GDPR-compliant data processing terms for business partners
Effective: July 18, 2025 | Last Updated: December 24, 2025
This Data Processing Agreement complies with GDPR Article 28 requirements when EventMaps processes personal data on behalf of data controllers (event organizers, venue partners, etc.).
Assist with providing data subject access to their personal data
Correct inaccurate personal data without delay
Delete personal data when instructed by the Data Controller
Provide data in structured, machine-readable format
EventMaps will provide reasonable assistance to the Data Controller in fulfilling data subject rights requests within applicable timeframes.
EventMaps will notify the Data Controller without undue delay, and no later than 72 hours after becoming aware of a personal data breach.
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Stripe | Payment Processing | EU/US | Stripe DPA |
| Google (Firebase) | Authentication, Analytics | EU/US | Google Cloud DPA |
| MongoDB Inc. | Database Hosting | EU | MongoDB DPA |
| Cloudinary | Image Storage | EU/US | Cloudinary DPA |
| Mapbox | Mapping Services | US | Mapbox DPA |
| Vercel | Web Hosting | EU/US | Vercel DPA |
Upon termination of this agreement:
EventMaps - Operated by Umit Hayim
Email: support@eventmaps.io
This DPA is governed by Spanish law and GDPR. Any disputes will be resolved in the courts of Barcelona, Spain. Data subjects retain the right to lodge complaints with their local supervisory authority.
EventMaps - Operated by Umit Hayim