PAIA manual
[placeholder: OPERATOR_NAME], operator of RSVP'd. Prepared under section 51 of the Promotion of Access to Information Act 2 of 2000, and the Protection of Personal Information Act 4 of 2013.
Some business details are not published yet
1. Contact details
- Private body
- [placeholder: OPERATOR_NAME]
- Registration
- [placeholder: OPERATOR_REG_NO]
- Head of the body
- [placeholder: OPERATOR_NAME]
- Information Officer
- The head of [placeholder: OPERATOR_NAME]
- Deputy Information Officer
- None designated
- Street and postal address
- [placeholder: OPERATOR_ADDRESS]
- Telephone
- [placeholder: OPERATOR_PHONE]
- hello@rsvpd.co.za
- Website
- https://rsvpd.co.za
2. The Regulator’s guide
The Information Regulator publishes a guide on how to use the Promotion of Access to Information Act and the Protection of Personal Information Act, in every official language. Get it from the Regulator (010 023 5200, inforegulator.org.za, enquiries@inforegulator.org.za, Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191), or ask our Information Officer for a copy using Form 01.
3. Records available without a request
We have published no notice under section 52. The terms, the privacy notice, the supplier details and this manual are on this website for anyone to read, free.
4. Records kept under other laws
Records we keep because a law requires it, where that law applies to us: the Companies Act 71 of 2008 (company records, if we are a company); the Tax Administration Act 28 of 2011 and the Income Tax Act 58 of 1962 (financial and tax records); the Value-Added Tax Act 89 of 1991 (if we are registered for VAT); the Electronic Communications and Transactions Act 25 of 2002; the Consumer Protection Act 68 of 2008; and the Protection of Personal Information Act 4 of 2013.
5. Subjects and categories of records
The business: registration documents and statutory records, agreements with our service providers, and correspondence.
Finance and tax: payment records (reference, amount, status, dates and the payment provider’s reference), receipts, accounting records and tax returns. A minimal record of each payment is kept even after the wedding it paid for is deleted.
Customers — couples and planners: account details (name, email address, a one-way hash of the password, whether the email is confirmed), weddings and their settings, team members and invitations, the attestation given before a first send with its date and time, notification subscriptions, support correspondence, and a record of deletions that holds counts but no personal information.
Guests, held as operator for the couple who invited them: names, email addresses and phone numbers, households, replies, meal choices, allergy and dietary information, song requests and notes, and the history of messages sent to them, including whether each was delivered.
Suppliers named by couples: the caterer’s name and email address, when each numbers pack was emailed to them, and when it was first opened, which the pack email records with a small image.
Security and operations: short-lived attempt counters keyed by a one-way fingerprint of an IP or email address, error reports, and a one-way fingerprint of every address that has unsubscribed, bounced or complained, kept so that it is never emailed again.
6. Why we process personal information
To provide the service couples and planners sign up and pay for: sending invitations, collecting replies, preparing the caterer’s numbers and showing the couple whether their caterer has opened them. To take and account for payments. To keep the service secure and working. To honour every unsubscribe. To meet our legal obligations, including tax.
Allergy and dietary information can reveal something about a guest’s health. It is processed only because the guest gave it for their meal, and it goes only to the couple and their caterer.
7. Who receives it
The couple and the team members they add see their own wedding and nothing else. Their caterer receives the headcount, the meal split and the allergy list, which names the guests it applies to but carries no contact details.
Our service providers, each only for what it does for us: Vercel (hosting the application), Supabase (the database), Resend (delivering email, which means it receives each recipient’s address and the message), Inngest (running scheduled jobs such as reminders and the caterer’s pack, which receives what each job needs: mostly identifiers, and the caterer’s name and email address), Yoco (taking payments), Anthropic (drafting invitation wording, which means it receives the wedding’s display name, date and venue from its settings and whatever the couple types under “Help me word it”; never a guest list) and, if we switch it on, Sentry (error reports).
Government bodies and courts, when a law or court order requires it.
8. Outside South Africa
The database is hosted by Supabase in Frankfurt, Germany, and the application runs on Vercel in Frankfurt, Germany — both in the European Union, under the GDPR. Vercel’s network also delivers pages from locations close to each visitor, and Vercel, Inc. is a United States company.
Resend, Inngest and Anthropic are United States companies: what they handle for us (email for delivery, scheduled jobs, and wording requests respectively) is processed outside South Africa. Sentry, if we switch it on, is also outside South Africa. Yoco processes payments in South Africa.
We transfer personal information to these providers under their data processing terms, which bind them to protect it to a standard substantially similar to POPIA’s, and because the transfer is needed to provide the service the couple asked for (POPIA section 72).
9. How we protect it
Everything travels over HTTPS. The database is encrypted at rest, every query is scoped to the couple’s own account, and every table has row-level security. Passwords, password-reset and email-confirmation codes are stored only as one-way hashes. Guest links are long, unguessable signed tokens. Card details never reach our systems. Access to production systems is limited to the people who run the service, and deletions are recorded.
10. How to request a record
Complete Form 02 (Request for Access to Record), available from the Information Regulator’s PAIA forms page, and send it to our Information Officer at hello@rsvpd.co.za or to the address above. Say which record you want, in what form, and, if you are asking on someone else’s behalf, in what capacity. You must also say which of your rights the record is needed to exercise or protect.
If you are asking for your own personal information, there is no request fee. Other requesters pay the request fee prescribed by the PAIA regulations, and any access fees for copies; we will tell you what applies (Form 03) before we do the work.
We decide within 30 days, and may extend that once by up to 30 days if the request is large or needs a third party to be consulted; we will tell you if we do. If we refuse, we give the reasons. You may then complain to the Information Regulator (Form 05) or apply to court.
For your own information, you can also simply ask us to see, correct or delete it, or object to how it is used, without a form.
11. This manual
This manual is on this website and available free of charge from our Information Officer. We update it when what we hold, why, or who receives it changes.