Legal
Data Processing Agreement
Data Processing Agreement (DPA) in accordance with Article 28 GDPR.
Effective from 1 April 2026
Version: 2026-04-01
1. Parties and Scope
This Data Processing Agreement ("DPA") is entered into between:
• The Data Controller ("Controller"): the Organizer using the EazyPazz platform to manage events, ticket sales and related processing
• The Processor: EazyPazz, acting under enterprise number 1003.713.438, represented by Ignace Mella
This DPA applies for the duration of the Controller’s use of the platform and is an integral part of the Terms of Service.
2. Nature and Purpose of Processing
The Processor processes personal data on behalf of the Controller for the following purposes:
• Ticket sales: processing orders, generating tickets and sending confirmations
• Event management: managing event data, visitor lists and check-in data
• Scan and check-in: ticket validation and attendance registration
• Cashless payments: managing wristband balances and transactions
• Communication: sending event-related emails
• Reporting: providing dashboards and statistics
Processing takes place within the European Economic Area (EEA), unless otherwise stated in Article 7.
3. Categories of Data Subjects and Data
Categories of data subjects:
• Event visitors (buyers)
• Organization team members
• Organizers
Categories of personal data:
• Identification data: name, email address, phone number
• Order data: purchase history, ticket type, billing data
• Payment data: processed by Stripe and Mollie (PCI-DSS compliant)
• Check-in data: scan logs, attendance
• Cashless data: wristband ID, balance, transaction history
• Communication data: support messages, email correspondence
4. Processor Obligations
The Processor undertakes to:
4.1 Process personal data only on documented instructions from the Controller, as laid down in this DPA and the platform functionality
4.2 Confidentiality: all persons processing personal data under the authority of the Processor are bound by a confidentiality obligation
4.3 Security: implement appropriate technical and organizational measures in accordance with Article 32 GDPR (see Article 6)
4.4 No further processing: not process personal data for purposes other than those stated in this DPA
4.5 Audit assistance: assist the Controller in exercising their audit rights
5. Sub-processors
The Processor uses the following sub-processors:
• Stripe, Inc. (US) — payment processing (Stripe Connect)
• Mollie B.V. (Netherlands) — payment processing (Mollie Connect)
• Resend, Inc. (US) — transactional emails
• Cloud infrastructure providers — hosting, storage and CDN
The Controller gives general authorization for the use of the above sub-processors. In case of changes to sub-processors, the Controller will be notified in time, with the possibility to object. The current list of sub-processors is available at eazypazz.com/privacy.
6. Security Measures
The Processor takes the necessary technical and organizational measures to ensure an appropriate level of security, including but not limited to:
• Encryption of data in transit (TLS 1.3) and at rest (AES-256)
• Access control and authentication (two-factor authentication, least privilege)
• Regular security audits and penetration tests
• Monitoring and logging of access and changes
• Incident response procedure and plan
• Separation of production and test environments
• Backups and disaster recovery
• Staff training on data protection
7. International Transfers
If personal data is transferred outside the EEA to sub-processors (notably Stripe and Resend in the US), the Processor ensures appropriate safeguards:
• Standard Contractual Clauses (SCCs) approved by the European Commission
• Additional measures in accordance with EDPB recommendations
The Processor makes the SCCs available to the Controller upon request.
8. Assistance with Data Subject Rights
The Processor enables the Controller to comply with requests from data subjects wishing to exercise their rights (access, rectification, erasure, restriction, portability, objection) in accordance with Articles 15-22 GDPR.
The Processor immediately informs the Controller of any direct request from a data subject, unless legally prohibited.
9. Deletion and Return of Data
After termination of this DPA:
9.1 The Processor deletes all personal data within 30 days of the Controller’s request, unless legal retention is required
9.2 If retention is legally required, the Processor limits processing to the legal purpose
9.3 The Controller may at any time request export of their data in a structured, commonly used and machine-readable format
9.4 The Controller submits the request via Dashboard → Organisation → Delete organisation and data. The erasure runs automatically after a 7-day cancellation window. Data falling under 9.2 is flagged as restricted instead of deleted.
10. Audit Right
The Controller has the right to conduct audits to verify compliance with this DPA. The Processor:
• Cooperates with audits
• Provides all relevant information and documentation
• Grants access to facilities and processing systems
• Provides upon request an independent audit report (e.g. ISO 27001, SOC 2)
Audits take place with reasonable notice, during office hours and without unreasonable disruption of the service.
11. Data Breach and Notification
11.1 The Processor notifies data breaches to the Controller within 48 hours of discovery, including:
• The nature of the breach, including categories and estimated number of affected individuals
• The likely consequences
• The measures taken or proposed
11.2 The Controller notifies data breaches to the supervisory authority within 72 hours in accordance with Article 33 GDPR, if the risk to the rights and freedoms of data subjects requires.
11.3 If the breach poses a high risk to data subjects, the Controller is assisted in informing data subjects in accordance with Article 34 GDPR.
12. Final Provisions
12.1 This DPA is governed by Belgian law.
12.2 Disputes are submitted to the competent courts of Brussels.
12.3 If a provision of this DPA is found invalid, the remaining provisions remain in force.
12.4 This DPA supplements the Terms of Service of EazyPazz. In case of contradiction between this DPA and the Terms of Service, this DPA prevails.
12.5 Versions of this DPA are dated and retained. The most recent version is available at eazypazz.com/dpa.