Data Processing Agreement

Version V1.1 · Effective date: 06.10.2026

1. Background and purpose

1.1 As part of the Subscriber's wish to use of the Bong Events' web-based administration portal (the "Services"), Bong Events (the "Processor") will process certain personal data on behalf of the customer (the "Controller"), each a "Party" and jointly the "Parties".

1.2 The purpose of this data processing agreement (the "DPA") is to set out the rights and obligations of the Parties concerning the Processor's processing of personal data on behalf of the Controller in order to provide Services pursuant to the at all times applicable terms and conditions of the Services (the "Agreement").

1.3 This DPA does not govern personal data that the Processor processes on its own behalf (as a controller), such as for bookkeeping purposes and customer relation purposes.

1.4 In the event of inconsistency between the terms of the Agreement and the DPA on matters specifically concerning data protection, the latter shall prevail.

2. Definitions

2.1 In this DPA, the following terms shall have the meanings set out below.

  • "Applicable Data Protection Law": Any applicable data protection and privacy law, including but not limited to the GDPR, or any law replacing or supplementing the GDPR, and local law implementing the GDPR.
  • "EEA": The European Economic Area.
  • "GDPR": The EU General Data Protection Regulation 2016/679.
  • "Standard Contractual Clauses": The standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, issued by the European Commission on 4 June 2021 and/or laid down by the European Commission or a relevant supervisory authority in accordance with Article 46(2)(c) or 46(2)(d) of the GDPR.
  • "Sub-processor": Another processor engaged by the Processor for the processing of personal data on behalf of the Controller.
  • "Third Country": A non-EEA country that is not approved by the EU Commission as having an adequate level of data protection (adequacy decision), or an international organisation.
  • Other terms shall have the meaning as given to them in the GDPR.

3. General obligations

3.1 Each Party shall comply with its obligations under Applicable Data Protection Law.

3.2 The Controller warrants that the personal data is processed for legitimate and objective purposes and that the Processor does not process more personal data than required for fulfilling such purposes. The Controller is responsible for ensuring that a valid legal basis for processing exists and that the data subjects are informed about the processing covered by this DPA in accordance with Applicable Data Protection Law.

3.3 The Controller hereby instructs the Processor to process personal data solely for the purposes and within the scope as set out in Annex 1 and otherwise in accordance with this DPA.

3.4 The Processor shall immediately inform the Controller in writing if, in its reasonable opinion, (i) an instruction from the Controller infringes Applicable Data Protection Law, or (ii) a legal requirement laid down by EEA law to which the Processor is subject requires the Processor to process personal data beyond the scope of the Controller's documented instructions, unless that law prohibits such information on important grounds of public interest (if so, the Processor shall inform the Controller as soon as permitted by law).

4. Assistance to the controller

4.1 The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to and comply with requests for exercising the data subject's rights laid down in Applicable Data Protection Law, including chapter III of the GDPR.

4.2 Taking into account the nature of processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with Article 32 to 36 of the GDPR, including the obligations of data security, personal data breach notification, data protection impact assessments and prior consultation with supervisory authorities.

4.3 The Processor shall not engage in any direct communication with data subjects or supervisory authorities, unless approved in advance by the Controller or required by applicable law. The Processor shall, without undue delay, forward to the Controller any request or complaint received from a data subject or a supervisory authority concerning the processing of personal data under this DPA, unless prohibited by applicable law (if so, the Processor shall inform the Controller as soon as permitted by such law).

4.4 The Controller shall bear any costs accrued by the Processor related to such assistance as set out in this clause 4.

5. Technical and organisational security measures

5.1 The Processor shall implement and maintain throughout the term appropriate technical and organisational data security measures to protect the personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access pursuant to Article 32 of the GDPR, and as set out or referred to in Annex 2. The Processor may from time to time amend these security measures, provided that the amendments will not adversely affect the level of data security.

5.2 The Processor shall limit the access to the personal data to its personnel on a need-to-know basis. The Processor shall ensure that the personnel have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that the confidentiality also applies after the termination of the DPA.

6. Use of sub-processors

6.1 The Processor shall only use Sub-processors upon the Controller's consent. The Controller has consented to the Sub-processors listed in Annex 3.

6.2 If the Processor intends to make changes by adding or replacing Sub-processors (including changes in processing locations of approved Sub-processors), the Processor shall notify the Controller about such intended change to enable the Controller to consider whether to object to such change. If the Controller does not consent to the change, the Controller must object to such change within three weeks from the Processor's notification. The Controller will be deemed to have consented to the change unless such objection is provided to the Processor within this time limit.

6.3 The Processor must ensure that materially the same data protection obligations as set out in this DPA are imposed upon any Sub-processor by a written agreement.

6.4 The Processor shall not in any way be liable for any processing carried out by the Sub-processor as a result of instructions received by the Sub-processor directly from the Controller.

7. International data transfers

7.1 The Processor must only transfer personal data to any Third Country after general consent from the Controller following the procedure set out in section 6.2 of this DPA. Processor shall at all times keep an updated list of Sub-processors in third countries.

7.2 If the Processor transfers personal data to a Third Country, the Processor shall ensure that the requirements of Applicable Data Protection Law regarding data transfers, including Chapter V of the GDPR, are complied with. Upon the Controller's reasonable request, the Processor shall provide the Controller with evidence that such requirements are complied with, including copies of Standard Contractual Clauses and/or transfer impact assessments (commercial terms may be redacted).

8. Personal data breaches

8.1 In the event of a personal data breach, the Processor shall without undue delay after becoming aware of it notify the Controller in writing about the breach. The notice shall contain all such information the Controller may reasonably require to enable the Controller to comply with its obligations pursuant to Article 33 and Article 34 of the GDPR, provided that the Processor possesses or may reasonably obtain such information.

8.2 The Processor shall without undue delay take adequate measures to address the personal data breach, including, where appropriate, reasonable measures aiming to mitigate its possible adverse effects and to avoid the re-occurrence of similar breaches.

8.3 The Controller is solely entitled to notify the supervisory authority and the data subjects about a personal data breach. The Processor shall refrain from communicating a personal data breach to the public or any third party, unless it is required to do so under Applicable Data Protection Law or unless the Controller has given its prior written approval.

9. Audits

9.1 The Processor shall maintain necessary records and make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law.

9.2 The Processor shall allow for and contribute to audits, including inspections, of the Processor's processing operations. The Controller may perform the audit itself or by use of a third-party auditor, subject to appropriate confidentiality undertakings. The request for audit shall be given in writing with a notice period of at least three weeks, unless otherwise is required under Applicable Data Protection Law. Audits cannot be requested more than once a year, unless the Controller has a particular reason to request additional audits on an ad-hoc basis. To the extent reasonably possible, the audits shall be conducted within ordinary working hours and without obstructing the Processor's activities.

9.3 Authorities who supervise the Controller have a right to request information from and to conduct audits of the Processor to the same extent as the Controller.

9.4 The Controller shall bear any costs related to audits initiated by the Controller or accrued in relation to audits of the Controller, including compensation to Processor for reasonable time spent by it and its employees complying with on premises audits. However, if an audit reveals material deviations from the obligations set out in Applicable Data Protection Law or this DPA caused by the Processor or any Sub-processor, the Processor's costs of the audit shall be borne by the Processor.

10. Liability

10.1 The Parties' liabilities are governed by the Agreement.

11. Term and termination

11.1 This DPA remains in force as long as the Processor is processing personal data on behalf of the Controller under the Agreement.

11.2 If the Processor has not implemented appropriate technical and organisational measures in such a manner that processing will meet the requirements of the GDPR, the Controller may terminate the DPA if the Processor has not implemented such measures within one month after the Controller's notification thereof.

11.3 Upon expiry or termination, the Processor shall, at the choice of the Controller, delete or return to the Controller the personal data. If the Controller chooses deletion, the Processor shall verify to the Controller that it has done so.

11.4 Notwithstanding the foregoing, the Processor is entitled to continue storing the personal data to the extent required to comply with applicable law, or to the extent it follows from the Processor's general backup routines, provided that clause 5 continues to apply for such data, and provided that the Processor does not actively process such data.

12. Governing law and legal venue

12.1 This DPA shall be governed by the laws of Norway and disputes shall be settled in accordance with the Agreement.

Annex 1 – Scope of the processing

Purpose of the processing:

The Processor shall process personal data on behalf of the Controller for the purpose of providing, operating, and maintaining the Services. This includes enabling the issuance, management, redemption, transfer, and administration of digital vouchers for food and beverages at events; ensuring proper functioning of the Services; facilitating customer and technical support; enabling correction or reversal of voucher transactions; generating aggregated statistics for reporting and invoicing; and ensuring compliance with applicable accounting, security, and data protection obligations.

Nature of the processing:

The processing activities comprise collection, registration, storage, and deletion of personal data as necessary to deliver and maintain the Services in accordance with the Controller's instructions. The Processor shall perform automated deletion or anonymisation of personal data following expiry of the applicable retention period or upon termination of the Agreement, unless otherwise required by law.

Categories of data:

  • First name and last name
  • Phone number
  • Email address
  • Voucher information
  • Support-related communication and transactional data necessary to fulfil user support or correction requests
  • Data that the Controller or the data subjects provide through use of the Services
  • Additional data categories that the Controller might provide (e.g. reports or other text files)

Categories of data subjects:

  • Guests and participants attending events organised by the Controller or customers of the Controller
  • Employees, representatives, and contractors of the Controller with access to the administrative interface
  • Event staff or partners authorised by the Controller to manage guests and vouchers

Annex 2 – Technical and organizational security measures

The Processor will take those measures set out below for the purpose of adequately protecting the personal data described in Annex 1 above.

Confidentiality measures

  • Access to personal data is restricted to authorised personnel who require such access to perform their duties in relation to the Services.
  • User authentication to systems and databases is protected through secure password policies and, where applicable, multi-factor authentication.
  • All access to production systems containing personal data is logged and monitored.
  • Personal data is encrypted in transit and encrypted at rest within the cloud environment.
  • The Services are hosted on a cloud provider located within the EEA, which maintains appropriate security certifications.

Integrity measures

  • System and administrative activities are logged to enable traceability in the event of an incident.
  • Regular software updates and security patches are applied to the Services and underlying infrastructure.

Availability measures

  • The Services are operated on cloud infrastructure with redundancy and built-in resilience.
  • Regular backups of essential data are performed and stored securely within the EEA.
  • Monitoring is in place to detect outages or technical incidents.

Annex 3 – Approved sub-processors

Microsoft Ireland Operations Ltd. One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland

  • Service: Cloud infrastructure and hosting services (Microsoft Azure)
  • Safeguard: N/A – Processing within the EEA

Fly.io Inc. 651 N Broad St, Suite 206, Middletown, DE 19709, USA

  • Service: Application hosting
  • Safeguard: Standard Contractual Clauses

Resend, Inc. 2261 Market Street #4376, San Francisco, CA 94114, USA

  • Service: Email delivery for notifications and support
  • Safeguard: Standard Contractual Clauses

PostHog, Inc. 2261 Market St., #4008, San Francisco, CA 94114, USA

  • Service: Product analytics, error tracking, session replay and AI-assisted issue analysis (PostHog Cloud EU, hosted in Frankfurt, Germany)
  • Safeguard: EU-U.S. Data Privacy Framework and Standard Contractual Clauses

GatewayAPI ApS Njalsgade 21E, 2300 København S, Denmark

  • Service: SMS delivery services for voucher distribution and user communication
  • Safeguard: N/A – Processing within the EEA

Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland

  • Service: Internal communication, email, and document management (Google Workspace)
  • Safeguard: N/A – Processing within the EEA