← All policies

Data Processing Agreement

Last updated: Draft — [date]

Draft for counsel review. Applies where an organizer (controller) uses Konvener (processor) to process participant personal data. — This document is not a substitute for legal advice.

This DPA forms part of the Terms between the organizer ("Controller") and Konvener ("Processor") and governs processing of participant personal data.

1. Scope & roles

The Controller determines the purposes of processing participant data; the Processor processes it only on the Controller's documented instructions (namely, to provide the Konvener service).

2. Subject matter

  • Nature & purpose: hosting a live workshop experience — agenda, questions, comments, feedback, expectations, evaluations, tasks.
  • Data subjects: workshop participants.
  • Data types: first name, institution, and voluntarily submitted contributions. No special-category data is requested.
  • Duration: for the term of the Controller's use, subject to the retention and deletion terms.

3. Processor obligations

  • Process only on documented instructions.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (encryption in transit, access controls, logging, least privilege).
  • Assist the Controller with data-subject requests and with security/breach obligations.
  • Delete or return data at the end of the engagement per the deletion terms.

4. Sub-processors

The Controller authorises the Processor to use the sub-processors listed in the Privacy Policy. The Processor remains responsible for their compliance and will give notice of material changes.

5. Security

Measures include TLS in transit, hashed credentials, secrets held in a secure store, strict access control, a strict Content-Security-Policy, rate limiting, and audit logging of administrative actions.

6. Breach notification

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data, with the information needed to meet the Controller's obligations.

7. Deletion

On request or on termination, the Processor deactivates immediately, provides a report within 24 hours, and permanently erases within the 60-day retention window.