1. Parties and Scope
This Data Processing Addendum ("Addendum") forms part of the Terms of Service between:
- Arctic Mopping Ltd (Business ID 3218773-8), operating under its auxiliary trade name Event Production Toolkit EPTK, PL 11, 00811 Helsinki, Finland ("we", "us", "Processor")
- the organisation that owns a workspace in the eptk.cloud service ("Customer", "Controller")
It governs our processing of personal data on the Customer's behalf, and gives effect to Article 28 of Regulation (EU) 2016/679 ("GDPR").
Where we determine the purposes and means of processing ourselves — account data, usage data, billing data and website data — we act as controller, that processing falls outside this Addendum, and our Privacy Policy governs it. Section 2 of the Privacy Policy states which role applies to which data.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: the personal data the Customer and its members store in a workspace while using the Service.
- Duration: for as long as the Customer has a workspace, and thereafter only as set out in section 11.
- Nature and purpose: providing the event production management service the Customer subscribed to — storing, organising, retrieving, displaying and transmitting workspace content, and performing the automated processing the Customer requests through the Service's features, including AI-assisted features.
3. Personal Data and Data Subjects
Categories of personal data, as determined by what the Customer chooses to store:
- identification and contact details (names, email addresses, telephone numbers, postal addresses)
- employment and engagement details (roles, organisations, working times, assignments)
- logistical details (travel and accommodation arrangements, vehicle and driver assignments, access and accreditation)
- location data (coordinates of vehicles or drivers, while a transport task is active)
- content of documents and files the Customer uploads, and any personal data they contain
- correspondence and notes recorded in the Service
Categories of data subjects:
- the Customer's personnel and workspace members
- performing artists and their representatives
- contractors, suppliers and their personnel
- volunteers, crew and accreditation applicants
- other individuals whose details the Customer records in the course of producing an event
We do not require or expect special categories of personal data (Article 9 GDPR) to be stored in the Service. Where the Customer chooses to record such data, it does so as controller and remains responsible for the lawfulness of doing so.
4. Instructions
We process personal data only on the Customer's documented instructions, including as regards transfers to a third country.
The following constitute the Customer's documented instructions:
- this Addendum and the Terms of Service
- the Customer's use of the Service's features, including its configuration of member roles and module access
- any further written instruction the Customer gives us
We inform the Customer if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law. We may suspend performance of that instruction until it is withdrawn, amended or confirmed.
5. Confidentiality
Persons authorised to process personal data under this Addendum are bound by an obligation of confidentiality, whether by contract or by statute, and that obligation survives the end of their engagement.
Access to production systems is limited to those who require it to operate the Service. Privileged administrative actions are recorded in an audit log the acting person cannot alter.
6. Security of Processing
We implement appropriate technical and organisational measures under Article 32 GDPR. The measures in force are described in our security documentation and include:
- Tenant isolation enforced by the database's own rules rather than by application code alone, so that a member of one workspace cannot read or write another's data. This boundary is covered by an automated test suite which runs on every change.
- Role and module based access control, so that a workspace member reaches only the modules the Customer has granted them, at the level granted.
- Encryption of data in transit (TLS) and at rest, using the cloud provider's managed encryption.
- Authentication with password or federated identity, with credentials handled by the identity provider and never stored by us in recoverable form.
- Audit logging of privileged and administrative actions, retained and protected against alteration by the acting party.
- Backups as described in section 12.
- Secure development practices: mandatory review gates, automated dependency and static analysis scanning, and an adversarial review procedure applied to changes affecting authorisation, tenant isolation, billing or personal data.
- Vulnerability disclosure through a published security contact.
These measures may change as the Service develops. We do not reduce the overall level of security during the term of this Addendum.
7. Sub-processors
The Customer gives a general written authorisation for our use of sub-processors, subject to this section.
The sub-processors we engage are named in our published Sub-processors list, together with what each one does and where it processes personal data. That list is the operative one, and it is versioned: this Addendum does not restate it, because a second copy of a list this section turns into a commitment is a copy that can quietly disagree with the first.
Where a sub-processor is engaged only because the Customer connects its own account with that provider, the content stored there is held under the Customer's own agreement with that provider, not under this Addendum.
We impose on each sub-processor data protection obligations no less protective than those in this Addendum, and remain fully liable to the Customer for their performance.
Changes. We notify the Customer, by email to the workspace owner, at least 30 days before a new sub-processor begins processing personal data, and we update the published list at the same time. The Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, either party may terminate the affected part of the Service.
8. Assistance with Data Subject Rights
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
The Service provides the Customer with direct access to workspace content, which allows most requests to be answered without our involvement. Where a request reaches us instead of the Customer, we do not respond to it on our own initiative: we pass it to the Customer and assist as required.
9. Personal Data Breaches
We notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this Addendum, and provide the information reasonably available to us to allow the Customer to meet its own obligations under Articles 33 and 34 GDPR.
10. Data Protection Impact Assessments
We assist the Customer, taking into account the nature of processing and the information available to us, with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.
11. Deletion and Return
At the Customer's choice, we delete or return the personal data processed under this Addendum after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage.
- Return is by the Customer's own export of workspace content through the Service's features, with our assistance on request. The Service does not today provide a single whole-workspace export, and this Addendum does not claim one.
- Deletion of a workspace removes its content within 30 days.
- Backups written before a deletion or erasure retain the data until they age out, which is at most 90 days. This is the ordinary position for backups. It has one consequence we state rather than leave implied: a restore from backup re-creates data erased after that backup was taken, and our recovery procedure requires erasure requests completed since the backup to be re-applied.
12. Availability and Backups
The following are measured properties of our backup arrangements, not aspirations:
- point-in-time recovery of the database covering the last 7 days, at minute granularity
- daily backups retained 30 days, and weekly backups retained 90 days
- file storage versioning, so that an overwritten file can be recovered
- a daily encrypted export of authentication data, retained 90 days
- a restore exercise performed on live data in our staging environment, with the restored contents checked by automated assertions
13. International Transfers
Personal data processed under this Addendum is stored and processed within the European Union, with one exception we state explicitly:
- Authentication data — email address, password hash and sign-in identifiers — is processed in the United States, because the authentication service we use offers no European location. The transfer is made under the European Commission's adequacy decision for the EU–US Data Privacy Framework and under Standard Contractual Clauses, as set out in the provider's data processing terms.
Other sub-processors may process data outside the European Union under equivalent safeguards. Where a sub-processor is engaged because the Customer connected its own account, the location of that processing follows the Customer's own arrangement with that provider.
14. Audits and Information
We make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
In the first instance we satisfy this by providing our security documentation, the results of our own assessments, and answers to the Customer's written questions. Where that is insufficient for the Customer to demonstrate compliance, an audit may be conducted on reasonable notice, during business hours, no more than once per year except following a personal data breach, and subject to confidentiality. The Customer bears its own costs.
15. Liability and Term
This Addendum takes effect when the Customer accepts it and continues for as long as we process personal data on the Customer's behalf. Sections 11, 13 and 15 survive its termination.
Liability under this Addendum is subject to the limitations set out in the Terms of Service, save where those limitations are not permitted by applicable law.
16. Contact
Questions about this Addendum, and any instruction under section 4, should be sent to support@eptk.cloud.