Venuebo
Template document — placeholders in brackets need your real business details filled in, and this should be reviewed by a qualified lawyer before you rely on it. It is not legal advice.

Data Processing Agreement

Last updated: 25 July 2026

1. Purpose and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between an Organization ("Controller") and [Company Legal Name] ("Processor", "Venuebo"), and applies where Venuebo processes personal data on the Controller's behalf as part of running its conferences ("Customer Data"). It is intended to reflect the requirements of applicable data protection law, including GDPR/UK GDPR Article 28 where relevant.

2. Roles

The Organization is the Controller for Customer Data — it decides what data to collect from its delegates and sponsor representatives, and why. Venuebo is the Processor, processing Customer Data only to provide the service and on the Controller's documented instructions (given through the Controller's use of the product, e.g. uploading a delegate list or configuring which fields are collected).

3. Subject matter and duration

Subject matter: operation of the Venuebo event intelligence platform. Duration: for as long as the Controller's subscription is active, plus any retention period described in the Privacy Policy or agreed separately.

4. Nature and purpose of processing

Hosting, storage, and processing of Customer Data to provide account management, conference/delegate/sponsor management, AI-assisted scoring and recommendations, messaging, and reporting features of the platform.

5. Categories of data subjects

  • Conference delegates (including speakers and vendor delegates)
  • Sponsor company representatives
  • The Controller's own admin, moderator, and staff users

6. Categories of personal data

  • Identity and contact data: name, email, phone, job title, employer
  • Profile data: photo, stated goals/interests, persona classification
  • Engagement data: check-in status, agenda selections, messages, meeting requests
  • Call-transcript-derived pain points, where the Controller uses that feature
  • Login credentials (hashed) for individuals with platform accounts

7. Processor obligations

Venuebo will:

  • Process Customer Data only on the Controller's documented instructions, including regarding international transfers;
  • Ensure personnel with access are bound by confidentiality obligations;
  • Implement appropriate technical and organizational security measures (see Privacy Policy §7), including role- and Organization-scoped access controls;
  • Not engage a new sub-processor without giving the Controller reasonable notice and the opportunity to object (see §8);
  • Assist the Controller, taking into account the nature of processing, in responding to data subject rights requests;
  • Assist the Controller in meeting its obligations around security, breach notification, and data protection impact assessments where applicable;
  • Notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Data;
  • At the Controller's choice, delete or return all Customer Data at the end of the subscription, except where retention is required by law;
  • Make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality.

8. Sub-processors

The Controller authorizes Venuebo to engage the following categories of sub-processors:

  • [Hosting Provider Name] — infrastructure hosting
  • LemonSqueezy — payment processing (billing data only)
  • Resend — transactional email delivery (only for Organizations with live email configured)
  • Anthropic — AI processing (only for Organizations with live AI configured; when not configured, no Customer Data is sent to an external AI provider)

We'll update this list and give reasonable notice before adding a new sub-processor category that processes Customer Data.

9. International transfers

Where Customer Data is transferred outside the Controller's jurisdiction, Venuebo will use appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.

10. Liability

Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service.

11. Governing law

This DPA is governed by the same governing law as the Terms of Service: [Governing Law / Jurisdiction].

12. Acceptance

An Organization accepts this DPA electronically when its admin creates the Organization on Venuebo, alongside the Terms of Service and Privacy Policy.

13. Contact

Data protection queries: [Contact Email].

← Back to Venuebo