Last Updated: March 13, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use between Eventship, Inc. ("Eventship", "Processor", "we", "us") and the event host ("Controller", "you", "Host") who uses the Service to collect and manage attendee data.
This DPA applies to the processing of Personal Data by Eventship on behalf of Hosts in connection with the provision of the Service, and reflects the parties' commitment to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service on behalf of the Controller.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.
"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates — primarily event attendees.
"Sub-processor" means any third party engaged by Eventship to process Personal Data on behalf of the Controller.
The Host acts as the Controller of attendee Personal Data. Eventship acts as the Processor, processing Personal Data solely on behalf of and in accordance with the Host's instructions as defined by the Host's use of the Service.
This DPA applies to all Personal Data that Eventship processes on behalf of Hosts through the Service, including data collected through event registration forms, check-in systems, the developer API, and the MCP server.
Event attendees who register for, attend, or interact with events organized by the Host through the Service.
Providing the Service as described in the Terms of Use, including event registration, attendee management, check-in, communication, introduction matching, and analytics.
Personal Data is processed for the duration of the Host's active account. Upon account termination, data is deleted or anonymized in accordance with our data retention policies, subject to legal obligations (e.g., financial records retained for 7 years).
Processing instructions: We process Personal Data only in accordance with the Host's documented instructions as expressed through the Host's use of the Service, unless required by applicable law.
Confidentiality: We ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
Security measures: We implement appropriate technical and organizational measures to protect Personal Data, including encryption in transit (HTTPS/TLS), access controls, and regular security reviews.
Data subject requests: We assist the Host in responding to requests from Data Subjects to exercise their rights (access, rectification, erasure, portability, objection) by providing relevant tools and data exports through the Service.
Data deletion: Upon termination of the Host's account, we delete or return all Personal Data processed on behalf of the Host, unless retention is required by applicable law.
Audit: We make available to the Host information necessary to demonstrate compliance with this DPA and allow for audits and inspections, conducted with reasonable notice and during business hours.
The Host authorizes Eventship to engage sub-processors to assist in providing the Service. A current list of sub-processors is maintained on our Sub-processors page.
We will provide at least 30 days' notice before engaging a new sub-processor by updating the Sub-processors page. If a Host objects to a new sub-processor, the Host may terminate the affected service by contacting us within the notice period.
Eventship ensures that all sub-processors are bound by data protection obligations no less protective than those set out in this DPA.
Personal Data is primarily processed in the United States using Google Cloud Platform infrastructure. Where Personal Data is transferred outside the European Economic Area (EEA) or United Kingdom, we rely on appropriate transfer mechanisms, including:
Eventship implements the following technical and organizational security measures:
In the event of a Personal Data breach, Eventship will notify the affected Host without undue delay, and no later than 72 hours after becoming aware of the breach.
The notification will include, to the extent available: the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
This DPA is effective for as long as the Host maintains an active account and Eventship processes Personal Data on the Host's behalf. It terminates automatically when the Host's account is closed.
Upon termination, Eventship will delete or anonymize all Personal Data processed on behalf of the Host within a reasonable timeframe, unless retention is required by applicable law (e.g., financial transaction records for tax compliance).
This DPA is governed by the laws of the State of California, United States, without regard to its conflict of law provisions. Where GDPR applies, this DPA shall be interpreted in accordance with the GDPR and applicable EU member state law.
For questions about this DPA or to exercise your rights as a data controller, please contact us at support[at]eventship.com.