ttikento
Produkt
PreiseHilfeBlog
AnmeldenKostenlos starten →
← Zurück zur Startseite

Data Processing Agreement (DPA)

Processing of attendee data on the organizer's behalf.

Version: 5 August 2026

This DPA forms an integral part of the Organizer Offer and governs the processing by TIKENTO LLC (the Tikento service, the "Processor") of personal data on behalf of the Organizer (the "Controller") regarding Buyers'/participants' data.

1. Roles

1.1. For Buyers'/participants' data, the Controller (Operator) is the Organizer, and the Processor is the Company (Tikento). The Controller determines the purposes and scope; the Processor acts on the Controller's documented instructions.

1.2. The Controller warrants a lawful basis for processing and for obtaining data subjects' consents.

2. Subject and purposes

2.1. The Processor processes personal data solely to provide the Service to the Controller: participant registration, ticket issuance and delivery, payment collection, communications on the Controller's instruction, event analytics, support.

2.2. The Processor does not process the data for its own purposes beyond the instruction (the Company's own-purpose processing is governed by its Privacy Policy).

3. Scope of processing and data categories

3.1. Actions: collection, recording, systematization, accumulation, storage, updating, use, transfer (within the instruction), anonymization, blocking, deletion, destruction — with and without automation.

3.2. Categories: name, contacts, order/ticket data, registration form answers, payment data as processed by the Service. Special categories only upon the Controller's express instruction and with a basis.

4. Processor obligations

4.1. Process personal data only on the Controller's instruction and within the defined scope.

4.2. Ensure confidentiality and require it from staff and engaged parties.

4.3. Apply security measures under Arts. 18.1, 19 of 152-FZ and RF Government Decree No. 1119 (and, where applicable, appropriate technical and organizational measures under Art. 32 GDPR).

4.4. Observe localization of Russian citizens' personal data in the Russian Federation (Art. 18(5) 152-FZ).

4.5. Assist the Controller with data subject requests and with regulators; notify the Controller of incidents within to be provided to enable timely regulator notification.

4.6. Upon completion of services or the Controller's request, cease processing and delete/anonymize (or return) the data unless the law requires retention.

5. Sub-processors

5.1. The Controller gives the Processor general authorization to engage sub-processors (hosting, email/Telegram notifications, payment providers, analytics), imposing equivalent obligations on them. The current list is available on request; the Processor notifies the Controller of changes.

6. Liability

6.1. The Processor is liable to the Controller for breach of this DPA. Toward the data subject the Controller is liable; the Processor is liable to the Controller by way of recourse unless the law provides otherwise (Art. 6(5) 152-FZ).

7. Term

7.1. This DPA is effective for the term of the Organizer Offer and until processing/deletion is completed.

ttikento

Veranstaltungsmanagement-Plattform in einem Tool.

✈◎▶in
Produkt
  • Registrierung
  • Tickets
  • Zahlungen
  • Analysen
  • Preise
Solutions
  • All solutions
  • Conferences
  • Webinars
  • Festivals
  • Corporate events
Ressourcen
  • Wissensdatenbank
  • Dokumentation
  • API
  • Vorlagen
  • Status
Unternehmen
  • Über uns
  • Team
  • Kontakt
  • Pressematerial
Rechtliches
  • Nutzungsbedingungen
  • Datenschutzerklärung
  • Cookies
  • Organizer offer
  • Ticket offer
  • Ticket refunds
  • DPA
  • Event rules
  • Anti-spam policy
  • Data consents
  • Impressum
© 2026 tikentosupport@tikento.com