Data Processing Agreement
Article 28 processor terms for organisers who use frequentix to process attendee data.
Last updated 13 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Squadron Web Limited (trading as frequentix, the “Processor”) and the organiser (the “Controller”). It applies where we process personal data on the organiser’s behalf, and reflects Article 28 of the UK GDPR.
1. Roles
For attendee and contact data processed through frequentix, the organiser is the controller and frequentix is the processor. Each party will comply with its obligations under UK data protection law.
2. Subject matter and duration
The subject matter is our provision of the platform to the organiser. Processing continues for as long as the organiser uses the platform and until data is deleted or returned in line with this DPA.
3. Nature and purpose
We process personal data to enable the organiser to sell tickets, register attendees, communicate with them, check them in, and manage their events — including collecting, storing, hosting, transmitting and deleting that data as part of running the platform.
4. Types of data and data subjects
Data subjects: the organiser’s attendees, ticket buyers, registrants and invitees.
Types of personal data: names, email addresses, mobile numbers where collected, order and ticket details, and the answers to any registration questions the organiser chooses to ask. Full details are in Annex 1.
5. Our obligations
We will:
- process personal data only on the organiser’s documented instructions, including as set out in the Terms and by use of the platform, unless required by law to do otherwise;
- ensure people authorised to process the data are under a duty of confidentiality;
- take the security measures described in section 6 and Annex 2;
- respect the conditions in section 7 for engaging sub-processors;
- assist the organiser, as described below, with data-subject requests and with its own compliance obligations.
6. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption of data in transit, encryption at rest of the identity details held in tickets, secure (hashed) storage of passwords, access controls with multi-factor authentication required for staff to reach personal data, logging, and UK-based hosting. Further detail is in Annex 2.
7. Sub-processors
The organiser gives general authorisation for us to engage the sub-processors listed in Annex 3 to help provide the platform. We impose data-protection obligations on them consistent with this DPA and remain responsible for their performance.
We will give reasonable notice of any intended change to our sub-processors so the organiser has a chance to object on reasonable data-protection grounds.
Where an organiser configures an integration that sends data to a system of their own choosing, that recipient is engaged by the organiser, not by us.
8. International transfers
Our primary storage is in the UK. Where a sub-processor processes data outside the UK, we rely on a transfer mechanism recognised under UK law, such as UK adequacy regulations or the UK International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses).
9. Assistance
Taking into account the nature of the processing, we will provide reasonable assistance to help the organiser respond to data-subject requests and to meet its obligations around security, breach notification, data protection impact assessments and prior consultation with the ICO. The platform includes tools — such as one-action erasure of a contact — to help the organiser act on these requests.
10. Personal data breaches
We will notify the organiser without undue delay after becoming aware of a personal data breach affecting their data, and provide the information reasonably needed to help them meet their own notification obligations.
11. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, on reasonable prior notice, during business hours, subject to confidentiality and without compromising the security or data of other customers.
12. Deletion or return
On the end of the service, we will delete or return the organiser’s personal data as they choose, unless we are required by law to keep it, and delete existing copies within a reasonable period.
13. Annexes
Annex 1 — Details of processing
- Subject matter: provision of the frequentix registration and ticketing platform.
- Duration: the term of the agreement, plus any deletion/return period.
- Nature and purpose: selling tickets, registering and communicating with attendees, and event check-in.
- Data subjects: attendees, buyers, registrants and invitees.
- Types of data: names, email addresses, mobile numbers (where collected), order/ticket data, and registration answers set by the organiser.
Annex 2 — Security measures
- encryption of data in transit (TLS);
- encryption at rest of ticket identity data;
- passwords stored only as secure hashes;
- role-based access controls and audit logging;
- multi-factor authentication required for staff to access personal data (two-step verification or single sign-on);
- UK-based hosting and infrastructure.
Annex 3 — Sub-processors
- Amazon Web Services — hosting, file storage and email delivery (UK / London region).
- Stripe — payment processing.
- Apple — Apple Wallet passes (where an attendee opts in).
- Google — Google Wallet passes (where an attendee opts in).
- Laravel Cloud — application hosting.
Legal information
frequentix is a trading name of Squadron Web Limited, a company registered in England & Wales (company number 08622468).
Registered office: 128 City Road, London, EC1V 2NX.
Registered with the UK Information Commissioner’s Office under reference ZC193207.
Not VAT-registered.
Contact: privacy@frequentix.com
