Data ProcessingAgreement
Contents
1. PREAMBLE
1.1.At the conclusion of the Terms and Agreement, The Processor Ticketbutler trading as Fredo, declares that it will implement the appropriate technical and organisational measures in such a way that the processing meets the requirements of the General Data Protection Regulation and ensures the protection of the data subjects' rights.
2. SUBJECT OF PROCESSING
2.1.The processing involves the fulfilment of the Terms and Agreement between the Processor, Ticketbutler trading as Fredo, and the Controller, the Organiser.
2.2.The duration of the processing activities follows the Terms and Agreement.
2.3.Attendee personal data is deleted 60 days after the end date of each event to which it relates. The Organiser is notified in writing in advance and may export the data at any time from the Fredo dashboard. On written request, the Organiser may ask for earlier deletion, or for an extended retention period of up to 180 days; requests for extension must be made before the start of the event. Extensions beyond 180 days require a separate written agreement between the parties.
2.4.Following deletion under clause 2.3, the Processor retains check-in records only in anonymised form, i.e. in a form that does not identify individual attendees and therefore is not regulated by the GDPR, cf. article 2(1).
2.5.Where an individual agreement between the parties specifies a different retention period, that period applies in place of clause 2.3.
2.6.The processing consists of collection, storage, use, further processing, and erasure for the purpose of on-site event check-in, scanning, session check-in, printing name badges on demand, and making the resulting data available to the Controller.
2.7.The processing includes Article 6 information submitted to the Processor by the Controller for the purposes set out in clause 2.6, in the form of contact and registration information, typically including name, company, job title, telephone number and e-mail and information that the data subject has been registered for a given event. The Controller determines which information is submitted.
2.8.The personal data related to the Controller's current and former event goers ("attendees"), employees, customers, suppliers and collaborators is processed.
2.9.The Service is not intended for the processing of special categories of personal data (Article 9 of the General Data Protection Regulation). Where the Controller chooses to collect information such as allergies or accessibility needs through the Service, this constitutes an instruction to process that information, and the Controller is responsible for ensuring a valid legal basis under Article 9(2). Such information is processed solely for the purpose of the Controller's own event and is deleted in accordance with clause 2.3.
3. INSTRUCTIONS
3.1.The Processor may only process personal data in accordance with documented instructions from the Controller.
3.2.The requirement for the Controller's documented instructions of The Processor's procedures under clause 3.1 can only be set aside if this is required by EU or national law to which The Processor is subject.
3.3.If clause 3.2 applies, The Processor shall notify the Controller of this legal claim without undue delay before processing, unless the court in question prohibits such notification based on important public interest.
4. THE RIGHTS OF DATA SUBJECTS
4.1.Taking into account the nature of the processing, The Processor will assist the Controller as far as possible by means of appropriate technical and organisational measures, in fulfilment of the Controller's obligation to respond to requests for exercising of the data subjects' rights as laid down in Chapter III of the general Data Protection Regulation.
5. DATA PROTECTION
5.1.The Processor assists the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36, taking into account the nature of the processing and the information available to The Processor. The Processor is entitled to separate payment in relation to the assistance mentioned above.
5.2.The Processor takes all measures required pursuant to Article 32.
5.3.The Processor ensures the persons authorised to process the personal data have committed themselves to confidentiality in their employment contract or are subject to an appropriate statutory obligation of confidentiality.
5.4.The Processor notifies the Controller without undue delay, and no later than 48 hours, after becoming aware of a personal data breach. The notification includes the information necessary for the Controller to fulfil its obligations under Articles 33 and 34 of the General Data Protection Regulation, provided in phases where it is not all available at the time of notification.
6. SUB-PROCESSORS
6.1.The Processor is hereby granted general written approval from The Controller to use sub-processors in relation to fulfilment of the Terms and Conditions. The Processor maintains an up-to-date overview of its sub-processors at hifredo.com/subprocessors. Changes are notified to the Controller in accordance with clause 6.2.
6.2.The Processor informs the Controller in writing of any intended addition or replacement of a sub-processor at least 30 days before the change takes effect.
6.3.If the Controller does not want the Processor to use an announced sub-processor, the Controller must object in writing within the notice period stated in clause 6.2. If the parties cannot resolve the objection, the Controller may terminate the Terms and Agreement with respect to the services affected by the change.
6.4.If The Processor makes use of a sub-processor in connection with the execution of specific processing activities on behalf of the Controller, the sub-processor shall be subject to the same data protection obligations as those set out in Article 28 of the General Data Protection Regulation.
6.5.If a Sub-Processor, as mentioned under 6.4, does not fulfil its data protection obligations, The Processor will remain fully liable to the Controller for the fulfilment of the Sub-Processor's obligations.
7. AUDIT
7.1.The Processor makes available to the Controller all information necessary to demonstrate compliance with the requirements laid down in Article 28 of the general Data Protection Regulation.
7.2.With 30 days notice, the data processor allows for and contributes to audits, including inspections, conducted by the Controller or another auditor authorised by the Controller.
7.3.The Processor shall immediately inform the Controller if an instruction regarding clause 7.1 or 7.2, in the Processors opinion, infringes the general Data Protection Regulation or data protection provisions of other union or Member State data protection provisions.
7.4.The Processor is entitled to invoice separately for work related to 7.1 and 7.2.
8. TERMINATION OF PROCESSING
8.1.On termination of the processing service, the Processor deletes all personal data processed on behalf of the Controller, unless the Controller has requested in writing, before the end of the Terms and Agreement, that the data be returned. Any remaining copies are deleted.
8.2.The obligations under clauses 2.3 and 8.1 do not apply where EU or Member State law requires continued storage of the personal data.
8.3.The Processor documents to the Controller, without undue delay, which rules under EU or Member State law require such storage, as mentioned in clause 8.2.
9. CHANGES
9.1.Statutory changes are introduced by the Processor and the Controller is notified of this as soon as possible. Such changes do not affect the validity of the agreements already concluded, nor do they require the adapted agreement to be signed.


