Data Processing Agreement

Last Updated: March 13, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Eventship, Inc. ("Eventship", "Processor", "we", "us") and the event host ("Controller", "you", "Host") who uses the Service to collect and manage attendee data.

This DPA applies to the processing of Personal Data by Eventship on behalf of Hosts in connection with the provision of the Service, and reflects the parties' commitment to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

1. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service on behalf of the Controller.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or erasure.

"Data Subject" means the identified or identifiable natural person to whom the Personal Data relates — primarily event attendees.

"Sub-processor" means any third party engaged by Eventship to process Personal Data on behalf of the Controller.

2. Scope and Roles

The Host acts as the Controller of attendee Personal Data. Eventship acts as the Processor, processing Personal Data solely on behalf of and in accordance with the Host's instructions as defined by the Host's use of the Service.

This DPA applies to all Personal Data that Eventship processes on behalf of Hosts through the Service, including data collected through event registration forms, check-in systems, the developer API, and the MCP server.

3. Details of Processing

Categories of Personal Data

  • Names and email addresses
  • Profile information (job title, company, bio, avatar)
  • Registration data (ticket type, registration status, registration date)
  • Check-in status and attendance records
  • Answers to custom registration questions set by the Host
  • Location data (approximate, based on IP address)
  • Messages sent between attendees (where enabled by the Host)

Data subjects

Event attendees who register for, attend, or interact with events organized by the Host through the Service.

Purpose of processing

Providing the Service as described in the Terms of Use, including event registration, attendee management, check-in, communication, introduction matching, and analytics.

Duration

Personal Data is processed for the duration of the Host's active account. Upon account termination, data is deleted or anonymized in accordance with our data retention policies, subject to legal obligations (e.g., financial records retained for 7 years).

4. Eventship's Obligations

Processing instructions: We process Personal Data only in accordance with the Host's documented instructions as expressed through the Host's use of the Service, unless required by applicable law.

Confidentiality: We ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.

Security measures: We implement appropriate technical and organizational measures to protect Personal Data, including encryption in transit (HTTPS/TLS), access controls, and regular security reviews.

Data subject requests: We assist the Host in responding to requests from Data Subjects to exercise their rights (access, rectification, erasure, portability, objection) by providing relevant tools and data exports through the Service.

Data deletion: Upon termination of the Host's account, we delete or return all Personal Data processed on behalf of the Host, unless retention is required by applicable law.

Audit: We make available to the Host information necessary to demonstrate compliance with this DPA and allow for audits and inspections, conducted with reasonable notice and during business hours.

5. Sub-processors

The Host authorizes Eventship to engage sub-processors to assist in providing the Service. A current list of sub-processors is maintained on our Sub-processors page.

We will provide at least 30 days' notice before engaging a new sub-processor by updating the Sub-processors page. If a Host objects to a new sub-processor, the Host may terminate the affected service by contacting us within the notice period.

Eventship ensures that all sub-processors are bound by data protection obligations no less protective than those set out in this DPA.

6. International Data Transfers

Personal Data is primarily processed in the United States using Google Cloud Platform infrastructure. Where Personal Data is transferred outside the European Economic Area (EEA) or United Kingdom, we rely on appropriate transfer mechanisms, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • EU-US Data Privacy Framework, where applicable
  • Other legally recognized transfer mechanisms as required

7. Security Measures

Eventship implements the following technical and organizational security measures:

  • Encryption of data in transit using HTTPS/TLS
  • Authentication and access control for all API and MCP endpoints
  • Role-based access control — hosts can only access data for their own events
  • Secure payment processing via Stripe (PCI DSS compliant)
  • Regular security reviews and infrastructure monitoring
  • Secure credential storage using cloud-native secret management

8. Breach Notification

In the event of a Personal Data breach, Eventship will notify the affected Host without undue delay, and no later than 72 hours after becoming aware of the breach.

The notification will include, to the extent available: the nature of the breach, the categories and approximate number of Data Subjects affected, the likely consequences, and the measures taken or proposed to address the breach.

9. Term and Termination

This DPA is effective for as long as the Host maintains an active account and Eventship processes Personal Data on the Host's behalf. It terminates automatically when the Host's account is closed.

Upon termination, Eventship will delete or anonymize all Personal Data processed on behalf of the Host within a reasonable timeframe, unless retention is required by applicable law (e.g., financial transaction records for tax compliance).

10. Governing Law

This DPA is governed by the laws of the State of California, United States, without regard to its conflict of law provisions. Where GDPR applies, this DPA shall be interpreted in accordance with the GDPR and applicable EU member state law.

Contact

For questions about this DPA or to exercise your rights as a data controller, please contact us at support[at]eventship.com.