Legal & Trust

Data Processing Addendum

Last updated: 31 August 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between ADVCY Ltd (“ADVCY”) and the Client.

1. Scope

This DPA applies where ADVCY processes Personal Data on behalf of Client in connection with the Services.

It applies to processing subject to:

  • the UK GDPR;
  • the Data Protection Act 2018;
  • applicable provisions of the Data (Use and Access) Act 2025;
  • the EU GDPR where applicable; and
  • other data-protection law expressly agreed by the Parties.

2. Definitions

“Client Personal Data” means Personal Data processed by ADVCY as processor on behalf of Client.

“Data Protection Law” means applicable data-protection legislation governing the relevant processing.

“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given under applicable Data Protection Law.

“Subprocessor” means another processor appointed by ADVCY to process Client Personal Data.

3. Roles

For Client Personal Data, Client is Controller and ADVCY is Processor.

If Client acts as Processor for another Controller, ADVCY acts as Client’s Subprocessor.

The Parties acknowledge that their roles must reflect the processing actually undertaken and not merely the terminology used in this DPA.

4. Client instructions

ADVCY will process Client Personal Data only:

  • on Client’s documented instructions;
  • as necessary to provide the Services; or
  • where required by applicable law.

The Agreement, Order Form, configuration selected by Client and written requests made through authorised channels constitute documented instructions.

If law requires ADVCY to process Client Personal Data other than on Client’s instructions, ADVCY will inform Client before doing so unless the law prohibits such notice.

ADVCY will inform Client if, in its reasonable opinion, an instruction infringes applicable Data Protection Law.

5. Processing details

Subject matter

Provision of the ADVCY services purchased by Client.

Duration

For the term of the Agreement and any limited period afterwards required to return, delete, secure or lawfully retain data.

Nature of processing

Processing may include:

  • collection;
  • receipt;
  • transmission;
  • storage;
  • organisation;
  • retrieval;
  • consultation;
  • analysis;
  • generation;
  • personalisation;
  • display;
  • verification;
  • updating;
  • deletion;
  • anonymisation; and
  • other processing necessary to provide the Services.

Purpose

Purposes may include:

  • providing digital wallet passes;
  • maintaining passes;
  • delivering operational communications;
  • operating AI concierge services;
  • providing messaging services;
  • registration;
  • event recommendations;
  • event navigation;
  • member engagement;
  • matching and introductions;
  • verification;
  • analytics;
  • customer support;
  • security; and
  • functionality specified in the Order Form.

Categories of Data Subjects

These may include:

  • attendees;
  • ticket holders;
  • fans;
  • customers;
  • members;
  • subscribers;
  • visitors;
  • speakers;
  • exhibitors;
  • sponsors;
  • Client employees;
  • contractors; and
  • other individuals authorised by Client.

Types of Personal Data

These may include:

  • name;
  • email;
  • telephone number;
  • messaging identifiers;
  • profile information;
  • message content;
  • preferences;
  • interests;
  • event registrations;
  • attendance information;
  • ticket or entitlement data;
  • wallet pass identifiers;
  • Apple device library identifiers;
  • Apple push tokens;
  • Google Wallet identifiers;
  • pass serial numbers;
  • barcode or QR identifiers;
  • consent and opt-out information;
  • verification records;
  • interaction history;
  • IP address;
  • device information;
  • system logs; and
  • other data expressly configured by Client.

Special Category Data

Special Category Data is not part of the standard Services and must not intentionally be processed unless expressly agreed. Where it is expressly agreed, Client is responsible for identifying the applicable Article 6 basis and Article 9 condition.

6. Confidentiality

ADVCY will ensure that people authorised to process Client Personal Data:

  • have a legitimate need for access;
  • are subject to appropriate confidentiality duties; and
  • receive appropriate data-protection and security guidance.

7. Security

ADVCY will implement technical and organisational measures appropriate to the risk as required by applicable Data Protection Law. Measures may include:

  • encryption in transit;
  • appropriate encryption at rest;
  • access control;
  • least privilege;
  • authentication controls;
  • credential and secrets management;
  • logging;
  • monitoring;
  • backup and recovery;
  • secure development;
  • vulnerability management;
  • incident response;
  • environment segregation; and
  • supplier management.

ADVCY may update security measures as technology and risks develop, provided the overall level of protection is not materially reduced.

8. Subprocessors

Client gives ADVCY general written authorisation to appoint Subprocessors. ADVCY will:

  • conduct proportionate diligence;
  • enter into a written agreement imposing applicable processor obligations;
  • remain responsible for the performance of the Subprocessor to the extent required by law; and
  • maintain a list at advcy.ai/subprocessors.

9. New subprocessors

ADVCY will provide reasonable prior notice of a new material Subprocessor by updating its Subprocessor list and, where Client subscribes to updates, by electronic notice.

Client may object to a new Subprocessor on reasonable data-protection grounds. The Parties will work in good faith to find a reasonable solution.

If no reasonable solution is available, Client may terminate the materially affected Service before the new Subprocessor begins processing Client Personal Data, as Client’s sole remedy for that objection.

10. International transfers

ADVCY will not knowingly make a restricted transfer of Client Personal Data unless an appropriate transfer mechanism applies. Depending on the circumstances this may include:

  • UK adequacy regulations;
  • the UK Extension to the EU-US Data Privacy Framework;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to EU Standard Contractual Clauses;
  • EU Standard Contractual Clauses; or
  • another lawful transfer mechanism.

ADVCY will undertake any transfer assessment required of it under applicable law.

11. Data-subject requests

Taking into account the nature of processing, ADVCY will provide reasonable assistance to Client in responding to Data Subject requests.

If ADVCY receives a request relating primarily to Client Personal Data, ADVCY will:

  • notify Client without undue delay;
  • not respond substantively except on Client’s instructions or where legally required; and
  • provide reasonable assistance.

12. Data protection complaints

ADVCY will reasonably assist Client with data-protection complaints relating to ADVCY’s processing.

Where a complaint concerns ADVCY’s own controller activities, ADVCY will handle that part directly.

13. Personal Data Breaches

ADVCY will notify Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data.

To the extent reasonably available, ADVCY will provide information including:

  • the nature of the incident;
  • categories of information involved;
  • categories of affected Data Subjects;
  • approximate numbers where available;
  • likely consequences;
  • containment measures;
  • mitigation measures; and
  • relevant contact information.

ADVCY may provide information in stages as the investigation progresses. Notification does not constitute an admission of fault.

Client is responsible for determining whether Client must notify a Supervisory Authority or affected individuals unless applicable law places that obligation directly on ADVCY.

14. DPIAs

Taking into account the nature of processing and information available to ADVCY, ADVCY will provide reasonable assistance with Client’s:

  • Data Protection Impact Assessments; and
  • prior consultation with a Supervisory Authority,

where the assessment relates to ADVCY’s processing of Client Personal Data.

15. Compliance information

ADVCY will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. This may include:

  • policies;
  • security documentation;
  • questionnaires;
  • independent reports where available;
  • certifications where available; and
  • other reasonable evidence.

16. Audits

Where the information provided under the previous section is reasonably insufficient for Client to establish compliance, Client may request an audit.

Unless required sooner by a regulator or following a material incident:

  • audits will be no more than once in a 12-month period;
  • Client will provide reasonable advance notice;
  • audits will occur during normal business hours;
  • audits will not unreasonably disrupt ADVCY;
  • Client and its auditor will comply with confidentiality and security requirements;
  • an auditor must not be a competitor of ADVCY; and
  • Client will bear its own audit costs.

ADVCY may charge reasonable costs for audit assistance beyond information ordinarily provided to customers.

17. Return and deletion

At termination or expiry and on Client’s written request, ADVCY will delete or return Client Personal Data unless applicable law requires retention.

Deletion from active systems will occur within a commercially reasonable period specified in ADVCY’s retention procedures or the Order Form.

Residual copies may remain temporarily in secure backups until overwritten through normal backup rotation. While retained solely in backup, Client Personal Data will remain protected and will not be restored for ordinary business purposes.

18. Suppression and compliance records

Where ADVCY acts solely as Processor, suppression and consent records will be handled according to Client’s instructions.

Where ADVCY independently needs a minimal record to comply with an obligation applying directly to ADVCY, that limited processing will be performed by ADVCY as Controller.

19. Liability

Liability arising under this DPA is subject to the liability provisions in the Client Terms or other governing Agreement.

20. Precedence

If this DPA conflicts with another provision of the Agreement regarding processing of Client Personal Data, this DPA prevails to the extent of the conflict.