Data Processing Agreement
Version 1.0 · Between organizer (controller) and Celebrio Events (processor).
1. Parties and roles
This Data Processing Agreement ("DPA") is between you as the organizer ("Controller") and Celebrio Events, operated by Danztrack Studios ("Processor," "we," "us"). It applies whenever we process personal data of attendees, guests, RSVP respondents, ticket buyers, event staff, or other individuals on your behalf in connection with your event on Celebrio. The Controller determines the purposes and means of processing; the Processor processes personal data only on documented Controller instructions and per this DPA.
2. Scope and subject matter
- Subject matter: processing personal data needed to operate your event on Celebrio.
- Duration: while your account or event remains active, plus retention periods stated in our Privacy Notice.
- Nature and purpose: hosting, ticketing, check-in, RSVP, messaging, payments, fraud prevention, analytics, and customer support.
- Types of data: identifiers (name, email, phone), event attributes (RSVP, dietary, accessibility), ticket and payment metadata, check-in scans, photos uploaded by attendees, device data, communications.
- Data subjects: attendees, RSVP respondents, guests, ticket buyers, event staff, sponsors, and other people you invite or interact with.
3. Controller obligations
- Establish a lawful basis for collecting and sharing personal data with Celebrio and any third parties you choose.
- Provide notice to data subjects (e.g. attendees) about how their data will be used, including disclosure to Celebrio as your processor.
- Handle data-subject requests directed to you, with our reasonable assistance.
- Use the platform's privacy controls (RSVP visibility, guest privacy, public pages) consistently with your notices.
4. Processor obligations
- Process personal data only on your documented instructions, which include your configuration of the Services.
- Ensure personnel authorized to access personal data are under confidentiality obligations.
- Implement appropriate technical and organizational security measures (see Section 6).
- Assist you, taking into account the nature of processing, with data-subject requests and with your obligations on security, breach notification, and impact assessments.
- On termination, delete or return personal data per Section 9.
5. Sub-processors
You authorize Celebrio to use sub-processors to deliver the Services, including infrastructure (Cloudflare, Lovable, Supabase), payment processing (Stripe, Xendit and local payment partners), transactional email (our notification subdomain provider), and analytics. We require sub-processors to be bound by data-protection obligations no less protective than this DPA.
We will provide a means to be notified of new sub-processors. You may object on reasonable grounds; if we cannot accommodate your objection, you may terminate the affected Services.
6. Security
- Encryption of personal data in transit (TLS) and at rest.
- Role-based access control with least-privilege, audit logging, and row-level security on tenant data.
- Hardened infrastructure with managed patching, secrets management, and segregated production environments.
- Vulnerability reporting program at /security/report and a documented breach-response process.
7. International transfers
Where personal data is transferred outside the Philippines, we rely on safeguards such as the recipient's data-protection certifications, contractual data-protection clauses, or other mechanisms recognized under the Data Privacy Act of 2012 (RA 10173) and applicable foreign law (including GDPR Standard Contractual Clauses where relevant).
8. Personal data breach notification
Celebrio will notify you without undue delay after becoming aware of a personal data breach affecting your data and will provide information reasonably necessary for you to meet your own notification obligations (including, where applicable, to the National Privacy Commission). See our breach-response checklist in docs/breach-response/.
9. Return and deletion
On termination of your account or your event, and after any regulatory or contractual retention period, Celebrio will delete or anonymize personal data processed on your behalf, except where retention is required by law (e.g. payments, tax, fraud prevention).
10. Audits
On reasonable written request, no more than once per year, we will make available information necessary to demonstrate compliance with this DPA, such as security summaries, third-party attestations of our sub-processors, or written responses to reasonable security questionnaires.
11. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations in our Terms of Service and Organizer Terms. For data-protection matters specifically, this DPA controls.
12. Governing law
This DPA is governed by the laws of the Republic of the Philippines, including the Data Privacy Act of 2012 (RA 10173) and its implementing rules, without prejudice to mandatory protections under the law of the data subject's residence.
13. Contact
For DPA matters and data-subject requests, reach our Data Protection Officer through the contact form.
