Forlods logo
Log in

Forlods Data Processing Agreement

Data Processing Agreement

Interim version – technical annexes pending verification

Last updated: 20. August 2026

This Data Processing Agreement (“DPA”) forms part of the Forlods Terms of Service (“Terms”) between:

Forlods ApS
CVR 46212339
Hostrups Have 56, 1. th
1954 Frederiksberg C
Denmark

(“Forlods” or the “Processor”)

and the person or entity using the Forlods platform (the “Customer”).

This DPA applies automatically to all Customers as part of the Terms.

The provisions of this DPA concerning the relationship between a controller and processor apply to the extent that the Customer is a controller of Personal Data under Applicable Data Protection Law and Forlods processes such Personal Data on behalf of the Customer.

Where the Customer's processing falls outside the scope of the GDPR or where Forlods processes Personal Data for its own purposes, the allocation of controller and processor roles in this DPA does not alter the roles resulting from applicable law.

1. Definitions

Applicable Data Protection Law means the GDPR and other applicable EU, EEA and Danish data protection legislation.

Customer Personal Data means Personal Data processed by Forlods on behalf of the Customer in connection with the Customer's use of the Services.

Data Subject, Personal Data, Processing, Controller, Processor and Supervisory Authority have the meanings given to them under the GDPR.

Services means the Forlods platform and associated services provided under the Terms.

Subprocessor means another processor engaged by Forlods to process Customer Personal Data on behalf of the Customer.

2. Scope and purpose of the Processing

Forlods provides a digital platform that allows Customers to plan and manage events, including guest administration and RSVP functionality.

Forlods may process Customer Personal Data to:

  • host and operate the Services;
  • store and display event and guest information;
  • provide RSVP and guest-management functionality;
  • send event-related communications where requested through the Services;
  • provide relevant information to event suppliers when instructed by the Customer;
  • provide technical support;
  • maintain the security and availability of the Services; and
  • otherwise perform the Services in accordance with the Terms and the Customer's instructions.

Details of the Processing are set out in Annex 1.

3. Customer instructions

Forlods shall process Customer Personal Data only on documented instructions from the Customer, unless Processing is required by applicable law.

The Customer's use and configuration of the Services in accordance with the Terms constitutes documented instructions to Forlods.

This includes instructions given through functionality in the Services, including:

  • collecting information through RSVP forms;
  • storing and managing guest information;
  • deleting or updating information;
  • communicating with guests; and
  • sharing relevant event or guest information with a supplier at the Customer's request.

The Customer may provide additional reasonable written instructions that are consistent with the Terms and the functionality of the Services.

If Forlods believes an instruction infringes Applicable Data Protection Law, Forlods shall inform the Customer unless prohibited by law.

4. Customer responsibilities

Where the Customer acts as Controller, the Customer is responsible for ensuring that:

  • Customer Personal Data is collected and processed lawfully;
  • guests and other Data Subjects receive any information required by law;
  • the Customer has an appropriate legal basis for the Processing;
  • any instructions given to Forlods comply with Applicable Data Protection Law; and
  • the Customer only requests and processes Personal Data that is reasonably relevant to the event.

Customers may use Forlods to collect information about dietary requirements, allergies and other special considerations.

Such information may constitute special categories of Personal Data under the GDPR. Where applicable, the Customer is responsible for ensuring that an appropriate legal basis and Article 9 condition exists for collecting and using such information.

5. Forlods' obligations

Forlods shall:

  • process Customer Personal Data only for the purposes described in this DPA, the Terms and the Customer's documented instructions;
  • ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations;
  • implement appropriate technical and organisational security measures;
  • limit access to Customer Personal Data to persons who require access for legitimate operational purposes;
  • assist the Customer with its obligations under Applicable Data Protection Law as described in this DPA; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

Forlods will not use guest allergy information, dietary requirements, special considerations or other Customer Personal Data processed under this DPA for its own advertising or unrelated marketing purposes.

6. Security

Forlods shall implement and maintain technical and organisational measures appropriate to the risk associated with the Processing in accordance with Article 32 GDPR.

Measures will address, where appropriate:

  • access control and authorisation;
  • confidentiality of Personal Data;
  • secure transmission and storage;
  • availability and resilience of systems;
  • backups and recovery;
  • logging and monitoring;
  • management of security vulnerabilities; and
  • procedures for responding to security incidents.

The detailed technical implementation of these measures is currently being reviewed and will be documented in Annex 3.

The final Annex 3 may be updated to accurately reflect Forlods' technical environment, provided that such updates do not materially reduce the overall level of protection of Customer Personal Data.

7. Personal Data breaches

Forlods shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.

Where available, the notification shall include information reasonably necessary for the Customer to assess the breach and comply with its own notification obligations.

Forlods shall reasonably assist the Customer in investigating and responding to the breach.

Forlods' contact for data protection and security matters is:

privacy@forlods.com

8. Data Subject requests

Taking into account the nature of the Processing, Forlods shall provide reasonable assistance to the Customer in responding to requests from Data Subjects relating to their rights under Applicable Data Protection Law.

If Forlods receives a request concerning Customer Personal Data for which the Customer is responsible, Forlods may refer the Data Subject to the Customer or otherwise assist in handling the request.

Forlods shall not independently respond to such a request on the Customer's behalf unless authorised to do so or required by law.

9. Assistance with compliance

Taking into account the nature of the Processing and the information available to Forlods, Forlods shall provide reasonable assistance with the Customer's obligations relating to:

  • security of Processing;
  • Personal Data breach notifications;
  • data protection impact assessments; and
  • consultations with Supervisory Authorities,

where such obligations relate to Processing performed by Forlods on behalf of the Customer.

10. Subprocessors

The Customer provides Forlods with general authorisation to engage Subprocessors for the provision of the Services.

Forlods shall ensure that each Subprocessor that processes Customer Personal Data is subject to data protection obligations providing a level of protection consistent with the requirements applicable to Forlods under this DPA.

Forlods remains responsible for its Subprocessors' performance of their data protection obligations to the extent required by Applicable Data Protection Law.

The current Subprocessor list is included in Annex 2.

Changes to Subprocessors

Forlods may add or replace Subprocessors.

Where reasonably practicable, Forlods will provide Customers with advance notice of a new Subprocessor that will process Customer Personal Data.

The Customer may object to a new Subprocessor on reasonable and documented data protection grounds.

The parties shall seek in good faith to resolve a valid objection.

If the objection cannot reasonably be resolved, Forlods may, where technically and commercially feasible, provide an alternative. If no reasonable alternative is available, either party may terminate the affected Services in accordance with the Terms.

Forlods is not required to obtain separate approval from each Customer for each individual Subprocessor.

11. International transfers

Forlods shall ensure that any transfer of Customer Personal Data outside the EU/EEA is carried out in accordance with Applicable Data Protection Law.

Where required, Forlods or its relevant Subprocessor shall rely on an appropriate transfer mechanism, which may include:

  • an adequacy decision by the European Commission;
  • the European Commission's Standard Contractual Clauses; or
  • another lawful transfer mechanism available under the GDPR.

Forlods shall implement supplementary safeguards where required by Applicable Data Protection Law.

12. Deletion and return of Personal Data

Customer Personal Data shall not be retained for longer than necessary to provide the Services or comply with applicable legal obligations.

The intended standard retention period for event and guest data is 12 months after the event date, unless the Customer deletes the data earlier.

A Customer may delete its account through the Services. Customer Personal Data associated with the account will be deleted in accordance with Forlods' deletion procedures, except for information Forlods is legally required to retain.

Forlods does not retain unrelated guest lists, allergies, dietary requirements or other event information for accounting purposes.

Deleted Personal Data may remain temporarily in backups or technical records until those copies are overwritten or deleted through normal retention cycles.

The exact automatic deletion process, backup retention periods and technical deletion procedures are currently being verified and will be updated following completion of the technical review.

Upon termination of Processing under this DPA, Forlods shall, at the Customer's choice and where required under Article 28 GDPR, delete or return Customer Personal Data and delete remaining copies, unless applicable law requires continued storage.

13. Audit and information rights

Forlods shall make available information reasonably necessary to demonstrate compliance with its obligations as Processor under this DPA.

The Customer may request reasonable documentation relating to Forlods' Processing and security measures.

Where the information provided is insufficient to demonstrate compliance, the Customer may request an audit relating specifically to Processing under this DPA.

Audits must, unless required following a security incident or by a Supervisory Authority:

  • be requested with reasonable advance notice;
  • take place during normal business hours;
  • avoid unreasonable interference with Forlods' operations;
  • be subject to appropriate confidentiality obligations; and
  • be limited to information and systems relevant to the Customer's Personal Data.

Where reasonable, documentation and remote review should be used before an on-site inspection.

Nothing in this section limits audit or inspection rights that cannot lawfully be restricted under Applicable Data Protection Law.

14. Confidentiality

Forlods shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or are subject to an appropriate statutory duty of confidentiality.

These obligations shall continue after the person's access to Customer Personal Data ends.

15. Liability

Liability arising under this DPA is subject to the liability provisions in the Terms to the extent permitted by Applicable Data Protection Law.

Nothing in the Terms or this DPA excludes or limits liability where such exclusion or limitation is prohibited by Applicable Data Protection Law.

16. Priority and duration

This DPA forms part of the Terms.

If there is a conflict between this DPA and the Terms concerning Processing of Customer Personal Data on behalf of the Customer, this DPA shall prevail in relation to that Processing.

The DPA applies for as long as Forlods processes Customer Personal Data on behalf of the Customer.

Forlods may update this DPA where reasonably necessary to:

  • comply with changes in Applicable Data Protection Law;
  • reflect changes to the Services or Processing;
  • update Subprocessors;
  • improve or clarify data protection provisions; or
  • accurately document technical and organisational measures.

Material changes that reduce the Customer's data protection rights will be communicated appropriately before taking effect.

Annex 1 – Details of Processing

Subject matter

Processing of Personal Data necessary to provide the Forlods event-planning, guest-management and RSVP Services.

Duration

For the duration of the Customer's use of the Services and the applicable retention period.

The intended standard retention period for event and guest information is 12 months after the relevant event date unless deleted earlier.

Exact deletion and backup procedures are pending technical verification.

Nature of Processing

Processing may include:

  • collection;
  • receipt;
  • organisation;
  • storage;
  • retrieval;
  • consultation;
  • display;
  • modification;
  • transmission at the Customer's request;
  • restriction; and
  • deletion.

Purpose

To provide the Services requested by the Customer, including event planning, RSVP management, guest administration and related functionality.

Categories of Data Subjects

Primarily:

  • guests invited to events managed through Forlods; and
  • other persons whose information the Customer lawfully records as part of managing an event.

Types of Personal Data

Depending on how the Customer uses the Services, Customer Personal Data may include:

  • name;
  • email address;
  • RSVP and attendance status;
  • food preferences;
  • dietary requirements;
  • allergies;
  • special considerations; and
  • information entered into notes or other free-text fields.

Because free-text fields are available, Customers and guests may enter additional types of Personal Data not specifically requested by Forlods.

Special categories of Personal Data

Information concerning allergies, medical dietary requirements or other special considerations may reveal information concerning health and may therefore constitute special categories of Personal Data.

The Services are not intended for the storage of special category information beyond information reasonably necessary for the organisation of an event.

Annex 2 – Subprocessors

Interim list – pending technical verification

Forlods uses or expects to use the following providers in connection with operation of the Services. Inclusion in the final Subprocessor list depends on whether the provider processes Customer Personal Data on behalf of the Customer.

Provider

Purpose

Customer Personal Data

Processing location

Supabase

Database, backend infrastructure and related services

To be confirmed

To be confirmed

Vercel

Hosting and application infrastructure

To be confirmed

To be confirmed

Resend

Email delivery

To be confirmed, including whether guest/event communications are processed

To be confirmed

The technical review will determine whether any additional providers qualify as Subprocessors for purposes of this DPA.

Services used by Forlods for its own purposes, such as payment processing, marketing or general analytics, are not automatically Subprocessors under this DPA merely because Forlods uses them.

The roles of PostHog, Plausible, Stripe and other current providers are being reviewed as part of the technical assessment.

Forlods will update this Annex once the review is completed.

Annex 3 – Technical and Organisational Measures

Interim version – detailed technical verification pending

Forlods shall maintain technical and organisational measures appropriate to the nature, scope and risks of the Processing.

The measures shall address, where applicable:

  1. Access control
    Measures designed to limit production-system and Personal Data access to authorised persons with a legitimate need for access.
  2. Authentication
    Appropriate authentication and account-security measures for systems providing access to Customer Personal Data.
  3. Encryption and secure communication
    Appropriate measures for protecting Personal Data during transmission and, where relevant, during storage.
  4. Hosting and infrastructure security
    Use of established infrastructure providers and appropriate configuration of systems processing Customer Personal Data.
  5. Backups and recovery
    Appropriate backup and recovery arrangements designed to protect availability and integrity of the Services.
  6. Logging and monitoring
    Appropriate technical logging and monitoring to support operation, security and investigation of incidents.
  7. Data minimisation
    Measures designed to limit unnecessary collection, disclosure and use of Customer Personal Data.
  8. Analytics and session recording
    Where product analytics or session-recording technology is used, Forlods shall take reasonable measures to prevent unnecessary capture of guest information, special category data and the contents of sensitive free-text fields.
  9. Incident response
    Procedures for assessing, responding to and documenting Personal Data breaches and other relevant security incidents.
  10. Deletion
    Procedures for deleting Customer Personal Data in accordance with the retention and deletion requirements of the Services.

The specific implementation, providers, processing locations, backup periods, logging periods and access-control measures will be added following completion of Forlods' current technical review.