Version V1.1 · Effective date: 06.10.2026
1.1 As part of the Subscriber's wish to use of the Bong Events' web-based administration portal (the "Services"), Bong Events (the "Processor") will process certain personal data on behalf of the customer (the "Controller"), each a "Party" and jointly the "Parties".
1.2 The purpose of this data processing agreement (the "DPA") is to set out the rights and obligations of the Parties concerning the Processor's processing of personal data on behalf of the Controller in order to provide Services pursuant to the at all times applicable terms and conditions of the Services (the "Agreement").
1.3 This DPA does not govern personal data that the Processor processes on its own behalf (as a controller), such as for bookkeeping purposes and customer relation purposes.
1.4 In the event of inconsistency between the terms of the Agreement and the DPA on matters specifically concerning data protection, the latter shall prevail.
2.1 In this DPA, the following terms shall have the meanings set out below.
3.1 Each Party shall comply with its obligations under Applicable Data Protection Law.
3.2 The Controller warrants that the personal data is processed for legitimate and objective purposes and that the Processor does not process more personal data than required for fulfilling such purposes. The Controller is responsible for ensuring that a valid legal basis for processing exists and that the data subjects are informed about the processing covered by this DPA in accordance with Applicable Data Protection Law.
3.3 The Controller hereby instructs the Processor to process personal data solely for the purposes and within the scope as set out in Annex 1 and otherwise in accordance with this DPA.
3.4 The Processor shall immediately inform the Controller in writing if, in its reasonable opinion, (i) an instruction from the Controller infringes Applicable Data Protection Law, or (ii) a legal requirement laid down by EEA law to which the Processor is subject requires the Processor to process personal data beyond the scope of the Controller's documented instructions, unless that law prohibits such information on important grounds of public interest (if so, the Processor shall inform the Controller as soon as permitted by law).
4.1 The Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to and comply with requests for exercising the data subject's rights laid down in Applicable Data Protection Law, including chapter III of the GDPR.
4.2 Taking into account the nature of processing and the information available to the Processor, the Processor shall assist the Controller in ensuring compliance with Article 32 to 36 of the GDPR, including the obligations of data security, personal data breach notification, data protection impact assessments and prior consultation with supervisory authorities.
4.3 The Processor shall not engage in any direct communication with data subjects or supervisory authorities, unless approved in advance by the Controller or required by applicable law. The Processor shall, without undue delay, forward to the Controller any request or complaint received from a data subject or a supervisory authority concerning the processing of personal data under this DPA, unless prohibited by applicable law (if so, the Processor shall inform the Controller as soon as permitted by such law).
4.4 The Controller shall bear any costs accrued by the Processor related to such assistance as set out in this clause 4.
5.1 The Processor shall implement and maintain throughout the term appropriate technical and organisational data security measures to protect the personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access pursuant to Article 32 of the GDPR, and as set out or referred to in Annex 2. The Processor may from time to time amend these security measures, provided that the amendments will not adversely affect the level of data security.
5.2 The Processor shall limit the access to the personal data to its personnel on a need-to-know basis. The Processor shall ensure that the personnel have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that the confidentiality also applies after the termination of the DPA.
6.1 The Processor shall only use Sub-processors upon the Controller's consent. The Controller has consented to the Sub-processors listed in Annex 3.
6.2 If the Processor intends to make changes by adding or replacing Sub-processors (including changes in processing locations of approved Sub-processors), the Processor shall notify the Controller about such intended change to enable the Controller to consider whether to object to such change. If the Controller does not consent to the change, the Controller must object to such change within three weeks from the Processor's notification. The Controller will be deemed to have consented to the change unless such objection is provided to the Processor within this time limit.
6.3 The Processor must ensure that materially the same data protection obligations as set out in this DPA are imposed upon any Sub-processor by a written agreement.
6.4 The Processor shall not in any way be liable for any processing carried out by the Sub-processor as a result of instructions received by the Sub-processor directly from the Controller.
7.1 The Processor must only transfer personal data to any Third Country after general consent from the Controller following the procedure set out in section 6.2 of this DPA. Processor shall at all times keep an updated list of Sub-processors in third countries.
7.2 If the Processor transfers personal data to a Third Country, the Processor shall ensure that the requirements of Applicable Data Protection Law regarding data transfers, including Chapter V of the GDPR, are complied with. Upon the Controller's reasonable request, the Processor shall provide the Controller with evidence that such requirements are complied with, including copies of Standard Contractual Clauses and/or transfer impact assessments (commercial terms may be redacted).
8.1 In the event of a personal data breach, the Processor shall without undue delay after becoming aware of it notify the Controller in writing about the breach. The notice shall contain all such information the Controller may reasonably require to enable the Controller to comply with its obligations pursuant to Article 33 and Article 34 of the GDPR, provided that the Processor possesses or may reasonably obtain such information.
8.2 The Processor shall without undue delay take adequate measures to address the personal data breach, including, where appropriate, reasonable measures aiming to mitigate its possible adverse effects and to avoid the re-occurrence of similar breaches.
8.3 The Controller is solely entitled to notify the supervisory authority and the data subjects about a personal data breach. The Processor shall refrain from communicating a personal data breach to the public or any third party, unless it is required to do so under Applicable Data Protection Law or unless the Controller has given its prior written approval.
9.1 The Processor shall maintain necessary records and make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law.
9.2 The Processor shall allow for and contribute to audits, including inspections, of the Processor's processing operations. The Controller may perform the audit itself or by use of a third-party auditor, subject to appropriate confidentiality undertakings. The request for audit shall be given in writing with a notice period of at least three weeks, unless otherwise is required under Applicable Data Protection Law. Audits cannot be requested more than once a year, unless the Controller has a particular reason to request additional audits on an ad-hoc basis. To the extent reasonably possible, the audits shall be conducted within ordinary working hours and without obstructing the Processor's activities.
9.3 Authorities who supervise the Controller have a right to request information from and to conduct audits of the Processor to the same extent as the Controller.
9.4 The Controller shall bear any costs related to audits initiated by the Controller or accrued in relation to audits of the Controller, including compensation to Processor for reasonable time spent by it and its employees complying with on premises audits. However, if an audit reveals material deviations from the obligations set out in Applicable Data Protection Law or this DPA caused by the Processor or any Sub-processor, the Processor's costs of the audit shall be borne by the Processor.
10.1 The Parties' liabilities are governed by the Agreement.
11.1 This DPA remains in force as long as the Processor is processing personal data on behalf of the Controller under the Agreement.
11.2 If the Processor has not implemented appropriate technical and organisational measures in such a manner that processing will meet the requirements of the GDPR, the Controller may terminate the DPA if the Processor has not implemented such measures within one month after the Controller's notification thereof.
11.3 Upon expiry or termination, the Processor shall, at the choice of the Controller, delete or return to the Controller the personal data. If the Controller chooses deletion, the Processor shall verify to the Controller that it has done so.
11.4 Notwithstanding the foregoing, the Processor is entitled to continue storing the personal data to the extent required to comply with applicable law, or to the extent it follows from the Processor's general backup routines, provided that clause 5 continues to apply for such data, and provided that the Processor does not actively process such data.
12.1 This DPA shall be governed by the laws of Norway and disputes shall be settled in accordance with the Agreement.
Purpose of the processing:
The Processor shall process personal data on behalf of the Controller for the purpose of providing, operating, and maintaining the Services. This includes enabling the issuance, management, redemption, transfer, and administration of digital vouchers for food and beverages at events; ensuring proper functioning of the Services; facilitating customer and technical support; enabling correction or reversal of voucher transactions; generating aggregated statistics for reporting and invoicing; and ensuring compliance with applicable accounting, security, and data protection obligations.
Nature of the processing:
The processing activities comprise collection, registration, storage, and deletion of personal data as necessary to deliver and maintain the Services in accordance with the Controller's instructions. The Processor shall perform automated deletion or anonymisation of personal data following expiry of the applicable retention period or upon termination of the Agreement, unless otherwise required by law.
Categories of data:
Categories of data subjects:
The Processor will take those measures set out below for the purpose of adequately protecting the personal data described in Annex 1 above.
Confidentiality measures
Integrity measures
Availability measures
Microsoft Ireland Operations Ltd. One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Fly.io Inc. 651 N Broad St, Suite 206, Middletown, DE 19709, USA
Resend, Inc. 2261 Market Street #4376, San Francisco, CA 94114, USA
PostHog, Inc. 2261 Market St., #4008, San Francisco, CA 94114, USA
GatewayAPI ApS Njalsgade 21E, 2300 København S, Denmark
Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland