Data Processing Agreement (DPA)

Version 1.0 — Effective date: 18 August 2026

This Data Processing Agreement (“DPA” or “Agreement”) forms an integral part of the Cloudsnap Terms of Use and governs the processing of personal data that we carry out on your behalf where you act as Controller and we act as Processor.

This Agreement must be read together with the Terms of Use, the Privacy Policy and, where applicable, the Cookies Policy. Terms written with an initial capital letter and not defined in this Agreement have the meanings assigned to them in the Terms of Use or Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”).

1. Parties, effectiveness and scope

1.1 The parties

This Agreement is entered into between:

  • a) the Organiser who creates or manages an Event through the Platform and whose details are derived from the Account or, where applicable, from a separate agreement (“Organiser”, “you” or “Controller”); and
  • b) SYAREX TECHNOLOGIES E.E., whose registered office is in Thessaloniki, at 83 Vasilissis Olgas Avenue, 546 42, and which is registered with the General Commercial Registry (GEMI) under number 184871106000 and with Tax Identification Number 802898595, and which operates Cloudsnap (“Cloudsnap”, “we”, “us” or “Processor”).

The Organiser and Cloudsnap are each referred to as a “Party” and together as the “Parties”.

1.2 Effective date and binding effect

This Agreement is entered into electronically and binds the Parties upon acceptance of the Terms of Use or upon its separate signature or acceptance, depending on the manner in which the relevant contract is concluded. It applies from the time you create or manage an Event in relation to which we process Event Personal Data on your behalf and for as long as the relevant processing continues.

The DPA applies to all Plans, including the Free Plan, to the extent that a Controller–Processor relationship arises under applicable law.

1.3 Limitation of scope

This Agreement applies only to processing activities for which the Organiser determines the purposes and essential means of processing and Cloudsnap processes personal data on the Organiser's behalf. It does not apply to activities for which Cloudsnap acts as an independent Controller, including in particular Account creation and management, Platform login and security, billing and payments, the management of our own operational communications, optional usage analytics, fraud and abuse prevention, the review of reports, compliance with legal obligations, and the establishment, exercise or defence of legal claims. The relevant processing is described in the Privacy Policy.

Where the Platform is used solely in the course of a personal or household activity and the relevant processing is outside the scope of data protection law, the roles of Controller and Processor may not arise under the GDPR. Use of the Platform remains governed by the Terms of Use and the Privacy Policy.

1.4 Order of precedence

In the event of a conflict between this Agreement and the Terms of Use concerning the processing of personal data on behalf of the Organiser, this Agreement prevails to the extent of the conflict. Any Standard Contractual Clauses applicable to an international transfer of personal data prevail to the extent necessary for their validity and effectiveness.

2. Definitions

“Data Protection Laws”: the GDPR, Greek Law 4624/2019, Greek Law 3471/2006 to the extent applicable, and any other binding provision of European Union or Member State law governing the specific processing of personal data.

“Event Personal Data”: any personal data included in invitations, participation details, settings, Content or related information of an Event that we process on behalf of the Organiser. Depending on the specific purpose of processing, the same type of data may also be processed separately by Cloudsnap as an independent Controller, in accordance with the Privacy Policy.

“Data Subject”: any natural person to whom Event Personal Data relate, such as the Organiser, Guests, invitation recipients, persons depicted or heard in Content, and other persons whose data are included in an Event.

“Documented Instructions”: the Organiser's instructions arising from this Agreement, the Terms of Use, the Event settings and choices, use of the available Platform features, and subsequent written or electronic requests accepted by Cloudsnap.

“Sub-processor”: any third-party Processor that we engage to carry out specific processing of Event Personal Data on behalf of the Organiser.

“Personal Data Breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Event Personal Data transmitted, stored or otherwise processed.

“Standard Contractual Clauses” or “SCCs”: the European Commission's standard contractual clauses for the transfer of personal data to third countries, as amended from time to time, including the clauses in Commission Implementing Decision (EU) 2021/914.

3. Roles and allocation of responsibilities

3.1 The Organiser as Controller

The Organiser determines the purpose of the Event, the persons who are invited or obtain access, the participation, privacy and publicity settings, the period during which uploading is permitted, and the manner in which Content is collected, displayed and managed in the Event Album. For the relevant processing activities, the Organiser acts, where the Data Protection Laws apply, as Controller.

3.2 Cloudsnap as Processor

We provide the technical infrastructure and features necessary to collect, receive, store, host, organise, technically adapt, display, share, manage, export and delete Event Personal Data in accordance with your Documented Instructions. We do not determine the purpose of the Event, select the invitees, or decide which Content is uploaded or which privacy setting is selected by the Organiser.

3.3 Cloudsnap's independent processing

Processing that we carry out as an independent Controller does not become processing on behalf of the Organiser merely because it concerns the same User, Event or technical element. Our role is assessed separately for each specific purpose and means of processing. In those cases, the Privacy Policy, rather than this DPA, applies.

3.4 No joint-controller relationship

Unless expressly agreed otherwise in a separate written agreement, this Agreement does not create a joint-controller relationship between the Organiser and Cloudsnap.

4. Subject matter and details of processing

The subject matter, duration, nature and purpose of processing, the categories of Data Subjects and the categories of Event Personal Data are described in detail in Section 21 of this Agreement.

Processing is carried out continuously during active use of the Event and for the retention periods resulting from the selected Plan, the Organiser's choices, the Terms of Use, the Privacy Policy and applicable law.

5. Obligations of the Organiser

As Controller, you are responsible for the lawfulness of the processing entrusted to Cloudsnap. In particular, you must:

  • a) ensure that you have a valid legal basis for the collection, use, disclosure and other processing of Event Personal Data and that, where required, the additional conditions applicable to special categories of data, minors' data or other particularly sensitive information are met;
  • b) provide Data Subjects with the information required under the Data Protection Laws and ensure that invitations, access settings and disclosure of Content are lawful;
  • c) ensure that you have the right to enter email addresses, invite persons and upload, or permit the uploading of, Content in which third parties are depicted or can be heard;
  • d) apply the data-minimisation principle and not entrust us with processing data that are unnecessary for the purpose of the Event;
  • e) select appropriate privacy, access and publicity settings, taking into account the nature of the Event, the Content, the persons depicted and potential risks, particularly where the Event includes minors or highly personal Content;
  • f) keep the data and instructions you provide to us accurate and up to date and rectify or delete data where required;
  • g) use the Services in accordance with the Terms of Use, protect access to your Account and notify us without undue delay if you become aware of unauthorised access, unlawful use or an incident that may affect Event Personal Data;
  • h) handle and decide on Data Subject requests, complaints and notification obligations for which you are responsible as Controller; and
  • i) ensure that your Documented Instructions are lawful, clear and consistent with this Agreement, the Terms of Use and the Data Protection Laws.

6. Documented Instructions and purpose limitation

6.1 Processing only on instructions

We process Event Personal Data only on your Documented Instructions, including instructions concerning transfers of data to a third country or international organisation, unless processing is required by a binding provision of European Union or Member State law applicable to us.

Where we are required by law to process Event Personal Data beyond your instructions, we will inform you before processing unless such information is prohibited for important reasons of public interest.

6.2 Manner of giving instructions

The settings you select on the Platform, such as participation, access, publicity, upload, approval, removal or download settings, constitute Documented Instructions. Selecting the option to delete an Event through the Platform constitutes a Documented Instruction for the Event to cease being available immediately and for access to it and its Content to be restricted. This action constitutes a soft delete and does not, in itself, constitute an instruction to permanently delete the related files and records from our systems. Additional instructions, including a separate instruction for the permanent deletion of Event Personal Data, may be provided in writing or electronically through the available support channels. An oral instruction must be confirmed in writing or electronically without undue delay.

6.3 Instructions that may infringe the law

If, in our reasonable opinion, a Documented Instruction infringes the GDPR or another applicable data-protection provision, we will inform you without undue delay. We may suspend performance of the specific instruction until it is confirmed, amended or withdrawn, without prejudice to any obligation on us to take immediate action for security reasons or to comply with the law.

6.4 Prohibited independent use

We do not sell or rent Event Personal Data or use them for advertising targeting, commercial profiling, independent commercial exploitation, facial recognition, creation of biometric templates or training of artificial intelligence models. We do not use Content for purposes unrelated to the provision, security and lawful operation of the Services.

6.5 Access to Content

We do not pre-screen or systematically review Event Content. Authorised personnel may access Content only to the extent necessary to provide support that you have requested, investigate a technical issue or security incident, implement a Documented Instruction, review a report, comply with a legal obligation or protect legal rights. Where we act for our own lawful purpose, the relevant processing is governed by the Privacy Policy.

7. Confidentiality and authorised personnel

We ensure that persons authorised to process Event Personal Data:

  • a) have access only to the extent necessary to perform their duties and in accordance with the need-to-know principle;
  • b) are subject to an appropriate contractual, professional or statutory duty of confidentiality;
  • c) receive appropriate instructions and information concerning personal data protection and information security; and
  • d) remain subject to the duty of confidentiality after their employment or contractual relationship ends, where required.

8. Security of processing

8.1 Appropriate technical and organisational measures

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks of varying likelihood and severity for the rights and freedoms of natural persons, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

The principal measures are described in Section 22. Those measures constitute the minimum contractual framework and may be supplemented by additional internal policies, procedures and technical controls.

8.2 Assessment and updates

We periodically review the appropriateness and effectiveness of the measures and adapt them where required by technological developments, changes to the Platform, new threats or changes in risk. We may modify individual measures provided that this does not materially reduce the overall level of protection of Event Personal Data.

8.3 The Organiser's security obligations

Security is a shared responsibility. You must protect your email address and the means of accessing your Account, not disclose OTP codes or access links to unauthorised persons, select appropriate privacy settings and keep your own copies of Content where necessary for your operational or legal obligations.

9. Sub-processors

9.1 General prior authorisation

You grant general prior written authorisation for the use of the Sub-processors included in Section 23 or in the then-current list that we make available.

9.2 Addition or replacement of a Sub-processor

We will inform you of our intention to add or replace a Sub-processor at least fifteen (15) calendar days before the relevant processing begins, by email, Platform notice or another appropriate electronic method. To the extent available and relevant, the notice will include the Sub-processor's identity, country of establishment or processing, service provided and applicable international-transfer mechanism.

Within the above period, you may submit a specific, reasoned objection on data-protection grounds. We will consider the objection in good faith and use reasonable efforts to find an appropriate solution. If the objection cannot reasonably be addressed, we may refrain from activating the relevant Sub-processor for the affected Services, or allow you to stop using the affected feature or terminate the affected part of the Services before the new processing begins. The financial consequences are governed by the Terms of Use, any separate agreement and mandatory law.

In an urgent case requiring an immediate change for reasons of security, availability, compliance or the prevention of serious disruption to the Services, we may make the change on shorter notice, informing you without undue delay and providing the relevant information.

9.3 Obligations of Sub-processors

Before processing begins, we impose on each Sub-processor, by contract or another binding legal instrument, data-protection obligations that are materially equivalent to those in this Agreement to the extent relevant to the service entrusted to it. The Sub-processor must provide sufficient guarantees that it will implement appropriate technical and organisational measures.

We remain liable to you for each Sub-processor's performance of its data-protection obligations in accordance with Article 28(4) GDPR.

9.4 Information about the processing chain

We keep available the information necessary to identify direct Sub-processors and, to the extent required by the Data Protection Laws, relevant further Sub-processors in the processing chain. At your reasonable request, we will provide additional information necessary for you to fulfil your obligations as Controller, subject to third-party rights and confidential information.

10. International transfers

We do not transfer Event Personal Data outside the European Economic Area or permit access to them from a third country unless the transfer is made in accordance with your Documented Instructions and the conditions of Chapter V GDPR are met.

Where applicable, the transfer may be based on a European Commission adequacy decision, the EU–US Data Privacy Framework for certified organisations, the Standard Contractual Clauses or another valid mechanism. Where required, we assess the circumstances of the transfer and implement appropriate supplementary measures.

Where Cloudsnap, as Processor, transfers data to a Sub-processor in a third country and no other appropriate basis is available, we enter into the applicable Standard Contractual Clauses, generally using the module for processor-to-processor transfers, and complete the required parts of the SCCs with the information relating to the specific processing.

Acceptance of this Agreement and approval of the Sub-processors in Section 23 constitute a Documented Instruction and authorisation for the international transfers expressly described in the relevant list, without relieving Cloudsnap of its obligation to apply a valid transfer mechanism.

11. Data Subject requests

11.1 Assistance to the Organiser

Taking into account the nature of processing, we assist you, through appropriate technical and organisational measures and to the extent possible, in responding to requests to exercise rights under Articles 12 to 22 GDPR. Assistance may be provided through available access, export, removal or deletion features, as well as by providing reasonable information available to us.

11.2 Requests received directly by us

If we receive a Data Subject request directly concerning Event Personal Data, we will forward it to you without undue delay where the relevant Event and responsible Organiser can be identified. We will not accept, reject or fulfil the request on your behalf without a Documented Instruction unless required by law or the action is necessary in connection with our independent obligation as provider or Controller.

We may acknowledge receipt of the request, ask for the information strictly necessary to identify the Event or inform the Data Subject of the appropriate contact method, without replacing your responsibility for deciding on the request.

11.3 Content removal requests

Requests to remove Content concerning privacy, image rights, personal data or other rights are reviewed in accordance with the Terms of Use and the Privacy Policy. Where we act solely as Processor, we will inform and assist you. We retain the ability to take independent measures where required by law, security, the protection of minors or other persons, or our obligations as Platform provider.

11.4 Cost of additional assistance

Assistance provided through the Platform's ordinary features is included in the Services. If a request requires exceptional, specialised or disproportionate work that is not caused by a breach of our obligations, we may, after prior notice, charge reasonable and documented costs in accordance with any separate agreement and applicable law.

12. Personal Data Breaches

12.1 Notification to the Organiser

When we become aware of a Personal Data Breach affecting Event Personal Data, we will inform you without undue delay and, where reasonably possible, within forty-eight (48) hours after becoming aware of the breach. The initial notification may be brief and supplemented in phases as further information becomes available.

12.2 Content of the notification

To the extent that the information is available, the notification will include:

  • a) a description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of affected Data Subjects and data records;
  • b) the details of the relevant contact point from which further information may be obtained;
  • c) the likely consequences of the breach, to the extent that they can be assessed;
  • d) the measures taken or proposed to contain, address and remedy the breach and, where possible, mitigate its possible adverse effects; and
  • e) any other available information reasonably necessary for you to fulfil your obligations under Articles 33 and 34 GDPR.

12.3 Response and cooperation

Without undue delay, we will take appropriate measures to contain, investigate, address and remedy the breach, maintain relevant documentation and reasonably cooperate with you in assessing the risk and fulfilling your obligations.

Responsibility for notifying the competent supervisory authority and informing Data Subjects remains with the Organiser as Controller. We will not make any such notification on your behalf without an instruction unless required by law. If we make a notification pursuant to an independent legal obligation, we will inform you and provide a copy or summary to the extent permitted.

13. Assistance with security, DPIAs and prior consultation

Taking into account the nature of processing and the information available to us, we reasonably assist you in complying with the obligations in Articles 32 to 36 GDPR, in particular with:

  • a) assessing and implementing appropriate security measures;
  • b) assessing and notifying Personal Data Breaches;
  • c) carrying out a data protection impact assessment where processing through the Platform is likely to result in a high risk; and
  • d) prior consultation with the competent supervisory authority where required.

Our assistance is limited to information concerning the processing that we carry out on your behalf and information reasonably available to us. We do not undertake the legal assessment of your own purposes, legal bases or obligations and do not replace your responsibility as Controller.

14. Compliance information and audits

14.1 Provision of information

At your reasonable written request, we will make available the information necessary to demonstrate our compliance with Article 28 GDPR and this Agreement. As appropriate, we may provide descriptions of security measures, questionnaire responses, policy extracts, independent audit reports, certifications or other suitable evidence, where available.

14.2 Right to audit

If the information provided under Section 14.1 is not reasonably sufficient to demonstrate compliance, we will allow and contribute to an audit, including an inspection, conducted by you or an independent auditor appointed by you, subject to the following conditions:

  • a) the audit is conducted on at least thirty (30) calendar days' prior written notice, unless a shorter period is required by a competent authority or justified by a serious incident or reasonable suspicion of a material breach;
  • b) the audit is conducted during normal business days and hours, in a manner that minimises disruption to our operations and does not compromise Platform security;
  • c) as a rule, no more than one (1) audit is conducted in any twelve-month period, unless required by a supervisory authority, following a Personal Data Breach, or where there is documented evidence of material non-compliance;
  • d) the auditor has appropriate expertise, is not a direct competitor of Cloudsnap and is subject to adequate confidentiality obligations;
  • e) the scope is limited to the facilities, systems, procedures and information relevant to the processing of Event Personal Data on your behalf; and
  • f) the audit must not disclose personal data or confidential information of other customers, sensitive security details, source code or third-party information beyond what is strictly necessary.

14.3 Costs and findings

The reasonable cost of the audit is borne by the Organiser unless the audit reveals a material breach of this Agreement by Cloudsnap, in which case we will bear the reasonable cost directly associated with verifying and remedying the breach. We will consider documented findings in good faith and take appropriate corrective action where required.

15. Return, export and deletion of data

15.1 Access and export before deletion

During the Event retention period, you may view, manage and, where supported, export or download Content and related data using the available Platform features. Before scheduled deletion, you will receive the notices provided for in the Terms of Use and Privacy Policy so that you can export in good time the data you wish to retain.

15.2 Choice of return or deletion

Following the end of the provision of the relevant Services or upon your valid instruction, and subject to the retention periods of the selected Plan, you may choose:

  • a) the return of Event Personal Data through the available export features or, where this is not technically feasible, by another reasonable and secure method agreed between the Parties; or
  • b) the secure deletion of Event Personal Data.

Deletion of an Event through the Platform, in accordance with Section 6.2, results only in its soft deletion and does not amount to the choice of permanent deletion in point (b). Permanent deletion requires a separate and express Documented Instruction, which may be submitted in writing or electronically through the available support channels. The return option must be exercised before permanent deletion is completed. If we do not receive a different Documented Instruction, the retention and deletion process corresponding to the selected Plan applies in accordance with the Terms of Use, the Privacy Policy and Section 15.3 of this Agreement.

15.3 Deletion from active systems and backups

When the Organiser deletes an Event through the Platform, the Event Personal Data immediately cease to be available or recoverable through the Platform, but the related files and records remain stored in our systems in a soft-deleted state with restricted access. Their permanent deletion from active systems is completed following a separate Documented Instruction under Section 15.2 or through the then-applicable erasure process.

After the scheduled deletion date, we delete Event Personal Data from our active systems and they cease to be available or recoverable through the Platform. Deleted data may remain temporarily in isolated backups for up to ninety (90) days, without being restored to active use, unless required for system recovery or by law. Copies are deleted or overwritten in accordance with the applicable retention cycle.

At your reasonable request, we will confirm completion of deletion in writing or electronically to the extent technically and organisationally feasible.

15.4 Statutory retention obligation

If European Union or Member State law requires specific data to be retained, we will retain only the data and for the period required, restrict processing to the relevant lawful purpose and inform you unless such information is prohibited by law.

16. Public-authority requests and mandatory disclosures

If we receive a binding request from a public, judicial, supervisory or law-enforcement authority for disclosure of Event Personal Data, we will review its lawfulness and scope and disclose only the required data. We will inform you before disclosure unless prohibited by law or doing so would compromise a lawful investigation.

Where reasonable and lawful, we will seek clarification, limitation or challenge of a request that is manifestly excessive, unclear or unlawful and will document the relevant response.

17. Records and cooperation with supervisory authorities

To the extent required, we maintain records of the categories of processing activities carried out on behalf of Controllers and cooperate with the competent supervisory authorities in accordance with the GDPR. At your reasonable request, we provide relevant information necessary to demonstrate compliance, subject to third-party rights and the security of our systems.

18. Liability

Each Party is responsible for performing the obligations applicable to it under the GDPR, other Data Protection Laws, this Agreement and the Terms of Use. The allocation of roles in this Agreement does not relieve either Party of obligations imposed directly on it by law.

Subject to mandatory provisions of law, including Article 82 GDPR, the Parties' liability under this Agreement is governed by the limitations and liability arrangements in the Terms of Use or any separate agreement. No contractual limitation applies to the extent that it would exclude or limit liability in a manner prohibited by applicable law.

19. Term, expiry and amendments

19.1 Term

This Agreement remains in force for as long as Event Personal Data are processed on your behalf, including any retention period or temporary presence in backups. Provisions which by their nature are intended to continue in force, in particular obligations concerning confidentiality, security, deletion, audits, liability and international transfers, survive expiry to the extent necessary.

19.2 Amendments

We may amend this Agreement to reflect changes in the Data Protection Laws, Services, technologies, Sub-processors or security practices. We will inform you in good time of material changes before they take effect by email, Platform notice or another appropriate method. Changes will not materially reduce the overall level of protection of Event Personal Data or remove the mandatory safeguards in Article 28 GDPR.

Where an amendment requires a new agreement or acceptance under applicable law or by reason of the nature of the change, we will request the corresponding acceptance before it is implemented. Changes to the list of Sub-processors are specifically governed by Section 9.

20. Governing law, jurisdiction and contact

20.1 Governing law and jurisdiction

This Agreement is governed by Greek law. Any dispute arising out of or relating to this Agreement is subject to the jurisdiction provisions of the Terms of Use, without prejudice to the powers of supervisory authorities, the rights of Data Subjects and the mandatory provisions of the Data Protection Laws.

20.2 Contact

For questions, instructions or notices concerning this Agreement, you may contact us at contact@cloudsnap.gr. Notices to the Organiser are sent to the email address associated with the Organiser's Account or to the contact details separately agreed. Each Party must inform the other of any material change to its contact details.

20.3 Language

This Agreement has been drafted in Greek and may also be made available in other languages for the convenience of the Parties. We make every reasonable effort to ensure that each translation accurately and completely reflects the Greek text. In the event of any discrepancy or inconsistency, the Greek text shall prevail.

21. Details of processing

21.1 This Section describes the principal details of the processing that we carry out as Processor on behalf of the Organiser in connection with the creation, management and operation of an Event through the Platform.

21.2 The subject matter of processing is the provision of the technical infrastructure and features that enable the Organiser to create and manage Events, invite Guests, and collect, store, organise, display, make available and manage photographs, videos and other supported Content through the Event Album.

21.3 The nature of processing includes in particular the collection, recording, receipt, storage, hosting, organisation, technical adaptation, display, making available, disclosure, management, restriction of access, export, deletion and, where required, recovery of Event Personal Data, in accordance with the Organiser's choices and Documented Instructions.

21.4 The purpose of processing is solely to provide the Services to the Organiser and Guests in accordance with the Terms of Use, Privacy Policy, this Agreement and the settings selected by the Organiser for each Event.

21.5 The duration of processing is the operating period of the Event and corresponding Plan, together with any additional period required to complete deletion, retain backups, export Content, address technical issues, comply with a legal obligation or establish, exercise or defend legal claims, in accordance with the Privacy Policy and Terms of Use.

21.6 Categories of Data Subjects may include in particular

  • a) the Organiser;
  • b) Guests;
  • c) persons who receive an invitation to participate in an Event;
  • d) persons who upload or manage Content;
  • e) persons depicted or heard in photographs, videos or other Event Content;
  • f) other persons whose personal data are included in Content or Event details.

21.7 Categories of Event Personal Data may include in particular

  • a) identification or display details, such as name, display name or User identifier;
  • b) contact details, such as an email address used to invite or participate in an Event;
  • c) Event details, such as title, date, description, and access, participation, upload, viewing and publicity settings;
  • d) participation details, such as User role and invitation, participation or approval status;
  • e) photographs, videos, image, voice and other supported Event Content;
  • f) captions, comments or other information accompanying Content, where supported by the Platform;
  • g) technical logs and records necessary for security, troubleshooting, abuse prevention and the proper operation of the Event.

21.8 Depending on the nature of the Event and the Content that Users choose to upload, Event Content may reveal highly personal information or special categories of data. We do not ask Users to upload such data and do not analyse Content for the purpose of drawing inferences about sensitive characteristics of the persons depicted or heard.

21.9 The Organiser is responsible for determining the appropriate legal basis, purpose and permitted Event-use settings and for providing the required information to Guests and other persons where required under applicable law.

22. Technical and organisational measures

22.1 We implement appropriate technical and organisational measures to protect Event Personal Data against unauthorised or unlawful processing, accidental loss, destruction, alteration, unauthorised access or disclosure.

22.2 Those measures take into account the nature, subject matter, context and purposes of processing, the state of the art, implementation costs and the risks to the rights and freedoms of natural persons.

22.3 The technical and organisational measures include, in particular, the following categories

  • a) Access control. We restrict access to systems, data and Content to authorised persons and only to the extent necessary to perform their duties.
  • b) Permission management. We implement appropriate management of roles and access permissions so that each person has access only to the data and features that are necessary.
  • c) Authentication and login control. Users access the Platform through supported authentication mechanisms, such as login using an email address and a six-digit One-Time Password or through supported third-party providers, in accordance with the Terms of Use.
  • d) Transmission security. We use appropriate measures to protect data while they are transmitted between the User's device and the Platform.
  • e) Storage security. We implement appropriate safeguards for data and Content stored in the systems and infrastructure used to provide the Services.
  • f) Protection of links and access to Events. Events are private by default and access to them is provided in accordance with the settings selected by the Organiser, as provided in the Terms of Use.
  • g) Logging and monitoring. We maintain appropriate logs for security, technical troubleshooting, abuse prevention and incident investigation, in accordance with the Privacy Policy.
  • h) Backup and recovery. We implement backup and recovery procedures to the extent necessary for the availability and resilience of the Services.
  • i) Protection against malicious use. We take measures to prevent, detect and respond to unauthorised access, malicious use, abuse of the Platform or technical attacks.
  • j) Confidentiality of personnel and contractors. We ensure that persons authorised to access Event Personal Data are subject to appropriate confidentiality obligations.
  • k) Security-incident management. We maintain procedures to detect, assess, contain, respond to and document security incidents that may involve personal data.
  • l) Sub-processor oversight. We select Sub-processors that provide appropriate data-protection guarantees and bind them by contractual obligations equivalent to those in this Agreement.

22.4 Those measures may evolve or be replaced by equivalent or stronger measures, provided that an appropriate level of security is maintained and protection of Event Personal Data is not materially reduced.

22.5 The Organiser acknowledges that the security of Event Personal Data also depends on the Organiser's own choices and actions, such as selecting access settings, sharing invitation links, selecting Guests, managing access permissions and downloading or deleting Content in good time.

23. List of Sub-processors

23.1 Cloudsnap maintains an available and up-to-date list of the Sub-processors used to process Event Personal Data on behalf of the Organiser.

23.2 The list may be made available through the Platform, Website, a dedicated link, electronic notice or at the Organiser's reasonable request.

23.3 To the extent applicable, the list includes the identity or category of the Sub-processor, the service provided, the purpose of processing, the processing region and, where required, the applicable international-transfer mechanism.

Sub-processorService provided and purpose of processingProcessing regionInternational-transfer mechanism
Hetzner Online GmbHHosting and storage of Event Personal DataEuropean UnionNot applicable
Twilio SendGridSending Event invitations and related operational notificationsUnited States of AmericaEuropean Commission Standard Contractual Clauses (SCCs)

23.4 The list supplements Section 9 of this Agreement and does not limit our obligations concerning prior notice, the opportunity to raise a reasoned objection, the imposition of equivalent contractual obligations and liability for Sub-processors.

23.5 The service providers with which we work are included in the list of Sub-processors only where, based on the actual technical implementation, they process Event Personal Data on behalf of the Organiser as Sub-processors.

23.6 Where those providers process data for our own purposes, for example for payments, security, usage analytics, consent-preference management or compliance with legal obligations, the relevant processing does not fall within this Agreement as Sub-processor processing on behalf of the Organiser and is described in the Privacy Policy and, where applicable, the Cookies Policy.

23.7 A Sub-processor is added or replaced in accordance with the notice and objection procedure in Section 9.