Legal

Subprocessors and recipients

Who, besides us, receives personal data from PartyPPL, what for, which data, where that party is based and how the data is protected when it leaves the EEA.

Last updated: 1 October 2026

1What this list is

Two lists. The first are the subprocessors for organisers: parties that process data an organiser is responsible for and we are the processor of, as the data processing agreement describes. The second are the other recipients: parties that receive data from what PartyPPL does itself as a controller, as the privacy statement describes.

Per party you find the purpose, which data, where it is based and the safeguard for transfers outside the European Economic Area (EEA).

The safeguard is the same rule everywhere: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses. Which of the two applies per supplier we are still checking. Until that check is done, we do not claim it per party.

2Subprocessors for organisers

For the guest list, door scans, exports and tickets from another shop we use these four:

OVHcloud · France, server in Germany
Purpose: our server, for hosting, database, file storage, realtime chat, backups and the server log. Data: everything in the portal, so also guest lists, door scans and tickets from another shop. Safeguard: the server is in Germany, inside the EEA; there is no transfer.
Cloudflare · US, with data centres worldwide
Purpose: DNS, CDN and attack protection. All traffic to and from the portal passes through Cloudflare, which decrypts it on the way and encrypts it again. Data: what is in the requests and answers, so also a guest list or export you open. Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses. We have not set an EU region at Cloudflare.
Resend · US
Purpose: e-mail, such as the message that a ticket from another shop is waiting and invitations to your team. Data: e-mail address, name, the event and the kind of ticket. Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.
Apple · Ireland and US
Purpose: push notifications to the iPhone app and Apple Wallet pass updates, also for tickets from another shop. Data: the device's push token and the text of the notification (the event and the ticket). Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.

3Other recipients

For what PartyPPL does itself: your account, the agenda, tickets, the apps and our channels.

OVHcloud, Cloudflare, Resend and Apple
The same four as above, for the whole platform: hosting and storage of everything at OVHcloud, all traffic and the forwarding of e-mail to addresses on partyppl.nl through Cloudflare, all our e-mail (login codes, tickets, cancellations, alerts, digests) through Resend, and push notifications, Live Activities, Wallet and Sign in with Apple. Sign in with Apple and the App Store are services Apple itself is responsible for.
Stripe · Ireland, parent company in the US
Purpose: payments, refunds and payouts to organisers through Stripe Connect. Data: amounts, your e-mail address and what you enter at Stripe; we never see your card number or IBAN. Stripe itself is responsible for your payment data. Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.
Anthropic · US
Purpose: Claude, to complete public event data. Data: title, date, venue, line-up and the organiser's name and website. No data about visitors. Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.
Your browser's push service
Purpose: web push notifications. Which service that is, your browser decides (for example Apple, Google or Mozilla). Data: the push address and the text of the notification. Safeguard: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.
Meta · Ireland and US, Bluesky · US, a Mastodon server, a webhook
Purpose: posts on our own channels. Data: only public data of nights (title, date, venue, city, genres, price, poster, link). Never data of visitors.
OpenFreeMap
Purpose: map tiles, loaded directly in your browser. Data: your IP address, as with any website. No cookies. Location: an open-source project; its location and safeguard we are still working out.
YouTube (Google), SoundCloud and Mixcloud
Purpose: videos and sets, only after a tap on play. Data: your IP address and whatever that service records itself. The still image of a YouTube video already comes from YouTube when you see the page. After your tap their rules apply.
Spotify · Sweden
Purpose: only if you link Spotify: reading which artists you follow there, with a key valid for at most 15 minutes. Artist photos we fetch from our server, without visitor data.
The organiser's ticket shop, with Pre-Buy
Purpose: buying a ticket in your name. Data: the names you give per ticket. The shop itself is responsible for what it does with them.
Organisers
Receive what they need to let you in: the name on your ticket, the type, the scan status and in the ticket export the buyer's e-mail address. See the privacy statement.
Without visitor data
OpenStreetMap (Nominatim), MusicBrainz, Wikipedia and Wikidata, Deezer and iTunes Search only receive requests from our server about public data of venues and artists.
Authorities
Only when the law requires it, such as on a valid order from the police or the public prosecutor, and no more than asked.

4Transfers outside the EEA

Some of these parties are based in the US or process data there. If personal data goes to a country without an adequate level of protection, the rule is: EU-US Data Privacy Framework where the supplier is certified, otherwise standard contractual clauses.

Which safeguard applies per supplier we record in our record of processing activities. Ask us through [email protected] and we will send it to you.

5Changes

If a subprocessor for organisers is added or replaced, we announce it at least 30 days in advance: on this page with the date, and by e-mail to the owners of every organisation. Organisers can object within that period, as the data processing agreement describes.

A new recipient for our own processing goes on this page and in the privacy statement, with what changed at the bottom.

Last change: since 30 September 2026 the database and the files are on our server at OVHcloud in Germany instead of at Cloudflare. Since then Cloudflare only does DNS, CDN and attack protection.

Announced changes: none.

What changed

  • New: this list as a page of its own, with per party the purpose, the data, the location and the safeguard for transfers.
  • OVHcloud added for hosting and storage, on a server in Germany. Cloudflare now only does DNS, CDN and attack protection.

Back to top