Skip to content

Data processing agreement

The DPA is available on request, before any commercial conversation and without a sales step in front of it. It is not published here because it is a signed instrument rather than a page, and because the version you sign names your own hosting region.

What the agreement covers

  • Roles: you are the controller of the data in your event organization, we are the processor.
  • Scope and duration of processing, and the categories of data and data subjects involved.
  • The named hosting region for your organization, fixed at setup.
  • The current subprocessor list, and notice before any addition to it.
  • Security measures, and the incident notification window — 72 hours from confirmation.
  • Assistance with data subject requests, and audit rights.
  • Deletion and return of data at the end of the agreement.
  • International transfer mechanism where one applies.

While you are waiting for it

The security page answers most of what a reviewer asks before the DPA arrives: hosting and residency, access control, backups and retention, incident response, subprocessors, and where we are on SOC 2. It is written for you rather than for a buyer, and it has no call to action on it.

Ask for the DPA: [email protected]