Wed OS← Back to home

Privacy Policy

Last updated: July 2026
Draft for review — this policy is a working draft and must be reviewed by legal counsel before WedOS onboards paying customers.

This Privacy Policy explains how Wed OS collects, uses, shares, and protects personal data when wedding-planning agencies and their teams use our platform. We are committed to handling data responsibly and in line with India's Digital Personal Data Protection Act, 2023 (DPDP), and, where applicable, the EU/UK General Data Protection Regulation (GDPR).

1. Who we are

Wed OS ("Wed OS", "we", "us", "our") is a multi-tenant Software-as-a-Service platform for wedding-planning agencies, covering the full lead-to-execution lifecycle: leads, weddings, guests and RSVP, vendors, budgets and invoicing, and an AI copilot. The platform is operated by AI First Solutions Pvt. Ltd., a company incorporated in India. Our website is https://wed-os.com.

For questions about this policy or your personal data, contact us at privacy@wed-os.com.

2. Our two roles: fiduciary vs. processor

Wed OS handles personal data in two distinct capacities, and the distinction matters for your rights:

a) When we act as a Data Fiduciary (Controller)

For data about the agency and its authorised users — the account holder's name, work email, login credentials, billing details, and how the agency's team uses the platform — Wed OS decides the purposes and means of processing. Under DPDP we are the Data Fiduciary; under GDPR we are the Controller.

b) When we act as a Data Processor

For the wedding and guest data an agency inputs into the platform — couple and guest names, contact details, RSVP responses, dietary notes, seating, vendor assignments, and similar — the agency is the Data Fiduciary/Controller and Wed OS is the Data Processor acting on the agency's behalf and instructions. The agency decides what guest data to collect and why; we process it to provide the service. Guests and couples whose data appears in an agency's workspace should direct data-rights requests to the agency in the first instance, and we will support the agency in responding.

3. Data we collect

Account data

Information you provide when creating and managing an agency account: name, business name, email address, phone number, password (stored only as a salted hash), role, and profile settings.

Wedding and guest data (entered by the agency)

Data the agency inputs about its clients and their events, which may include: couple and guest names, contact information (email, phone, address), relationship and household groupings, RSVP status, dietary requirements and allergies, accessibility notes, gift and budget records, vendor details, and event logistics. Some of this may constitute sensitive personal data (for example, dietary notes that reveal religious practice), and the agency is responsible for having a lawful basis and, where required, consent to collect it.

Guest identity documents (optional, on-device only)

Where an agency uses the optional ID-capture feature (for example, to verify guest identity for a destination wedding), any scanning or text-extraction from a passport, Aadhaar, or similar document is performed on-device, inside the guest's or agency's own web browser. The raw ID image is never uploaded to or stored on Wed OS servers. Only the specific fields the agency chooses to save (for example, a name and document number) are retained, and the agency is responsible for the lawfulness of collecting them. We strongly recommend agencies avoid storing full ID numbers unless strictly necessary.

Usage and technical data

Log and device information generated when you use the platform: IP address, browser and device type, pages and features accessed, timestamps, referring URLs, and diagnostic or error data. We use this to operate, secure, and improve the service.

Cookies and similar technologies

We use strictly necessary cookies and browser storage to keep you signed in and to remember your preferences. See our Cookie Policy for full details.

4. How we use data

We do not sell personal data, and we do not use guest data uploaded by agencies to train third-party AI models.

5. Legal basis for processing

Under the DPDP Act, 2023 (India)

We process personal data on the basis of the individual's consent, or on the basis of certain legitimate uses permitted by the Act (such as processing necessary to provide a service that has been requested, to comply with law, or for related purposes). Where consent is the basis, it can be withdrawn at any time.

Under the GDPR (for EU/UK data subjects)

Because agencies serve international and destination-wedding clients, some guests may be in the EU or UK. Where GDPR applies, we (or the agency, as Controller) rely on one or more of the following lawful bases: performance of a contract, legitimate interests (balanced against the individual's rights), consent, and compliance with a legal obligation. For any special-category data, an additional condition (typically explicit consent) is required, which the agency is responsible for obtaining.

6. Third-party processors we rely on

We share personal data with a limited set of vetted service providers ("sub-processors") strictly to operate the platform. Each is bound by contractual data-protection obligations and may only process data on our instructions:

ProviderPurposeData involved
RazorpayPayment processing for subscriptionsBilling and transaction data. Wed OS does not store full card numbers; card details are handled by Razorpay.
ResendTransactional and notification email deliveryRecipient email address and message content
Google GeminiPowering AI copilot featuresThe specific content submitted to the copilot for a given request
Cloud hosting providerApplication hosting, storage, and infrastructureAll platform data, encrypted in transit and at rest

We may add or change sub-processors as the platform evolves; material changes will be reflected in this policy. We may also disclose data where required by law, to protect our rights, or in connection with a corporate transaction (with continued protection of the data).

7. Data retention

We retain account and agency data for as long as the account is active and as needed to provide the service. Guest and wedding data is retained on behalf of the agency and is deleted or returned in accordance with the agency's instructions and our data-processing terms. After account closure, we delete or anonymise personal data within a reasonable period, except where we are required to retain certain records (for example, invoices and tax records) to meet legal, accounting, or regulatory obligations.

8. Security measures

We implement technical and organisational safeguards appropriate to the risk, including encryption of data in transit (TLS) and at rest, hashed credentials, role-based access controls, tenant isolation in our multi-tenant architecture, audit logging, and least-privilege access for our team. The on-device design of ID scanning is itself a privacy safeguard, keeping raw identity images off our servers. No system is perfectly secure, but we work continuously to protect personal data against unauthorised access, loss, or misuse.

9. Your rights

Under the DPDP Act

Subject to the Act, individuals (Data Principals) have the right to: access a summary of their personal data and how it is processed; correct, complete, or update inaccurate data; erase personal data no longer needed; nominate another person to exercise rights in the event of death or incapacity; and grievance redressal. You may also withdraw consent where consent is the basis of processing.

Under the GDPR

Where GDPR applies, data subjects additionally have rights to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing, and the right to lodge a complaint with a supervisory authority.

Because much of the guest data on the platform is processed on behalf of agencies, if you are a guest or couple please contact the agency that holds your data first. If you are unsure who that is, or need our help, email privacy@wed-os.com and we will assist or route your request appropriately.

10. Cross-border transfers

Wed OS is operated from India, and agencies serving international clients may cause data to move across borders. Where personal data is transferred outside its country of origin — including transfers involving EU/UK data subjects — we take steps to ensure an adequate level of protection consistent with applicable law, such as contractual safeguards (for example, standard contractual clauses) with our providers and restricting transfers to jurisdictions and vendors that maintain appropriate protections. Transfers from India are made in accordance with the DPDP Act and any restrictions notified by the Government of India.

11. Children's data

The Wed OS platform is intended for use by wedding-planning professionals and is not directed to children. We do not knowingly create accounts for children. Guest lists managed by an agency may occasionally include minors (for example, children attending a wedding); the agency is responsible for obtaining verifiable parental or guardian consent where the DPDP Act or GDPR requires it before entering a child's personal data, and for limiting such data to what is necessary.

12. Breach notification

If we become aware of a personal data breach, we will act promptly to contain and assess it. Where we act as Data Fiduciary/Controller, we will notify the relevant supervisory authority (including the Data Protection Board of India, and any GDPR supervisory authority where applicable) and affected individuals as required by law and within applicable timelines. Where we act as Processor on an agency's behalf, we will notify the affected agency without undue delay so it can meet its own notification obligations.

13. Contact and grievance officer

For privacy questions, to exercise your rights, or to raise a grievance, contact:

Privacy / Grievance Officer
AI First Solutions Pvt. Ltd.
Email: privacy@wed-os.com
General support: support@wed-os.com

We will acknowledge and respond to grievances within the timelines required by the DPDP Act and other applicable law.

14. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify account holders. Your continued use of the platform after an update constitutes acceptance of the revised policy.