1.1. This Data Processing Agreement (the "DPA") is entered into between:
A. Agorify AB, incorporated and registered in Sweden with company registration number 559179-4150, whose registered office is at Kompassbacken 14, 16433 Stockholm, and
B. The Host, as defined in the Terms of Service.
1.2. The Host and Agorify are referred to below collectively as the "Parties" and individually as a "Party".
2. Introduction
2.1. The Parties have entered into an agreement regarding Agorifys provision of certain services to the Host (the "Terms of Service"). This DPA is incorporated to the Terms of Service by reference, and constitutes an appendix to the Terms of Service, and sets forth the terms on which the Parties will Process Personal Data in connection with the Service.
2.2. Agorify and the Host each act as an independent controller of Participant Data. In all other circumstances, the Host is the Controller of Event Data (hereinafter referred to as the "Controller") and Agorify is the Processor (hereinafter referred to as the "Processor"). Both Parties shall comply with all applicable requirements of the applicable Laws.
2.3. The Controller hereby engages the Processor for the Processing of Personal Data in the manner specified in this DPA and the Processor hereby accepts the assignment. This DPA governs the Controller’s rights and obligations as a Personal Data Controller and the Processor’s rights and obligations as a Personal Data Processor.
2.4. Both Parties shall each act in accordance and comply with their respective obligations under all applicable national regulations, legal requirements and applicable data protection and privacy legislation in force from time to time. The Processor shall Process Personal Data in accordance with the GDPR and all applicable national data protection laws made under, pursuant to or that apply in conjunction with the GDPR and/or SCC if applicable, in each case as may be amended or superseded from time to time.
2.5. In the event of any indecency or conflict regarding the Processing of Personal Data between the provisions of this DPA and any other agreement between the Parties, the provisions of this DPA shall prevail to the extent of such indecency or conflict.
2.6. This DPA may be written in other language versions. The English version shall always prevail in the event of any conflict and/or confusion between the documents.
3. Definitions
3.1. In addition to the terms defined in the text of this DPA, the following definition shall have the meanings set forth below when they are indicated with a capital letter, regardless of whether they are used in the plural or singular, in definite or indefinite form:
3.1.1. “Controller” refers to the one who determines the purpose of a particular Processing of Personal Data and how the Processing is to be carried out. Natural persons, legal persons, authorities, institutions or other bodies may be Personal Data Controllers.
3.1.2. “Data Subject” means the natural person who can be identified through the Personal Data.
3.1.3. “Data Protection Legislation” include all applicable privacy and data protection laws that are in effect at any given time and that are relevant to a Party relating to the use of Personal Data, such as for example but not limited to: the General Data Protection Regulation (EU) (2016/679).
3.1.4. “Event Data” is (a) any Personal Data registered within the Host Account by the Host and/or its Team Members; (b) any Personal Data contained in speaker bios and/or other materials submitted by Host in the course of creating or during an Event; and (c) any Personal Data embedded in event recordings, participant chat transcripts and/or other Host event related content.
3.1.5. “Event” means an event facilitated by or hosted on the Platform, such as hybrid events, online events and/or onsite events.
3.1.6. “GDPR” refers to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation).
3.1.7. “Law” includes Data Protection Legislation as well as any other applicable regulations, laws, ordinances, orders, or codes, of any governmental entity having authority over the Parties, Services or Events.
3.1.8. “Participant Data” is any Personal Data relating to individuals in the creation of an Agorify account (or other means of access) to attend or engage with an Event through the Service.
3.1.9. “Personal Data” includes all data that, directly or indirectly, alone or together with other data, can be linked to an identified or identifiable physical living person. Common examples of Personal Data are: name, telephone number, address, email address, user ID.
3.1.10. “Platform” means Agorify’s event platform accessible from www.agorify.com which include its associated services, products, software, components, networks, APIs, Documentation and information.
3.1.11. “Processing” refers to everything that is made with Personal Data, automated or otherwise. Processing can take place through an individual measure or through a combination of different measures. Examples of common Processes of Personal Data are storage, erasure, sharing, usage, registration, copying, collection, organization, adjustment, destruction, etc.
3.1.12. “Processing” refers to everything that is made with Personal Data, automated or otherwise. Processing can take place through an individual measure or through a combination of different measures. Examples of common Processes of Personal Data are storage, erasure, sharing, usage, registration, copying, collection, organization, adjustment, destruction, etc.
3.1.13. “SCC” refers to Commission implementing decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, or later updated version.
3.1.14. “Service” includes the services and products which are stated in an Order or otherwise provided by Agorify, for example a Subscription Plan and any additional features or functionality such as Add-Ons, ticketing, check-in & badge printing, event app, and/or lead retrieval, and may also include the Platform. Third-party Services are expressly excluded.
3.1.15. “Third party” refers to someone other than the Personal Data Controller (and the persons who are authorized to Process the Personal Data), the Data Subject or the Personal Data Processor (and the persons who are authorized to Process the Personal Data). A Third party may be a legal person or a natural person, institution, authority or other body.
3.2. Any other GDPR-related terms not defined herein shall have the same meaning in this DPA as set forth in Article 4 of the GDPR.
4. Instructions
4.1. The Processor shall only Process Personal Data on the documented instructions from the Controller as stated in this DPA and the Terms of Service, including with regard to transfers of Personal Data to a third country or an international organization, unless other Processing is required by applicable law in the EU or in one of the EU Member States to which the Processor is subject. If a Processing that the Controller has not instructed the Processor to perform is required by applicable law, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.2. The Processor shall promptly inform the Controller if it lacks instructions regarding the Processing of Personal Data in a specific situation or if, in the Processor's opinion, instructions given by the Controller infringes the GDPR or the applicable Union or Member State data protection provisions.
5. Description of data processing
5.1. Subject matter: Processing of Personal Data related to the Services as described in the Terms of Service.
5.2. Nature and purpose: Processing of Personal Data to provide the Services as described in the Terms of Service.
5.3. Processing activities: The Processor may use such type of Processing that is necessary to fulfill the terms of this DPA, the Terms of Service and the GDPR, such as any Processing activity or set of Processing which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, in order to, for example: create a User account, handle support cases, comply with the obligations stated in this DPA, the Terms of Service and to provide the Service in accordance with the Terms of Service.
5.4. Duration: During the term of the Terms of Service and up to 60 days of backup data storage after the termination of the Terms of Service, or for as long as the Processor is required to retain the Personal Data.
5.5. Place for Processing: The Processing takes place within the EU/EEA-area. Personal Data may also be processed by the sub-processors approved by the Controller (and their respective sub-processors).
5.6. Frequency: Personal Data will be transferred and provided continuously where necessary for the provision of the Service to the Host.
5.7. Categories of Personal Data:
Participant Data, such as:
first and last name, contact details and any additional Personal Data provided directly to the Processor when registering for and engaging with the Service;
IP address;
event name, time and date and any other event participation information; and
any usage data, including metadata relating to an individual's interaction with the Service, such as for example but not limited to length of visit, navigation paths, page views, page interaction information, timing, frequency and patterns of use.
Event Data, such as:
any Personal Data registered within the Host Account by the Host and/or its Team Members;
any Personal Data contained in speaker bios and/or other materials submitted by Host in the course of creating or during an event; and
Personal Data embedded in event recordings, participant chat transcripts and/or other in other Host event related content.
5.8. Categories of Data Subjects: Individuals who participate in Events and individuals whose Personal Data is contained in Event Data.
6. The controller’s responsibilities
6.1. The Controller hereby certifies that it complies with the provisions of all applicable regulations, legal requirements and laws relating to the Processing of Personal Data, regarding its Processing of Personal Data and the engagement of the Processor.
6.2. For the purposes of this DPA, the Controller ensures that it has all necessary and appropriate consents and notices in place to enable a) lawful disclosure of Event Data to the Processor, and/or b) lawful collection or other Processing of Event Data by the Processor on behalf of the Controller.
6.3. The Controller will not instruct the Processor to Process any Personal Data, including Event Data, in violation of Applicable Data Protection Legislation.
6.4. The Controller shall provide the Processor with the information and the Personal Data necessary for the Processor to be able to fulfill its obligations under the DPA and comply with applicable legislation at all times.
6.5. The Controller hereby confirms that the Controller:
has informed the Data Subjects about the Processing of Personal Data to the extent and in the manner required by Applicable Data Protection Legislation,
has the right to Process Personal Data and assign the Processor to perform Processing on behalf of the Controller to the extent and for the purposes specified this DPA, including the right to disclose the relevant Personal Data to any sub-processors that the Processor engages in accordance with the DPA,
shall immediately notify the Processor of any changes in the instructions regarding the Processing of Personal Data and provide correct information to the Processor if the previously provided instructions are incomplete, incorrect or need to be changed for other reasons,
without undue delay shall inform the Processor of the Data Subject's, the Supervisory authorities or other Third party's relevant requests in connection with the Processing of Personal Data.
6.6. The Controller hereby confirms that the organizational and technical security measures that the Processor undertakes to implement and that are defined in Appendix: Technical and organizational security measures are adequate to protect the Data Subjects' rights, and the Controller considers that the Processor has provided sufficient guarantees in this regard.
7. Security measures
7.1. The Processor guarantees to implement appropriate technical and organizational measures in such a manner that Processing will meet the requirements of the GDPR and ensure the protection of the rights of the Data subject.
7.2. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. When the appropriate level of security is assessed, special consideration is given to the risk of unintentional or illegal destruction, loss, alteration or to unauthorized disclosure or access to Personal Data.
7.3. When assessing the appropriate level of security, special consideration shall be given to the risk of unintentional or illegal destruction, loss, alteration or to unauthorized disclosure or access to Personal Data. The measures may include (a) the pseudonymization and encryption of Personal Data; (b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (c) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing.
7.4. The Processor has the right to solely decide on which appropriate measures it shall implement to ensure an appropriate level of security.
8. Notifications
8.1. The Processor shall, to the extent practicable and lawful, notify the Controller of requests for disclosure of Personal Data received from a Data Subject, authority or other Third party.
8.2. The Processor may not, without the prior written consent of the Controller, respond directly to requests from Data Subjects (other than making a referral to the Controller), disclose or otherwise make Personal Data available to Third parties, unless otherwise provided by Applicable Data Protection Legislation, applicable law, authority, or court decision.
8.3. If an authority, Data Subject or other Third party wishes to receive information concerning the Processing of Personal Data from the Processor, the Processor shall refer to the Controller. The Processor does not have the right to represent the Controller or act on its behalf towards any Data Subject, the Supervisory authority or another Third party.
9. Assistance
9.1. The Processor shall assist the Controller with appropriate technical and organizational measures, taking into account the nature of the Processing and the information available to the Processor, in order for the Controller to comply with the requirements of Article 28 of the GDPR, and for the Controller to comply its obligations pursuant to Articles 32 to 36 of the GDPR regarding: security in connection with the Processing, notification of a Personal Data breaches to the Supervisory authority, information to the Data subject about a Personal Data breach, impact assessment regarding data protection and prior consultation.
9.2. The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the Data subject's rights laid down in Chapter 3 of the GDPR.
9.3. The Processor is entitled to compensation in accordance with the Processor’s applicable hourly rates for work performed or assistance provided pursuant to the obligations under this DPA.
10. Confidentiality
10.1. The Processor shall Process the Personal Data with confidentiality and ensure that persons authorized to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The confidentiality commitment shall continue to apply even after the termination of this DPA.
11. Personal Data breaches
11.1. The Processor shall notify the Controller without undue delay after becoming aware of any Personal Data breach affecting any Personal Data regulated under this DPA.
12. Audit
12.1. The Processor will make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in article 28 GDPR and in this DPA, and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Such audits or inspections shall be subject to the provisions stated below.
12.2. For security reasons, the Processor has the right to request that an audit shall be carried out by a neutral Third Party that works under confidentiality and enters into a confidentiality agreement with the Processor. However, a natural or legal person who directly or indirectly conducts competing activities in relation to the Processor's activities, may not be appointed as an auditor to carry out an audit referred to in this section. Competitive operations refer to all operations, without geographical restriction and regardless of company form, which are conducted within the same business area, and which are aimed at the same target group, as the Processor's operations.
12.3. Audit shall also be subject to the following conditions:
a) it is conducted at the Controllers sole expense;
b) the Processor will be reimbursed for time expended by the Processor or its sub-processors;
c) the Processor shall only be required to use reasonable endeavors to assist the Controller in procuring access to any Third-Party records, assets or in information as part of any audit;
d) it may only cover the Personal Data that the Processor Processes on behalf of the Controller covered by this DPA;
e) it shall be carried out only at the Processor's registered units, offices and personnel that are used and involved in the Processing of Personal Data and in accordance with the Processor's security and confidentiality policy;
f) it may only be carried out for a maximum of two (2) working days, during office hours on weekdays between 08:00-16:00 (CET) and shall be carried out as smoothly and efficiently as possible to minimize disruption to the Processors business operations;
g) the audit must not reveal any trade secrets protected by law;
h) no more than one (1) audit per year may be performed, unless it takes place after a significant breach of the Processing of Personal Data has been identified or if this is required by applicable law, government decision or similar;
i) information on the intention to conduct an audit shall be communicated in writing to the Processor at least thirty (30) days before the proposed date for conducting the audit. The Processor has the right to propose a new audit date, which shall fall within seven (7) working days after the date proposed by the Controller; and
j) the audit or inspection and any results thereof shall be confidential information.
12.4. The Controller is responsible for ensuring that the Processor has access to a written audit report without undue delay after the audit has been completed, which contains summaries of the results of the audit. The report shall constitute confidential information that may not be disclosed to Third Parties, without the Processor's prior written permission, if notification is not required by applicable law.
13. Sub-processors
13.1. The Controller hereby provides the Processor a prior general written authorization to engage another processor (“Sub-processor”) for carrying out specific processing activities on behalf of the controller. The sub-processors used for the Processing are listed in Appendix: Approved sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of other Sub-processors, thereby giving the Controller the opportunity to object to such changes.
13.2. Where the Processor engages another sub-processor for carrying out specific processing activities on behalf of the Controller, the same data protection obligations as set out in this DPA or other legal act between the Controller and the Processor shall be imposed on that other Sub-processor by way of a contract or other legal act under Union or Member State law, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of the GDPR. At the request of the Controller, the Processor shall send a copy of the contract signed by both the Processor and the sub-processor.
13.3. Where that other Sub-processor fails to fulfill its data protection obligations, the initial Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.
13.4. The Host may, within ten (10) business days of such notice, reasonably object to such changes for important reasons relating to data protection which have been proven to the Processor. If an objection is made by the Controller on this basis, the Processor will have the opportunity to make changes in the Service or recommend a commercially reasonable change to the Controllers configuration to avoid Processing of Event Data by the objected new sub-processor, insofar is it made without unreasonably burdening the Controller. The Host loses its right to object to the corresponding engagement if the Controller does not object to the changes of Sub-processors within ten (10) business days after the notification date. The Processor is entitled to terminate the Terms of Service with reasonable notice, if an objection is made in accordance with the provisions stated herein.
14. Liability
14.1. If the Controller or the Processor has been held liable against a Data subject or Third Party or has been subject to an administrative fine for its conduct in breach of the GDPR or this DPA, the respective Party shall be liable for the consequences of its action in accordance with the decision of the court or other competent authority.
14.2. If the court or other competent authority has not already ruled on the liability of each of the Parties in the decision referred to in the preceding paragraph, the Parties shall comply with the provisions of Article 82 of the GDPR.
14.3. For situations when article 82 of the GDPR is applicable, no limitations of liability set out in the Terms of Service shall apply to the Parties’ liability under this DPA.
15. Term and termination
15.1. This DPA enters into force when it is accepted by the Controller and will remain in full force and effect so long as the Processor Process Personal Data on behalf of the Controller.
15.2. The Processor shall, at the choice of the Controller, delete or return all the Personal Data to the Controller after the end of the provision of services relating to Processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.
15.3. If the Processor does not receive a response from the Controller to the above actions within thirty (30) days after the termination of this DPA, the Controller shall be deemed to require the deletion of the Personal Data in question.
16. General provisions
16.1. Should any provision (or part thereof) in this DPA be found to be ineffective or void by a competent jurisdiction, general court or arbitration, it shall not affect the validity and enforceability of the remaining provisions. Instead, to the extent the invalidity significantly affects a Party’s benefit from or performance according to the DPA, reasonable adjustment to the DPA shall be made.
16.2. If any necessary provision is missing, the Parties shall in good faith add an appropriate provision.
17. Governing law and jurisdiction
17.1. This DPA, and any dispute, controversy or claim arising out of or in connection with this contract or its subject matter or formation, or the breach, termination, or invalidity thereof, shall be governed by and construed in accordance with the law of Sweden.
17.2. Each Party irrevocably agrees that the courts of Sweden shall have exclusive jurisdiction to settle any dispute or claim (including non-contractual disputes or claims), arising out of or in connection with this DPA or its subject matter or formation.
18. Signatures
18.1. The individual who represents the Controller when accepting this DPA confirms that the individual has the authority and right to enter into legally binding agreements on behalf of the Controller and that this DPA becomes binding between the Parties.
18.2. The Controller accepts this DPA in connection to registering its Account to the Service.