Data Processing Agreement

This Data Processing Agreement forms part of the Terms of Service between Fomomento OÜ and the Organizer and governs the Processing of Personal Data by Fomomento on behalf of the Organizer.

  1. Definitions

The following defined terms apply in this DPA:

    1. Controller - the entity which determines the purposes and means of Processing Personal Data.

    2. Data Protection Law - the GDPR and any national law implementing, supplementing or applying the GDPR that is applicable to the Processing under this DPA.

    3. Data Subject - an identified or identifiable natural person to whom Personal Data relates.

    4. GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council.

    5. Organizer Personal Data - Personal Data Processed by Fomomento on behalf of the Organizer in connection with the Platform, as described in Annex I.

    6. Personal Data - any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.

    7. Personal Data Breach - a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

    8. Processing - any operation or set of operations performed on Personal Data, as defined in Article 4(2) GDPR, and Processed and Process have corresponding meanings.

    9. Processor - an entity which Processes Personal Data on behalf of a Controller.

    10. Sub-processor - a Processor engaged by Fomomento to Process Organizer Personal Data on behalf of the Organizer.

    11. Terms - Fomomento's Terms of Service, as amended in accordance with their provisions.

Capitalised terms not defined in this DPA have the meanings given to them in the Terms.

  1. Scope and allocation of roles

    1. This DPA is binding on Fomomento OÜ, as Processor, and the Organizer that accepts or is otherwise bound by the Terms, as Controller.

    2. The Organizer appoints Fomomento to Process Organizer Personal Data only to provide, secure and support the Platform and to perform the Processing described in Annex I. The subject matter, duration, nature and purposes of the Processing, the categories of Data Subjects and the categories of Personal Data are set out in Annex I.

    3. The Organizer remains responsible for determining the purposes and essential means of Processing Organizer Personal Data. Fomomento remains responsible for the correct operation and security of the technical functionality that Fomomento designs and operates to implement the Organizer's lawful configuration and documented instructions.

    4. Fomomento acts as an independent Controller for Personal Data that it processes for its own purposes, including Organizer account administration, authentication, billing, legal compliance, service security and direct support communications. Such Processing falls outside this DPA and is described in the Privacy Policy.

    5. If this DPA conflicts with the Terms, this DPA prevails to the extent of the conflict in relation to the Processing of Organizer Personal Data. Mandatory provisions of Data Protection Law and any applicable standard contractual clauses prevail over both documents.

  2. Documented instructions

    1. Fomomento shall Process Organizer Personal Data only on the Organizer's documented instructions, including instructions concerning transfers to a third country or an international organisation, unless Union or Member State law requires otherwise.

    2. The Terms, this DPA, the Organizer's configuration and use of the Platform, supported instructions submitted through the Platform, and other written instructions accepted by Fomomento constitute the Organizer's documented instructions. An instruction that materially changes the agreed scope or requires custom work is subject to Fomomento's written acceptance and may be subject to reasonable additional charges agreed in advance.

    3. Where Fomomento is required by law to Process Organizer Personal Data other than on the Organizer's instructions, Fomomento shall inform the Organizer of that requirement before Processing, unless the law prohibits the information on important grounds of public interest.

    4. Fomomento shall immediately inform the Organizer if, in Fomomento's opinion, an instruction infringes the GDPR or another applicable provision of Union or Member State data protection law. Fomomento may suspend the affected Processing until the Organizer confirms, modifies or withdraws the instruction. This does not transfer the Organizer's responsibility for the lawfulness of its instructions to Fomomento.

    5. Fomomento shall not sell Organizer Personal Data, use it for third-party advertising, or use it to train a general-purpose artificial intelligence model, unless the Organizer has separately instructed and lawfully authorised that Processing and the relevant Processing and providers have been disclosed in this DPA.

    6. Without prejudice to Articles 82, 83 and 84 GDPR, if Fomomento determines the purposes and means of Processing Organizer Personal Data contrary to this DPA and the Organizer's lawful instructions, Fomomento shall be considered a Controller in respect of that Processing in accordance with Article 28(10) GDPR.

  3. Obligations of Fomomento

    1. Fomomento shall ensure that persons authorised to Process Organizer Personal Data are bound by confidentiality obligations, have access only to the extent necessary for their functions and Process Organizer Personal Data only on the Organizer's documented instructions, unless Union or Member State law requires otherwise.

    2. Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, Fomomento shall implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR. The measures currently applicable to the Platform are described in Annex II.

    3. Fomomento shall maintain the records required from a Processor under Data Protection Law and shall make available to the Organizer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, subject to safeguards necessary to protect the rights of other customers, security-sensitive information and legally protected information.

    4. Fomomento shall cooperate with a competent supervisory authority in the performance of its tasks where required by Data Protection Law and shall inform the Organizer, to the extent legally permitted, of a binding request or proceeding specifically concerning Organizer Personal Data.

    5. Fomomento shall periodically review the measures in Annex II and may update them to reflect technical development, provided that the overall level of protection is not materially reduced.

  4. Data Subject rights and regulatory assistance

    1. If Fomomento receives a request from a Data Subject concerning Organizer Personal Data, Fomomento shall forward it to the Organizer without undue delay and shall not respond on the Organizer's behalf unless instructed or legally required to do so.

    2. Taking into account the nature of the Processing, Fomomento shall assist the Organizer through available Platform functionality and appropriate technical or organisational measures to respond to requests under Chapter III GDPR.

    3. Taking into account the nature of the Processing and the information available to Fomomento, Fomomento shall assist the Organizer with compliance under Articles 32 to 36 GDPR, including security assessments, breach notifications, data protection impact assessments and prior consultation where relevant to the Platform Processing.

    4. Where assistance requires exceptional work beyond the standard Platform functionality and the need for that work was not caused by Fomomento's breach of this DPA, the Parties may agree reasonable charges before the work begins. This does not limit assistance that Fomomento must provide without charge under mandatory law.

  5. Personal Data Breaches

    1. Fomomento shall notify the Organizer without undue delay after becoming aware of a Personal Data Breach affecting Organizer Personal Data and shall provide the information available to it in time to enable the Organizer to comply with its obligations under Articles 33 and 34 GDPR.

    2. To the extent known and available, the notification shall describe the nature of the Personal Data Breach, the categories and approximate number of affected Data Subjects and records, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information. Information may be provided in phases where it cannot reasonably be supplied at the same time.

    3. Fomomento shall take reasonable steps to contain, investigate and mitigate the Personal Data Breach and shall cooperate with the Organizer in relation to notifications to a supervisory authority or communications to Data Subjects.

    4. The Organizer remains responsible for deciding whether notification or communication is required under Articles 33 or 34 GDPR. A notification by Fomomento under this section is not an admission of fault or liability.

  6. Sub-processors

    1. The Organizer grants Fomomento general written authorisation to engage the Sub-processors listed in Annex III for the Processing described in this DPA.

    2. Fomomento shall enter into a written agreement with each Sub-processor that imposes the same data protection obligations as those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of the GDPR, in accordance with Article 28(4) GDPR. Fomomento remains fully liable to the Organizer for the performance of the Sub-processor's obligations.

    3. Fomomento shall give the Organizer reasonable advance notice, by email or another Durable Medium, of an intended addition or replacement of a Sub-processor. Unless a longer period is stated in the notice, the Organizer may object on reasonable and documented data protection grounds within 15 days after receipt.

    4. Fomomento shall consider a timely objection in good faith and shall use reasonable efforts to address it. If no reasonable alternative is available, either Fomomento may discontinue the affected functionality or the Organizer may stop using that functionality or terminate the affected service before the new Sub-processor begins Processing. An objection does not create a right to require Fomomento to provide a materially different service at its own cost.

  7. International transfers

    1. Fomomento may transfer Organizer Personal Data outside the European Economic Area or permit access to it from outside the European Economic Area only where the transfer complies with Chapter V GDPR. A provider's EEA storage region does not, by itself, exclude a restricted transfer where support, administration or onward Processing may occur elsewhere.

    2. Where a transfer is not covered by an applicable adequacy decision, Fomomento shall use an appropriate safeguard, including the relevant module of the European Commission's standard contractual clauses, and shall implement supplementary measures where required by the circumstances of the transfer.

    3. Fomomento shall take reasonable steps to verify the identity, location and role of each relevant Sub-processor and the transfer mechanism relied upon. The Organizer shall provide information reasonably required to identify the competent supervisory authority and complete transfer documentation.

    4. If Processing is to be subject to data protection law outside the European Economic Area, the Parties shall agree any additional contractual transfer mechanism or local-law terms required for that Processing before it begins.

  8. Return, deletion and retention

    1. At the Organizer's choice, Fomomento shall return or delete Organizer Personal Data after the end of the relevant Processing services and shall delete existing copies, unless Union or Member State law requires continued storage.

    2. Unless the Organizer gives a different lawful instruction, Fomomento shall complete deletion from active systems within 30 days after termination of the relevant Processing services. The production database and object-storage mirror are backed up separately, in each case daily with rolling retention of up to seven days. Deleted database records or files are not individually removed from an existing backup and may therefore remain until the relevant backup expires, for no longer than seven days after deletion from active systems. During that period the backup remains protected under this DPA, is unavailable for ordinary use and may be restored only for disaster recovery or legal compliance. If a backup is restored, the applicable deletion or restriction instructions shall be reapplied without undue delay.

    3. Before closing the Account, the Organizer should use the export functionality then available or request a return of Organizer Personal Data in a commonly used format. Fomomento is not required to retain Organizer Personal Data after the applicable deletion period solely because the Organizer did not export it.

    4. Fomomento may retain limited information to establish, exercise or defend legal claims or comply with law, provided that such information is segregated where practicable, access is restricted and no other Processing takes place.

  9. Audit and compliance information

    1. Fomomento shall make available all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA. Where appropriate, Fomomento may satisfy a request initially by providing current independent audit reports, certifications, security summaries, supplier documentation or written responses.

    2. Fomomento shall allow for and contribute to audits, including inspections, conducted by the Organizer or an independent auditor mandated by the Organizer and bound by confidentiality if the information provided under section 10.1 is insufficient to demonstrate compliance. Except following a Personal Data Breach, a substantiated compliance concern or a request from a competent authority, an audit may take place no more than once in any 12-month period and on reasonable advance notice.

    3. The scope, timing and manner of an audit shall, where practicable, be agreed in advance, shall be limited to Processing relevant to the Organizer and shall avoid unreasonable disruption, access to another customer's information, disclosure of security-sensitive information or infringement of third-party rights. These safeguards shall not be applied in a manner that prevents the Organizer or a competent supervisory authority from exercising a right or power under Data Protection Law.

    4. The Organizer bears its own audit costs and Fomomento may charge reasonable costs for substantial assistance, unless the audit identifies a material breach of this DPA by Fomomento or charging would restrict an audit or assistance that must be provided under mandatory Data Protection Law. Fomomento shall remedy a verified material deficiency without undue delay, taking into account its nature and risk.

  10. Obligations of the Organizer

    1. The Organizer shall comply with Data Protection Law and shall ensure that Organizer Personal Data, the purposes of Processing and all instructions to Fomomento are lawful, fair and transparent. The Organizer shall provide all required privacy information and respond to Data Subject requests.

    2. The Organizer is responsible for establishing an applicable lawful basis under Article 6 GDPR and, where special categories of Personal Data are involved, a valid condition under Article 9(2) GDPR. The Organizer shall not use a general acceptance of terms or acknowledgement of a privacy notice as explicit consent.

    3. Where the Organizer relies on consent, it shall actively select the relevant supported template, whose purpose is fixed and stated in the template, confirm that this purpose matches its own, and confirm its identity as Controller and use the separate control made available for that purpose. Fomomento shall supply and version the standard consent wording, which states the template's fixed purpose, insert the Organizer's identity, present and operate a separate unticked control for each protected template in accordance with the Organizer's documented instruction, record the wording and version, affirmative action, timestamp and withdrawal status, and make the relevant status and evidence available to the Organizer. The Organizer is not responsible for drafting Fomomento's standard consent sentence, but remains responsible for selecting a template whose purpose matches its own, establishing the applicable conditions under Articles 6 and 9 GDPR, providing accurate privacy information and applying withdrawals to data held outside the Platform. A standardised template does not determine or guarantee the Organizer's lawful basis. Until a suitable control is available and correctly configured, the Organizer shall not use the Platform to collect special-category data.

    4. Where a Data Subject withdraws consent through the Platform, Fomomento shall record the withdrawal and, in accordance with the Organizer's documented configuration and instructions, stop the relevant Processing and delete or restrict the corresponding answer in active Platform systems where no other lawful retention instruction applies. Fomomento may retain separately the minimum consent record required for accountability or legal claims, without retaining the content of a special-category answer and for no longer than necessary. The Organizer remains responsible for implementing the withdrawal in relation to copies exported from the Platform or disclosures made to other recipients.

    5. The Organizer shall not treat a Buyer's declaration concerning another competent adult as consent given by that adult. Health-related or other special-category data concerning a companion shall be collected directly from that person through the ticket-access flow, in which that person confirms control of their own email address, unless another Article 9(2) condition clearly applies.

    6. The Organizer is responsible for authorising its Team Members, configuring their permissions, securing devices used to access the Platform and promptly removing access that is no longer required. Fomomento remains responsible for operating the Platform's access controls as described in Annex II.

    7. The Organizer shall not submit full payment-card details, government identification documents or other data that the Platform is not designed to collect. The Organizer shall use reasonable data minimisation and retention settings and shall not instruct Fomomento to Process Personal Data for an unlawful or incompatible purpose.

  11. Duration, liability and general provisions

    1. This DPA begins when it is incorporated into or accepted with the Terms and continues for as long as Fomomento Processes Organizer Personal Data on behalf of the Organizer.

    2. Termination or expiry of the Terms terminates this DPA, subject to sections that must continue in order to protect Organizer Personal Data, complete deletion or comply with law.

    3. Liability arising under this DPA is governed by the limitations and exclusions in the Terms, without limiting liability or Data Subject rights that cannot lawfully be excluded or restricted under Articles 82 to 84 GDPR or other mandatory law.

    4. The confidentiality provisions in the Terms apply in addition to the specific confidentiality duties in this DPA. If the provisions conflict in relation to Organizer Personal Data, the provision providing the higher level of protection applies.

    5. The governing-law and jurisdiction provisions in the Terms apply to this DPA, without prejudice to mandatory rights, remedies and powers under Data Protection Law.

    6. Data-protection enquiries concerning this DPA may be sent to privacy@fomomento.events.

Annex I. Details of Processing

  1. Subject matter. Provision, operation, security and support of the Platform for the Organizer, including Event creation and administration, free and paid ticket and Order management, card and bank-transfer checkout records, attendee registration and ticket claiming, check-in, scheduling, collaboration, vendor and contract workflows, embeddable public Event content and transactional communications.

  2. Duration. For the term of the relevant Platform services and any limited period required to return, delete or lawfully retain Organizer Personal Data under this DPA.

  3. Nature of Processing. Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, making available, restriction, alignment, synchronisation, export and deletion, together with security monitoring and support operations necessary for the Platform.

  4. Purposes. Enabling the Organizer to plan and operate Events, sell or issue tickets, manage Orders, payment status and refunds, create or allocate pro forma, invoice and credit-note records where available, register and communicate with Attendees, coordinate Team Members, Vendors and collaborators, manage schedules and tasks, sign Event-related contracts, publish Event information selected by the Organizer, perform check-in and obtain technical support.

  5. Categories of Data Subjects. Buyers, Attendees and registrants; Vendors, venues, speakers, sponsors, collaborators and their representatives; persons whose identity or contribution the Organizer includes in Event materials; invited Team Members; and other persons whose Personal Data the Organizer lawfully submits to the Platform.

  6. Categories of Personal Data. Names, email addresses, optional telephone numbers and company details; ticket, Order, price, payment-method, payment-status, refund, pro forma, invoice and credit-note metadata; registration answers; attendance, ticket-claim and check-in status; an Attendee email address confirmed through the ticket-access flow and the time of that confirmation; one-time access-code challenge records, comprising a hashed code, its expiry, the number of attempts made and any name supplied with the request; identity attestation records, comprising the wording identifier and version presented and the times at which the statement was made, confirmed and cleared; hashed, Event-scoped ticket-access session records; Event roles, tasks, schedules, messages and communications; contract, signature and audit-trail data; images, logos, files and other Organizer-provided content; and IP address, device, session, timestamp, security and activity-log data generated in connection with the relevant Platform interaction. Fomomento does not store full payment-card details or hold ticket-sale funds. The Organizer’s bank-account details used to configure bank-transfer payments are covered by the Privacy Policy to the extent that they constitute Personal Data Processed by Fomomento for its own Account-administration purposes.

  7. Special categories. During the beta, dietary-requirements and accessibility-requirements questions are treated as special-category templates and may be answered only by the Data Subject, through a ticket-access session established for the Event by confirming control of their own email address. One such session resolves every ticket that person holds in that Event, across cycles and Orders. The Organizer may use those templates only after establishing an applicable condition under Article 9(2) GDPR and configuring the relevant controls in accordance with this DPA. An ordinary template, answer option or Event context must not be used to solicit special-category data, and Fomomento shall not use ordinary answers to infer such data.

  8. Frequency. Continuous or intermittent, as determined by the Organizer's use and configuration of the Platform and the lifecycle of the relevant Event.

  9. Retention. As instructed by the Organizer and for no longer than required to provide the Platform, subject to section 9 and the documented retention and backup cycle. Local offline check-in data is retained only for the operational period described in Annex II.

  10. Product analytics. Product analytics carried out by Fomomento for its own purposes in relation to use of the authenticated Organizer portal by Organizer Account holders and Team Members is undertaken by Fomomento as Controller and falls outside this DPA. Aggregate operational measurement on public Buyer surfaces also falls outside this DPA only where it is generated without Personal Data and cannot be linked to a Buyer, Attendee, Order, ticket or other Data Subject. Fomomento shall not use Organizer Personal Data for its own analytics or disclose such data to an analytics provider. Any analytics of Organizer Personal Data carried out on the Organizer's behalf requires the Organizer's documented instructions and a prior update of the relevant information in Annexes I and III.

Annex II. Technical and organisational measures

  1. Security governance and risk review. Fomomento maintains security responsibilities, reviews material risks and updates safeguards in light of changes to the Platform, processing scope and reasonably available technology.

  2. Access control. Access to production systems and Organizer Personal Data is limited to authorised persons with a business need. Access rights are role-based where supported, reviewed periodically and removed when no longer required. Privileged access is protected by strong authentication, including multi-factor authentication where technically supported.

  3. Authentication and sessions. Account access uses the authentication controls provided by the Platform. Collaborator workspaces require verification through the invited person's recorded email address; possession of an invitation link alone does not provide access. Sessions expire and require renewed verification after the configured period.

  4. Attendee credentials and ticket access. A ticket code is a bearer credential that only starts the ticket-access flow. Presenting it returns no Attendee Personal Data, no answer, no consent, no acceptance and no door credential. Reaching any of those requires a one-time code sent to an email address that the claimant enters and then proves control of. Issuance of one-time codes is limited to five requests per ten minutes for each combination of Event and originating network address, a further interval of sixty seconds is required between successive codes for the same email address in the same Event, and five incorrect entries invalidate the challenge. A successful verification creates a session scoped to a single Event; a session presented against a different Event is refused. Only a SHA-256 hash of the session bearer is stored, never the bearer itself, which is returned once and held in the browser's session storage rather than persistent storage so that it does not survive the browsing session. A session expires fourteen days after issue. Clearing or releasing a ticket detaches it from its Attendee record and thereby removes it from every session that previously resolved it, with no separate revocation step.

  5. Purchaser access to answers. The Order-management view available to a Buyer returns ordinary registration answers only. An answer to a special-category question, and an answer that records another person's consent choice, are withheld from that view in every state of the ticket, as is any answer whose question can no longer be resolved as unlocked. A Buyer cannot write an answer; every answer is recorded by the Attendee through an established ticket-access session.

  6. Confidentiality and personnel. Persons authorised to access Organizer Personal Data are subject to confidentiality duties and receive information or training appropriate to their responsibilities.

  7. Encryption and secrets management. Network communications use current transport encryption. Core data stores and backups are encrypted at rest where supported by the relevant infrastructure provider. Production secrets and service credentials are stored in a dedicated secrets-management service separately from application content, and access to them is restricted to authorised persons and service identities.

  8. Hosting and segregation. Core application and database services are configured in EEA regions. Organizer data is logically segregated by Account, Event and assigned role. A collaborator can access only the tasks and materials assigned to that collaborator; an Organizer's proposed value is not treated as supplied by the collaborator until the collaborator confirms or replaces it.

  9. Availability, resilience and restoration. The production database is backed up through Supabase each day with rolling retention of up to seven days. Object-storage buckets are mirrored each day to a Cloudflare R2 bucket configured in the European Union, also with rolling retention of up to seven days. Access to both backup sets is restricted, and restored data remains subject to the controls in this Annex. Before the paid beta opens, Fomomento shall complete and record a restoration test covering the database and object storage together. Subject to successful completion of that test, Fomomento's recovery time objective for a full restore is two hours. Restoration shall be retested on a risk-based basis and after material changes, and material deficiencies shall be addressed without undue delay.

  10. Application and change security. Security-relevant changes are subject to appropriate review and testing. Dependencies and systems are updated in accordance with risk, and identified vulnerabilities are assessed and remediated according to their severity.

  11. Logging and monitoring. Security and operational events are logged to the extent appropriate for detection, investigation and support. Access to logs is restricted, log content is minimised and retention is limited in accordance with documented operational periods.

  12. Incident management. Fomomento maintains a process for identifying, assessing, containing, documenting and remediating security incidents and for notifying the Organizer in accordance with section 6. Fomomento maintains an internal incident register recording the known facts, effects, decisions and remedial action in sufficient detail to support the Organizer's compliance with Articles 33 and 34 GDPR and its breach documentation obligations.

  13. Data minimisation and retention. Platform flows are designed to limit collection to the fields configured or required for the relevant function. Retention and deletion are implemented through the Platform, documented operational processes and supplier retention controls.

  14. Consent, choice and confirmation evidence. Where the Platform provides a consent, permission, choice or confirmation control, it records the relevant status and, where applicable, the wording or version presented, the affirmative action and the timestamp. Consent-based choices concerning photography or filming, a public attendee list, sponsor sharing or electronic marketing are separate, unticked and optional. A consent-based special-category question may be enabled only through a separate, recipient-specific control and answered directly by the Data Subject. The Organizer's event-specific privacy notice is made available before the relevant answer or choice is submitted. Withdrawal or opt-out status is recorded and applied to the relevant functionality; where applicable, the answer is deleted or restricted in active systems and the minimum consent evidence is retained separately without the content of the special-category answer. These controls do not determine the Organizer's lawful basis or guarantee the legal suitability of the Organizer's purpose.

  15. Offline check-in. The check-in function limits the locally stored roster to the ticket identifier, display name, masked email, a non-reversible per-Event grouping key, ticket type, door hint, entry code, activation-code hash and validity, check-in, refund and activation status needed for the assigned Event scope. Raw email addresses, telephone numbers, registration answers and payment data are not stored on the device. Personal Data in the manifest, device credential and offline queue is sealed as AES-GCM 256-bit encrypted browser-storage data using a non-extractable origin key. Successfully synchronised queue records are deleted after server confirmation. The roster is deleted on overwrite, authentication failure, manual wipe, re-pairing or expiry, which is set at the end of the relevant cycle plus approximately 24 hours and is capped at 90 days from device pairing. A revoked device is blocked on its next online contact and then wipes locally; no server-push remote wipe is available while the device remains offline.

  16. Supplier management. Fomomento evaluates relevant providers, enters into appropriate data-processing terms, restricts their Processing to the services required for the Platform and reviews available assurance and transfer documentation proportionately to risk.

  17. Effectiveness review. Fomomento maintains a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the Processing. Fomomento documents material changes, and measures may be replaced by equivalent or stronger measures without amending this DPA.

Annex III. Authorised Sub-processors

  1. The following providers are authorised to Process Organizer Personal Data solely for the stated services. An authorisation takes effect only after Fomomento has entered into the written terms required by section 7.2 and enabled the relevant service. Fomomento shall maintain current information concerning the provider's legal entity, Processing location and transfer mechanism in its supplier records and in any public Sub-processor list made available to Organizers.

Provider

Service

Processing location

Transfer position

Supabase Pte. Ltd.

Database, authentication and file storage

Primary data stored in Ireland; global support or administration may occur

SCCs and supplementary measures where required under the supplier terms

Railway Corporation

Server and application hosting

Production deployment in Amsterdam; provider documentation identifies primary processing operations in the United States

DPF certification or SCCs and supplementary measures under the supplier DPA, subject to Fomomento validly executing that DPA before Processing begins

Cloudflare, Inc.

CDN, WAF, Turnstile, Workers and R2 object-storage backup

Global network; R2 backup bucket configured in the European Union

Applicable EU-US Data Privacy Framework adequacy decision or SCCs and supplementary measures under the supplier DPA, subject to Fomomento validly executing that DPA before Processing begins

Plus Five Five, Inc. (Resend)

Transactional email delivery

EU sending infrastructure in Ireland; metadata or logs in the United States and authorised locations

Applicable adequacy mechanism or SCCs and supplementary measures

airSlate / SignNow

Electronic signatures and contract workflow

United States and authorised provider locations

Applicable adequacy mechanism or SCCs under the supplier DPA executed on 18 August 2026

Functional Software, Inc. (Sentry)

Errors-only crash diagnostics; tracing, replay and default PII collection disabled

Configured EU region in Germany; potential global or United States support access

Applicable EU-US Data Privacy Framework adequacy decision or SCCs and supplementary measures under the supplier DPA, subject to Fomomento validly accepting that DPA before Processing begins

Google Ireland Limited (Google Maps Platform)

Server-side venue-address formatting, search and time-zone lookup where submitted venue data contains Personal Data

EEA and other authorised Google locations

Applicable adequacy mechanism or SCCs and supplementary measures where required

Proton

Business email used for support, privacy and legal communications where those communications contain Organizer Personal Data

Switzerland and authorised provider locations

Adequacy decision for Switzerland and other safeguards where required

Crisp IM SAS (conditional)

Organizer support channel

European Union and authorised provider locations

Authorised only after the supplier DPA is executed and the integration is enabled

Stripe. Stripe is not treated in this Annex as a Sub-processor solely for Processing that Stripe performs under its direct relationship with the Organizer's connected Stripe account or as an independent Controller. If Fomomento appoints Stripe to Process Organizer Personal Data on Fomomento's behalf and under the Organizer's instructions, the applicable Stripe entity, service and transfer position must be added to this Annex before that Processing begins.