Privacy policy

Last updated: 21 September 2026. The Danish version prevails if the two differ.

1. Who is responsible

Mathi ApS (Danish company registration no. 32890032), Nygårdsvænget 25, 8370 Hadsten, Denmark, runs Invity and is the data controller for the information you give us when you create an account and use the platform. Questions about your data? Write to us.

When a host creates an invitation, the host decides which details guests are asked for. Invity stores and shows that information on the host's behalf and uses it for nothing but running the event.

2. What we process

Hosts

  • Name and email (used to log in with a link by email).
  • Phone number, if you add it yourself.
  • The events, invitations, messages and settings you create.

Guests

  • Name, email and possibly phone number, entered by the host or by you when you reply.
  • Your reply, number of attendees, and any notes such as dietary needs and allergies.
  • Photos and greetings, if the host has enabled photo sharing or the guestbook and you upload or write something.
  • Check-in time, if the host uses check-in on arrival.

Technical

  • IP address and browser details in server logs, used for troubleshooting and to stop abuse.
  • Visitor statistics without cookies and without personal data (see the cookie policy).

3. Why we process it

  • To show the invitation, collect replies and give the host an overview. Basis: the agreement with the host (GDPR article 6(1)(b)).
  • To send invitations, reminders, confirmations and login links by email, and by SMS where the host has enabled it. Basis: the agreement with the host.
  • To keep the platform secure and prevent spam and abuse. Basis: our legitimate interest (article 6(1)(f)).

We do not sell data, and we do not use it to market to guests.

4. Who we share it with

We use these providers to run Invity. They process data only on our instructions:

  • Hosting: the platform and all data, including photos, live on our own server in Germany (EU). Data does not leave the EU.
  • InMobile (Denmark): delivery of email and SMS.
  • Cloudflare Turnstile: spam protection on the login and sign-up forms.

We do not pass data to anyone else unless the law requires it.

5. How long we keep it

  • Your account and events are kept until you delete them.
  • An event's public pages close about two weeks after the event. The data stays so the host can see replies and photos, until the host deletes the event.
  • Deleting an event deletes its guest list, replies, photos and greetings immediately.
  • Deleting your account deletes all your events and guest lists immediately.
  • Server logs are kept for up to 30 days.

6. Your rights

You have the right to access the data we hold about you, to have it corrected or deleted, to restrict processing, to object, and to receive your data in a common format.

  • Hosts can edit their details under Settings, download the guest list as CSV from the Invited page, delete an event, and delete the whole account under Settings.
  • Guests can change their reply through the link in the invitation. To have your data deleted, contact the host or write to us and we will help.

You can complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark, datatilsynet.dk.

7. Security

All traffic is encrypted (HTTPS). Login uses one-time links by email, so there are no passwords to leak. Every event has its own link, and a guest's personal page can only be opened with the link sent to that guest. Event pages are marked so search engines do not index them.

8. Changes

If we change this policy, we update the date at the top. For significant changes, hosts are notified by email.