We process personal data exclusively to support your marriage process in Denmark cleanly. In accordance with GDPR, the Swiss revDSG and the requirements of the Danish Familieretshuset. This page explains what data, why, and for how long.
1. Controller
The controller within the meaning of Art. 4 (7) GDPR and Art. 5 (j) revDSG is the provider named in the imprint. Please send privacy enquiries to info@wedding-denmark.com.
2. What data we process and what we do not
- Enquiry data: names, dates of birth (only if relevant to the marriage), marital status, nationalities
- Contact data: email, phone, WhatsApp number
- Authority and contract data: booked package, consents, version numbers, timestamps of confirmation and technical evidence of submission
- Authority documents: exclusively those that the Danish Familieretshuset requires for the application: passport or national ID, marital/civil status certificate, the legally binding divorce decree for divorced applicants, the death certificate for widowed applicants, the residence permit or visa for third-country nationals
- Payment data: processed via our payment provider; we do not store card numbers
- Technical data: IP, browser headers for operational and abuse protection
Private relationship evidence: photos of you as a couple, private chat histories, social media profiles or relationship histories are not collected as standard. If such evidence sensibly strengthens your case or Familieretshuset requests it in an individual case, we will process it only after separate agreement, in the minimum necessary scope and with manual pre-review.
3. Legal bases
- Art. 6 (1) (b) GDPR: performance of contract
- Art. 6 (1) (c) GDPR: legal obligations
- Art. 9 (2) (g) GDPR: transmission to the Danish authority in the public interest
- revDSG: contract and consent
4. Recipients and processors
A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with each of the processors listed below. Where a provider is headquartered outside the EU/EEA, Standard Contractual Clauses (SCC) under Art. 46 (2) (c) GDPR plus supplementary technical and organisational measures apply additionally, see § 4a below.
- Hosting & edge functions: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Data processing in the EU region (Frankfurt, fra1). DPA + SCC in place.
- Database, file storage & authentication: Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. We use the EU region (Frankfurt) exclusively. DPA + SCC in place.
- Payment processing: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. PCI-DSS Level 1 certified. We do not store card numbers.
- Transactional emails: Namecheap, Inc., 4600 East Washington Street, Suite 300, Phoenix, AZ 85034, USA (Private Email SMTP service). TLS-encrypted transmission. DPA + SCC in place.
- OCR / document text recognition: Mistral AI SAS, 15 rue des Halles, 75001 Paris, France (EU). If enabled, uploaded documents (passports, marital-status certificates, etc.) may be transmitted to Mistral's vision-LLM API for automated text extraction and classification, this helps our team verify your documents faster. The transfer stays within the EU. DPA under Art. 28 GDPR in place. Mistral stores inputs and outputs for at most 30 days for abuse detection and deletes them afterwards; they are not used for model training (paid tier). You can object to OCR processing (Art. 21 GDPR) at any time by writing to info@wedding-denmark.com, your documents will then be reviewed manually only.
- WhatsApp contact (optional): WhatsApp Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (subsidiary of Meta Platforms, Inc., USA). We use WhatsApp Business only if you deliberately contact us via the WhatsApp link. Your phone number and message content are then processed by Meta, we have no control over that. Email and phone are available as alternatives.
- Telegram contact (optional): Telegram Messenger Inc., based outside the EEA; EU representative under Art. 27 GDPR: European Data Protection Office (EDPO), Avenue Huart Hamoir 71, 1030 Brussels, Belgium. We use Telegram only if you deliberately write to us via the Telegram link. Your phone number or Telegram account and message content are then processed by Telegram, also in third countries without an adequacy decision; we have no control over that. Email and phone are available as alternatives.
- Consultation booking (optional): Cal.com, Inc., San Francisco, CA, USA. If you book a video consultation via our "book a consultation" link, the data you enter there (first names, nationalities, marital status, your note, email) is transmitted to Cal.com for appointment management. Legal basis for the transfer: Standard Contractual Clauses (Art. 46 GDPR) or the EU-US DPF. Use is optional, a consultation is also available by email or phone.
- Familieretshuset (Denmark): statutory recipient of the application documents, not a processor under GDPR, but an independent controller.
- Danish municipalities, apostille offices, sworn translators, postal services: only insofar as necessary for application, appointment, certificate, apostille, translation or dispatch, each acting as independent controllers.
All documents are reviewed manually by our team, no automated third-party evaluation within the meaning of Art. 22 GDPR. A complete list of all current service providers and their respective processing locations is sent to you on request at info@wedding-denmark.com.
4a. Transfers to third countries
Several of the processors named above are headquartered in a third country (USA or Singapore): Vercel, Supabase, Namecheap and, when you book a consultation, Cal.com. The personal data itself is technically processed in the EU where possible (Vercel/Supabase: Frankfurt region; Namecheap: TLS transmission), but the parent companies sit outside the EEA. Following the CJEU's Schrems-II ruling (C-311/18), the following applies to such configurations:
- Legal basis: Standard Contractual Clauses under Art. 46 (2) (c) GDPR, Module 2 ("Controller to Processor")
- Supplementary measures: encryption in transit (TLS 1.2+) and at rest (AES-256), pseudonymised access logs, EU-only storage regions, MFA for admin access
- EU–US Data Privacy Framework: Vercel and Stripe are certified participants in the EU–US DPF (as of 2026), so the EU Commission's adequacy decision of 10 July 2023 (Decision (EU) 2023/1795) applies to them in addition to the SCC. Namecheap is not a DPF participant; its transfers are safeguarded by the Standard Contractual Clauses named above.
A copy of the relevant SCC is available on request at info@wedding-denmark.com.
5. Retention period
Enquiry data is deleted after 12 months if no contract is concluded. Contract data and document copies are retained for 10 years in accordance with commercial law requirements and are then automatically deleted.
6. Your rights
Access, rectification, erasure, restriction of processing, data portability and objection. At any time by email to info@wedding-denmark.com. You also have the right to lodge a complaint with the competent data protection authority of your country of residence.
7. Cookies and tracking
We use only strictly necessary cookies (language preference, login session). We run no analytics or tracking tools whatsoever: no Google Analytics, no Meta/Facebook Pixel, no Vercel Analytics, no advertising pixels and no cross-site tracking. If we ever introduce more than cookieless, anonymous audience measurement, we will first add a genuine opt-in consent banner with a reject option (Art. 6 (1) (a) GDPR, § 25 TDDDG) before anything loads.
Source of enquiries (advertising measurement). If you reach us through an advertisement or a link and then send an enquiry or booking, we store the technical source information with that enquiry (e.g. the Google Ads click ID «gclid» from the address bar, or the referring page) so that we can see which measure works. This happens without cookies, only from the address called up or the referrer, without access to your device and without advertising pixels; there is no profiling and no disclosure to advertising networks (legal basis: legitimate interest in measuring success, Art. 6 (1) (f) GDPR).