Data Processing Addendum (DPA) for Organizers
Last Updated: January 4, 2023. This Data Processing Addendum ("DPA") sets forth the terms and conditions related to the privacy, confidentiality and security of Personal Data associated with Services provided by 91制片厂 to Organizer pursuant to the Agreement. In this DPA references to "you" means the Organizer and references to "we,'' "us," "our" and "91制片厂" means 91制片厂, Inc. and our affiliates. To learn more about 91制片厂's Legal Terms, take a look听.
In this article
Overview and Definitions.
1. Applicability of DPA and scope of data processing activities.
2. Data processing clauses.
3. Cross-Border Transfers.
Overview and Definitions.
The terms of this DPA are hereby incorporated into the 91制片厂 Terms of Service, Privacy Policy or any other applicable services agreement between you and 91制片厂 (the "Agreement").
With respect to provisions regarding Processing of Personal Data, in the event of a conflict between the Agreement and this DPA, the provisions of this DPA shall control. In the event of a conflict between this DPA and any other provision of the Agreement between you and us, this DPA will control; except where Organizer and 91制片厂 have individually negotiated data processing terms that are different from this DPA and which meet the requirements of applicable Data Protection Laws in full, in which case those negotiated terms will control.
鈥CCPA鈥 means the California Consumer Privacy Act (as amended by the California Privacy Rights Act) and associated regulations.
鈥Data Protection Laws鈥 means all applicable laws or regulations related to the privacy, confidentiality and security of Personal Data.
鈥Business,鈥 "Data Controller," "Data Processor," "Data Subject," "Processing," "Personal Data," and 鈥Service Provider鈥 shall have the meanings ascribed to them in applicable Data Protection Laws.
"Data Security Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, Personal Data Processed by 91制片厂 on Organizer鈥檚 behalf as part of Organizer鈥檚 use of the Services.
鈥New EU SCCs鈥 means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
鈥Services鈥 means any services provided by 91制片厂 to Organizer, as defined in the 91制片厂 Terms of Service of any other applicable services agreement between Organizer and 91制片厂.
"Technical and Organizational Security Measures" means reasonable security measures implemented by 91制片厂 appropriate to the type of Personal Data being Processed on Organizer鈥檚 behalf and the Services being provided by 91制片厂 designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration or disclosure.
鈥UK SCC Addendum鈥 means the United Kingdom International Data Transfer Addendum to the European Commission鈥檚 Standard Contractual Clauses for international data transfers version B1.0 issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act of 2018 and entering into force on 21 March 2022, as updated, amended, or replaced from time to time.
1. Applicability of DPA and scope of data processing activities.
1.1 In using 91制片厂's Services, Organizer acts as a Business and is a Data Controller of the Personal Data associated with an individual using 91制片厂 Services, or on whose behalf an individual is using 91制片厂 Services, to register for or purchase a ticket to attend such Organizer's event ("Consumer"). Organizer represents and warrants that it has provided any necessary notices and if required, obtained any necessary consents related to the collection of such Personal Data from the Consumer and Organizer has the right to share such Personal Data with 91制片厂.
1.2 Where 91制片厂 Processes the Personal Data of Consumers on behalf of Organizer as part of the Services, 91制片厂 is a Data Processor or Service Provider in performing such Processing and Organizer is the Data Controller or Business. This includes circumstances where 91制片厂 obtains Personal Data as a result of the provision of its core ticketing services (for example, where 91制片厂 facilitates the transmission of emails to Consumers at the request of Organizers, processes payments, or provides event reports and tools to enable Organizers to gain insights into the effectiveness of various sales channels).
In respect of some processing of Consumers' Personal Data, 91制片厂 may act as a Data Controller or Business, for example, where Consumers have engaged with aspects of 91制片厂's Applications beyond those relating to Organizer's event or where Consumers' Personal Data is Processed by 91制片厂 to conduct research and analysis to enable 91制片厂 to improve its products and features and provide targeted recommendations. With regard to such processing, 91制片厂 is an independent Data Controller and not a joint Data Controller with Organizer.
To the extent that 91制片厂 processes Personal Data as a Data Processor or Service Provider on behalf of Organizer, Section 2 of this DPA shall apply, however, when 91制片厂 is acting as a Business or Data Controller of Consumers' Personal Data, 91制片厂's processing shall not be subject to this DPA.
1.3 Details about the Personal Data to be processed by 91制片厂 and the Processing activities to be performed under the Agreement are as follows: (i) duration - as set out in the Agreement; (ii) nature, purpose and subject matter - to enable Organizer to organize and promote events and manage ticketing using 91制片厂 Services; (iii) data categories - name, email address, billing and payment information, information related to events booked and attended, relationship to Organizer and any other Personal Data that Organizer requests of its Consumers; (iv) data subjects - Consumers.
2. Data processing clauses.
2.1 Whenever 91制片厂 processes Personal Data on behalf of Organizer, 91制片厂 shall:
2.1.1 Process Personal Data only on the documented instructions of Organizer, unless required to do otherwise by applicable law. 91制片厂 shall inform Organizer of the legal requirement before processing Personal Data other than in accordance with Organizer's instructions, unless that same law prohibits 91制片厂 from doing so on important grounds of public interest. Organizer will ensure that its instructions comply with all laws, regulations and rules applicable to the Personal Data, and that 91制片厂鈥檚 processing of such Personal Data will not cause 91制片厂 to violate any applicable law, regulation or rule, including Data Protection Laws. 91制片厂 will notify Organizer, if in its opinion, an instruction is in breach of applicable Data Protection Laws. Organizer hereby instructs 91制片厂, and 91制片厂 hereby agrees, to process Personal Data as necessary to perform 91制片厂's obligations under the Agreement and for no other purpose, unless otherwise specified in this DPA or required to comply with the law or other binding governmental order. In the event that this DPA or any actions to be taken or contemplated in performance of this DPA do not or would not satisfy either party鈥檚 obligations under applicable Data Protection Laws, the parties shall negotiate in good faith upon an appropriate amendment to this DPA;
2.1.2 Comply with all applicable provisions of Data Protection Laws and provide the same level of protection for Personal Data as required of Organizer under Data Protection Laws.听 91制片厂 will process Personal Data only as necessary to perform 91制片厂鈥檚 obligations under the Agreement, or as otherwise permitted by Data Protection Laws. Without limiting the foregoing, 91制片厂 will not (i) 鈥渟ell鈥 or 鈥渟hare鈥 the Personal Data, as such terms are defined in the CCPA; (ii) 91制片厂 shall not retain, use, or disclose any such data outside of the direct business relationship between Organizer and 91制片厂 unless permitted by Data Protection Laws, or (iii) retain, use or disclose Personal Data for any purpose other than the business purposes specified in this DPA or otherwise permitted by Data Protection Laws.听 91制片厂 shall comply with any applicable restrictions under Data Protection Laws on combining Personal Data with personal data that 91制片厂 receives from, or on behalf of, another person or persons, or that 91制片厂 collects from any interaction between it and any individual.
2.1.3 Have in place Technical and Organizational Security Measures which include, but are not limited to, the measures described here:听;
2.1.4 Notify Organizer in the event of a Data Security Breach without undue delay, unless otherwise prohibited by law or otherwise instructed by a law enforcement or data protection authority. In the event of any Data Security Breach, 91制片厂, in its sole discretion, may provide data breach notification to affected data subjects directly.听Where 91制片厂 does not provide such notification, 91制片厂 shall provide reasonable assistance, where required by applicable Data Protection Laws and at Organizer鈥檚 request, to enable Organizer to comply with its data breach obligations as a Data Controller or Business;
2.1.5 Ensure that its personnel are subject to binding obligations of confidentiality with respect to Personal Data of Consumers Processed by 91制片厂 on Organizer鈥檚 behalf;
2.1.6 Impose obligations on its sub-processors that have access to Personal Data of Consumers Processed by 91制片厂 on Organizer鈥檚 behalf that are the same as or equivalent to those set out in this Section 2 by way of written contract, and remain fully liable to Organizer for any failure by a sub-processor to fulfill its obligations in relation to such Personal Data;
2.1.7 Provide reasonable assistance to Organizer in responding to individual rights requests or other communications received under applicable Data Protection Laws from any applicable data protection authority or Consumer who is the subject of any Personal Data processed by 91制片厂 on Organizer鈥檚 behalf. In the event that a Consumer submits a Personal Data deletion request to 91制片厂, Organizer hereby instructs and authorizes 91制片厂 to delete or anonymize the Consumer's Personal Data on Organizer's behalf.听 Where necessary, Organizer shall inform 91制片厂 of any other individual rights request that 91制片厂 must comply with, and provide the information necessary for 91制片厂 to comply with the request.;
2.1.8 Upon Organizer's written request, make available to Organizer all information reasonably necessary to demonstrate its compliance with the obligations set out in this Section 2, provide reasonable assistance with privacy and data protection impact assessments and related consultations of data protection authorities, and allow for and co-operate with any audits. Any on-site audits shall be: (i) permitted only on reasonable advance notice to 91制片厂; (ii) subject to appropriate confidentiality undertakings; and (iii) limited to once every three (3) years and only in order to evaluate a specific suspected deficiency after exhausting all other reasonable means; and
2.1.9 Except for that Personal Data with respect to which 91制片厂 acts as a Data Controller or Business, return, delete, or destroy (at Organizer's election) the Personal Data of Consumers processed on Organizer鈥檚 behalf and copies thereof, at Organizer's request (unless applicable law requires the storage of such Personal Data).
2.2 Organizer hereby consents and authorizes 91制片厂 to disclose or transfer Personal Data to, or allow access to Personal Data by, 91制片厂's听听(i.e. those listed on 91制片厂's website on the Effective Date of this DPA or the Agreement, whichever is later) ("Current Sub-Processors") to process Personal Data on Organizer鈥檚 behalf.
2.3 Organizer hereby consents to 91制片厂 appointing additional and replacement sub-processors ("Replacement Sub-Processors") to process Personal Data on Organizer鈥檚 behalf. 91制片厂 shall听give notice to Organizer of the identity of intended Replacement Sub-Processors (i) via听email听where Organizer has opted in to receive such email notifications and (ii) by updating 91制片厂's website (Organizer is responsible for regularly checking and reviewing 91制片厂's website for any such changes).听Organizers interested in receiving听email notice of Replacement Sub-Processors must opt in and subscribe using this听听(Organizer is solely responsible for ensuring its contact information remains accurate). 91制片厂 shall also give the Organizer the opportunity to object to such changes that take place after the Effective Date of the Agreement, in accordance with the terms that follow in Section 2.4 of this DPA.
For the avoidance of doubt, any termination rights available herein shall only apply in the instance of objections to Replacement Sub-Processors appointed after the Effective Date of this DPA that are not remedied in accordance with the terms herein, and shall not apply in relation to Current Sub-Processors.
2.4 Organizer shall raise any objection to the appointment of Replacement Sub-Processors within ten (10) days of 91制片厂 posting the changes on its website. Organizer shall send its objection to听privacy@eventbrite.com听with the subject line 'Objection to Replacement Sub-Processor'.
Provided that Organizer's objection: (i) concerns the Replacement Sub-Processor's ability to allow 91制片厂 to materially comply with its data protection obligations under this DPA; and (ii) includes sufficient detail to support its objection and provides specific examples, 91制片厂 will then use commercially reasonable efforts to review and respond to Organizer's objection within thirty (30) days of receipt of Organizer's objection with 91制片厂's determined method of accommodation.
If 91制片厂 determines in its sole discretion that it cannot reasonably accommodate Organizer's objection, upon notice from 91制片厂, Organizer may choose to terminate the Agreement by providing written notice to 91制片厂, and complying with the terms herein, which shall be Organizer's sole and exclusive remedy. Without limiting the generality of the foregoing, Organizer's termination right under this Section 2.4 will be deemed an additional termination right of Organizer under the "Term and Termination" Section of the Agreement (if any) and if exercised will be deemed a termination pursuant to such Section. Such written notice must be sent to听legal@eventbrite.com听and must specifically reference this Section 2.4 of the DPA. The day 91制片厂 receives an Organizer's written termination notice under this Section 2.4 will be referred to as the "Objection Date" in this DPA. Should Organizer choose to terminate the Agreement as a result of a Replacement Sub-Processor, then nothing in this Section 2 shall relieve Organizer from any of its payment and/or repayment obligations to 91制片厂 under the Agreement.
Without limiting 91制片厂's other rights and remedies, if Organizer terminates the Agreement pursuant to this Section 2.4, then Organizer will immediately pay to 91制片厂 (1) all amounts accruing and owed to 91制片厂, including, without limitation, obligations to pay and/or repay 91制片厂 for Fees, Sponsorship Payments, Advances, and/or Advance payments of Event Registration Fees, as such terms are defined in the Agreement and only to the extent applicable to Organizer, (2) if the Agreement includes a minimum number of tickets Organizer must sell, a minimum amount of Event Registration Fees or 91制片厂 Services Fees that must be processed (each such sales or processing threshold, a "Minimum Threshold"), and/or a requirement to pay 91制片厂 the portion of Service Fees 91制片厂 would have received had a Minimum Threshold been met, then Organizer agrees to pay 91制片厂 an amount equal to (x) the amount that 91制片厂 would have received in Service Fees had the Minimum Threshold been met in each year of the term up to the date of such termination (with such Minimum Threshold prorated as to any partial year of the Term), less (y) the amount that 91制片厂 actually received in Service Fees attributable to Organizer's sales during the Term up to the date of such termination; and (3) 80% of the anticipated Fees 91制片厂 would have earned during the remainder of the Term had the Agreement not been terminated with respect to (x) events on sale on the Site as of the Objection Date, and (y) any future events contemplated under the Agreement intended to go live in the ninety (90) days following the Objection Date.
2.5 91制片厂 hereby certifies that it understands the restrictions and obligations set forth in this DPA and that it will comply with them. 91制片厂 will notify Organizer if 91制片厂 makes a determination that it can no longer meet its obligations under Data Protection Laws.
2.6 Organizer shall have the right, upon fourteen (14) business days鈥 notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data by 91制片厂.
3. Cross-Border Transfers.
3.1 Organizer agrees that 91制片厂 may transfer Personal Data of Consumers to various locations in connection with providing the Services. Transfers will be made in accordance with legally enforceable transfer mechanisms where required by applicable Data Protection Laws. 91制片厂鈥檚 exclusive transfer mechanism for data exported from the European Economic Area, United Kingdom and Switzerland is the use of听, which have been pre-signed by 91制片厂 for Organizer compliance records. To make transfers from the United Kingdom, 91制片厂 has also incorporated the UK SCC Addendum in section 3.2 of this DPA.
3.2 UK Transfers. With respect to 91制片厂 Personal Data transferred from the United Kingdom for which United Kingdom law (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, the UK SCC Addendum forms part of this DPA and take precedence over the rest of this DPA as set forth in听the UK SCC Addendum, unless the United Kingdom issues updates to the UK SCC Addendum, in which case the updated UK SCC Addendum will control. Undefined capitalized terms used in this provision shall mean the definitions in the UK SCC Addendum. Organizer hereby agrees to enter into the UK SCC Addendum, which is incorporated into this DPA by this reference and completed as follows:
In Table 1, the Parties鈥 details shall be the Parties as set forth in Annex I of the听听as executed by the Parties pursuant to this DPA.
In Table 2, the Approved EU SCCs shall be the听听as executed by the Parties pursuant to this DPA.
In Table 3, Annex 1A and Annex 1B shall be as set forth in Annex I of the听听as executed by the Parties pursuant to this DPA.
Table 3, Annex II shall be as set forth in Annex II of the听听as executed by the Parties pursuant to this DPA.
In Table 4, either party may end this DPA as set out in Section 19 of the UK SCC Addendum.
3.3. Switzerland Transfers. With respect to Personal Data transferred from Switzerland for which Swiss law (and not the law in any European Economic Area jurisdiction) governs the international nature of the transfer, (i) references to the GDPR in Clause 4 of the New EU SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority shall include the Swiss Federal Data Protection and Information Commissioner; and (ii) as so amended, the New EU SCCs are incorporated herein by reference and shall apply, form a part of this DPA, and take precedence over the rest of this DPA to the extent of conflict.
3.4.听EEA Transfers. With respect to Personal Data transferred from the European Economic Area, the听听incorporated herein shall apply and form part of this DPA. In the event of a conflict between any provision of the New EU SCCs and any provision of this DPA, the New EU SCCs will control to the extent of conflicts.