Data Processing Addendum
Version: 1.0
Effective Date: 21 August 2026
This Data Processing Addendum (the “DPA”) forms part of the agreement between Deuce Creative Limited (trading as Grofomo)(“we”, “us”, “our”, “Grofomo”) and the organisation using Grofomo to run its events (“you”, the “Customer”). It records how we handle personal data that we process on your behalf, and it is written to satisfy Article 28 of the UK GDPR.
In one paragraph. When you use Grofomo to sell tickets, hold contacts, message your audience, or manage volunteers and suppliers, you decide what happens to that data and we act on your instructions. This document is our promise about how we do that: we only use the data to run the service for you, we keep it secure, we tell you who else touches it, we help you answer requests from the people it belongs to, and we give it back or delete it when you leave.
1. When this DPA applies, and what it overrides
1.1 This DPA applies whenever we process personal data on your behalf in providing the Grofomo services to you.
1.2 Acceptance. This DPA takes effect when you first use the services to process personal data, and applies for as long as you keep doing so. Where you have signed a separate written data processing agreement with us, that agreement takes precedence over this one to the extent they conflict. If you need a signed and countersigned copy of this DPA for your records, ask us at privacy@grofomo.com and we will provide one.
1.3 Order of precedence. On any question about the processing of personal data, this DPA prevails over our Organiser Terms, over our Terms of Service, and over any other agreement between us. On every other question, those other agreements prevail.
1.4Nothing in this DPA limits any right the people whose data we process have under data protection law, and nothing in it limits either party’s obligations to the Information Commissioner.
2. Definitions
2.1“Data Protection Law” means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and, where they apply to the processing, the EU GDPR.
2.2“controller”, “processor”, “personal data”, “processing”, “special category data”, “personal data breach” and “data subject” have the meanings given in the UK GDPR.
2.3“Customer Personal Data” means personal data we process on your behalf under this DPA, described in Annex 1.
2.4“Subprocessor” means a third party we engage to process Customer Personal Data. The current list is published at https://events.grofomo.com/subprocessors and forms Annex 3.
3. Our roles, which are not the same everywhere
3.1 Grofomo is not a processor for everything it does. Reading it that way would be convenient but wrong, and it would leave the parts where we are a controller unaccounted for. The split is:
3.2 Where we are your processor
You are the controller and we are your processor for the data you bring to the platform or gather through it:
- Ticket buyers and attendees for your events, and their orders
- Your contacts, mailing list subscribers, and pre-sale registrants
- Answers to questions you add to your checkout or your forms
- Your WhatsApp, email, and SMS conversations with your audience
- Your volunteers, suppliers, vendors, and guest lists
- Your own team members, in respect of what they do inside your account
3.3 Where we are an independent controller
For the following we decide the purposes ourselves, and we are a controller in our own right rather than your processor. Our Privacy Policy governs these, not this DPA:
- Marketing that Grofomo sends about Grofomo, where a person has separately agreed with us. This is recorded against Grofomo, kept apart from your consent records, and is not derived from your instructions.
- The Grofomo mobile app: the accounts, devices, favourites, and friend connections of people who use it, including at your events.
- The public artist catalogue and event directory, including entries compiled from public sources.
- Account, sign-in, and billing records for your team, considered as our own customer records.
- Operating the platform itself: security, fraud prevention, service statistics, and meeting our own legal and tax obligations.
3.4 Where we each act as an independent controller for the same person, for example a buyer who agrees to hear from you and separately from us, we are not joint controllers. Each of us is responsible for our own processing.
3.5 We sell tickets as your disclosed commercial agent. That is a commercial role and it does not change the data protection roles set out above.
4. What we will do
We will:
4.1 Process only on your instructions. We process Customer Personal Data only on your documented instructions, including on transfers, unless we are required to do otherwise by law. Your instructions are: this DPA, our agreement with you, and what you do through the product. If we believe an instruction breaches Data Protection Law, we will tell you and may pause that processing while we resolve it. If a law requires us to process beyond your instructions, we will tell you first unless that law forbids it.
4.2 Keep it confidential. Everyone we allow to access Customer Personal Data is bound by a duty of confidentiality, is given access only where they need it for their role, and is trained on handling it.
4.3 Keep it secure. We maintain the technical and organisational measures in Annex 2, appropriate to the risk, in line with Article 32.
4.4 Control who else is involved. We engage subprocessors only on the terms in clause 6.
4.5 Help you answer the people whose data it is. See clause 7.
4.6 Help you meet your own obligations on security, breach notification, impact assessments, and prior consultation, taking into account what we know and the nature of the processing. See clauses 8 and 9.
4.7 Delete or return it when you stop using the services, as set out in clause 11.
4.8 Show our work. We will give you the information you reasonably need to show that we are meeting these obligations, and allow audits as set out in clause 10.
4.9 Never sell it. We do not sell Customer Personal Data, share it with advertisers, or use it to train machine learning models. We do not use it to build profiles for our own commercial purposes.
5. What you must do
5.1 You are responsible for having a lawful basis for the processing you instruct, for giving the people concerned the information they are entitled to, and for the accuracy of what you upload.
5.2 Marketing. Where you send marketing through the platform, you are responsible for the consent or legitimate interest you rely on, and for honouring objections and withdrawals. The platform records consent wording, timestamps, and the form version at the point of collection, and applies suppressions, but the lawful basis is yours.
5.3 Imported lists. When you import contacts you confirm that you may lawfully send to them. We record that confirmation with the import. Importing a list you cannot lawfully use is a breach of this DPA.
5.4 Free-text and custom fields, which matter more than they look. Several parts of the platform let you ask your audience anything you like: questions on your checkout, questions on your forms, and notes fields throughout. We cannot see in advance what you will ask. If you use them to collect special category data, for example health conditions, accessibility needs, dietary requirements that reveal health or religion, or data about children, then:
- you must have an Article 9 condition for it, and identify it in your own records;
- you must tell the people concerned what you are collecting and why, before they give it; and
- you should collect it only where you genuinely need it, and mark it as personal data in the question settings so our erasure tooling removes it on request.
5.5 Volunteer records. The volunteer features are built to hold date of birth, emergency contacts, dietary requirements, and qualifications including safeguarding and DBS checks. That is special category data, third-party data, and potentially data about children. You are the controller for all of it. You must have a lawful basis and an Article 9 condition, you must tell emergency contacts that you have recorded their details, and where you record criminal records information you need an appropriate policy document under Schedule 1 of the Data Protection Act 2018.
5.6 What you switch on. Where you connect your own advertising pixel, WhatsApp Business account, social accounts, or webhook destination, you are instructing a transfer to that third party and you are responsible for it. See the third group on the subprocessors page.
5.7 Your team. You are responsible for who you invite into your account and what you let them see. The platform provides roles and per-member permissions for this.
6. Subprocessors
6.1 Authorisation. You give us general written authorisation to engage subprocessors. The current list is published at https://events.grofomo.com/subprocessors and is Annex 3 to this DPA. It is maintained as the canonical record and is complete at all times.
6.2 Terms we impose. We put each subprocessor under written terms that offer protection equivalent to this DPA. We remain fully liable to you for what our subprocessors do.
6.3 Notice. We give you at least 30 days notice before a new subprocessor starts processing Customer Personal Data, by email to your billing address. Where a change is needed urgently to keep the service running or secure, we may make it immediately and will tell you as soon as we reasonably can.
6.4 Objection. If you have a reasonable data protection objection, tell us within the notice period. We will work with you to find a way forward. If we cannot, you may stop using the affected part of the service, or terminate the affected services without penalty and receive a refund of any fees paid in advance for the unused period.
6.5 What this clause does not cover. Services you connect yourself are not subprocessors we appoint, and clauses 6.1 to 6.4 do not apply to them. They are listed separately for transparency.
7. Requests from the people whose data it is
7.1 Taking into account the nature of the processing, we help you respond to requests to exercise rights under Chapter III of the UK GDPR, through the following, at no additional charge:
- Access and portability. We can produce a structured export of everything the platform holds about a ticket buyer or contact.
- Erasure. We can erase a person from your account specifically, leaving their relationship with other organisers untouched, or from the platform entirely. Erasure removes identifying details and withdraws and logs consent across every channel.
- Rectification and restriction. Contact records are editable in the console, and marketing can be suppressed per channel.
- Objection to marketing. Every marketing email carries an unsubscribe link, replying STOP ends SMS, and WhatsApp opt-outs are honoured automatically. These work without you doing anything.
7.2 If a request reaches us directly and relates to your account, we will not respond to it on your behalf. We will tell you promptly and let the person know they should contact you, unless answering ourselves is clearly the right thing for that person and is consistent with your instructions.
7.3 Some records survive an erasure by design, because removing them would defeat the purpose of holding them:
- The financial record of a sale, without identifying details, is kept for tax and accounting purposes and to reconcile with the payment provider. We are required to keep these.
- Consent and provenance records are kept as evidence that consent was given and later withdrawn. Destroying them would destroy the only proof that the processing was lawful, and they are relied on for the establishment or defence of legal claims under Article 17(3)(e).
Neither of these is used to contact the person again, and both are stripped of identifying details wherever the record still serves its purpose without them.
8. Personal data breaches
8.1 We will tell you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 Our notice will describe what we know: the nature of the breach, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose. Where we do not have all of it at once, we will send what we have and follow up.
8.3 We will help you meet your own obligations to notify the Information Commissioner and, where required, the people affected. We will not notify the Commissioner on your behalf unless you ask us to.
8.4 Notifying you is not an admission of fault by either of us.
9. Impact assessments
9.1 On request, we will give you reasonable help with data protection impact assessments and with prior consultation of the Information Commissioner, limited to the processing we carry out for you and to information we hold.
9.2 Annex 1 and Annex 2 are written to be usable directly in an assessment.
10. Audits
10.1 On request, and no more than once a year unless there has been a personal data breach affecting you or the Commissioner requires it, we will give you the information reasonably necessary to demonstrate compliance with this DPA. In the first instance this means our documented security measures and answers to a reasonable security questionnaire.
10.2 Where that genuinely is not enough, you may audit us, or appoint an independent auditor who is not a competitor of ours to do so, on 30 days written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear the cost, unless the audit reveals a material breach of this DPA by us, in which case we do.
10.3 An audit may not extend to another customer data, to our personnel records, or to anything that would put us in breach of a duty we owe someone else.
11. Deletion and return
11.1 While you are a customer, you can export your data at any time from the console.
11.2 When you stop using the services, we will, at your choice, return Customer Personal Data to you in a structured, commonly used, machine readable format, or delete it. You have 30 days from termination to tell us which and to retrieve anything you want. After 90 days we delete it, unless we are required by law to keep it.
11.3 Retention while you are still with us. The platform applies retention periods automatically, and several are yours to set:
- Ticket buyer records are anonymised after your retention window, which defaults to seven years to match tax record-keeping, and which you can shorten.
- People who started a checkout and never completed it are anonymised after 180 days, because there is no basis for keeping their details.
- Pre-sale registrations are deleted after the window set for that event, which defaults to two years.
- WhatsApp message content is redacted after your inbox retention window, which defaults to 24 months.
- Short-link click records are deleted after 400 days, and checkout analytics 180 days after the event ends.
11.4 Backups are overwritten on a rolling cycle and are fully replaced within 60 days. Data in a backup is not restored to live use except to recover from an incident.
12. International transfers
12.1 Customer Personal Data is stored in the United Kingdom.
12.2 Some processing takes place outside the United Kingdom, as set out for each provider on the subprocessors page. Where it does, we rely on the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, or the UK Extension to the EU-US Data Privacy Framework where the provider is certified under it.
12.3 Where the Standard Contractual Clauses apply and you are the data exporter, you appoint us to enter into them with the relevant provider on your behalf, in the module appropriate to the transfer.
12.4 We carry out transfer risk assessments where required, and will provide them on request under clause 10.
13. Liability, changes, and law
13.1 Each party liability under this DPA is subject to the limitations and exclusions in our agreement with you. Nothing in this DPA limits liability that cannot lawfully be limited, and nothing in it affects any right a data subject has to compensation.
13.2 We may update this DPA where the law changes, where we change how the platform works, or to make it clearer. Where a change materially reduces your rights, we will give you at least 30 days notice by email before it takes effect. The version number and date at the top always reflect the current text.
13.3 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: what we process for you
Subject matter and duration
Providing the Grofomo platform to you: ticketing, customer records, marketing and messaging, artist and lineup management, and event operations. Processing lasts for as long as you are a customer, plus the periods in clause 11.
Nature and purpose
Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to the recipients you nominate, restriction, erasure and destruction, for the purpose of selling tickets to your events, admitting people to them, communicating with your audience, and running your event operations.
Categories of data subject
- Ticket buyers and attendees, including people named on a ticket by someone else
- Mailing list subscribers and pre-sale registrants
- Contacts you import or add
- People who message you on WhatsApp
- Your team members
- Artists and their representatives
- Volunteers, and the emergency contacts they give you
- Suppliers and vendors, including sole traders
- Guest list entries and their guests
- Affiliates and ambassadors who sell on your behalf
Categories of personal data
- Identity and contact. Name, email address, phone number, and for merchandise orders a postal address.
- Transaction. Orders, tickets, amounts, payment plan status, promotional and affiliate codes, refunds. Card details are handled by our payment provider and never reach our systems.
- Consent and marketing. Per-channel permissions, the exact wording shown at the time, the lawful basis relied on, timestamps, the form and version used, and the IP address and browser at the moment of collection.
- Communications. Email, WhatsApp, and push message content and delivery status, and inbound replies.
- Event operations. Check-in records, guest lists, volunteer records, supplier records, and answers to your custom questions.
- Technical. IP address at the point of order, consent, or check-in, browser and device information, locale, and a pseudonymous device identifier for mobile app users.
- Media. Photographs and video uploaded by you or submitted by attendees, which will usually show identifiable people.
Special category data
The platform does not require special category data and we do not ask for it. It can nonetheless arise in three places, and clause 5 puts responsibility for it with you:
- Volunteer records: date of birth, dietary requirements, and safeguarding or DBS qualifications
- Custom checkout and form questions, where you choose to ask
- Free-text notes and artist rider or hospitality fields
Children
The platform is not directed at children under 13. Buying a ticket requires you to be 18 or over. Data about children can still arise: a parent naming a child on a ticket, a young performer, or a volunteer under 18, which the volunteer features expressly support through an under-18 flag. Where you process it, you are the controller and additional protections apply.
Frequency
Continuous, for as long as the services are in use.
Annex 2: how we keep it secure
These are the technical and organisational measures required by Article 32. They are reviewed as the platform changes.
Access control
- Every table in the database enforces row-level security, so a query can only ever return rows the requesting account is entitled to. Access is decided by the database, not only by the application.
- Access is scoped to an organisation and, where you configure it, to a specific event, a role template, or an individual permission.
- Administrative access is restricted to named staff, requires a separate privileged flag on the account, and is enforced at the routing layer rather than only in the interface.
- Sign-in supports one-time email links and Google or Apple accounts. Credentials are handled by our authentication provider and passwords are never stored by us.
Encryption
- All traffic is encrypted in transit with TLS. Data is encrypted at rest.
- Third-party access tokens, such as the credentials for a connected social or WhatsApp account, are encrypted with AES-256-GCM before storage.
- Secrets are held in environment-scoped stores, never in source control, and differ per environment.
- One-time codes and API secrets are stored as hashes and cannot be recovered from our systems.
Data minimisation and separation
- File storage is separated into public and private buckets. Private buckets have no direct client access at all: every read is a short-lived signed link and every write goes through the server.
- Link analytics deliberately discard the IP address before writing. Only the referring site, a coarse device class, and a two-letter country are kept.
- Install attribution uses a salted hash of the IP address with a 60 minute lifetime. The raw address is never written.
- Location is never collected. There is no GPS, and analytics resolve no finer than country.
Integrity and accountability
- Consent is recorded in append-only ledgers, per person, per channel, per organisation, with the wording as shown and a version stamp. Changing history is not possible.
- Scheduled jobs are authenticated with a shared secret and are written to be safe to re-run, so a retry cannot duplicate a send.
- Bulk sends record a per-recipient ledger row, so a retry never sends twice.
- Public forms are protected against automated abuse and are rate limited.
Resilience
- The database is managed, with automated backups and point-in-time recovery, in the United Kingdom.
- Application hosting is redundant, with automatic failover and rollback.
- Restoration from backup is tested.
Organisational
- Staff and contractors are bound by written confidentiality obligations.
- Access follows least privilege and is removed when a role ends.
- Changes to the platform go through review and automated checks before release, including checks that specifically guard data protection behaviour.
- Subprocessors are assessed before engagement and are covered by written data protection terms.
Annex 3: subprocessors
The current list is published and maintained at https://events.grofomo.com/subprocessors, including for each provider what it does, what data it can reach, where it processes, and the transfer safeguard relied on. That page forms part of this DPA.
Contact
Deuce Creative Limited, a company registered in England and Wales, company number 07991249.
Unit 8 Great Bramshot Farm Barns
Bramshot Lane
Fleet
Hampshire
GU51 2SF
United Kingdom
Data protection enquiries: privacy@grofomo.com