Legal
Privacy policy
Last updated 9 September 2026. Applies to I Said Yes, operated by I Said Yes Ltd.
I Said Yes is wedding planning software for professional planners in the United Kingdom. This policy explains what personal data passes through it, who is responsible for it, where it is kept and what you can ask us to do with it. It is written to meet the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
The short version: the planner who owns a workspace decides what goes in and is the controller of it. We process it on their instructions, keep it in Ireland, never sell it, and delete it for good 30 days after they ask.
1.Who we are
I Said Yes is operated by I Said Yes Ltd, a company registered in England and Wales (company number 00000000) with its registered office at Registered office to be confirmed, Gloucestershire, England. Our ICO registration: Registration pending.
For anything to do with personal data, email privacy@isaidyes.ai. We do not currently have a statutory Data Protection Officer; the same address reaches the person responsible for data protection.
2.Controller and processor
Two roles apply, and they matter because they decide who answers for what.
- The planner is the controller. A planner (the person or business that owns a workspace) enters details about the couples they work for, those couples' guests, suppliers, budgets and schedules. The planner decides why and how that data is used. Under UK GDPR they are the controller of it, and their own privacy notice to their clients should cover their use of I Said Yes.
- We are the processor for that data. We store it, show it to the people the planner has invited, send the emails the planner asks us to send, and nothing more. Section 8 sets out our processor commitments, which form part of our terms with every planner.
- We are the controller for a small amount of data about the planner's own account: their name, email address, password hash, sign-in history and billing details, plus the emails we send about their account.
Couples, their families and guests: your planner put your details in. If you want something changed or removed, ask your planner first. If you would rather ask us, email privacy@isaidyes.ai and we will help, working with the planner where we must.
3.What we process
As processor, on the planner's instructions:
- Couples: first and last names, email addresses, phone numbers, postal addresses, the wedding date and venue, and anything the planner writes in notes.
- Guests: names, household groupings, postal and email addresses, phone numbers, RSVP responses, meal choices, dietary requirements, accessibility needs, ages of children, gift and thank-you notes. Dietary and accessibility details can reveal health information, which is special category data; we process it only because the planner needs it to feed and seat people safely.
- Suppliers: business and contact names, emails, phone numbers, addresses, private ratings and notes.
- Team members and clients who sign in: names, email addresses, when they last signed in, the comments they write and the tasks they tick.
- Files the planner uploads: contracts, invoices, plans, mood board images.
As controller, about the planner's account:
- Name, email address, business name, address, phone, website, VAT status.
- A one-way hash of the password (we never see the password itself), sign-in timestamps and session identifiers.
- Subscription and payment records once billing launches, handled by our payment provider; we do not store card numbers.
- Support emails you send us.
4.Why we process it (lawful basis)
- Contract (Article 6(1)(b)): providing the service a planner signed up for, including their account, and processing their clients' data on their instructions.
- Legitimate interests (Article 6(1)(f)): keeping the service secure, preventing abuse, and emailing planners about changes to the service. You can object at any time.
- Legal obligation (Article 6(1)(c)): keeping invoicing records for HMRC and responding to lawful requests.
For dietary and accessibility details, the planner relies on the couple's and guests' explicit consent, given when they tell the planner or fill in an RSVP. We process them only as the planner's processor.
We do not use anyone's data for advertising, profiling or automated decisions, and we do not sell it.
5.Where your data is kept
The database and uploaded files live in Ireland (Supabase's eu-west-1 region), inside the European Economic Area. The UK government recognises the EEA as providing an adequate level of protection, so no additional transfer safeguard is needed for personal data to sit there. The application runs on Vercel, whose servers may briefly process requests elsewhere; no data is stored there. Transactional email is sent by Resend.
Where a sub-processor is outside the UK, transfers rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and on each provider's security certifications.
6.Sub-processors
We use three companies to run the service. We do not share personal data with anyone else, except where the law requires it.
| Company | What they do | Where |
|---|---|---|
| Supabase | Database, file storage and backups | Ireland (EEA) |
| Vercel | Hosting the application and serving pages | Global network, UK and EU regions preferred; nothing stored |
| Resend | Sending invitations, reminders and digests by email | United States (EU sending region where available) |
We will email every workspace owner at least 30 days before adding or changing a sub-processor, so they can object.
7.How long we keep it
- While a workspace is active, everything in it is kept so the planner can use it.
- When a planner deletes a guest, a wedding or a whole workspace, it is hidden at once and kept for 30 days so a mistake can be undone. After 30 days it is deleted for good, uploaded files included. Encrypted database backups held by Supabase expire within a further 30 days.
- A client (a couple or family member) can have their account deleted by their planner. Their sign-in details are erased straight away; their name is removed from the account record.
- Account and billing records for the planner are kept for six years after the subscription ends, because HMRC requires it.
- Support emails are kept for two years.
8.Our commitments as processor
For every workspace owner, and as required by Article 28 UK GDPR, we:
- process personal data only on your documented instructions, given through the service;
- make sure everyone with access to it is bound by confidentiality;
- keep it secure: encryption in transit and at rest, row-level access control in the database so one workspace can never read another, hashed passwords, signed single-use links;
- use only the sub-processors listed above and tell you before that changes;
- help you answer requests from the people whose data you hold: every workspace can be exported as JSON and CSV from Settings, and any guest or client can be erased;
- tell you without undue delay, and in any case within 48 hours, if we become aware of a personal data breach affecting your workspace;
- delete or return everything at the end of the service, as described in section 7;
- give you the information you need to show you have met your own obligations.
9.Security
All traffic is encrypted with TLS. Data is encrypted at rest. Every table in the database carries the workspace it belongs to and the database itself enforces that a signed-in person only ever sees their own workspace or their own wedding. Passwords are stored as salted hashes. Invitation, sign-in, export and restore links are signed and expire. Cron jobs and internal routes need a secret. No one at I Said Yeslooks at a workspace unless the owner asks us to for support.
10.Your rights
Under UK GDPR you can ask to:
- see the personal data held about you (access);
- have mistakes corrected (rectification);
- have it deleted (erasure);
- restrict or object to how it is used;
- receive a copy in a portable format;
- withdraw consent where consent is the basis.
Planners: everything above is available from Settings (export, delete workspace) and from each wedding (delete a guest for good, delete a client's account). For anything else email privacy@isaidyes.ai.
Couples and guests: your planner is the controller, so start with them. If you contact us directly we will pass the request on and make sure it is dealt with within one month.
You also have the right to complain to the UK regulator. We would rather hear from you first, but you can contact them at any time:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113. ico.org.uk/make-a-complaint.
11.Children
Guest lists include children. Planners record only what is needed to feed and seat them: a name, that they are a child, sometimes an age and a meal. Children never sign in to I Said Yes. The service itself is for adults running a business.
12.Changes to this policy
When this policy changes in a way that matters, we email every workspace owner and update the date at the top. Earlier versions are available on request.
Questions about any of this? Email privacy@isaidyes.ai. See also our privacy policy, terms and cookies page.