Data processing agreement
The DPA is available on request, before any commercial conversation and without a sales step in front of it. It is not published here because it is a signed instrument rather than a page, and because the version you sign names your own hosting region.
What the agreement covers
- Roles: you are the controller of the data in your event organization, we are the processor.
- Scope and duration of processing, and the categories of data and data subjects involved.
- The named hosting region for your organization, fixed at setup.
- The current subprocessor list, and notice before any addition to it.
- Security measures, and the incident notification window — 72 hours from confirmation.
- Assistance with data subject requests, and audit rights.
- Deletion and return of data at the end of the agreement.
- International transfer mechanism where one applies.
While you are waiting for it
The security page answers most of what a reviewer asks before the DPA arrives: hosting and residency, access control, backups and retention, incident response, subprocessors, and where we are on SOC 2. It is written for you rather than for a buyer, and it has no call to action on it.
Ask for the DPA: hello@roadmap.events