Who we are
Sposa is operated by SPOSA LIMITED, a company registered in Scotland
(company number SC889364). We are registered with the UK Information
Commissioner's Office (ICO) as a data controller — registration number pending,
will be published here as soon as it is issued.
For any privacy or data-protection question, write to our Data Protection Officer at dpo@sposa.ai. We aim to acknowledge within two working days and respond fully within thirty.
What we collect
From you, when you sign up
- Email address (used as your sign-in identifier).
- Names of you and your partner (display, brief generation, vendor outreach).
- Wedding date, region, guest count, ceremony type, day-of-week, vibe, formality, optional budget.
From you, as you use Sposa
- Emails you forward, or that vendors reply to, addressed to your per-thread
reply alias at
agent.sposa.ai— plus any attachments (contracts, quotes, schedules). - If you connect Gmail: messages you put the “Sposa” label on —
and only those. The connection uses Google’s read-only scope
(
gmail.readonly); Sposa cannot send, delete or modify mail, and unlabelled mail is never fetched. The OAuth refresh token is envelope-encrypted with a dedicated AWS KMS key. Revoke at any time from your Google account or the Account page. - If you connect Google Drive: files Sposa lists and reads under the read-only
scope (
drive.readonly) to find wedding documents you point it at. Same encryption, same revocation. - Image URLs or images you submit to a mood board.
- Manual edits, task completions, calendar entries.
The plain-English mechanics of inbox access live on the security page.
Generated by Sposa from your data
- Structured records derived from your forwarded emails: suppliers, contracts, payments, dates, prices, action items.
- Your personalised checklist (~80–120 tasks).
- Mood-board palette and "the look" prose.
- Outreach drafts Sposa writes for your review before sending.
From Stripe, when you subscribe
We never see or store your card number. Stripe processes the payment and tells us only the metadata we need to give you the service: a customer ID, a subscription ID, the price you paid, and the status of each invoice. The full Stripe data shadow is managed by Stripe, not us — see their privacy notice.
Why we collect it
Solely to provide the service you've subscribed to: read your inbox for you, structure the data, draft your vendor outreach, generate your brief and checklist, and surface your wedding's operational state on a single dashboard.
We do not sell your data. We do not show you targeted advertising. We do not take affiliate fees or kickbacks from any supplier Sposa recommends.
Lawful basis (UK GDPR)
- Article 6(1)(b) — necessary for the performance of the contract you've signed up to (the core service).
- Article 6(1)(f) — legitimate interest, for routine product analytics on aggregated, non-identifying usage patterns.
- Article 6(1)(a) — explicit consent, for any optional marketing communications.
Sposa does not make solely-automated decisions of legal or significant effect about you (Article 22). Every recommendation Sposa surfaces is advisory; you make the decisions and you send the emails.
Special-category data
Some dietary requirements (kosher, halal, etc.) imply religious belief and therefore count as special-category data under Article 9. If you provide these, we process them only to the extent necessary to share with your caterer, on the basis of explicit consent at the point of entry.
Where your data lives
All primary data is hosted in the AWS London region (eu-west-2): our
Postgres database, S3 bucket of raw email and attachments, mood-board images, and
generated documents. AI inference uses Anthropic Claude via AWS Bedrock in the same eu-west-2 region. Anthropic does not retain Bedrock inputs and does
not train on customer data.
Our complete list of sub-processors, the data category each one handles, and their processing region is below. Where data crosses the UK/EEA border (Stripe, for example, may route through their US payment infrastructure), appropriate Standard Contractual Clauses are in place under the relevant DPA.
Sub-processors
| Processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, database, file storage, AI inference (Bedrock) | UK (eu-west-2) |
| Stripe Payments UK Ltd | Subscription billing, card processing | UK / EU (some US routing) |
| Brevo (Sendinblue SAS) | Outbound transactional email (welcome, vendor outreach) | EU (France) |
| Anthropic, PBC | Claude model weights (accessed via AWS Bedrock) | UK (via AWS eu-west-2) |
| Google LLC (Workspace) | DPO mailbox forwarding (dpo@sposa.ai) | EU / US (DPA + SCCs) |
| Amazon Cognito | Sign-in & account identity | UK (eu-west-2) |
Material changes to this list are announced at least 14 days in advance via email so you can object before the change takes effect.
How long we keep it
- While your subscription is active: retained for the duration of your service.
- After cancellation: a 30-day grace period (in case you change your mind), then anonymised — your name, email and supplier names are removed; aggregate non-identifying patterns may be retained for product improvement under legitimate interest.
- On your explicit deletion request: within 30 days, all primary copies and reachable backups are expired. Audit and billing-event rows are anonymised in place (legal retention obligation; we cannot just drop them).
Your rights
You have the right to:
- Access the data we hold on you — one-click JSON export from your account page.
- Correct inaccurate data — edit your intake or your partner's email at any time on the account page.
- Request deletion — the "Delete my account" button on the account page, or email dpo@sposa.ai.
- Port your data — the same JSON export is machine-readable.
- Object to processing on legitimate-interest grounds — write to dpo@sposa.ai.
- Withdraw consent for any processing based on consent.
- Lodge a complaint with the ICO at ico.org.uk.
Security
TLS 1.3 in transit. KMS-encrypted at rest in S3 and AES-256 at rest in RDS. IAM least-privilege, no shared credentials, mandatory MFA on every admin account. Stripe Checkout means we never touch raw card data — the payment form is hosted by Stripe and PCI compliance sits with them.
Cookies
Sposa uses the minimum cookies needed to keep you signed in and to remember your cookie-banner choice. We do not use third-party analytics, advertising or tracking cookies. See our cookies page for the complete list and purpose of each one.
Changes to this notice
Material changes are notified by email and dated above. Minor edits (typo fixes, link updates) are made in place and reflected in the "Last updated" date.