Data Processing Addendum

This Data Processing Addendum (‘DPA’) sets out the terms and conditions related to the privacy, confidentiality and security of Personal Data associated with Software and Services provided by Event Maestro to event organisers pursuant to the Event Organiser Terms and Conditions (‘Agreement’).

In this DPA references to ‘we’, ‘us’, or ‘our’ means Event Maestro Ltd and references to ‘you’ means the Event Organiser.

  1. Overview and Definitions.

The terms of this DPA are hereby incorporated into the Agreement, Privacy Policy/Notice or any other applicable services agreement between you and us.

With respect to provisions regarding Processing of Personal Data, in the event of a conflict between the Agreement and this DPA, the provisions of this DPA shall prevail. In the event of a conflict between this DPA and any other provision of the Agreement between you and us, this DPA will prevail; except where you and Event Maestro have individually negotiated data processing terms that are different from this DPA and which meet the requirements of applicable Data Protection Laws in full, in which case those negotiated terms will prevail.

In this DPA these words or terminology have the following meanings:

  • Agreement’ means the Agreement between you or your organisation and Event Maestro;
  • Data Controller’, ‘Controller’, ‘Data Processor’, ‘Data Subject’, ‘Processing’ and shall have the same meanings as in applicable Data Protection Laws;
  • DPA18’ means the Data Protection Act 2018;
  • ‘Data Protection Laws’ and ‘Applicable Laws’ means all domestic Data Protection Laws and Regulations of the UK related to the privacy, confidentiality and security of Personal Data and, to the extent applicable, the data protection or privacy laws of any other country;
  • Data Security Breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Personal Data Processed by Event Maestro on the Event Organiser’s behalf as part of the Event Organiser’s use of the Software and Services.
  • Event Organiser‘, ‘you‘ and ‘user’ means any person or legal entity who has an Account and uses any of the Software and Services, including event delegates;
  • EU SCCs’ means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council;
  • EU GDPR’ means the General Data Protection Regulation (EU) 2016/679.
  • Personal Information‘ or ‘Personal Data’ has the meaning given in the UK General Data Protection Regulation and Data Protection Act 2018 and/or the EU General Data Protection Regulation where this applies to EU citizens or residents;
  • Privacy Policy‘ means our privacy policy and as amended from time to time;
  • Services‘ means access to and use of the Software and event management and ticketing to register and manage tickets to events and activities, the QR Code Generation, and all other services made available by us to you on, or through the Software or otherwise;
  • Software‘ means the software that we provide to you to help you manage your event including all protected areas and mobile sites, apps, APIs and widgets;
  • Sub-processor; means any natural or legal person (but excluding an employee of Event Maestro Ltd) appointed by or on behalf of Event Maestro Ltd or any Event Maestro Affiliate to process Personal Data on behalf of any Event Organiser or Account Holder in connection with the Main Contract;
  • Technical and Organisational Measures’ means reasonable security measures implemented by Event Maestro appropriate to the type of Personal Data being Processed on the Event Organiser’s behalf and the Services being provided by Event Maestro designed to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure;
  • UK GDPR’ means the UK General Data Protection Regulation as enacted by The Data Protection, Privacy and Electronic Communications (Amendments etc)(EU Exit) Regulations 2019;
  • UK IDTA’ means the UK International Data Transfer Agreement, an international data transfer addendum to the European Commission’s Standard Contractual Clauses for international data transfers issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act of 2018 and entering into force on 21 March 2022, as updated, amended, or replaced from time to time.
  1. Applicability of DPA and scope of data processing activities.
    • In using Event Maestro’s Software and Services, you act as the Controller of the Personal Data associated with an Account or a user of the Software or Services, or on whose behalf you are using the Software or Services, to register for or purchase a ticket to attend such event (‘Delegate’). You represent and warrant that you have provided any necessary notices and if required, obtained any necessary consents related to the collection of such Personal Data from the delegate and you have the right to share such Personal Data with Event Maestro (us).
    • Where Event Maestro Processes the Personal Data of Delegates on your behalf as the Event Organiser, as part of agreed Services, we are a Data Processor in performing such Processing and you are the Controller. This includes circumstances where we obtain Personal Data as a result of the provision of its ticketing services or QR Code generator (for example, where we facilitate the transmission of emails to Delegates at your request, process payments, or provide event reports and tools to enable you to gain insights into the effectiveness of various sales channels).
    • In respect of some Processing of Delegates’ Personal Data, we may act as a Controller, for example, where Delegates have engaged with aspects of the Software and Services beyond those relating to your event or where Delegates’ Personal Data is Processed by us to conduct research and analysis to enable improvement of software and features and provide targeted recommendations. With regard to such processing, we are an independent Controller and not a Joint Controller with you as the Event Organiser.
    • To the extent that we Process Personal Data as a Data Processor or Service Provider on your behalf, Section 3 of this DPA shall apply, however, when we are acting as a Controller of Delegates’ Personal Data, our processing shall not be subject to this DPA.
    • The Event Organisers, as the Controller, shall provide Users and Delegates with details of the purpose of processing of Personal Data, duration, nature, types of Personal Data, and categories of data Subjects, in the form of a Privacy Notice that they make available at the point of collection of the Personal Data.
    • Details about the Personal Data of Delegates to be processed by us as Data Processors, and the Processing activities to be performed under the Agreement are as follows:
      • duration – as set out in the Agreement;
      • nature, purpose, and subject matter – to enable you as the Event Organiser to organise and promote events, manage ticketing, take payments, and provide QR Codes to Delegates;
      • data categories – name, email address, billing and payment information, information related to events booked and attended, relationship to Event Organiser and any other Personal Data that you as the Event Organiser requests of its Delegates;
      • data subjects – Delegates.
    • Details about the Personal Data of others including Speakers and individual Sponsors to be processed by us as Data Processors, and the Processing activities to be performed under the Agreement are as follows:
      • duration – as set out in the Agreement;
      • nature, purpose, and subject matter – to enable you as the Event Organiser to organise and promote events, take or make payments, provide information to others including Speakers and individual Sponsors;
      • data categories – name, email address, billing and payment information, information related to events booked and attended, relationship to Event Organiser and any other Personal Data that you as the Event Organiser requests of others including Speakers and Individual Sponsors;
      • data subjects – Speakers, and individual Sponsors.

 

  1. Data processing clauses.
    • Whenever we process Personal Data on behalf of an Event Organiser, we shall:
      • Process Personal Data only on the documented instructions of you, the Event Organiser as the Controller, unless required to do otherwise by applicable law. We shall inform you of the legal requirement before processing Personal Data other than in accordance with your instructions unless that same law prohibits us from doing so on important grounds of public interest. You will ensure that instructions comply with all laws, regulations, and rules applicable to the Personal Data, and that our processing of such Personal Data will not cause us to violate any applicable law, regulation or rule, including Data Protection Laws. We will notify you, if in our opinion, an instruction is in breach of applicable Data Protection Laws. You as the Controller, hereby instructs us, Event Maestro, and we hereby agree, to process Personal Data as necessary to perform our obligations under the Agreement and for no other purpose, unless otherwise specified in this DPA or required to comply with the law or other binding governmental order. In the event that this DPA or any actions to be taken or contemplated in performance of this DPA do not or would not satisfy either party’s obligations under applicable Data Protection Laws, the parties shall negotiate in good faith upon an appropriate amendment to this DPA;
      • Comply with all applicable provisions of Data Protection Laws and provide the same level of protection for Personal Data as required of you the Controller under Data Protection Laws.  We will process Personal Data only as necessary to perform our obligations under the Agreement, or as otherwise permitted by Data Protection Laws. Without limiting the foregoing, We
        • Will not Sell or share the Personal Data;
        • Shall not retain, use, or disclose any such data outside of the direct business relationship between us unless permitted by Data Protection Laws or where the Delegate, Speaker or Sponsor has consented by means of opt-in to receive direct marketing; or
        • Shall not retain, use or disclose Personal Data for any purpose other than the business purposes specified in this DPA or otherwise permitted by Data Protection Laws.
      • Have Technical and Organisational Measures in place to protect and secure Personal Data;
      • Notify you in the event of a Data Security Breach without undue delay, unless otherwise prohibited by law or otherwise instructed by a law enforcement or data protection authority. In the event of any Data Security Breach, we may provide data breach notification to affected data subjects directly. Where we do not provide such notification, we shall provide reasonable assistance, where required by applicable Data Protection Laws and at your request, to enable you to comply with its data breach obligations as a Data Controller;
      • Ensure that its personnel are subject to obligations of confidentiality with respect to Personal Data of Delegates Processed by us on your behalf;
      • Impose obligations on its sub-processors that have access to Personal Data of Delegates Processed by us on your behalf that are the same as or equivalent to those set out in this DPA by way of written contract, and remain fully liable to you for any failure by a sub-processor to fulfil its obligations in relation to such Personal Data;
      • Provide reasonable assistance to you in responding to Data Subjects rights requests, complaints or other communications received under applicable Data Protection Laws from any supervisory authority or Delegate who is the subject of any Personal Data processed by us your behalf. In the event that a Delegate submits a Personal Data deletion request to Event Maestro directly, the Event Organiser as the Controller hereby instructs and authorises us to delete, restrict the processing or anonymise the Delegate’s Personal Data on behalf of the Controller. Where necessary, you as the Controller shall inform us of any other individual rights request that we must comply with and provide the information necessary for us to comply with the request.;
      • Upon your written request, make available to you all information reasonably necessary to demonstrate our compliance with the obligations, and allow for and co-operate with any audits. Any on-site audits shall be:
        • permitted only on reasonable advance notice to us, Event Maestro;
        • subject to appropriate confidentiality undertakings; and
        • limited to once every three (3) years and only in order to evaluate a specific suspected deficiency after exhausting all other reasonable means; and
      • Except for that Personal Data with respect to which we act as a Data Controller, return, delete, or destroy the Personal Data of Delegates processed on your behalf and copies thereof, at you request (unless applicable law requires the storage of such Personal Data).
    • The Event Organiser as Controller hereby consents to Event Maestro’s current sub-processors(on the Effective Date of this DPA or the Agreement, whichever is later) to process Personal Data on its behalf.
    • The Event Organiser hereby consents to us appointing additional and replacement sub-processors to process Personal Data on its behalf. We shall give notice to you of the identity of intended sub-processors via email where you have opted in to receive such email notifications. It is your responsibility to regularly check and review sub-processors with us. We shall also give you the opportunity to object to such changes that take place after the Effective Date of the Agreement, in accordance with the terms that follow in Section 3.4 of this DPA.
    • For the avoidance of doubt, any termination rights available herein shall only apply in the instance of objections to sub-processors appointed after the Effective Date of this DPA that are not remedied in accordance with the terms herein, and shall not apply in relation to current sub-processors.
      • Organizer shall raise any objection to the appointment of sub-processors within ten (10) days of us informing you of the changes. You shall send its objection in writing to us.
      • Provided that your objection:
        • concerns the sub-processor’s ability to allow us to materially comply with its data protection obligations under this DPA; and
        • includes sufficient detail to support its objection and provides specific examples,

We will then use commercially reasonable efforts to review and respond to your objection within thirty (30) days of receipt.

  • If we determine in its sole discretion that it cannot reasonably accommodate the objection, upon notice from us, you may choose to terminate the Agreement by providing written notice to us, and complying with the terms herein, which shall be your sole and exclusive remedy in accordance with the Agreement.
  • Event Maestro hereby certifies that it understands the restrictions and obligations set forth in this DPA and that it will comply with them. We will notify you if we make a determination that it can no longer meet its obligations under Data Protection Laws.
  • As the Controller, you shall have the right, upon fourteen (14) business days’ notice, to take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Data by us.
  1. Cross-Border Transfers.
    • The Event Organisers, as the Controller, agrees that Event Maestro (we) may transfer Personal Data of Delegates to various locations in connection with providing the Software and Services. Transfers will be made in accordance with legally enforceable transfer mechanisms where required by applicable Data Protection Laws. Our transfer mechanism for data exported from the United Kingdom is the UK IDTA which forms part of this DPA and take precedence over the EU SCCs.
  2. Governing law.

The Clauses shall be governed by the laws of England.

  1. Variation of the contract.

The parties undertake not to vary or modify this DPA without mutual agreement.