Skip to main content

Data Processing Addendum

Last updated: 1 June 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and EventOps ("Processor") for the use of EventOps.

1. Roles

For personal data your agency uploads about your teammates, vendors, and clients, you act as the Controller and EventOps acts as the Processor. EventOps processes that data only on your documented instructions, which include providing the service and these terms.

2. Scope of processing

  • Subject matter: provision of the EventOps service.
  • Duration: for as long as your account is active, then deletion per the Privacy Policy.
  • Categories of data: account details, event and task data, vendor and client contact details, uploaded files.
  • Data subjects: your staff, vendors, and clients.

3. Sub-processors

You authorise EventOps to engage the sub-processors listed in our Privacy Policy (Supabase, Vercel, Resend, Stripe, Sentry, PostHog). We will give notice before adding a new sub-processor so you can object.

4. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit, row-level access controls, and least-privilege access for our team.

5. Data subject requests

We will assist you, taking into account the nature of processing, in responding to requests from data subjects to access, correct, export, or delete their data.

6. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations.

7. Return and deletion

On termination, we delete your personal data within 90 days, except limited records we must retain by law.

8. Contact

Data protection enquiries: privacy@eventops.app.