
This agreement governs the processing of personal data Eventleash carries out on behalf of its customers, under Article 28 of Regulation (EU) 2016/679. It is accepted automatically together with the Terms and Conditions of Service: no signature is required.
If your organisation needs a countersigned copy for its records, write to privacy@eventleash.com and we will send it as a PDF.
Processor (the "Processor" or "Provider"): NSS EVENTS S.r.l.s., registered office at Via G. E. Pestalozzi, 4 — 20143 Milan (MI), Italy, VAT and tax number 12624870965, certified e-mail (PEC) nssevents@pec.it, e-mail privacy@eventleash.com.
Controller (the "Controller" or "Customer"): the party that has accepted the Eventleash Terms and Conditions of Service and whose identifying details appear in the Account and in the billing information.
This agreement (the "DPA") forms an integral part of the Terms and Conditions of Service (the "Terms") and is deemed accepted by the Controller upon acceptance of the Terms. In the event of conflict between the DPA and the Terms, the DPA prevails as regards the processing of personal data.
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach", "special categories of data" and "supervisory authority" have the meaning given in Article 4 of Regulation (EU) 2016/679 (the "GDPR"). Terms defined in the Terms (Account, User, Recipient, Message, Customer Data, Platform) retain the same meaning in this DPA.
"Applicable law" means the GDPR, Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018, the measures issued by the Italian Data Protection Authority and, where applicable, electronic communications rules.
3.1 The Processor processes the personal data contained in the Account on behalf of and on the instructions of the Controller, solely for the purpose of providing the Platform under the Terms. Processing details (categories of data subjects, categories of data, purposes, nature and duration) are set out in Annex 1.
3.2 The Controller determines the purposes and means of processing: it selects the Recipients, the content of communications, the fields collected on public pages, the notices and consents displayed, and the retention applied to its own data within the Platform.
3.3 The Processor acts instead as an independent controller in respect of: the Customer's and its administrator Users' registration and billing data; technical and security logs required to protect the Platform; support data; and the aggregated, anonymous statistical data referred to in clause 12.5 of the Terms. Those processing activities are described in the Privacy Policy published at www.eventleash.com/privacy-policy and are not governed by this DPA.
3.4 The Processor does not use the Controller's data for its own purposes, does not disclose it to third parties, does not use it to train machine learning models and does not use it for marketing.
3.5 Where the Controller uses the Platform to organise events for its own clients (the typical agency use case) and, in respect of that data, itself acts as a processor for an end client, the Controller represents that it is authorised by the end client to appoint the Processor as a sub-processor and assumes all information obligations towards that end client.
4.1 This DPA takes effect on the date the Terms are accepted and remains in force for the entire term of the contract.
4.2 After the contract ends, this DPA continues to apply until the deletion or return operations described in clause 12 are complete, including residual retention in backup copies.
5.1 The following constitute the Controller's documented instructions: the Terms and this DPA; the configurations, settings and commands issued by Users through the Platform interface or the APIs; and written requests sent to privacy@eventleash.com.
5.2 The Processor shall inform the Controller without delay if, in its reasonable opinion, an instruction infringes applicable law, and may suspend performance of the disputed instruction until it is confirmed or amended.
5.3 The Processor processes data solely within those instructions, unless required otherwise by Union or Member State law: in that case it informs the Controller beforehand, unless the applicable law prohibits it on important grounds of public interest.
5.4 Activities outside ordinary instructions (for example extraordinary migrations, bulk extractions, action on individual records upon request) are carried out only at the written request of an administrator User and may be subject to separate charges.
The Processor undertakes to:
6.1 Confidentiality. Grant access to the data only to authorised personnel who genuinely need it to provide the service, bound by confidentiality obligations and adequately instructed on personal data protection. The Processor maintains a record of authorised roles and revokes access that is no longer needed.
6.2 Security. Implement and maintain the appropriate technical and organisational measures under Article 32 GDPR described in Annex 2, taking into account the state of the art, the costs of implementation and the risks to data subjects' rights and freedoms. Measures may be updated over time, without reducing the overall level of security.
6.3 Sub-processors. Engage sub-processors only within the limits of clause 8.
6.4 Assistance with data subject rights. Assist the Controller, through the Platform's features and with reasonable support, in handling data subject requests, in accordance with clause 10.
6.5 Assistance with compliance. Assist the Controller, within the information available to it, in complying with its obligations under Articles 32 to 36 GDPR, including any data protection impact assessment and prior consultation with the supervisory authority.
6.6 Personal data breaches. Notify breaches in accordance with clause 9.
6.7 Record of processing. Maintain the record of categories of processing carried out on behalf of the Controller under Article 30(2) GDPR and make it available on request.
6.8 Deletion or return. Delete or return the data at the end of the processing, in accordance with clause 12.
6.9 Information and verification. Make available to the Controller the information needed to demonstrate compliance with its obligations and allow verification in accordance with clause 11.
7.1 The Controller warrants that data uploaded to or collected through the Platform is processed in compliance with applicable law and that it holds a valid legal basis for such processing and for sending communications to Recipients, in particular commercial or promotional communications.
7.2 The Controller provides data subjects with a complete and accessible privacy notice, covering the use of third-party suppliers to deliver the service and any transfers outside the European Economic Area, and collects, where required, freely given, specific, informed, purpose-separated and documentable consents.
7.3 The Controller shall refrain from uploading or collecting special categories of data under Article 9 GDPR and data relating to criminal convictions and offences. The Platform is not designed for that purpose: free-text fields (notes, guest notes, custom public page fields) must not be used for such data. If, for event-related reasons, the Controller enters information capable of revealing data of that nature (for example accessibility needs, health conditions or food intolerances), it assumes full responsibility, identifies an appropriate legal basis under Article 9(2) GDPR and limits the scope to the strict minimum.
7.4 The Controller warrants the accuracy and currency of its data, the proper handling of unsubscribes and the deletion of data that is no longer necessary, using the Platform's features.
7.5 The Controller is responsible for managing its Users, the permissions granted to them and the prompt revocation of access.
7.6 The Controller is responsible for configurations that give rise to further processing: enabling measurement or tracking tools on its public pages, additional optional fields, and external integrations built through the APIs.
8.1 The Controller grants the Processor general written authorisation to engage sub-processors to provide the service. The sub-processors in place as at the date of this DPA are listed in Annex 3, with their role and processing locations; the current version is published at www.eventleash.com/sub-processors.
8.2 The Processor imposes on each sub-processor, by contract, data protection obligations no less onerous than those set out in this DPA, and remains liable to the Controller for their conduct.
8.3 Changes. The Processor notifies the Controller of its intention to add or replace a sub-processor with at least 30 days' notice, by e-mail or in-platform notice. The Controller may object within 15 days of the notice, on reasonable and documented data protection grounds. Where an objection is raised, the parties cooperate in good faith to find an alternative solution; if none is reasonably available, the Controller may terminate the contract in respect of the affected services, with a refund of the fee portion relating to the unused period.
8.4 For urgent security or business continuity reasons the Processor may immediately engage a replacement sub-processor, informing the Controller without delay.
9.1 The Processor notifies the Controller of any personal data breach affecting data processed on its behalf without undue delay and, where possible, within 48 hours of becoming aware of it.
9.2 The notification, sent to the Account administrator's e-mail address, contains the available information on: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Information not immediately available is provided in phases, without further delay.
9.3 The Processor cooperates with the Controller and takes reasonable measures to identify the cause, contain the effects and prevent recurrence, documenting the incident.
9.4 Notification to the supervisory authority and to data subjects remains the Controller's responsibility, which assesses whether the conditions are met. The Processor does not make notifications or communications on the Controller's behalf, save for its own statutory obligations or at the Controller's written request.
9.5 Unsuccessful access attempts, incidents with no impact on data, and temporary service unavailability that does not involve loss, alteration or unauthorised access to data do not constitute notifiable breaches.
10.1 The Platform allows the Controller to handle data subject requests autonomously: viewing, editing and exporting contacts and guests, deleting individual records, and managing unsubscribes and collected consents.
10.2 Where those features are not sufficient, the Processor provides reasonable assistance upon written request to privacy@eventleash.com, within the necessary technical timeframes and in any event so as to allow the Controller to meet statutory deadlines.
10.3 If a data subject request is addressed directly to the Processor, it does not act on it independently: it forwards the request to the Controller without delay and informs the data subject that the Customer is the controller, without disclosing further information.
10.4 Assistance is provided free of charge within ordinary limits; extraordinary or repeated activities requiring significant effort may be subject to previously agreed charges.
11.1 Upon written request and no more than once per contract year, the Processor makes available to the Controller the information and documentation needed to demonstrate compliance, including: a description of the technical and organisational measures, the list of sub-processors, responses to a security questionnaire in a reasonable format and, where available, its own or its sub-processors' attestations or certifications.
11.2 Where that documentation is not reasonably sufficient, the Controller may request an on-site inspection with at least 30 days' notice, during business hours, without prejudice to service continuity and subject to appropriate confidentiality undertakings. The inspection may be carried out by an independent auditor with no conflict of interest with the Processor.
11.3 An inspection may under no circumstances involve access to data, systems or information relating to other customers of the Processor, nor to information whose disclosure would compromise the security of the Platform.
11.4 Inspections are at the Controller's expense. The Processor may charge the reasonable costs of its support effort, unless the inspection establishes a material breach by the Processor.
11.5 Where further inspections are requested within the same year following an established personal data breach, only reasonable notice applies and the costs are borne by the Processor.
12.1 On termination of the contract, for any reason, the Account becomes read-only for 30 days: within that window the Controller may autonomously access and export its data in the formats made available by the Platform.
12.2 After those 30 days, the Processor permanently deletes the Controller's data and the resources dedicated to the Account, including the tenant database and the associated sending identities. Deletion is irreversible and entails the loss of any possibility of recovery.
12.3 Backup copies are deleted according to the rotation cycles of the systems used, within a maximum of 14 days from the deletion of the primary data. During that period the data is neither accessible nor processed for other purposes, save for restoration for business continuity.
12.4 The Processor may retain data beyond those periods only where retention is required by Union or Member State law (in particular tax and accounting records) and for technical and security logs in minimised form, processed as an independent controller and solely for the purposes for which the obligation exists.
12.5 Upon written request received before the 30-day window expires, the Processor may grant an extension to allow exports to be completed, on terms to be agreed.
12.6 At the Controller's request, the Processor confirms deletion in writing.
13.1 All processing locations are within the European Union: data is stored and processed in Ireland, region eu-west-1, for the relational database, the document database and the sending infrastructure alike.
13.2 Some sub-processors belong to groups headquartered outside the European Economic Area and may access data for support, maintenance or security purposes. In that case the transfer relies, in order of preference, on: an adequacy decision of the European Commission; the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, in the module applicable to the relationship; or another appropriate instrument under Chapter V GDPR.
13.3 The Processor adopts, where necessary, supplementary measures such as encryption in transit and at rest, minimisation of the data accessible to support staff, restriction of access to strictly necessary personnel, and documented handling of third-country authority requests.
13.4 The Processor informs the Controller, to the extent permitted by law, of any legally binding request for access to data from a third-country authority and, where admissible, challenges it.
14.1 Each party is liable for damage caused by its own non-compliant processing, in accordance with Article 82 GDPR.
14.2 As between the parties, the Processor's liability under this DPA is subject to the limits set out in clause 20 of the Terms, except where such limits are not permitted by law, including cases of wilful misconduct or gross negligence and of breach of data protection obligations attributable to the Processor.
14.3 The Controller shall indemnify the Processor against claims by data subjects or authorities arising from the Controller's unlawful instructions, the absence of a valid legal basis for sending communications, the inadequacy of the notices given to data subjects, or the uploading of data in breach of clause 7.3.
15.1 This DPA supplements the Terms and does not alter their other provisions.
15.2 This DPA is governed by Italian law; any dispute falls within the exclusive jurisdiction of the Court of Milan, Italy, without prejudice to data subjects' rights and to the powers of supervisory authorities.
15.3 The Processor may update this DPA to reflect legal changes, measures issued by authorities, or changes to its sub-processors, giving at least 30 days' notice and granting the Controller the right to terminate under clause 24 of the Terms.
15.4 This DPA is drawn up in Italian and English; in the event of discrepancy, the Italian version prevails.
Provision of the Eventleash Platform on a SaaS basis: collection, recording, organisation, structuring, storage, retrieval, use, transmission by e-mail, extraction, export, restriction and erasure of the data uploaded or generated by the Controller, together with the related technical operations of queuing, backup, monitoring and support.
Contact and guest data: first and last name; e-mail address; telephone number; street address, city and country; gender, including the free-text self-description field; date of birth; company and job role; social profiles; contact photograph; sizes and measurements (where used for gifts or kit); preferred language; assigned groups, categories and type; free-text notes; subscription or unsubscribe status; count of failed deliveries and suppression status.
Attendance data: membership of event lists; number of companions declared and verified; invited, confirmed or declined status; check-in date and time; assigned slot or time band; guest-related notes; privacy consents collected, with outcome, date and reference text.
Message data: recipient e-mail address; message content and identifying elements; technical sending identifiers; delivery, open, bounce and abuse complaint outcomes, with timestamps.
Controller's User data: name, e-mail address, role and permissions, credentials in hashed form, any second authentication factor, and sign-in dates and times.
Technical and browsing data: IP address, device and browser identifiers, request dates and times, relating to public pages and use of the application.
Special categories of data: none. Processing of data under Article 9 GDPR is neither envisaged nor permitted, save as provided in clause 7.3.
For the term of the contract, with data retained until the deletion provided for in clause 12. Retention of individual data within the Account is determined by the Controller, which may delete it at any time using the Platform's features. Entries in the technical sending queue are removed once the message has been sent; entries that cannot be processed are retained for a maximum of 90 days for diagnostic purposes and then deleted.
| Sub-processor | Activity | Processing location | Basis for any transfer |
|---|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Application hosting, managed relational database, e-mail sending, serverless functions, storage | European Union — Ireland (eu-west-1) | No transfer for storage. Support access from third countries covered by Standard Contractual Clauses |
| MongoDB Ltd / MongoDB, Inc. | Managed document database holding tenant data | European Union | Standard Contractual Clauses for non-EEA support access |
| Cloudflare Ltd / Cloudflare, Inc. | Content delivery network, application protection, edge execution of the front-end | European Union, on a globally present network | Standard Contractual Clauses |
| Stripe Payments Europe Ltd (Ireland) | Payment and recurring billing management. In respect of payment and anti-fraud data, Stripe acts as an independent controller | European Union — Ireland, with group access | Standard Contractual Clauses |
The Processor engages no further sub-processors for the processing of the Controller's data. As at the date of this DPA no statistical measurement or tracking tools are active on the application or on tenants' public pages; should any be enabled, this Annex will be updated with the notice period set out in clause 8.3.
The Processor's internal staff and collaborators act as authorised persons under Article 29 GDPR and not as sub-processors.