Data Processing Addendum
Last updated: 19 July 2026
1. Roles
The Controller determines the purposes and means of processing its vendors’, customers’, and guests’ personal data. The Processor processes that data only on the Controller’s documented instructions, which are given by creating an account, configuring the Platform’s settings, and using its features.
Creating an account constitutes an instruction to process personal data for the purposes described in §3.
2. Subject matter and duration
Processing lasts for the term of the Controller’s account, plus the retention periods in §7, after which data is deleted.
3. Nature and purpose of processing
- Operating markets: vendor applications, booth assignment, attendance, document compliance, invoicing, and sales reporting.
- Operating experiences and venues: bookings, schedules, capacity, waivers, waitlists, reminders, and feedback.
- Presenting vendors, customers, and their history to the Controller’s staff.
- Sending the service email described in the Privacy Policy, including operational notices the Controller composes for its vendors.
- Processing payments through Stripe on the Controller’s behalf.
4. Categories of data and data subjects
Data subjects: the Controller’s staff, vendors, customers, guests, and attendees.
Personal data: names, email addresses, phone numbers, postal addresses (vendors), vendor business profiles and uploaded compliance documents, electronic-signature records (typed signature, IP address, browser identifier), booking and payment status records, waiver acceptance records, feedback, and activity history.
Not processed: payment card details or bank account numbers (payments are collected on Stripe-hosted pages), government identifiers of individuals, and special-category data as defined by GDPR Article 9. The Processor has no facility to store these.
5. Processor obligations
The Processor shall:
- Process personal data only on documented instructions, including for international transfers.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures in §6.
- Not engage a sub-processor without notice to the Controller (§8).
- Assist the Controller in responding to data subject requests (§9).
- Assist with security, breach notification, and impact assessments, taking into account the nature of processing and the information available.
- Delete data on termination, per §7.
- Make available the information needed to demonstrate compliance.
6. Technical and organisational measures
| Measure | What is actually implemented |
|---|---|
| Encryption in transit | TLS on all endpoints |
| Encryption at rest | Provided by Cloudflare for database, key-value, and file storage |
| Credential protection | Passwords stored as salted PBKDF2-SHA256 hashes (100,000 iterations); platform API secrets held as deployment secrets, not in code or the database |
| Access control | Role-based access; server-side sessions delivered as HttpOnly, Secure cookies; bot protection and rate limiting on authentication flows |
| Tenant isolation | Every Controller-owned record carries the organization identifier; queries are organization-scoped; cross-organization isolation is covered by automated tests |
| Payment isolation | Card data never touches the Platform; Stripe webhook messages are cryptographically verified |
| Auditability | Writes to Controller data are recorded in an audit log with actor and before/after state |
| Retention enforcement | Automated daily archival of aged operational records, with archives verified readable before originals are removed |
| Environment separation | Production, staging, and development use separate databases and storage |
Not currently claimed: the Processor holds no third-party security certification (SOC 2, ISO 27001), does not commission independent penetration testing, and does not currently offer multi-factor authentication for user accounts. The Controller should weigh this.
7. Retention and deletion
Staff, vendor, and customer records are retained for the term of the Controller’s account. Aged operational records are moved to cold storage on a schedule: audit events after 400 days, notification records after 180 days, resolved payment-reconciliation records after 90 days. Abandoned draft bookings are deleted after 7 days. Financial records (invoices, payments) are retained for approximately 7 years to meet tax obligations.
On termination of the account, the Processor will, at the Controller’s written request, delete or return the Controller’s personal data within 30 days, save for records the Processor is legally required to retain.
8. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, database, file storage, bot protection, AI features | Global network |
| Stripe, Inc. | Payment processing and billing | Global |
| Twilio Inc. (SendGrid) | Transactional email delivery | United States |
The Processor will give notice before adding or replacing a sub-processor, and the Controller may object by closing its account.
9. Data subject requests
Requests from the Controller’s data subjects received directly by the Processor are referred to the Controller. On the Controller’s verified instruction, the Processor will report the records held for a data subject, or delete them, within 30 days — except records tied to an unpaid invoice or records the Processor is legally required to retain.
10. Personal data breach
The Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting the Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken.
11. International transfers
Data is processed on Cloudflare’s global network. Where transfers leave the EEA or UK, the parties rely on ⟨Standard Contractual Clauses / UK Addendum — confirm with counsel⟩.
12. Audit
The Processor shall make available information necessary to demonstrate compliance and allow for audits by the Controller or an appointed auditor, on reasonable notice and no more than once per year unless required by a supervisory authority.
13. Liability and term
⟨To be aligned with the Terms of Service — counsel to complete.⟩