ECTreasure Events.
Legal

Data Processing Addendum

Effective date: September 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Use between the account holder (“Owner,” the “Controller”) and Eagle Crest Treasure LLC (“we,” the “Processor”), operator of ECTreasure Events (the “Service”). It applies where we process personal data about an Owner’s Guests (“Guest Data”) on the Owner’s behalf and where Applicable Data Protection Law requires such terms. If there is any conflict on the subject of data processing, this DPA controls over the Terms of Use.

1. Definitions

Applicable Data Protection Law” means privacy and data-protection laws that apply to the processing, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA). “Controller,” “Processor,” “personal data,” “processing,” “data subject,” and “sub-processor” have the meanings given in Applicable Data Protection Law. Under the CCPA/CPRA, we act as a “service provider.”

2. Roles and instructions

The Owner is the Controller of Guest Data and we are the Processor. We will process Guest Data only (a) on the Owner’s documented instructions — which include the Owner’s use of the Service and these Terms — and (b) as required by law, in which case we will inform the Owner unless the law prohibits it. The Owner is responsible for the accuracy and lawfulness of Guest Data and for having a valid legal basis and any required notices or consents before providing it to us.

3. Scope of processing (Annex)

  • Subject matter & nature: hosting, storing, and processing Guest Data to provide event-planning features (guest lists, RSVPs, invitations, galleries, public event pages, messaging, programs, and analytics).
  • Purpose: to provide the Service to the Owner and perform the actions the Owner requests.
  • Duration: for the term of the Owner’s account, and until deletion as described below.
  • Types of personal data: names, email addresses, phone numbers, RSVP responses, meal choices, group/seating details, messages and well-wishes, photographs and video, and related event information the Owner provides.
  • Categories of data subjects: the Owner’s invited guests, their plus-ones, and visitors to the Owner’s event pages.

4. Our obligations as Processor

  • Confidentiality: we ensure persons authorized to process Guest Data are bound by confidentiality.
  • Security: we implement appropriate technical and organizational measures suited to the risk (Article 32 GDPR), including encryption in transit, access controls, password hashing, and administrator-access logging.
  • Assistance: taking into account the nature of the processing, we assist the Owner with responding to data-subject requests and, so far as applicable, with security, breach notification, and data-protection impact assessments.
  • Breach notification: we notify the Owner without undue delay after becoming aware of a personal-data breach affecting Guest Data, with information reasonably available to us.
  • Deletion or return: on termination or on the Owner’s request, we delete or return Guest Data and delete existing copies, except where retention is required by law (residual backup copies are cleared within a limited period).
  • Records & audits: we make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to reasonable audits, which may be satisfied by our documentation and answers to reasonable questionnaires.

5. CCPA/CPRA

We process Guest Data solely to provide the Service and will not (a) “sell” or “share” it, (b) retain, use, or disclose it for any purpose other than performing the Service, or for a commercial purpose other than providing the Service, or (c) combine it with data from other sources except as permitted for a service provider. We certify that we understand and will comply with these restrictions.

6. Sub-processors

The Owner gives general authorization for us to engage sub-processors to help provide the Service. We currently use: a hosting provider (application and database hosting), an email-delivery provider (sending the Owner’s and account emails), and payment processors (Stripe and Paystack) for paid plans. We impose data-protection obligations on each sub-processor no less protective than this DPA and remain responsible for their performance. We will give the Owner notice of any intended change to sub-processors and a reasonable opportunity to object on legitimate data-protection grounds.

7. International transfers

Where Guest Data is transferred from the EEA, the UK, or Switzerland to a country without an adequacy decision, the transfer is made under appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where they apply.

8. Data-subject and Guest requests

If we receive a request from a Guest to exercise their rights, we will, unless legally required to act, refer the Guest to the relevant Owner and assist the Owner in responding. The Owner is responsible for handling such requests as the Controller.

9. Liability, term, and governing law

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Use. This DPA takes effect when the Owner accepts the Terms and continues while we process Guest Data. It is governed by the same law and dispute-resolution terms as the Terms of Use.

10. Contact

Questions about this DPA, or requests related to data processing, can be sent to sales@ectreasure.com.

See also: Terms of Use · Privacy Policy · Agreement of Use · Cookie Policy · Disclaimer

← Back