This Data Processing Agreement ("DPA") forms part of the Strobo Terms of Service between TOURINGTUNES Sp. z o.o. (the "Processor") and the Organizer (the "Controller") and is concluded by accepting the Terms during organizer onboarding. It implements Article 28 GDPR.
1. Subject matter and roles
The Processor processes personal data on behalf of the Controller to the extent the Controller uses Strobo to manage attendee and marketing data: guest lists, CRM contacts and their attributes, marketing opt-ins collected at checkout for the Controller, blast recipients, waitlist entries tied to the Controller's events, entry-scan records of the Controller's events.
For clarity, the following are outside this DPA (Processor acts as independent controller): platform account data, billing, security logs, aggregated product analytics — see the Strobo Privacy Policy.
2. Details of processing
- Duration: the term of the Organizer's use of Strobo, plus the deletion window in §7.
- Nature and purpose: hosting, storage, display, segmentation, export, and dispatch of communications initiated by the Controller.
- Data subjects: the Controller's event attendees, ticket buyers, marketing contacts, guest-list entrants.
- Categories of data: name, email, phone, city, event attendance and ticket/order references, opt-in status and source, check-in timestamps. No special categories are intended; the Controller must not upload them.
3. Controller instructions
The Processor processes such data only on documented instructions of the Controller, given through the platform's functions (import, export, blast, segment, delete) and this DPA, unless EU/member-state law requires otherwise (in which case the Processor informs the Controller unless prohibited).
4. Confidentiality and security
Persons authorized to process the data are bound by confidentiality. Taking into account the state of the art, the Processor implements appropriate technical and organizational measures (Art. 32 GDPR), including: encryption in transit and at rest, row-level security isolating each Controller's data, role-based access (door staff see no financial or contact data), signed single-purpose access tokens, audit trails of entry scans, and least-privilege service credentials.
5. Subprocessors
The Controller grants general authorization to engage the subprocessors listed at /legal/subprocessors (currently: Stripe Payments Europe, Supabase, Vercel, Clerk, Resend, and their hosting providers). The Processor will announce changes to the list at least 14 days in advance; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution or the Controller may terminate the affected service. Subprocessors are bound by data-protection obligations no less protective than this DPA. Transfers outside the EEA rely on adequacy decisions (including the EU–US Data Privacy Framework) or Standard Contractual Clauses.
6. Assistance
The Processor assists the Controller, insofar as possible and taking into account the nature of processing: with data-subject requests (the platform provides search, export, correction and deletion functions), and with obligations under Articles 32–36 GDPR (security, breach notification, DPIAs). The Processor notifies the Controller of a personal data breach affecting the Controller's data without undue delay after becoming aware of it, providing the information required by Article 33(3) GDPR as it becomes available.
7. Deletion and return
Upon termination of the Organizer's account, the Controller may export their data for 30 days; thereafter the Processor deletes it, unless EU or Polish law requires further storage (e.g. accounting records). Backup copies are purged on backup rotation.
8. Audit
The Processor makes available information necessary to demonstrate compliance with Article 28 GDPR (including summaries of security measures and subprocessor agreements) and allows audits — in the first instance by written questionnaire; on-site audits no more than once per year, on 30 days' notice, at the Controller's cost, without access to other controllers' data.
9. Liability and final provisions
Liability follows Article 82 GDPR and the limitations of the Terms of Service to the extent permitted. Polish law governs. In case of conflict between this DPA and the Terms regarding personal data, the DPA prevails.