Document: eventOS Data Processing Addendum Version: 1.1 Last updated: 20 July 2026 Effective date: 20 July 2026
This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Organiser Terms of Service (the "Agreement") between DZND Limited (RC 9483106) ("DZND", "Processor") and the Organiser ("Controller"). It applies to DZND's processing of personal data on the Controller's behalf through the eventOS platform. It is issued under the Nigeria Data Protection Act 2023 (NDPA) and the GAID.
Where this DPA conflicts with the Agreement on the subject of data protection, this DPA prevails.
1. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor", and "personal data breach" have the meanings given in the NDPA. "Attendee Data" means personal data of the Controller's attendees and prospective attendees that DZND processes on the Controller's behalf to provide the Platform. "Sub-processor" means a third party engaged by DZND to process Attendee Data.
2. Roles of the parties
2.1 In respect of Attendee Data that DZND processes on the Controller's documented instructions to provide the Platform, the Controller is the controller and DZND is the processor.
2.2 DZND is an independent controller for limited purposes of its own: platform security and fraud prevention, KYC and sanctions compliance, billing of its platform fee, aggregate/de-identified product analytics, compliance with law, the attendee AI assistant (an attendee-initiated support interaction in the attendee's own account), attendee community features (groups, invites, shared events, roll-call responses and blocks), and event recommendations shown to attendees. This DPA does not govern those independent-controller activities, which are covered by the Privacy Notice.
2.3 The Controller warrants that it has a lawful basis and has provided any required privacy information for the Attendee Data it instructs DZND to process, and that its instructions comply with the NDPA.
3. Subject matter and details of processing
- Subject matter: processing of Attendee Data to operate ticketing, admission, and audience features for the Controller's events.
- Duration: for the term of the Controller's account and as required thereafter for legal/retention purposes (clause 9).
- Nature and purpose: collection, recording, organisation, storage, retrieval, use, transmission, and deletion/anonymisation in connection with ticket sales, ticket issuance and delivery, admission/scanning, transfers, and organiser-initiated audience messaging.
- Types of personal data: attendee name, email, phone, event city, purchase/ticket history, payment references (no card data), QR/admission token material and hashes, attendance records.
- AI-assisted processing (only where AI features are enabled): where the Controller uses the organiser AI tools, DZND transmits the Controller's own event details and aggregate event statistics to the AI Sub-processor identified in the Register to generate a draft, marketing copy or a post-event report. Attendee-level personal data is not sent to the AI Sub-processor for organiser AI tools. Where an attendee uses the attendee AI assistant, DZND acts as independent controller for that interaction (clause 2.2), not as the Controller's processor. AI Sub-processors are engaged on terms that prohibit training on the data, and no credentials, card/bank data, KYC identifiers or QR signing material are ever transmitted to them.
- Community features (only where enabled): attendee-created groups, invitations, shared events and roll-call responses are operated by DZND as independent controller in the attendee relationship (clause 2.2), not on the Controller's instructions.
- Categories of data subjects: the Controller's attendees and prospective attendees.
- Special-category data: none is required or intended; the Controller must not instruct processing of special-category data through general features.
4. Processor obligations (NDPA §29)
DZND will:
4.1 Process Attendee Data only on the Controller's documented instructions (including the Agreement, this DPA, and the Controller's configuration and use of the Platform), unless required by law, in which case DZND will inform the Controller where lawfully able.
4.2 Ensure persons authorised to process Attendee Data are bound by confidentiality.
4.3 Implement appropriate technical and organisational security measures (Annex A) appropriate to the risk.
4.4 Engage Sub-processors only in accordance with clause 5.
4.5 Taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject-rights requests, and to meet the Controller's security, breach-notification, and data-protection-impact-assessment obligations.
4.6 Notify the Controller without undue delay after becoming aware of a personal-data breach affecting Attendee Data, providing information reasonably available to support the Controller's own notification duties.
4.7 At the Controller's choice, delete or return Attendee Data at the end of the provision of the services, and delete existing copies unless legally required to retain them (anonymisation may be used where deletion would break financially- required records).
4.8 Make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits under clause 7.
4.9 Immediately inform the Controller if, in DZND's opinion, an instruction infringes the NDPA.
5. Sub-processors
5.1 The Controller provides a general authorisation for DZND to engage the Sub-processors listed in the Sub-processor Register to process Attendee Data.
5.2 DZND imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains responsible to the Controller for each Sub-processor's performance.
5.3 DZND will give notice before adding or replacing a Sub-processor (for example by updating the Register and notifying account contacts), and the Controller may object on reasonable, documented data-protection grounds within a reasonable period; the parties will then work in good faith toward a resolution, and the Controller may, as its sole remedy, suspend or terminate the affected service if no resolution is reached.
6. International transfers
Where a Sub-processor processes Attendee Data outside Nigeria, DZND ensures an appropriate transfer mechanism under NDPA §41–43 (adequacy where available, otherwise standard contractual clauses or equivalent binding safeguards). The location and transfer basis for each Sub-processor are in the Sub-processor Register.
7. Audit
7.1 DZND will make available records demonstrating compliance with this DPA.
7.2 The Controller may, on reasonable prior written notice and no more than once per year (or following a personal-data breach or a regulator request), verify DZND's compliance through DZND's documentation and, where reasonably necessary and proportionate, an audit that: is conducted during business hours; does not unreasonably disrupt DZND's operations; and does not compromise other customers' confidentiality or the security of the Platform. The Controller bears its own audit costs.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent the NDPA provides for direct statutory liability to data subjects that cannot be so limited.
9. Term, deletion and return
This DPA takes effect on the Controller's acceptance of the Agreement and continues while DZND processes Attendee Data. On termination, clause 4.7 applies. DZND may retain Attendee Data to the extent, and for the period, required by law.
10. Governing law
This DPA is governed by the laws of the Federal Republic of Nigeria, and disputes are resolved as set out in the Agreement.
Annex A — Technical and organisational security measures
Measures implemented by the eventOS platform include:
- Access control: row-level security (RLS) on all database tables; service-role separation; least-privilege API-key scopes; organiser ownership checks on every data path; separate internal-admin authorisation boundary with reason-required, audited writes.
- Authentication: hashed credentials; two-factor authentication (TOTP), required for sensitive organiser actions; passkey (WebAuthn) step-up and maker-checker approval for sensitive internal administrative actions.
- Encryption: TLS in transit; AES-256-GCM encryption of offline mobile admission manifests at rest on the device; encrypted two-factor secrets; signed (HMAC-SHA256 / Ed25519) admission tokens and QR codes.
- Resilience and integrity: idempotent write handling; atomic inventory and payment-claim operations; webhook signature verification with independent transaction re-verification before fulfilment; immutable audit logging with before/after state for administrative changes.
- Operational security: rate limiting; sanctions screening on organiser onboarding; secret scanning in the CI/pre-commit pipeline; PII-minimised structured logging with automatic redaction of credentials, tokens, BVN and NIN.
- Breach response: 72-hour NDPC notification process (Privacy Notice §9); processor-to-controller notification without undue delay.
*Measures evolve with the platform; the current implementation is reflected in BLUEPRINT.md §12 and the codebase.
Annex B — Sub-processors
The authorised Sub-processors, their roles, locations and transfer bases are maintained in the Sub-processor Register / Vendor DPA Register, which forms part of this DPA.
© 2026 DZND Limited. eventOS is a product of DZND Limited (RC 9483106).