Skip to content
FacilEvents

Data Processing Agreement (DPA)

Version 1 — August 2026. This English version prevails.

This agreement forms part of the Terms of Service and applies whenever the platform processes personal data on behalf of a customer organisation. The organisation is the controller; the platform is the processor, under UK GDPR.

1. Subject matter and duration

Processing of the data described in the Privacy Policy (buyers, guests, team), exclusively to provide the service, for the duration of the contract.

2. Instructions

The platform processes data only on the organisation’s documented instructions — normal use of the product constitutes that instruction. We never use buyers’ data for our own purposes.

3. Confidentiality and security

Access is limited to platform operators under confidentiality duties. Technical measures include: encryption in transit, payment credentials encrypted at the application layer (AES-256-GCM, key held outside the database), per-customer isolation in the database, and administrative access records.

4. Sub-processors

The organisation authorises the sub-processors listed in the Privacy Policy (Supabase, Vercel, Resend, Stripe, SumUp). Changes are notified with reasonable notice and a right to object.

5. Assistance and breaches

The platform assists the organisation with data-subject requests (access, erasure, portability) and notifies the organisation of any data breach without undue delay after becoming aware.

6. End of processing

On termination, data is returned (full export) and then deleted, unless a legal retention duty applies. Deletion is confirmed in writing on request.