Data processing agreement
The arrangements for the personal data you, as an organiser, have processed through PartyPPL: who is responsible for what, what we promise as a processor and what we ask of you. Part of the organiser terms.
Last updated: 1 October 2026Draft. Drafted to article 28 GDPR, but not yet reviewed by a lawyer. You are always welcome to go through it with your own lawyer as a contract; we are glad to hear comments.
1Parties and acceptance
- Processor
- PartyPPL, a product of NEXG3N, Chamber of Commerce 97359866, VAT NL005264805B67. Address in the colophon.
- Controller
- The organisation that has an organisation account in the portal, "you" below.
- Contact
- [email protected], with "verwerkersovereenkomst" in the subject.
This agreement is part of the organiser terms. You accept it together with those terms when you create an organisation in the portal. Whoever creates the organisation declares that they may represent it.
If you want a signed copy for your own records, mail us. The text is the same as here.
2Who is responsible for what
Not everything that happens around your events we do for you. Per processing:
- Guest list
- You are the controller, we are the processor. The names and kinds of guests you or your team enter, and whether they are in.
- Door scans
- You are the controller, we are the processor. What is scanned at your door: the code, the result, the time, which door and which staff member scanned.
- Exports
- You are the controller, we are the processor for making the ticket export, the guest list, the door export and the finance export at your request. What you download then sits with you; we have no view of it after that.
- Tickets from another shop
- You are the controller, we are the processor. You sold them; we store them, mail the buyer that their ticket is waiting, link it to their account and scan it at the door.
- Ticket sales through PartyPPL
- PartyPPL is the controller itself for ordering, payment, delivery, resale and refunds. What you see of that in your portal or export, you use as an independent controller, only to let people in and to inform them about your event.
- Accounts and the platform
- PartyPPL is the controller itself for accounts, "I'm going", friends, group chats, the forum, notifications, statistics and the accounts of your team members. You only see counts of those.
If a processing is not listed here, we are not your processor for it. What PartyPPL does as a controller is in the privacy statement.
3Subject, duration, nature and purpose
- Subject
- The processing in the previous article for which we are your processor.
- Duration
- As long as your organisation account exists, and after that until the data has been deleted or returned under the article on the end.
- Nature
- Storing, organising, showing in the portal and the door app, matching when scanning, sending e-mails and push notifications for tickets from another shop, exporting as CSV and deleting.
- Purpose
- Letting people into your events, registering the door, keeping guest lists, delivering and scanning tickets from your own shop, and giving you overviews and exports. Nothing else: not for our own marketing, not for profiles and not sold.
4Types of data and data subjects
- Data subjects
- Your guests and invitees, buyers of tickets from your own shop, visitors scanned at your door and your own door staff.
- Data
- Names, e-mail addresses (for tickets from another shop until they are delivered or linked, after that only an encrypted fingerprint), ticket code, ticket type, price, kind of guest, status, scan time, door, scan result and which staff member scanned.
- No special categories
- Do not enter data about health, religion, ethnicity or criminal records, and no identity numbers such as a citizen service number. The portal does not ask for them and the agreement does not cover them.
5Only on your instructions
We process your data only on your instructions. Those instructions are this agreement, the organiser terms, the settings in the portal and what you or your team do there: entering, loading, scanning, exporting, deleting. Any other instruction is given by an owner or administrator by e-mail.
If we think an instruction breaks the GDPR, we say so at once and do not carry it out until it is clear.
If the law requires us to do something with your data, for example on a court order, we tell you in advance, unless the law forbids that.
6Confidentiality
Whoever has access to your data on our side is bound to confidentiality, by contract or by a legal duty. Only those who need it for their work have access: the administration of the platform and, on a report, moderation. Administrators log in with two-factor authentication.
We do not give your data to others, except to the subprocessors in the article on them or when the law requires us to.
7Security
We take appropriate technical and organisational measures, as article 32 GDPR asks. The main ones:
- everything over HTTPS with HSTS and a strict Content Security Policy;
- roles in the portal that are checked on the server for every screen and every export;
- session tokens, API tokens and scanner pairings are stored only as a hash;
- passkeys and two-factor authentication, mandatory for administrators;
- an origin check on every change and rate limits on logging in, uploading and the API;
- documents such as the Chamber of Commerce extract in shielded storage;
- e-mail addresses of tickets from another shop are erased as soon as they are delivered or linked;
- administrator actions and login attempts are logged.
The full list is in the privacy statement; how to report a vulnerability is on Security. We review the measures again when the platform changes substantially. There has been no external audit or penetration test yet.
8Subprocessors
You give us general written authorisation to engage the subprocessors listed on Subprocessors, under "Subprocessors for organisers". At the moment those are OVHcloud (hosting and storage), Cloudflare (DNS, CDN and attack protection; the traffic passes through it), Resend (e-mail) and Apple (push notifications and Wallet).
- If a subprocessor is added or replaced, we announce it at least 30 days in advance: by e-mail to the owners of your organisation and on that page, with the date.
- Within those 30 days you can object, with a reasonable ground. If we cannot resolve it, you can stop using the feature the subprocessor affects or close your organisation account at no cost.
- We impose on every subprocessor the same obligations this agreement imposes on us, through their processing terms, and remain liable to you for what they do.
9Transfers outside the EEA
If data goes to a country outside the European Economic Area without an adequate level of protection, it only goes to a subprocessor on the list and with a safeguard: the EU-US Data Privacy Framework where the supplier is certified under it, otherwise the European Commission's standard contractual clauses.
Your data is on our server at OVHcloud in Germany, inside the EEA. Cloudflare, which sits in front, handles the traffic in the data centre it picks itself; we have not set an EU region there. That is on Subprocessors too.
10Help with data subjects' rights
Much you do yourself in the portal: removing a guest, making an export, withdrawing a ticket from another shop.
If a request reaches us about data you are responsible for, we forward it within five working days and do not answer it ourselves, unless you ask us to. If it also concerns our own processing, we answer that part ourselves.
We help you, as far as reasonable, with a data subject's request, a DPIA and a prior consultation of the Dutch Data Protection Authority.
11Data breaches
If we discover a security breach that affects your data, we report it without undue delay, at the latest within 36 hours of discovering it, to the owners of your organisation. That leaves you time within the 72 hours you have to report it to the Dutch Data Protection Authority.
The report holds what we know at that moment:
- what happened and when;
- which data and roughly how many people it affects;
- the likely consequences;
- what we have done and proposals to limit the consequences;
- who you can call or mail on our side.
If we do not know everything yet, we add to the report as soon as we know more. You decide whether to report it to the Dutch Data Protection Authority and whether to inform data subjects; we help you with that. We record every breach in our breach register, also when it does not have to be reported.
12Retention, deletion and return
While the agreement runs, these periods apply. A daily task deletes whatever is past its period:
- Door scans
- 12 months after the night.
- Tickets from another shop
- 13 months after the night. The e-mail address earlier, as soon as the ticket is delivered or linked.
- Guest lists
- As long as the event is in your portal. There is no fixed period yet; on request we delete earlier.
When the agreement ends, you can still export your data for 30 days. After that we delete the guest lists, door scans and tickets from another shop of your events, at the latest 60 days after the end. If you would rather have them returned than deleted, we send an export.
What we must keep ourselves as a controller, such as orders and tickets sold through PartyPPL (seven years, for the tax authorities), is not covered by this. Copies in our own database backups are deleted after 15 days.
13Checks and audits
On request we give you the information you need to see that we keep to this agreement: this text, the description of the security, the list of subprocessors and the certifications they publish themselves.
If that is not enough, you may once a year, or after a data breach, have an audit done by an independent expert bound to confidentiality. You announce it at least 30 days in advance, it takes place on working days, touches no data of other organisers and the costs are yours. If it shows we fall short, we fix that at our cost.
14Liability
Each party is liable for damage caused by its own breach of the GDPR or of this agreement, as article 82 GDPR provides.
Between us the limitation in the article on liability in the organiser terms applies. That limitation does not apply to intent or deliberate recklessness, and not towards data subjects themselves.
If a party receives a fine or a claim caused by the other, the other indemnifies it, as far as the fault lies with that other party.
15Precedence, changes and governing law
If this agreement conflicts with the organiser terms on personal data, this agreement prevails.
We announce changes at least 30 days in advance by e-mail to the owners. We do not introduce a change that lowers the protection of the data without you being able to terminate at no cost.
This agreement is governed by Dutch law. Disputes go to the District Court of Oost-Brabant, 's-Hertogenbosch location. Where the English translation differs, the Dutch text prevails.
What changed
- New: the full data processing agreement as a page of its own. It replaces the short article in the organiser terms.
- The roles per processing are in it: you are the controller for the guest list, door scans, exports and tickets from another shop, PartyPPL for accounts, the platform and its own ticket sales.
- Set down: we report breaches within 36 hours, announce subprocessors 30 days ahead, and the retention periods and deletion at the end.
- Since 30 September 2026 OVHcloud is the subprocessor for hosting and storage, on a server in Germany. Cloudflare now only does DNS, CDN and attack protection.