Version 1.0 | Effective July 17, 2026 | Controlling language: English
This Data Protection Addendum (the "DPA") forms part of, and is incorporated by reference into, the AFICH Organizer Agreement between AFICH LLC, a Delaware limited liability company ("AFICH," "we," "us"), and the organizer that creates, publishes, or manages events on the AFICH platform (the "Organizer," "you"). AFICH and the Organizer are each a "Party" and together the "Parties."
This DPA governs how the Organizer handles the personal data of attendees, buyers, and guests (together, "Attendees") that the Organizer receives through the AFICH platform, and it sets out each Party's data-protection roles and obligations. It is designed to help both Parties meet their obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), together with other applicable data protection laws.
What this means: AFICH runs the ticketing technology and payment facilitation. When you sell tickets, you receive real personal data about your Attendees. This DPA is the contract that says what you are allowed to do with that data, what you must protect, and who is responsible for what. It is written to line up with the main privacy laws that apply to events sold on AFICH. It does not make AFICH your lawyer, and it does not replace your own legal advice.
Capitalized terms not defined here have the meaning given in the Organizer Agreement or in applicable Data Protection Law.
1.1 "Applicable Data Protection Law" means all privacy, data protection, and data security laws that apply to a Party's processing of Attendee Personal Data, including the GDPR, the UK GDPR, and the CCPA/CPRA, and any implementing or successor legislation.
1.2 "Attendee Personal Data" means personal data / personal information relating to Attendees that the Organizer receives, accesses, or processes through the AFICH platform, including name, email address, order and purchase records, check-in and scan records, seat and ticket assignments, and any data the Organizer exports (for example, CSV or reporting exports).
1.3 "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," "Processing," and "Supervisory Authority" have the meanings given in the GDPR (and their equivalents under the UK GDPR).
1.4 "Business," "Consumer," "Contractor," "Sell," "Share," "Service Provider," and "Personal Information" have the meanings given in the CCPA/CPRA.
1.5 "Platform Services" means the ticketing, access-control, event-management, payment-facilitation, and related technology services AFICH provides to the Organizer under the Organizer Agreement.
1.6 "Sub-processor" means any third party engaged by a Processor (or Service Provider) to process Personal Data on its behalf.
1.7 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to third countries; "UK Addendum" means the UK International Data Transfer Addendum to the EU SCCs (or the UK International Data Transfer Agreement, the "UK IDTA"), as applicable.
What this means: These are the shared definitions so we both use the same words the same way. "Attendee Personal Data" is the specific set of buyer/attendee data you get through AFICH- that is the data this DPA is about.
2.1 Organizer as Controller. With respect to Attendee Personal Data that the Organizer receives through the platform and uses for its own purposes- running its events, communicating with Attendees, access control at the door, and (with a valid lawful basis) its own marketing- the Organizer acts as an independent Controller (and, under CCPA/CPRA, as a Business). The Organizer decides the purposes and means of that processing for its own account.
2.2 AFICH as Processor / Service Provider. With respect to Attendee Personal Data that AFICH processes on the Organizer's behalf solely to provide the Platform Services (for example, storing the Organizer's Attendee list, generating the Organizer's check-in records, and producing the Organizer's exports), AFICH acts as a Processor and, under CCPA/CPRA, as a Service Provider to the Organizer, and processes that data only on the Organizer's documented instructions as set out in the Organizer Agreement, this DPA, and the platform's configuration.
2.3 AFICH as Controller of its own Platform Data. AFICH also processes Attendee-related data as an independent Controller for its own purposes, including operating and securing the platform, facilitating payments through Stripe Connect, fraud and risk detection, dispute and chargeback handling, meeting AFICH's own legal, tax, and regulatory obligations, and improving the Platform Services. AFICH's processing as a Controller is governed by the AFICH Privacy Policy, not by the Organizer's instructions.
2.4 Joint controllership (limited). In some flows the Parties may jointly determine certain purposes and means (for example, aspects of the checkout and ticket-delivery experience presented to a buyer). To the extent a processing activity is found to be joint controllership under Article 26 GDPR, the Parties will act in accordance with a joint-controller arrangement describing their respective responsibilities, and the essence of that arrangement will be made available to Data Subjects.
2.5 Payment and regulated functions run through Stripe Connect. Payment processing, payment-method data, KYC/AML checks, and money movement are performed by Stripe through Stripe Connect. AFICH is not a bank, money transmitter, or money-services business; the Organizer is the seller/merchant of its own events. Stripe acts as an independent Controller (and/or processor) for the payment data it handles under its own terms and privacy notices.
What this means: For the data you use to run your own events and marketing, you are the boss of that data (an independent Controller / Business) and you carry the matching legal duties. When AFICH is just holding or moving that data to run the platform for you, AFICH acts as your Processor / Service Provider and follows your instructions. Separately, AFICH is its own Controller for things like security, fraud, and legal compliance, governed by AFICH's Privacy Policy. Card and identity-verification data goes through Stripe, not AFICH.
3.1 Permitted purposes. The Organizer may process Attendee Personal Data only for legitimate event and business purposes connected to the events the Organizer runs on AFICH, including:
3.2 Purpose limitation. The Organizer will not process Attendee Personal Data for any purpose that is incompatible with the purpose for which it was collected, and will not use it for unrelated products, unrelated third parties, or any purpose the Attendee would not reasonably expect.
3.3 No unlawful or deceptive use. The Organizer will not use Attendee Personal Data to unlawfully discriminate, to build or enrich profiles unrelated to the event, or in any way that is deceptive, harmful, or prohibited by Applicable Data Protection Law.
3.4 Onward disclosures. The Organizer will not disclose Attendee Personal Data to any third party except (a) to its own service providers/processors under a written contract meeting Section 8, (b) where required by law, or (c) with the Attendee's consent or another valid lawful basis.
What this means: Use Attendee data to run the event you sold, and to serve your customers. Do not repurpose it- no selling it on, no unrelated campaigns, no uses the Attendee would find surprising. Marketing is allowed, but only if you have a proper legal basis (and consent where the law requires it).
As an independent Controller / Business, the Organizer is responsible for its own compliance with Applicable Data Protection Law, including the following.
4.1 Lawful basis. The Organizer will identify and maintain a valid lawful basis (GDPR Article 6, and where relevant Article 9 for special-category data) for each processing activity it carries out, and will be able to demonstrate it.
4.2 Notice and transparency. The Organizer will provide Attendees with its own clear, accurate privacy notice describing who the Organizer is, what it does with Attendee data, the lawful bases, retention, and how Attendees can exercise their rights. AFICH's Privacy Policy does not satisfy the Organizer's own notice obligations.
4.3 Consent for marketing. Where the Organizer sends marketing or promotional communications, it will obtain and record any consent required by law (for example, GDPR/ePrivacy consent, or applicable US requirements such as CAN-SPAM opt-out), honor opt-outs and unsubscribe requests promptly, and not rely on AFICH platform contact permissions as a substitute for its own consent records.
What this means: Marketing consent is yours to get and yours to prove. If an Attendee unsubscribes, stop. You cannot point at AFICH and say "the platform let me email them."
4.4 Data-subject and consumer requests. For Attendee Personal Data the Organizer holds or controls, the Organizer is responsible for receiving and honoring Data Subject requests (access, rectification, erasure, restriction, portability, objection) and Consumer requests (know, delete, correct, opt-out of sale/sharing, limit use of sensitive PI) within the timelines required by law. AFICH will provide reasonable assistance under Section 11. That assistance may include AFICH platform administrators, acting on a verified request and with audit logging, correcting an attendee or order contact email and reassigning the affected order or ticket records so a rectification or correction request can be satisfied. AFICH's platform-side correction and reassignment are operated as controls to support the Organizer's request; they do not transfer to AFICH the Organizer's own legal responsibility to receive, verify, and answer the request within the required timelines.
What this means: If an Attendee tells you their email on a ticket or order is wrong, AFICH staff can correct or reassign that record for you after verifying identity, and the change is logged. You still own the request and its deadline.
4.5 Data minimization. The Organizer will collect and retain only the Attendee Personal Data it actually needs for the permitted purposes, and will not request additional Attendee data through the platform beyond what is necessary for its events.
4.6 Accuracy. The Organizer will take reasonable steps to keep Attendee Personal Data accurate and up to date for its purposes, and to correct or delete inaccurate data.
4.7 Accountability. The Organizer will maintain records of its processing activities as required by law, carry out data protection impact assessments where required, and cooperate with Supervisory Authorities as required.
4.8 Special-category and children's data. The AFICH platform is intended for users aged 18 and over. If the Organizer's events involve special-category data (Article 9 GDPR) or data relating to minors, the Organizer is solely responsible for meeting the additional legal conditions that apply, and will not use the platform to collect such data without a valid legal basis and appropriate safeguards.
What this means: As Controller you own the legal homework: pick a lawful basis, give Attendees your own privacy notice, get marketing consent where needed, answer their rights requests on time, collect only what you need, and keep it accurate. AFICH helps where it can, but the core duties are yours.
5.1 Appropriate technical and organizational measures. The Organizer will implement and maintain appropriate technical and organizational security measures to protect Attendee Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, and risks of the processing. At a minimum, the Organizer will:
5.2 Exports and offline copies. The Organizer is responsible for the security of any Attendee Personal Data it exports or downloads from the platform. Once data leaves the AFICH platform, AFICH cannot control it, and the Organizer bears responsibility for protecting it.
5.3 Personnel and vendors. The Organizer will ensure that its staff, volunteers, contractors, and vendors who handle Attendee Personal Data are bound by confidentiality and trained appropriately, and will flow down equivalent security obligations to its own processors.
What this means: The moment you download an Attendee list or scan tickets on a device, you are holding real personal data. Lock it down: limited access, MFA, encryption, no stray spreadsheets lying around, and delete copies you no longer need. If it leaves AFICH, protecting it is on you.
6.1 Organizer to AFICH. If the Organizer becomes aware of a Personal Data Breach affecting Attendee Personal Data obtained through the platform, the Organizer will notify AFICH without undue delay, and no later than seventy-two (72) hours after becoming aware, at privacy@afichtickets.com, with enough detail for AFICH to understand the nature, scope, and likely impact of the incident.
6.2 AFICH to Organizer. If AFICH becomes aware of a Personal Data Breach affecting Attendee Personal Data that AFICH processes as Processor on the Organizer's behalf, AFICH will notify the Organizer without undue delay and provide reasonable information to help the Organizer meet its own notification obligations.
6.3 Regulator and Data-Subject notifications. As independent Controller of the Attendee Personal Data it holds, the Organizer is responsible for making any required notifications to Supervisory Authorities (for example, within 72 hours under GDPR Article 33 where the threshold is met), to affected Data Subjects (Article 34), and under applicable US state breach-notification laws. The Parties will cooperate and coordinate so that notifications are consistent and not duplicative, and neither Party will name the other in a public notification without prior consultation except where legally required.
6.4 Records. Each Party will document the facts, effects, and remedial actions of Personal Data Breaches it is responsible for.
What this means: If Attendee data you hold is breached, tell AFICH fast (within 72 hours) and, where the law requires, tell the regulators and affected people yourself and on time. If AFICH's systems are breached in a way that affects data AFICH holds for you, AFICH will tell you and help. We coordinate so the story is consistent.
7.1 AFICH's Sub-processors. For the Platform Services it provides as Processor, AFICH may engage Sub-processors (including cloud hosting, communications, and Stripe for payments). AFICH will (a) impose data-protection and security obligations on each Sub-processor that are materially no less protective than this DPA, and (b) remain responsible to the Organizer for its Sub-processors' performance. AFICH maintains a list of its Sub-processors and will provide reasonable notice of intended changes so the Organizer can object on reasonable data-protection grounds.
7.2 Organizer's Sub-processors. Where the Organizer engages its own processors/service providers to handle Attendee Personal Data (for example, a CRM or email tool), the Organizer will enter into a written contract with each that imposes obligations equivalent to those in this DPA and Applicable Data Protection Law, and remains responsible for their acts and omissions.
What this means: AFICH uses a vetted set of vendors (including Stripe) under contract, keeps a list, and tells you before it changes. If you plug in your own tools to handle Attendee data, you must put them under equivalent contracts- and you stay responsible for them.
8.1 Cross-border transfers. Attendee Personal Data may be processed in, or transferred to, countries other than the one in which it was collected, including the United States. Each Party will ensure that any transfer of Attendee Personal Data it is responsible for is made in accordance with Applicable Data Protection Law.
8.2 Transfer mechanisms. Where a transfer is subject to the GDPR or UK GDPR and is made to a country without an adequacy decision, the transfer will be governed by an approved transfer mechanism, such as the EU Standard Contractual Clauses, the UK Addendum / UK IDTA, the Swiss addendum (where relevant), or reliance on an adequacy decision or an applicable data-transfer framework. The relevant SCCs (with completed annexes) are incorporated by reference and will control in the event of conflict with this DPA to the extent required by law.
8.3 Transfer impact. Each Party will cooperate to complete any transfer impact assessment reasonably required and to implement supplementary measures where necessary.
What this means: Data may move across borders, including to the US. When EU/UK law applies, the transfer has to ride on an approved legal mechanism (usually the SCCs or the UK IDTA). The applicable transfer clauses and completed annexes must match the final role mapping and transfer mechanism.
This Section applies to Attendee Personal Information subject to the CCPA/CPRA.
9.1 Roles. With respect to Attendee Personal Information the Organizer controls and uses for its own purposes, the Organizer is a Business. To the extent AFICH processes Attendee Personal Information on the Organizer's behalf to provide the Platform Services, AFICH acts as the Organizer's Service Provider / Contractor.
9.2 Service-Provider / Contractor restrictions. When acting as the Organizer's Service Provider / Contractor, AFICH will:
9.3 No Sale / No Share by the Organizer. The Organizer certifies that it will not Sell or Share Attendee Personal Information in violation of the CCPA/CPRA or of Attendees' choices, will honor Consumer opt-out of sale/sharing and limit-use-of-sensitive-PI requests, and will not process Attendee Personal Information for cross-context behavioral advertising except in compliance with the CCPA/CPRA and after providing any required notice and opt-out.
9.4 Organizer as Service Provider to AFICH. To the extent the Organizer processes any Personal Information on AFICH's behalf for AFICH's business purposes, the Organizer acts as AFICH's Service Provider / Contractor and accepts the restrictions in Section 9.2, applied to it.
9.5 Consumer requests. Each Party will reasonably assist the other in responding to Consumer requests directed to it that concern Personal Information the other controls.
What this means: For California data: you are the "Business" for the Attendee data you use for your own purposes, and AFICH is your "Service Provider" for the parts it runs for you- which means AFICH will not sell or share that data or use it for its own unrelated purposes. You promise the same: don't sell or share Attendee data against the law or against Attendees' choices, and respect their opt-outs.
10.1 Retention limits. Each Party will retain Attendee Personal Data only for as long as necessary for the permitted purposes, or as required by law (for example, tax, accounting, or dispute/chargeback records), and then delete or de-identify it.
10.2 AFICH retention schedule. AFICH retains and deletes Attendee-related data it holds in accordance with the retention practices described in the AFICH Privacy Policy and AFICH's Data Retention Schedule, including retention needed to facilitate payments through Stripe Connect, resolve disputes and chargebacks, and meet legal and regulatory obligations.
10.3 Event completion. After an event is completed, the Organizer will delete or stop processing Attendee Personal Data it no longer needs, except data it must keep for a permitted purpose (for example, financial records or an ongoing dispute) or where an Attendee has consented to continued processing (for example, marketing).
10.4 Account closure. On termination of the Organizer Agreement or closure of the Organizer's account, the Organizer will delete Attendee Personal Data it holds outside the platform (including exports) unless retention is legally required, and AFICH will delete or return Attendee Personal Data it processes as Processor in accordance with its standard timelines and the Privacy Policy, subject to legally required retention and to data AFICH holds as an independent Controller.
10.5 Legal holds. Either Party may retain Attendee Personal Data to the extent required to comply with a legal hold, subpoena, regulatory requirement, or the establishment, exercise, or defense of legal claims, for as long as required.
What this means: Don't keep Attendee data forever. Once the event is over, clear out what you no longer need- especially exported spreadsheets- unless the law makes you keep it or the Attendee agreed to hear from you. AFICH keeps what it needs for payments, disputes, and legal reasons on its own retention schedule.
11.1 Assistance. Taking into account the nature of the processing, each Party will provide the other with reasonable assistance to: (a) respond to Data-Subject / Consumer requests; (b) meet security, breach-notification, and data-protection-impact-assessment obligations; and (c) respond to Supervisory Authorities.
11.2 Demonstrating compliance. On reasonable written request and no more than once per year (unless required more often by a Supervisory Authority or following a Personal Data Breach), AFICH will make available information reasonably necessary to demonstrate its compliance with this DPA in respect of the Attendee Personal Data it processes as Processor.
11.3 Audits. Where Applicable Data Protection Law grants the Organizer an audit right in respect of AFICH's processing as Processor, that right will first be satisfied by AFICH's then-current third-party audit reports or certifications (for example, SOC 2 or ISO 27001) where available. On-site audits will be limited to the systems relevant to the Platform Services, conducted on reasonable prior notice, during business hours, subject to confidentiality, and in a manner that does not disrupt AFICH's operations or compromise other customers' data.
What this means: We help each other answer regulators and Attendee requests. Once a year (or after an incident) AFICH will show reasonable proof it is doing its part, ideally through standard audit reports rather than someone walking through the data center.
12.1 Term. This DPA takes effect when the Organizer Agreement takes effect (or when this DPA is accepted, if later) and remains in force for as long as either Party processes Attendee Personal Data under or in connection with the Organizer Agreement.
12.2 Survival. Obligations that by their nature should survive- including confidentiality, security for retained data, breach cooperation, retention/deletion, the CCPA/CPRA restrictions, and legal-hold obligations- survive termination until the relevant Attendee Personal Data is deleted or de-identified.
12.3 Order of precedence. This DPA supplements the Organizer Agreement and the AFICH Privacy Policy. In the event of a conflict on a data-protection matter:
For all matters not concerning the processing of Attendee Personal Data, the Organizer Agreement controls. Except as expressly modified here, all terms of the Organizer Agreement (including limitations of liability) remain in full force.
12.4 Governing law. This DPA is governed by the governing-law and dispute-resolution provisions of the Organizer Agreement, except where Applicable Data Protection Law or an incorporated transfer mechanism requires otherwise.
What this means: This DPA lives on top of the Organizer Agreement and the Privacy Policy and lasts as long as anyone is still processing Attendee data. If two documents ever disagree about data, follow this order: transfer clauses first, then this DPA, then the Organizer Agreement, then the Privacy Policy. Everything else in the Organizer Agreement still applies.
Questions about this DPA or AFICH's data practices:
The English-language version is the official and controlling text. Localized versions are provided for convenience only.