Data Processing Agreement

Effective Date: 13 AUGUST 2026

This Data Processing Agreement (“DPA”) supplements, and forms an integral part of, the Terms of Service between the applicable EventPlanner.ai operating entity (EventPlanner.ai Inc for US customers, Better Faster Oy for EU/rest-of-world customers — together “Service Provider”, “we”, “us”) and the customer (“Customer”, “you”) for use of the Service. It restates, in one standalone document, the data-processing terms already built into Section 3 (“Data Security and Data Processing”) of our Terms of Service, so business customers can review, share, and reference them for their own compliance and procurement purposes. In case of any conflict between this DPA and the Terms of Service, the Terms of Service govern.

For a plain-language overview of our data handling — what personal data we process, where it lives, and how AI is used — see our Compliance Pack, available on request at hello@eventplanner.ai.

1. Definitions

Terms used in this DPA follow the definitions in the Terms of Service. In addition: “Customer Personal Data” means personal data processed by the Service Provider or a Sub-Processor on the Customer’s behalf under the Agreement. “Data Protection Laws” means the GDPR and, to the extent applicable, other data protection laws governing the processing described in this DPA. “Sub-Processor” means any processor engaged by the Service Provider to process Customer Personal Data on the Service Provider’s behalf. “Security Incident” means any unauthorized or unlawful breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.

2. Roles

With respect to the processing of Customer Personal Data, the Customer acts as data controller (or, where the Customer processes personal data on behalf of a further controller, as processor) and the Service Provider acts as data processor, processing Customer Personal Data only on the Customer’s documented instructions as set out in this DPA and the Terms of Service.

3. Customer Responsibilities

The Customer is responsible for complying with Data Protection Laws applicable to its own use of the Service, including having a lawful basis for the personal data it enters into the Service, informing data subjects of the processing as required, obtaining any necessary consents, and minimizing the personal data it inputs. By using the Service, the Customer instructs the Service Provider to process Customer Personal Data to provide the Service and perform its obligations under the Agreement — including billing, account management, technical support, and product development — and pursuant to any further written instructions the Customer gives and the Service Provider accepts.

4. Service Provider Obligations

The Service Provider will only process Customer Personal Data on the Customer’s documented instructions, except where otherwise required by applicable law — in which case the Service Provider will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Service Provider takes reasonable steps to ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and have received appropriate training, and that access is limited to those who need it to provide the Service.

5. Personal Data Being Processed

The Service Provider processes Customer Personal Data as necessary to provide the Service pursuant to the Agreement and as further instructed by the Customer through use of the Service. The subject matter of the processing under this DPA is the Customer Personal Data described below; the duration of the processing is until termination of the Agreement, subject to Section 12 (Deletion or Return of Customer Personal Data).

Categories of data subjects. The persons whose personal data the Customer enters into the Service, such as the Customer’s personnel, clients, and event attendees.

  • Name, surname, and contact information of the Customer’s personnel, clients, and event attendees;

  • Event-related data provided by the Customer, including event details, attendee names, and other information input by the Customer for content generation purposes;

  • Technical data related to the Service, including IP address, location, metadata, and system logs; and

  • Other Input data provided to the Service by the Customer.

6. Confidentiality

The Service Provider keeps the Customer’s personal data and Customer Content confidential, protected by appropriate technical and organizational security measures and confidentiality agreements. Access to the data is limited to the Service Provider’s own personnel and those partners who need access for the maintenance and development of the Service.

7. Security

The Service Provider maintains appropriate technical and organizational measures for the security, confidentiality, and integrity of Customer Personal Data, including:

  • Encryption: TLS for data in transit; encryption at rest for databases and file storage;

  • Authentication: hashed passwords, supported Google sign-in and passwordless email links, short-lived session tokens with rotating refresh tokens;

  • Access control: tiered workspace roles (Owner, Admin, Editor) in the product; internal administrative access restricted to named staff;

  • Isolation: EU and US customer data live in separate regional deployments with separate databases; secrets are held in a managed secrets vault, never in code;

  • Backups & recovery: automated daily database backups with a documented disaster-recovery runbook; and

  • Payment security: card data is handled entirely by Stripe (PCI-DSS Level 1) and never touches the Service Provider’s systems.

8. Sub-Processing

The Customer agrees that the Service Provider may engage Sub-Processors to process Customer Personal Data in order to provide the Service, including the third-party AI providers used to generate Output as described in the Terms of Service. The Service Provider imposes data protection terms on its Sub-Processors that provide the same level of protection as this DPA, to the extent applicable to the nature of their services. Sub-Processors that process Customer Personal Data outside the EU/EEA are subject to the EU–US Data Privacy Framework (where certified) or Standard Contractual Clauses, as described in Section 13. The Service Provider will notify the Customer of any new Sub-Processor in advance; the Customer may object within fourteen (14) days of that notice by contacting hello@eventplanner.ai. If the Service Provider is unable to avoid the objected-to processing within a reasonable time, the Customer may cancel or terminate the affected portion of the Service.

Sub-Processor list — providers that receive event or account data

  • OpenAI — AI text generation (event details and briefing text sent for generation). Location: US. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

  • Anthropic — AI text generation (same as above). Location: US. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

  • Google (Gemini) — AI text generation (same as above). Location: US. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

  • xAI — AI text generation (same as above). Location: US. Safeguard: Standard Contractual Clauses.

  • Gamma — Turns finished plans into slide presentations. Location: US. Safeguard: Standard Contractual Clauses.

  • Qdrant — Search over our curated idea catalog — anonymous numerical search vectors only, not raw customer text. Location: Per deployment. Safeguard: Standard Contractual Clauses where applicable.

  • Amazon Web Services — Hosting: databases, file storage, email delivery, stored in the customer’s region. Location: EU region for EU customers; US region for US customers. Safeguard: AWS GDPR data processing addendum.

  • Stripe — Payments, subscriptions, tax — card data never touches our systems. Location: US/EU. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

  • Intercom — In-app support chat and help desk. Location: US. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

  • PostHog — Product analytics and session replay, only after cookie consent. Location: US company, region configurable. Safeguard: Data Privacy Framework + Standard Contractual Clauses.

Auxiliary services that are not data processors for us: Google Sign-In (optional login, Google acts as an independent controller), Google Maps (venue/location search typed by the user), Cloudflare (network security and content delivery), ip-api.com (fallback country lookup for regional routing), and the Meta Pixel (marketing measurement, loads only after cookie consent). Reviewed quarterly; adding a provider requires a data processing agreement, a security review, and advance notice to customers under Section 8 above.

9. Assistance and Data Subject Rights

Taking into account the nature of the processing, the Service Provider will reasonably assist the Customer in responding to requests from data subjects exercising their rights under Data Protection Laws, to the extent the Customer cannot address the request through the Service itself. The Service Provider will promptly notify the Customer of any request it receives directly from a data subject regarding Customer Personal Data, and will not respond to it except on the Customer’s instructions or as required by law. The Service Provider will also reasonably assist the Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required under Article 35 or 36 of the GDPR and to the extent the Customer does not otherwise have access to the relevant information.

10. Security Incident Notification

The Service Provider will notify the Customer without undue delay after becoming aware of and confirming a Security Incident affecting Customer Personal Data, and will provide the information reasonably available to it, and reasonably requested by the Customer, to help the Customer meet its own notification obligations to affected data subjects and authorities under Data Protection Laws.

11. Demonstration of Compliance

On reasonable request, and not more than once per year, the Service Provider will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA, including by completing a reasonable due-diligence questionnaire. The Customer acknowledges that the Service is hosted on infrastructure Sub-Processors that maintain independently validated security programs, and that any external audit must be conducted by a non-competitor auditor, on reasonable notice, at the Customer’s cost.

12. Deletion or Return of Customer Personal Data

Following termination, Customer Content is archived and is no longer accessible through the Service. The Service Provider retains archived Customer Content for a maximum of twenty-four (24) months following termination — during which period it can be restored on the Customer’s request — after which the Service Provider will delete or irreversibly anonymize it, unless a longer retention is required by applicable law. The Customer may request earlier deletion or return of its Customer Personal Data at any time; the Service Provider will complete such deletion without undue delay and at the latest within thirty (30) days of a verified request.

13. International Data Transfers

Where the Service Provider or its Sub-Processors transfer Customer Personal Data outside the EU/EEA, an adequate level of protection is ensured through the EU–US Data Privacy Framework (where the recipient is certified) or the Standard Contractual Clauses adopted by the European Commission, together with any supplementary measures required by Data Protection Laws. Where the destination country is recognized as providing an adequate level of protection under Article 45(3) of the GDPR, no Standard Contractual Clauses are required for as long as that adequacy decision remains in force.

This DPA is governed by, and forms part of, the Terms of Service applicable to the Customer’s region (EU or US) — see the EU Terms of Service or the US Terms of Service for governing law and dispute resolution. Questions about this DPA can be sent to hello@eventplanner.ai.