Data Processing Agreement (DPA)
Annex to the PassPass General Terms of Use
Last updated: 23 June 2026
Preamble
This Data Processing Agreement (the "DPA") forms an integral part of the General Terms of Use accepted by the Organiser (the "Terms") and sets out the conditions relating to the processing of personal data. It is concluded between:
the Organiser, acting as controller within the meaning of Article 4(7) GDPR for its Attendees' data,
and TLJ SRL, operating the service under the trade name PassPass, with registered office at Tienne du Sarment 8, 1300 Wavre (Belgium), registered with the Belgian Crossroads Bank for Enterprises under number BE 1008.206.815, acting as processor within the meaning of Article 4(8) GDPR.
The purpose of this DPA is to define the conditions under which PassPass processes, on behalf and on the instructions of the Organiser, the personal data necessary to provide the service, in accordance with Article 28 GDPR and the Belgian law of 30 July 2018. In the event of a conflict between this DPA and the Terms on a data protection matter, this DPA prevails.
This DPA only covers the processing for which PassPass acts as processor of the Organiser. The processing that PassPass carries out for its own purposes, as a controller, is governed by the PassPass Privacy Policy and does not fall within this DPA.
Article 1. Definitions
Capitalised terms not defined here have the meaning given to them by the Terms. The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them by Article 4 GDPR. "GDPR" means Regulation (EU) 2016/679. "the Law" means the Belgian law of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
Article 2. Subject matter, nature and purpose of the processing
PassPass processes the Attendees' personal data on behalf of the Organiser for the sole purpose of providing the ticketing service and the associated services described in the Terms. The subject matter, nature, purpose of the processing, the categories of data and of data subjects, and the duration, are described in Annex A.
The Organiser remains solely responsible for the lawfulness of the processing, for the appropriate legal basis, for informing the data subjects and, where applicable, for obtaining their consent.
Article 3. Documented instructions
PassPass processes the personal data only on the basis of the Organiser's documented instructions, including with regard to transfers to a third country, unless required to do so by a legal obligation to which PassPass is subject. In the latter case, PassPass informs the Organiser of that legal obligation before processing, unless the applicable law prohibits this on important grounds of public interest.
The Terms, the configuration of the Events carried out by the Organiser on the Platform and this DPA constitute the Organiser's documented instructions. Any additional instruction is communicated in writing. If PassPass considers that an instruction infringes the GDPR or the Law, it informs the Organiser without delay.
Article 4. Duration
This DPA applies throughout the duration of the provision of the service under the Terms. The obligations which, by their nature, must survive its term remain in force after the end of the contractual relationship, in particular those relating to confidentiality and to the fate of the data.
Article 5. Confidentiality
PassPass ensures that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to the data is limited to staff members and providers who need it to provide the service, on a need-to-know basis.
Article 6. Security
PassPass implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures are described in Annex B. PassPass may change them during the term of the contract, provided it does not lower the level of security.
Article 7. Sub-processors
The Organiser gives PassPass general authorisation to engage sub-processors for the provision of the service. The list of sub-processors in force is set out in Annex A.
PassPass imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA, and remains fully liable to the Organiser for the performance by that sub-processor of its obligations.
PassPass informs the Organiser of any intended addition or replacement of a sub-processor, thereby giving the Organiser the opportunity to raise legitimate objections within a reasonable time. In the event of an unresolved legitimate objection, the Organiser may terminate the service in accordance with the Terms.
Article 8. Transfers outside the European Union
The data is in principle processed within the European Union. Where a sub-processor processes data outside the European Union, PassPass ensures that the transfer is governed by a valid mechanism within the meaning of Chapter V GDPR, in particular an adequacy decision, the standard contractual clauses of the European Commission, or any other recognised mechanism. The sub-processors concerned and the applicable mechanisms are identified in Annex A.
Article 9. Assistance with data subjects' rights
Taking into account the nature of the processing, PassPass assists the Organiser, by appropriate technical and organisational measures and insofar as possible, in fulfilling its obligation to respond to requests for the exercise of data subjects' rights: rights of access, rectification, erasure, objection, restriction and portability. If a data subject addresses such a request directly to PassPass, PassPass forwards it to the Organiser without delay and does not respond to it itself, unless instructed by the Organiser.
Article 10. Assistance with security, breaches and impact assessments
Taking into account the information available to it, PassPass assists the Organiser in ensuring compliance with its obligations regarding the security of processing, the notification of data breaches, the communication of breaches to data subjects, data protection impact assessments and prior consultation of the supervisory authority, in accordance with Articles 32 to 36 GDPR.
Article 11. Notification of data breaches
PassPass notifies the Organiser of any personal data breach concerning it without undue delay after becoming aware of it, by electronic means. This notification is accompanied by the relevant information enabling the Organiser, where applicable, to notify the breach to the competent supervisory authority and to the data subjects. It is for the Organiser, in its capacity as controller, to carry out these notifications.
Article 12. Fate of the data at the end of the contract
At the end of the provision of the service, PassPass, at the choice of the Organiser, deletes or returns the personal data processed on its behalf, and destroys the existing copies, unless required to retain the data by law. In the absence of an instruction from the Organiser within a reasonable time, PassPass deletes the data under the conditions of Annex A.
Article 13. Audits and inspections
PassPass makes available to the Organiser the information necessary to demonstrate compliance with the obligations of this DPA and allows for audits, including inspections, by the Organiser or an auditor it mandates. Audits are carried out at reasonable intervals, on reasonable notice, with respect for the confidentiality and security of PassPass's other clients, and without disproportionately disrupting its activity. PassPass may satisfy this obligation by producing existing certifications or audit reports.
Article 14. Records
PassPass maintains a record of the categories of processing activities carried out on behalf of the Organiser, in accordance with Article 30(2) GDPR.
Article 15. Liability
The liability of each Party under this DPA is governed by the provisions of the Terms, without prejudice to the mandatory provisions of the GDPR relating to liability and penalties.
Annex A. Description of the processing
Subject matter of the processing: provision of an online ticketing platform enabling the sale of Tickets and the management of the relationship with Attendees on behalf of the Organiser.
Nature of the operations: collection, recording, organisation, storage, consultation, communication, making available and deletion of the data, via the Platform.
Purposes: management of the sale of Tickets and registrations; access control to the Events; communication of practical information to the Attendees; performance, where applicable, of the communication and attendee relationship management services configured by the Organiser.
Categories of data subjects: Attendees and purchasers of Tickets to the Organiser's Events.
Categories of data: identification and contact data (surname, first name, email address, telephone number); data relating to the order and the Ticket; data collected via the form fields defined by the Organiser during configuration; technical connection data (IP address); payment reference. PassPass does not collect any special categories of data, unless the Organiser configures their collection, under its sole responsibility.
Retention period: the data is kept for the duration necessary to provide the service, then, after the end of the Event or the closure of the account, for the duration required by the legal obligations applicable to the Organiser. At the end of these periods, it is deleted or returned in accordance with Article 12.
Place of processing: European Union, subject to the sub-processors identified below.
Sub-processors:
- Brevo, sending of communications and emailing, processing in France (EU).
- Hetzner, hosting and storage of data, processing in Germany (EU).
This list is established on the basis of the sub-processors actually used. It is kept up to date by PassPass and any change is communicated to the Organiser in accordance with Article 7.
Annex B. Technical and organisational security measures
In accordance with Article 32 GDPR, PassPass implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope and context of the processing, and the risks to the rights and freedoms of data subjects. The following measures are in place:
- Antivirus and antimalware installed and kept up to date on workstations and servers;
- Regular backups and measures to prevent data loss;
- System access via a unique identifier and secure authentication for each user;
- Two-factor authentication (2FA) available and configurable by the Organiser to protect its account;
- Robust password policy and protection of stored passwords;
- Access to data limited on a need-to-know basis;
- HTTPS connection and encryption of data in transit;
- Encryption of workstations and mobile devices;
- Systematic software updates and configuration limiting vulnerabilities;
- Logging of access, distinguishing user and administrator roles;
- Physical security and controlled access to storage environments, provided via the hosting sub-processors;
- Secure and irreversible deletion of data at the end of the retention period;
- Staff awareness of data protection.
PassPass reviews and develops these measures on an ongoing basis in order to maintain an appropriate level of security.