisploft, Wilhelminastraat 12, 1432 GC Aalsmeer, registered with the Kamer van Koophandel under 84530383. Send questions and privacy requests to hello@wisploft.com or use the contact form.
Data and purposes
Wisploft processes wishlist titles, gift and optional event details, RSVP answers, random owner and visitor tokens, reservations, invitation briefs, content notices, reviews and aggregate outbound-click counts. We use them to create, display, edit and protect the service, prevent duplicate gifts, deliver requested invitations, moderate public content and understand aggregate product use.
Private access and deletion tokens are random and pseudonymous. Only cryptographic hashes are stored in the database. A public list or event link is intended to be shared, but it is not indexed by Wisploft and should still be treated as accessible to anyone who receives it.
Legal bases and required information
Providing wishlists, reservations, RSVP, invitations and contact responses is necessary to perform our agreement with you or take steps you request before it. Publishing an optional review is based on consent. Security, abuse prevention, service logs and aggregate measurements rely on our legitimate interest in operating a safe and reliable service. We also process data when necessary to comply with law or establish, exercise or defend legal claims.
A wishlist requires a title. An invitation requires an email address and the names to print. A contact message requires an email address so we can reply. An RSVP requires a display name and answer so the host can plan. Its optional note is shown to the host and may reveal sensitive information if you write about accessibility, health, diet or religion, so share only what the host genuinely needs. Fields marked optional may be left blank.
Private links, emails and invitations
When you ask us to email a private management link, the address is sent to our email-delivery provider for that message and is not stored on the wishlist record or added to a mailing list. Email providers and mailbox operators necessarily process delivery data. Treat the private link as a password and rotate it from the management page if it may have been exposed.
An invitation request contains an email address, occasion details and photographs you choose to provide. We use them only to prepare, discuss and deliver the invitation. Uploaded photographs are re-encoded to remove embedded metadata such as location before private storage.
We may use design or AI tools, including the OpenAI API, only when they are useful for preparing a requested invitation. We minimise the brief before sending it. OpenAI states that API data is not used to train its models by default; standard abuse-monitoring logs may be retained for up to 30 days unless a different approved control applies. The current providers and safeguards can be requested at hello@wisploft.com.
Reviews, notices and contact
A review contains the name or nickname, rating and words you submit. It remains private until moderation. If approved, those fields become public and are labelled as an unverified experience because Wisploft does not process purchases. An encrypted necessary cookie lets the same browser delete it; only a hash of the deletion token is stored.
The contact and illegal-content forms send the supplied contact details and message to our mailbox. A content notice is also stored so its status and decision can be recorded. We use this correspondence to investigate, reply, meet legal duties and handle any appeal; it is not used for marketing.
Recipients and processors
Data is processed only where needed by Wisploft and providers acting for us, such as hosting and storage, email delivery and mailbox, encrypted off-site backup, and design or AI providers used for an invitation. We do not sell personal data and do not permit providers to use it for their own marketing.
A shop receives information directly from your browser when you follow an outbound product link, under that shop's privacy notice. When you search a supported shop catalogue inside Wisploft, we send the search words to that catalogue service; catalogue images are fetched and served by Wisploft so the shop does not receive the visitor's browser request.
International transfers
If a provider processes personal data outside the European Economic Area, we rely on an EU adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses. Ask hello@wisploft.com for current provider and safeguard information.
Retention
Closed invitation briefs are removed from the live service after 90 days. Pending reviews are removed after 90 days, rejected reviews after 30 days, and published reviews when their author deletes them or withdraws consent. Inactive wishlists are removed after 24 months. A deleted wishlist becomes inaccessible immediately and is purged from the live database after 30 days.
Contact and notice correspondence is kept only while needed to answer, investigate, document the outcome or meet a legal obligation, and is normally reviewed for deletion within 12 months after closure. Abuse-event records are removed after 90 days. Encrypted backups follow the configured operational rotation; a restored backup is subjected again to the live deletion rules. Infrastructure and email providers may keep limited security or delivery logs under their own documented operational schedules.
Cookies and technical data
Only necessary first-party cookies are used: CSRF and encrypted session cookies, the owner grant, review-deletion grant, pseudonymous visitor token and short-lived receipt for a newly issued private link. They support security and the accountless features; none is used for advertising or cross-site tracking. Removing them may remove editing, deletion, RSVP or reservation access.
Outbound clicks are stored only as totals per gift and day, without IP addresses or browser fingerprints. Rate-limit and abuse keys are one-way hashes derived with rotating application secrets. Fonts and application assets are self-hosted, and public pages do not load an analytics provider.
Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw review consent at any time. Because Wisploft deliberately knows little about you, we may ask for a private management link, review-deletion cookie or another proportionate check; a public list link or an email address alone is not proof of ownership. We do not require a full identity-document copy for an ordinary request.
Automated decisions and complaints
Wisploft does not make automated decisions producing legal or similarly significant effects and does not profile people for advertising. Contact hello@wisploft.com first so we can investigate. You may also complain to the Autoriteit Persoonsgegevens or the data protection authority where you live or work.