Roles of the parties
For personal data about registrants, guests, waiver signers and message recipients that Customer submits to the service, Customer is the controller and Eventikit is the processor. For account, billing and usage data about Customer's own users, Eventikit acts as an independent controller under the Privacy Policy.
Details of processing
- Subject matter
- Hosting event pages and registration forms, storing registrations, sending event communications, check-in, reporting and integrations Customer enables.
- Duration
- The term of the Agreement, plus the export and deletion periods described below.
- Data subjects
- Registrants, their guests, waiver signers, onsite staff and message recipients.
- Categories of data
- Contact details, registration answers, ticket and session selections, payment status (not card numbers), check-in times, waiver signatures, and message delivery events. Customer may configure fields that collect other data; fields Customer marks as sensitive are stored with that flag and restricted in exports.
Eventikit's obligations
- Process personal data only on Customer's documented instructions, which include using the service as configured.
- Ensure personnel with access are bound by confidentiality.
- Assist Customer, taking into account the nature of processing, with data subject requests, security, breach notification and data protection impact assessments.
- Notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data.
- Make available information reasonably necessary to demonstrate compliance, and allow audits no more than once a year on 30 days' notice, or more often after a breach.
Security measures
- Encryption in transit (TLS 1.2 or higher) and at rest.
- Organization-scoped data access enforced in the database with row-level security.
- Role-based permissions in the portal, with optional required multi-factor authentication.
- Integration credentials stored in an encrypted secret vault, never in plain text.
- Signed and verified webhooks from payment, email and SMS providers.
- Rate limiting on authentication and public registration endpoints.
- An activity log of administrative actions available to Customer.
- Backups with point-in-time recovery, and tested restore procedures.
Subprocessors
Customer authorizes Eventikit to engage the subprocessors listed on the Subprocessors page. Eventikit imposes data protection terms on each that are no less protective than this Addendum, and remains responsible for their performance. We will give at least 30 days' notice before adding a subprocessor; Customer may object on reasonable data protection grounds, and if we cannot address the objection, Customer may terminate the affected service and receive a refund of prepaid fees for it.
International transfers
Where personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to Module Two (controller to processor) of the Standard Contractual Clauses, with the UK International Data Transfer Addendum where applicable, which are incorporated by reference.
Return and deletion
Customer can export its data at any time. On termination, Eventikit will keep Customer data available for export for 30 days, then delete it from active systems within 30 days and from backups within a further 35 days, unless the law requires longer retention.