EventikitLegal

Customers · Last updated September 15, 2026

Data Processing Addendum

How Eventikit processes registrant and other personal data on a customer's behalf, and the safeguards it commits to.

01Roles of the parties

For personal data about registrants, guests, waiver signers and message recipients that Customer submits to the service, Customer is the controller and Eventikit is the processor. For account, billing and usage data about Customer's own users, Eventikit acts as an independent controller under the Privacy Policy.

02Details of processing

Subject matter
Hosting event pages and registration forms, storing registrations, sending event communications, check-in, reporting and integrations Customer enables.
Duration
The term of the Agreement, plus the export and deletion periods described below.
Data subjects
Registrants, their guests, waiver signers, onsite staff and message recipients.
Categories of data
Contact details, registration answers, ticket and session selections, payment status (not card numbers), check-in times, waiver signatures, and message delivery events. Customer may configure fields that collect other data; fields Customer marks as sensitive are stored with that flag and restricted in exports.

03Eventikit's obligations

  • Process personal data only on Customer's documented instructions, which include using the service as configured.
  • Ensure personnel with access are bound by confidentiality.
  • Assist Customer, taking into account the nature of processing, with data subject requests, security, breach notification and data protection impact assessments.
  • Notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data.
  • Make available information reasonably necessary to demonstrate compliance, and allow audits no more than once a year on 30 days' notice, or more often after a breach.

04Security measures

  • Encryption in transit (TLS 1.2 or higher) and at rest.
  • Organization-scoped data access enforced in the database with row-level security.
  • Role-based permissions in the portal, with optional required multi-factor authentication.
  • Integration credentials stored in an encrypted secret vault, never in plain text.
  • Signed and verified webhooks from payment, email and SMS providers.
  • Rate limiting on authentication and public registration endpoints.
  • An activity log of administrative actions available to Customer.
  • Backups with point-in-time recovery, and tested restore procedures.

05Subprocessors

Customer authorizes Eventikit to engage the subprocessors listed on the Subprocessors page. Eventikit imposes data protection terms on each that are no less protective than this Addendum, and remains responsible for their performance. We will give at least 30 days' notice before adding a subprocessor; Customer may object on reasonable data protection grounds, and if we cannot address the objection, Customer may terminate the affected service and receive a refund of prepaid fees for it.

06International transfers

Where personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the parties agree to Module Two (controller to processor) of the Standard Contractual Clauses, with the UK International Data Transfer Addendum where applicable, which are incorporated by reference.

07Return and deletion

Customer can export its data at any time. On termination, Eventikit will keep Customer data available for export for 30 days, then delete it from active systems within 30 days and from backups within a further 35 days, unless the law requires longer retention.