Eventleash
ITBlogGet startedSign in
HomeDPA

Data Processing Agreement (DPA)

This agreement governs the processing of personal data Eventleash carries out on behalf of its customers, under Article 28 of Regulation (EU) 2016/679. It is accepted automatically together with the Terms and Conditions of Service: no signature is required.

If your organisation needs a countersigned copy for its records, write to privacy@eventleash.com and we will send it as a PDF.

Version
1.0
Last updated
5 August 2026

Contents

  1. 1 Parties
  2. 2 Definitions
  3. 3 Subject matter and roles
  4. 4 Duration
  5. 5 Controller's instructions
  6. 6 Processor's obligations
  7. 7 Controller's obligations
  8. 8 Sub-processors
  9. 9 Personal data breaches
  10. 10 Data subject rights
  11. 11 Documentation, audits and inspections
  12. 12 Deletion and return of data
  13. 13 Transfers to third countries
  14. 14 Liability
  15. 15 Final provisions
  16. Annex 1 — Processing details
  17. Annex 2 — Technical and organisational measures
  18. Annex 3 — List of sub-processors

1. Parties

Processor (the "Processor" or "Provider"): NSS EVENTS S.r.l.s., registered office at Via G. E. Pestalozzi, 4 — 20143 Milan (MI), Italy, VAT and tax number 12624870965, certified e-mail (PEC) nssevents@pec.it, e-mail privacy@eventleash.com.

Controller (the "Controller" or "Customer"): the party that has accepted the Eventleash Terms and Conditions of Service and whose identifying details appear in the Account and in the billing information.

This agreement (the "DPA") forms an integral part of the Terms and Conditions of Service (the "Terms") and is deemed accepted by the Controller upon acceptance of the Terms. In the event of conflict between the DPA and the Terms, the DPA prevails as regards the processing of personal data.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach", "special categories of data" and "supervisory authority" have the meaning given in Article 4 of Regulation (EU) 2016/679 (the "GDPR"). Terms defined in the Terms (Account, User, Recipient, Message, Customer Data, Platform) retain the same meaning in this DPA.

"Applicable law" means the GDPR, Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, the measures issued by the Italian Data Protection Authority and, where applicable, electronic communications rules.

3. Subject matter and roles

3.1 The Processor processes the personal data contained in the Account on behalf of and on the instructions of the Controller, solely for the purpose of providing the Platform under the Terms. Processing details (categories of data subjects, categories of data, purposes, nature and duration) are set out in Annex 1.

3.2 The Controller determines the purposes and means of processing: it selects the Recipients, the content of communications, the fields collected on public pages, the notices and consents displayed, and the retention applied to its own data within the Platform.

3.3 The Processor acts instead as an independent controller in respect of: the Customer's and its administrator Users' registration and billing data; technical and security logs required to protect the Platform; support data; and the aggregated, anonymous statistical data referred to in clause 12.5 of the Terms. Those processing activities are described in the Privacy Policy published at www.eventleash.com/privacy-policy and are not governed by this DPA.

3.4 The Processor does not use the Controller's data for its own purposes, does not disclose it to third parties, does not use it to train machine learning models and does not use it for marketing.

3.5 Where the Controller uses the Platform to organise events for its own clients (the typical agency use case) and, in respect of that data, itself acts as a processor for an end client, the Controller represents that it is authorised by the end client to appoint the Processor as a sub-processor and assumes all information obligations towards that end client.

4. Duration

4.1 This DPA takes effect on the date the Terms are accepted and remains in force for the entire term of the contract.

4.2 After the contract ends, this DPA continues to apply until the deletion or return operations described in clause 12 are complete, including residual retention in backup copies.

5. Controller's instructions

5.1 The following constitute the Controller's documented instructions: the Terms and this DPA; the configurations, settings and commands issued by Users through the Platform interface or the APIs; and written requests sent to privacy@eventleash.com.

5.2 The Processor shall inform the Controller without delay if, in its reasonable opinion, an instruction infringes applicable law, and may suspend performance of the disputed instruction until it is confirmed or amended.

5.3 The Processor processes data solely within those instructions, unless required otherwise by Union or Member State law: in that case it informs the Controller beforehand, unless the applicable law prohibits it on important grounds of public interest.

5.4 Activities outside ordinary instructions (for example extraordinary migrations, bulk extractions, action on individual records upon request) are carried out only at the written request of an administrator User and may be subject to separate charges.

6. Processor's obligations

The Processor undertakes to:

6.1 Confidentiality. Grant access to the data only to authorised personnel who genuinely need it to provide the service, bound by confidentiality obligations and adequately instructed on personal data protection. The Processor maintains a record of authorised roles and revokes access that is no longer needed.

6.2 Security. Implement and maintain the appropriate technical and organisational measures under Article 32 GDPR described in Annex 2, taking into account the state of the art, the costs of implementation and the risks to data subjects' rights and freedoms. Measures may be updated over time, without reducing the overall level of security.

6.3 Sub-processors. Engage sub-processors only within the limits of clause 8.

6.4 Assistance with data subject rights. Assist the Controller, through the Platform's features and with reasonable support, in handling data subject requests, in accordance with clause 10.

6.5 Assistance with compliance. Assist the Controller, within the information available to it, in complying with its obligations under Articles 32 to 36 GDPR, including any data protection impact assessment and prior consultation with the supervisory authority.

6.6 Personal data breaches. Notify breaches in accordance with clause 9.

6.7 Record of processing. Maintain the record of categories of processing carried out on behalf of the Controller under Article 30(2) GDPR and make it available on request.

6.8 Deletion or return. Delete or return the data at the end of the processing, in accordance with clause 12.

6.9 Information and verification. Make available to the Controller the information needed to demonstrate compliance with its obligations and allow verification in accordance with clause 11.

7. Controller's obligations

7.1 The Controller warrants that data uploaded to or collected through the Platform is processed in compliance with applicable law and that it holds a valid legal basis for such processing and for sending communications to Recipients, in particular commercial or promotional communications.

7.2 The Controller provides data subjects with a complete and accessible privacy notice, covering the use of third-party suppliers to deliver the service and any transfers outside the European Economic Area, and collects, where required, freely given, specific, informed, purpose-separated and documentable consents.

7.3 The Controller shall refrain from uploading or collecting special categories of data under Article 9 GDPR and data relating to criminal convictions and offences. The Platform is not designed for that purpose: free-text fields (notes, guest notes, custom public page fields) must not be used for such data. If, for event-related reasons, the Controller enters information capable of revealing data of that nature (for example accessibility needs, health conditions or food intolerances), it assumes full responsibility, identifies an appropriate legal basis under Article 9(2) GDPR and limits the scope to the strict minimum.

7.4 The Controller warrants the accuracy and currency of its data, the proper handling of unsubscribes and the deletion of data that is no longer necessary, using the Platform's features.

7.5 The Controller is responsible for managing its Users, the permissions granted to them and the prompt revocation of access.

7.6 The Controller is responsible for configurations that give rise to further processing: enabling measurement or tracking tools on its public pages, additional optional fields, and external integrations built through the APIs.

8. Sub-processors

8.1 The Controller grants the Processor general written authorisation to engage sub-processors to provide the service. The sub-processors in place as at the date of this DPA are listed in Annex 3, with their role and processing locations; the current version is published at www.eventleash.com/sub-processors.

8.2 The Processor imposes on each sub-processor, by contract, data protection obligations no less onerous than those set out in this DPA, and remains liable to the Controller for their conduct.

8.3 Changes. The Processor notifies the Controller of its intention to add or replace a sub-processor with at least 30 days' notice, by e-mail or in-platform notice. The Controller may object within 15 days of the notice, on reasonable and documented data protection grounds. Where an objection is raised, the parties cooperate in good faith to find an alternative solution; if none is reasonably available, the Controller may terminate the contract in respect of the affected services, with a refund of the fee portion relating to the unused period.

8.4 For urgent security or business continuity reasons the Processor may immediately engage a replacement sub-processor, informing the Controller without delay.

9. Personal data breaches

9.1 The Processor notifies the Controller of any personal data breach affecting data processed on its behalf without undue delay and, where possible, within 48 hours of becoming aware of it.

9.2 The notification, sent to the Account administrator's e-mail address, contains the available information on: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Information not immediately available is provided in phases, without further delay.

9.3 The Processor cooperates with the Controller and takes reasonable measures to identify the cause, contain the effects and prevent recurrence, documenting the incident.

9.4 Notification to the supervisory authority and to data subjects remains the Controller's responsibility, which assesses whether the conditions are met. The Processor does not make notifications or communications on the Controller's behalf, save for its own statutory obligations or at the Controller's written request.

9.5 Unsuccessful access attempts, incidents with no impact on data, and temporary service unavailability that does not involve loss, alteration or unauthorised access to data do not constitute notifiable breaches.

10. Data subject rights

10.1 The Platform allows the Controller to handle data subject requests autonomously: viewing, editing and exporting contacts and guests, deleting individual records, and managing unsubscribes and collected consents.

10.2 Where those features are not sufficient, the Processor provides reasonable assistance upon written request to privacy@eventleash.com, within the necessary technical timeframes and in any event so as to allow the Controller to meet statutory deadlines.

10.3 If a data subject request is addressed directly to the Processor, it does not act on it independently: it forwards the request to the Controller without delay and informs the data subject that the Customer is the controller, without disclosing further information.

10.4 Assistance is provided free of charge within ordinary limits; extraordinary or repeated activities requiring significant effort may be subject to previously agreed charges.

11. Documentation, audits and inspections

11.1 Upon written request and no more than once per contract year, the Processor makes available to the Controller the information and documentation needed to demonstrate compliance, including: a description of the technical and organisational measures, the list of sub-processors, responses to a security questionnaire in a reasonable format and, where available, its own or its sub-processors' attestations or certifications.

11.2 Where that documentation is not reasonably sufficient, the Controller may request an on-site inspection with at least 30 days' notice, during business hours, without prejudice to service continuity and subject to appropriate confidentiality undertakings. The inspection may be carried out by an independent auditor with no conflict of interest with the Processor.

11.3 An inspection may under no circumstances involve access to data, systems or information relating to other customers of the Processor, nor to information whose disclosure would compromise the security of the Platform.

11.4 Inspections are at the Controller's expense. The Processor may charge the reasonable costs of its support effort, unless the inspection establishes a material breach by the Processor.

11.5 Where further inspections are requested within the same year following an established personal data breach, only reasonable notice applies and the costs are borne by the Processor.

12. Deletion and return of data

12.1 On termination of the contract, for any reason, the Account becomes read-only for 30 days: within that window the Controller may autonomously access and export its data in the formats made available by the Platform.

12.2 After those 30 days, the Processor permanently deletes the Controller's data and the resources dedicated to the Account, including the tenant database and the associated sending identities. Deletion is irreversible and entails the loss of any possibility of recovery.

12.3 Backup copies are deleted according to the rotation cycles of the systems used, within a maximum of 14 days from the deletion of the primary data. During that period the data is neither accessible nor processed for other purposes, save for restoration for business continuity.

12.4 The Processor may retain data beyond those periods only where retention is required by Union or Member State law (in particular tax and accounting records) and for technical and security logs in minimised form, processed as an independent controller and solely for the purposes for which the obligation exists.

12.5 Upon written request received before the 30-day window expires, the Processor may grant an extension to allow exports to be completed, on terms to be agreed.

12.6 At the Controller's request, the Processor confirms deletion in writing.

13. Transfers to third countries

13.1 All processing locations are within the European Union: data is stored and processed in Ireland, region eu-west-1, for the relational database, the document database and the sending infrastructure alike.

13.2 Some sub-processors belong to groups headquartered outside the European Economic Area and may access data for support, maintenance or security purposes. In that case the transfer relies, in order of preference, on: an adequacy decision of the European Commission; the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, in the module applicable to the relationship; or another appropriate instrument under Chapter V GDPR.

13.3 The Processor adopts, where necessary, supplementary measures such as encryption in transit and at rest, minimisation of the data accessible to support staff, restriction of access to strictly necessary personnel, and documented handling of third-country authority requests.

13.4 The Processor informs the Controller, to the extent permitted by law, of any legally binding request for access to data from a third-country authority and, where admissible, challenges it.

14. Liability

14.1 Each party is liable for damage caused by its own non-compliant processing, in accordance with Article 82 GDPR.

14.2 As between the parties, the Processor's liability under this DPA is subject to the limits set out in clause 20 of the Terms, except where such limits are not permitted by law, including cases of wilful misconduct or gross negligence and of breach of data protection obligations attributable to the Processor.

14.3 The Controller shall indemnify the Processor against claims by data subjects or authorities arising from the Controller's unlawful instructions, the absence of a valid legal basis for sending communications, the inadequacy of the notices given to data subjects, or the uploading of data in breach of clause 7.3.

15. Final provisions

15.1 This DPA supplements the Terms and does not alter their other provisions.

15.2 This DPA is governed by Italian law; any dispute falls within the exclusive jurisdiction of the Court of Milan, Italy, without prejudice to data subjects' rights and to the powers of supervisory authorities.

15.3 The Processor may update this DPA to reflect legal changes, measures issued by authorities, or changes to its sub-processors, giving at least 30 days' notice and granting the Controller the right to terminate under clause 24 of the Terms.

15.4 This DPA is drawn up in Italian and English; in the event of discrepancy, the Italian version prevails.

Annex 1 — Processing details

A. Subject matter and nature of the processing

Provision of the Eventleash Platform on a SaaS basis: collection, recording, organisation, structuring, storage, retrieval, use, transmission by e-mail, extraction, export, restriction and erasure of the data uploaded or generated by the Controller, together with the related technical operations of queuing, backup, monitoring and support.

B. Purposes of the processing

  • Managing the Controller's contact database (CRM) and organising it into groups, categories and tags.
  • Creating and managing events, guest lists, time slots and available places.
  • Composing and sending invitations and communications by e-mail to the Recipients designated by the Controller, including sending queue management.
  • Collecting attendance confirmations (RSVP), registrations and consents through public pages configured by the Controller.
  • Managing event access and on-site check-in, including via QR codes.
  • Producing sending, delivery, open, confirmation and attendance statistics for the Controller.
  • Managing unsubscribes, suppressions and the quality of sending lists.
  • Backup, business continuity, Platform security and technical support to the Controller.

C. Categories of data subjects

  • Contacts in the Controller's database.
  • Invitees and attendees of the Controller's events, including companions.
  • Persons completing the Controller's public pages (RSVP, registration, sign-up).
  • The Controller's Users accessing the Account (employees, collaborators, agency staff).
  • Contact persons at the Controller's end clients, where the Platform is used on their behalf.

D. Categories of personal data

Contact and guest data: first and last name; e-mail address; telephone number; street address, city and country; gender, including the free-text self-description field; date of birth; company and job role; social profiles; contact photograph; sizes and measurements (where used for gifts or kit); preferred language; assigned groups, categories and type; free-text notes; subscription or unsubscribe status; count of failed deliveries and suppression status.

Attendance data: membership of event lists; number of companions declared and verified; invited, confirmed or declined status; check-in date and time; assigned slot or time band; guest-related notes; privacy consents collected, with outcome, date and reference text.

Message data: recipient e-mail address; message content and identifying elements; technical sending identifiers; delivery, open, bounce and abuse complaint outcomes, with timestamps.

Controller's User data: name, e-mail address, role and permissions, credentials in hashed form, any second authentication factor, and sign-in dates and times.

Technical and browsing data: IP address, device and browser identifiers, request dates and times, relating to public pages and use of the application.

Special categories of data: none. Processing of data under Article 9 GDPR is neither envisaged nor permitted, save as provided in clause 7.3.

E. Duration of the processing

For the term of the contract, with data retained until the deletion provided for in clause 12. Retention of individual data within the Account is determined by the Controller, which may delete it at any time using the Platform's features. Entries in the technical sending queue are removed once the message has been sent; entries that cannot be processed are retained for a maximum of 90 days for diagnostic purposes and then deleted.

Annex 2 — Technical and organisational measures

1. Isolation and segregation

  • Multi-tenant architecture with logical separation per Account: each Customer's data resides in a document database dedicated to the tenant, with distinct credentials; relational data (accounts, users, subscriptions, domains) is segregated by account identifier and filtered at application level on every operation.
  • Public pages and APIs are served on per-Account subdomains, with ownership checks on the resources requested.
  • A shared technical sending queue temporarily holds the message identifier, the Account identifier and the recipient's e-mail address until the message has been sent, after which the entry is removed; access is restricted to system processes.

2. Access control

  • User authentication with personal credentials, passwords stored using a non-reversible hash function.
  • Multi-factor authentication available to Account Users.
  • Role-based permission management following the principle of least privilege; User invitation, suspension and revocation managed by the Controller.
  • Administrative access by the Processor's personnel restricted to authorised individuals, logged and reviewed periodically.
  • Access to production systems through individual credentials and time-bound assumed roles, with no shared static credentials.

3. Encryption

  • Data in transit: TLS encryption on all public connections (interface, public pages, APIs) and towards infrastructure services.
  • Data at rest: the document database holding tenant data (contacts, guests, messages, consents) is encrypted at rest by the managed service used. The relational database, which holds only account, user, subscription and domain data, is protected by network isolation, dedicated credentials and access restricted to authorised personnel.
  • User passwords stored solely as non-reversible hashes; service secrets and credentials held in non-versioned configuration, never exposed to the front-end.

4. Infrastructure security

  • Infrastructure hosted with certified providers (see Annex 3), in data centres with documented physical and environmental controls.
  • Front-end delivered through an edge network with protection against major volumetric attacks and application-level filtering.
  • Periodic updating of software components and dependencies; security fixes applied according to severity.

5. Logging and monitoring

  • Logging of application, sending and error events, with logs retained for 7 days.
  • Monitoring of availability, sending metrics, delivery rates and abuse complaints, with alert thresholds.
  • Logging of sensitive Account operations (creation, suspension, deletion, subscription changes).

6. Business continuity and backup

  • Automatic backups of the managed databases, with a 14-day retention window and continuous rotation.
  • Data restoration from the backup copies available within the retention window.

7. Minimisation and integrity

  • Collection limited to the data necessary for the purposes; unnecessary fields can be disabled by the Controller on its own public pages.
  • Automatic and permanent suppression of addresses generating definitively failed deliveries, to avoid repeated sending to invalid addresses.
  • Immediate recording and execution of unsubscribes, with unsubscribed Recipients excluded from subsequent sendings.
  • Export and deletion features available to the Controller for handling data subject rights.

8. Organisational measures

  • Personnel bound by confidentiality obligations and instructed on personal data processing.
  • Record of categories of processing carried out on behalf of controllers, under Article 30(2) GDPR.
  • Internal procedure for handling incidents and personal data breaches, with the notification timeframes set out in clause 9.
  • Supplier assessment prior to engagement and processing agreements with each sub-processor.
  • Documented handling of data access requests from authorities.

Annex 3 — List of sub-processors

Sub-processorActivityProcessing locationBasis for any transfer
Amazon Web Services EMEA SARL (Luxembourg)Application hosting, managed relational database, e-mail sending, serverless functions, storageEuropean Union — Ireland (eu-west-1)No transfer for storage. Support access from third countries covered by Standard Contractual Clauses
MongoDB Ltd / MongoDB, Inc.Managed document database holding tenant dataEuropean UnionStandard Contractual Clauses for non-EEA support access
Cloudflare Ltd / Cloudflare, Inc.Content delivery network, application protection, edge execution of the front-endEuropean Union, on a globally present networkStandard Contractual Clauses
Stripe Payments Europe Ltd (Ireland)Payment and recurring billing management. In respect of payment and anti-fraud data, Stripe acts as an independent controllerEuropean Union — Ireland, with group accessStandard Contractual Clauses

The Processor engages no further sub-processors for the processing of the Controller's data. As at the date of this DPA no statistical measurement or tracking tools are active on the application or on tenants' public pages; should any be enabled, this Annex will be updated with the notice period set out in clause 8.3.

The Processor's internal staff and collaborators act as authorised persons under Article 29 GDPR and not as sub-processors.

Terms and conditionsSub-processors

Features

  • Contacts CRM
  • Email invites
  • RSVP and registration
  • QR check-in
  • Domain and deliverability

Solutions

  • Corporate events
  • Event agencies

Company

  • Blog
  • Contact us
  • Terms and conditions
  • Privacy policy
  • Cookie policy
All rights reserved ©Eventleash
nss events srls - VAT IT12624870965 - Via G.E. Pestalozzi, 4 20143 Milano (MI) Italy
info@eventleash.com