Data Processing Addendum
Last updated: 1 June 2026
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and EventOps ("Processor") for the use of EventOps.
1. Roles
For personal data your agency uploads about your teammates, vendors, and clients, you act as the Controller and EventOps acts as the Processor. EventOps processes that data only on your documented instructions, which include providing the service and these terms.
2. Scope of processing
- Subject matter: provision of the EventOps service.
- Duration: for as long as your account is active, then deletion per the Privacy Policy.
- Categories of data: account details, event and task data, vendor and client contact details, uploaded files.
- Data subjects: your staff, vendors, and clients.
3. Sub-processors
You authorise EventOps to engage the sub-processors listed in our Privacy Policy (Supabase, Vercel, Resend, Stripe, Sentry, PostHog). We will give notice before adding a new sub-processor so you can object.
4. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit, row-level access controls, and least-privilege access for our team.
5. Data subject requests
We will assist you, taking into account the nature of processing, in responding to requests from data subjects to access, correct, export, or delete their data.
6. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations.
7. Return and deletion
On termination, we delete your personal data within 90 days, except limited records we must retain by law.
8. Contact
Data protection enquiries: privacy@eventops.app.