GDPR · organizer terms

Data Processing Agreement

The roles, instructions, security controls and subprocessors used when Eventnado handles attendee data for an Organizer.

Version: DPA-2026-08-11-v1Effective from: 11 August 2026Free pilot

1. Parties and formation

The controller is the Organizer identified in the Eventnado organization profile (the “Controller”). The processor is 9ne.pl Jarosław Staroń, Polish Tax ID 8942787122, ul. Starobielawska 32a, 54-061 Wrocław, Poland (the “Processor”).

This DPA is an annex to the Terms of Service. It is concluded electronically when an organization owner, after the documents are made available, enables registrations, adds attendee data or otherwise starts using a feature that processes data for the Organizer. Confirmation of the current version can be requested from the owner email at contact@eventnado.com.

2. Roles and boundaries

The Processor handles attendee, club member, invitee, team and business-contact data only to provide features selected by the Controller. The Controller determines purposes, form scope, recipients, publication, communications and event-specific retention needs.

The Processor is a separate controller for account authentication, security, service accountability, complaints and its own operational communications. Those activities are covered by the Privacy Policy and are not processing on behalf of the Organizer.

3. Subject, purpose and duration

Processing covers storage, organization, retrieval, display, transmission, export, security, backups, anonymization and deletion needed for Eventnado features. It runs from first use until return or deletion after termination, subject to controlled backup rotation and legal duties.

Documented instructions include Controller actions in the dashboard, form and access settings, API requests and instructions sent by an organization owner or administrator. If an instruction infringes data-protection law, the Processor informs the Controller before acting unless law prohibits such notice.

4. Data subjects and data

Data subjectsExamples
Attendees and applicantsname, email, phone, city, form answers, consent records, registration status, ticket and check-in identifiers
Club and community memberscontact details, membership number, role, status, invitation and communication history
Organizer teamaccount identifier, role, permissions and organization audit activity
Partners and contactsprofessional details, requests, offers and engagement history
Automotive event attendeesvehicle details, safety answers and Organizer-required documents

Special-category data, criminal-conviction data and identity-document numbers must not be collected unless the Controller has first confirmed necessity, lawful basis, access scope and additional safeguards. Eventnado does not store full payment-card details.

5. Processor duties

  • process data only on documented Controller instructions, including for international transfers;
  • restrict access to persons bound by confidentiality and least privilege;
  • maintain Article 32 GDPR measures appropriate to risk and the pilot stage;
  • assist with data-subject requests, impact assessments, consultations and security duties;
  • notify the Controller of a personal-data breach without undue delay and provide available information;
  • not sell data, use it for advertising or combine organizations for the Processor’s own profiling.

6. Technical and organizational measures

Access

OIDC/Keycloak, organization roles, membership checks, tenant separation and least privilege.

Transit and secrets

TLS, certificate validation, secrets outside application images and no repository passwords.

Data and files

PostgreSQL RLS for critical tables, private object storage, file scanning and controlled exports.

Resilience

Consistent relational/object backups, SHA-256 checks, encrypted off-site copy, restore testing and rotation.

Detection

Audit logs, readiness monitoring, alerts, rate limiting and automated-abuse controls.

Lifecycle

Versioned retention, anonymization, legal holds, rights requests and deletion re-application after disaster recovery.

The Controller remains responsible for team roles, recipients, forms, event retention choices and secure devices.

7. Subprocessing

The Controller gives general authorization for the entities and categories below. The Processor gives at least 14 days’ notice of a planned material change and allows a reasoned objection. Subprocessors receive obligations no less protective than this DPA.

Entity / categoryPurposeLocation and safeguard
OVHcloud — the contracted group entityVPS, network, domains, DNS and email transportMain infrastructure in the EEA; encrypted transit and restricted administrative access
Isolated backup node controlled by 9ne.pl on Toronto infrastructureEncrypted disaster-recovery copyCanada; AES-256 archive only, upload-only SFTP and no decryption key at the destination

Keycloak, PostgreSQL, Redis, Garage, ClamAV and Gotenberg run inside private Eventnado infrastructure and are not separate subprocessors.

8. Location and transfers outside the EEA

Active production and primary data are hosted on an OVHcloud VPS in the EEA. A second disaster-recovery copy is encrypted with AES-256 before transfer and stored as an unreadable archive on an isolated Toronto node. The sending account cannot list, retrieve, rename or delete copies, and the destination infrastructure operator does not receive the decryption key.

If any future recipient outside the EEA is to access readable data, the Processor will first ensure a GDPR Chapter V mechanism — such as an applicable adequacy decision or Standard Contractual Clauses with a transfer assessment — and update the subprocessor list.

9. Rights and compliance assistance

The Processor provides search, export, correction, anonymization and deletion capabilities supported by the product. A request received directly from a person concerning Organizer-controlled data is forwarded to the Controller unless law requires otherwise. The Processor supplies information reasonably needed for risk assessment, DPIA and compliance evidence.

10. Breaches and cooperation

After becoming aware of a breach of entrusted data, the Processor notifies the Controller without undue delay and provides, as available, the incident nature, affected categories, approximate scale, likely consequences, measures taken or proposed and a contact point. Details may be supplied in phases. The Controller decides on regulatory and data-subject notification unless law places that duty directly on the Processor.

11. Return, deletion and backups

On termination, the Controller may request an export before deletion. The Processor then deletes or anonymizes data and copies unless law requires retention. Inactive backups expire by rotation and are not used for ordinary operations. Earlier deletions are re-applied after disaster recovery.

12. Information and audit

On reasonable request, the Processor supplies control descriptions, relevant test results or other compliance evidence. An audit must not weaken security for other organizations or disclose secrets. It normally occurs once a year after scope and timing are agreed; a breach or authority request may justify more. Documentation and remote review are used first.

This DPA applies for the duration of processing services. Mandatory GDPR rules prevail. A material data-protection change requires notice and publication of a new version.