Data Processing Addendum

Version: 1.0
Effective Date: 21 August 2026

This Data Processing Addendum (the “DPA”) forms part of the agreement between Deuce Creative Limited (trading as Grofomo)(“we”, “us”, “our”, “Grofomo”) and the organisation using Grofomo to run its events (“you”, the “Customer”). It records how we handle personal data that we process on your behalf, and it is written to satisfy Article 28 of the UK GDPR.

In one paragraph. When you use Grofomo to sell tickets, hold contacts, message your audience, or manage volunteers and suppliers, you decide what happens to that data and we act on your instructions. This document is our promise about how we do that: we only use the data to run the service for you, we keep it secure, we tell you who else touches it, we help you answer requests from the people it belongs to, and we give it back or delete it when you leave.

1. When this DPA applies, and what it overrides

1.1 This DPA applies whenever we process personal data on your behalf in providing the Grofomo services to you.

1.2 Acceptance. This DPA takes effect when you first use the services to process personal data, and applies for as long as you keep doing so. Where you have signed a separate written data processing agreement with us, that agreement takes precedence over this one to the extent they conflict. If you need a signed and countersigned copy of this DPA for your records, ask us at privacy@grofomo.com and we will provide one.

1.3 Order of precedence. On any question about the processing of personal data, this DPA prevails over our Organiser Terms, over our Terms of Service, and over any other agreement between us. On every other question, those other agreements prevail.

1.4Nothing in this DPA limits any right the people whose data we process have under data protection law, and nothing in it limits either party’s obligations to the Information Commissioner.

2. Definitions

2.1“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where they apply to the processing, the EU GDPR.

2.2“controller”, “processor”, “personal data”, “processing”, “special category data”, “personal data breach” and “data subject” have the meanings given in the UK GDPR.

2.3“Customer Personal Data” means personal data we process on your behalf under this DPA, described in Annex 1.

2.4“Subprocessor” means a third party we engage to process Customer Personal Data. The current list is published at https://events.grofomo.com/subprocessors and forms Annex 3.

3. Our roles, which are not the same everywhere

3.1 Grofomo is not a processor for everything it does. Reading it that way would be convenient but wrong, and it would leave the parts where we are a controller unaccounted for. The split is:

3.2 Where we are your processor

You are the controller and we are your processor for the data you bring to the platform or gather through it:

3.3 Where we are an independent controller

For the following we decide the purposes ourselves, and we are a controller in our own right rather than your processor. Our Privacy Policy governs these, not this DPA:

3.4 Where we each act as an independent controller for the same person, for example a buyer who agrees to hear from you and separately from us, we are not joint controllers. Each of us is responsible for our own processing.

3.5 We sell tickets as your disclosed commercial agent. That is a commercial role and it does not change the data protection roles set out above.

4. What we will do

We will:

4.1 Process only on your instructions. We process Customer Personal Data only on your documented instructions, including on transfers, unless we are required to do otherwise by law. Your instructions are: this DPA, our agreement with you, and what you do through the product. If we believe an instruction breaches Data Protection Law, we will tell you and may pause that processing while we resolve it. If a law requires us to process beyond your instructions, we will tell you first unless that law forbids it.

4.2 Keep it confidential. Everyone we allow to access Customer Personal Data is bound by a duty of confidentiality, is given access only where they need it for their role, and is trained on handling it.

4.3 Keep it secure. We maintain the technical and organisational measures in Annex 2, appropriate to the risk, in line with Article 32.

4.4 Control who else is involved. We engage subprocessors only on the terms in clause 6.

4.5 Help you answer the people whose data it is. See clause 7.

4.6 Help you meet your own obligations on security, breach notification, impact assessments, and prior consultation, taking into account what we know and the nature of the processing. See clauses 8 and 9.

4.7 Delete or return it when you stop using the services, as set out in clause 11.

4.8 Show our work. We will give you the information you reasonably need to show that we are meeting these obligations, and allow audits as set out in clause 10.

4.9 Never sell it. We do not sell Customer Personal Data, share it with advertisers, or use it to train machine learning models. We do not use it to build profiles for our own commercial purposes.

5. What you must do

5.1 You are responsible for having a lawful basis for the processing you instruct, for giving the people concerned the information they are entitled to, and for the accuracy of what you upload.

5.2 Marketing. Where you send marketing through the platform, you are responsible for the consent or legitimate interest you rely on, and for honouring objections and withdrawals. The platform records consent wording, timestamps, and the form version at the point of collection, and applies suppressions, but the lawful basis is yours.

5.3 Imported lists. When you import contacts you confirm that you may lawfully send to them. We record that confirmation with the import. Importing a list you cannot lawfully use is a breach of this DPA.

5.4 Free-text and custom fields, which matter more than they look. Several parts of the platform let you ask your audience anything you like: questions on your checkout, questions on your forms, and notes fields throughout. We cannot see in advance what you will ask. If you use them to collect special category data, for example health conditions, accessibility needs, dietary requirements that reveal health or religion, or data about children, then:

5.5 Volunteer records. The volunteer features are built to hold date of birth, emergency contacts, dietary requirements, and qualifications including safeguarding and DBS checks. That is special category data, third-party data, and potentially data about children. You are the controller for all of it. You must have a lawful basis and an Article 9 condition, you must tell emergency contacts that you have recorded their details, and where you record criminal records information you need an appropriate policy document under Schedule 1 of the Data Protection Act 2018.

5.6 What you switch on. Where you connect your own advertising pixel, WhatsApp Business account, social accounts, or webhook destination, you are instructing a transfer to that third party and you are responsible for it. See the third group on the subprocessors page.

5.7 Your team. You are responsible for who you invite into your account and what you let them see. The platform provides roles and per-member permissions for this.

6. Subprocessors

6.1 Authorisation. You give us general written authorisation to engage subprocessors. The current list is published at https://events.grofomo.com/subprocessors and is Annex 3 to this DPA. It is maintained as the canonical record and is complete at all times.

6.2 Terms we impose. We put each subprocessor under written terms that offer protection equivalent to this DPA. We remain fully liable to you for what our subprocessors do.

6.3 Notice. We give you at least 30 days notice before a new subprocessor starts processing Customer Personal Data, by email to your billing address. Where a change is needed urgently to keep the service running or secure, we may make it immediately and will tell you as soon as we reasonably can.

6.4 Objection. If you have a reasonable data protection objection, tell us within the notice period. We will work with you to find a way forward. If we cannot, you may stop using the affected part of the service, or terminate the affected services without penalty and receive a refund of any fees paid in advance for the unused period.

6.5 What this clause does not cover. Services you connect yourself are not subprocessors we appoint, and clauses 6.1 to 6.4 do not apply to them. They are listed separately for transparency.

7. Requests from the people whose data it is

7.1 Taking into account the nature of the processing, we help you respond to requests to exercise rights under Chapter III of the UK GDPR, through the following, at no additional charge:

7.2 If a request reaches us directly and relates to your account, we will not respond to it on your behalf. We will tell you promptly and let the person know they should contact you, unless answering ourselves is clearly the right thing for that person and is consistent with your instructions.

7.3 Some records survive an erasure by design, because removing them would defeat the purpose of holding them:

Neither of these is used to contact the person again, and both are stripped of identifying details wherever the record still serves its purpose without them.

8. Personal data breaches

8.1 We will tell you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.2 Our notice will describe what we know: the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose. Where we do not have all of it at once, we will send what we have and follow up.

8.3 We will help you meet your own obligations to notify the Information Commissioner and, where required, the people affected. We will not notify the Commissioner on your behalf unless you ask us to.

8.4 Notifying you is not an admission of fault by either of us.

9. Impact assessments

9.1 On request, we will give you reasonable help with data protection impact assessments and with prior consultation of the Information Commissioner, limited to the processing we carry out for you and to information we hold.

9.2 Annex 1 and Annex 2 are written to be usable directly in an assessment.

10. Audits

10.1 On request, and no more than once a year unless there has been a personal data breach affecting you or the Commissioner requires it, we will give you the information reasonably necessary to demonstrate compliance with this DPA. In the first instance this means our documented security measures and answers to a reasonable security questionnaire.

10.2 Where that genuinely is not enough, you may audit us, or appoint an independent auditor who is not a competitor of ours to do so, on 30 days written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear the cost, unless the audit reveals a material breach of this DPA by us, in which case we do.

10.3 An audit may not extend to another customer data, to our personnel records, or to anything that would put us in breach of a duty we owe someone else.

11. Deletion and return

11.1 While you are a customer, you can export your data at any time from the console.

11.2 When you stop using the services, we will, at your choice, return Customer Personal Data to you in a structured, commonly used, machine readable format, or delete it. You have 30 days from termination to tell us which and to retrieve anything you want. After 90 days we delete it, unless we are required by law to keep it.

11.3 Retention while you are still with us. The platform applies retention periods automatically, and several are yours to set:

11.4 Backups are overwritten on a rolling cycle and are fully replaced within 60 days. Data in a backup is not restored to live use except to recover from an incident.

12. International transfers

12.1 Customer Personal Data is stored in the United Kingdom.

12.2 Some processing takes place outside the United Kingdom, as set out for each provider on the subprocessors page. Where it does, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it.

12.3 Where the Standard Contractual Clauses apply and you are the data exporter, you appoint us to enter into them with the relevant provider on your behalf, in the module appropriate to the transfer.

12.4 We carry out transfer risk assessments where required, and will provide them on request under clause 10.

13. Liability, changes, and law

13.1 Each party liability under this DPA is subject to the limitations and exclusions in our agreement with you. Nothing in this DPA limits liability that cannot lawfully be limited, and nothing in it affects any right a data subject has to compensation.

13.2 We may update this DPA where the law changes, where we change how the platform works, or to make it clearer. Where a change materially reduces your rights, we will give you at least 30 days notice by email before it takes effect. The version number and date at the top always reflect the current text.

13.3 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.


Annex 1: what we process for you

Subject matter and duration

Providing the Grofomo platform to you: ticketing, customer records, marketing and messaging, artist and lineup management, and event operations. Processing lasts for as long as you are a customer, plus the periods in clause 11.

Nature and purpose

Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to the recipients you nominate, restriction, erasure and destruction, for the purpose of selling tickets to your events, admitting people to them, communicating with your audience, and running your event operations.

Categories of data subject

Categories of personal data

Special category data

The platform does not require special category data and we do not ask for it. It can nonetheless arise in three places, and clause 5 puts responsibility for it with you:

Children

The platform is not directed at children under 13. Buying a ticket requires you to be 18 or over. Data about children can still arise: a parent naming a child on a ticket, a young performer, or a volunteer under 18, which the volunteer features expressly support through an under-18 flag. Where you process it, you are the controller and additional protections apply.

Frequency

Continuous, for as long as the services are in use.


Annex 2: how we keep it secure

These are the technical and organisational measures required by Article 32. They are reviewed as the platform changes.

Access control

Encryption

Data minimisation and separation

Integrity and accountability

Resilience

Organisational


Annex 3: subprocessors

The current list is published and maintained at https://events.grofomo.com/subprocessors, including for each provider what it does, what data it can reach, where it processes, and the transfer safeguard relied on. That page forms part of this DPA.


Contact

Deuce Creative Limited, a company registered in England and Wales, company number 07991249.

Unit 8 Great Bramshot Farm Barns
Bramshot Lane
Fleet
Hampshire
GU51 2SF
United Kingdom

Data protection enquiries: privacy@grofomo.com