Data Processing Agreement
The terms that apply when event.clinic processes personal data on behalf of a client, under Article 28 of the EU GDPR.
Last updated: October 2026
1. Roles
Where event.clinic processes personal data to deliver services to a client, the client is the controller and event.clinic is the processor. This agreement supplements the main services agreement between the parties.
2. Scope and instructions
event.clinic processes personal data only on the client's documented instructions, including as to transfers, unless required otherwise by EU or Hungarian law. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
3. Confidentiality
event.clinic ensures that people authorised to process the data are bound by an appropriate duty of confidentiality.
4. Security
event.clinic implements appropriate technical and organisational measures under Article 32 GDPR, as described in Annex 1, Section 6.
5. Sub-processors
The client gives general authorisation for event.clinic to engage sub-processors, provided event.clinic imposes equivalent data-protection obligations on them and informs the client of intended changes, giving the client the chance to object. The authorised sub-processors and the conditions of their use are set out in Annex 2.
6. Assisting the controller
event.clinic assists the client, as far as possible, in responding to data-subject requests and in meeting the client's obligations on security, breach notification, data-protection impact assessments and prior consultation.
7. Personal data breaches
event.clinic notifies the client without undue delay after becoming aware of a personal data breach and provides the information the client needs to meet its own obligations.
8. International transfers
Any transfer of personal data outside the EEA is made only under an adequacy decision or appropriate safeguards, such as the Standard Contractual Clauses.
9. Return or deletion
At the end of the services, event.clinic deletes or returns all personal data and deletes existing copies, unless EU or Hungarian law requires continued storage.
10. Audits
event.clinic makes available the information needed to demonstrate compliance and allows for and contributes to audits, including inspections, by the client or an auditor the client appoints.
11. Governing law
This agreement is governed by the laws of Hungary and by the GDPR.
Annex 1, Details of Processing and Security Measures
This Annex 1 forms an integral part of the data processing agreement between the Controller and the Processor and sets out the details of the processing as required under Article 28(3) GDPR.
1. Subject matter of the processing
The subject matter of the processing is the Processor's provision of website-related services to the Controller, including hosting, maintenance, support, user communications, form handling, account administration, analytics, and other related processing activities carried out on behalf of the Controller in connection with the operation of the website and associated digital services.
2. Duration of the processing
The processing shall continue for the duration of the underlying services agreement, or for so long as the Processor processes personal data on behalf of the Controller, whichever is longer. Upon termination or expiry of the services, the Processor shall, at the choice of the Controller, delete or return all personal data to the Controller, unless Union law or Member State law requires storage of the personal data.
3. Nature and purpose of the processing
The processing consists of the collection, recording, organisation, structuring, storage, consultation, use, disclosure by transmission where necessary for service delivery, restriction, erasure, and other processing operations required to provide the contracted website and related support services on behalf of the Controller.
The purpose of the processing is to enable the Controller to operate the website, receive and manage enquiries, administer user or customer accounts, deliver requested information or services, maintain system security, monitor service performance, and manage the Controller's business relationships with website users and other relevant contacts.
4. Types of personal data
Subject to the Controller's actual use of the website and its functions, the categories of personal data processed may include the following:
- Identification data, including first name, last name, username, and account identifier.
- Contact data, including email address, telephone number, postal address, and company contact details.
- Professional data, including employer name, job title, department, and business affiliation.
- Account and authentication data, including login credentials, password hashes, user roles, and account status data, where applicable.
- Transaction and billing data, including payment-related details, invoicing information, and order or subscription records, where applicable.
- Communications data, including enquiry content, support requests, messages, attachments, and correspondence submitted through the website or associated service channels.
- Technical and usage data, including IP address, device identifiers, browser type, operating system, timestamps, log data, cookies, and website usage information.
- Any other personal data submitted by or on behalf of the Controller through forms, uploads, integrations, or other website features made available under the services.
Special categories of personal data within the meaning of Article 9 GDPR shall not be processed unless expressly authorised by the Controller in writing and subject to appropriate additional safeguards required by applicable law.
5. Categories of data subjects
Depending on the Controller's use of the services, the categories of data subjects may include the following:
- Website visitors.
- Prospective customers or clients.
- Customers and customer representatives.
- Registered users and account holders.
- Newsletter subscribers and marketing recipients, where applicable.
- Service providers, partners, or other business contacts of the Controller whose data is submitted or stored via the website.
- Individuals who communicate with the Controller through website forms, email channels, chat functions, support tools, or other related interfaces.
6. Technical and organisational security measures
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.
Such measures shall include, as appropriate:
- Measures to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
- Measures to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident, including backup and recovery procedures.
- Processes for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
- Logical access controls, including user authentication, role-based access management, least-privilege allocation, and periodic review of access rights.
- Protection of data in transit and, where appropriate, at rest through encryption, pseudonymisation, or equivalent safeguards.
- Logging, monitoring, and incident detection controls designed to identify unauthorised access, misuse, or abnormal processing activity.
- Vulnerability management, security patching, malware protection, and other measures designed to maintain secure systems.
- Personnel confidentiality obligations, internal policies, staff awareness measures, and training appropriate to the personnel's access to personal data.
- Procedures for security incident management and personal data breach escalation to support the Controller's compliance obligations under the GDPR.
- Measures governing the use of sub-processors, including contractual flow-down of data protection and security obligations where sub-processing is authorised.
The Processor shall review and update these measures where necessary to ensure that the security of the processing remains appropriate to the risk.
7. Instructions and controller rights
The Processor shall process personal data only on documented instructions from the Controller, unless otherwise required by Union law or Member State law to which the Processor is subject. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection provisions.
The Controller retains all rights and obligations required under Article 28 GDPR, including the right to give documented instructions, to approve or object to sub-processors in accordance with the agreement, and to verify compliance through information requests, audits, or inspections as provided in the data processing agreement.
Annex 2, Authorised Sub-processors
This Annex 2 forms an integral part of the data processing agreement between the Controller and the Processor and sets out the conditions governing the appointment and use of sub-processors in accordance with Article 28(2) and Article 28(4) GDPR.
1. Authorisation principle
The Processor shall not engage another processor to carry out specific processing activities on behalf of the Controller without the Controller's prior specific or general written authorisation.
Where the Controller grants general written authorisation, the Processor shall inform the Controller in advance of any intended addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes within the period specified in the data processing agreement.
2. Minimum contractual requirements
The Processor shall ensure that each authorised sub-processor is bound by a written contract imposing data protection obligations that are no less protective than those set out in the data processing agreement between the Controller and the Processor, in particular with regard to confidentiality, security of processing, assistance, deletion or return of personal data, audit support, and compliance with documented instructions.
Where a sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
3. List of authorised sub-processors
As of the effective date of the data processing agreement, the following sub-processors are authorised, to the extent they are actually used in connection with the services:
| Sub-processor | Registered address | Processing activity | Personal data involved | Location | Transfer mechanism |
|---|---|---|---|---|---|
| Cloudflare, Inc. | 101 Townsend St, San Francisco, CA 94107, USA | Hosting of the website, API and toolset; content delivery; security, including bot protection (Turnstile); web analytics | Technical and usage data (IP address, log data); data passing through the services | USA and global edge network | EU–US Data Privacy Framework and Standard Contractual Clauses |
| Neon, Inc. (a Databricks company) | 160 Spear Street, Suite 1300, San Francisco, CA 94105, USA | Toolset database hosting | Contact, communications and account data; event data the customer enters | Frankfurt, Germany (EU) | Data stored in the EU; any access from the USA is governed by Neon’s data processing addendum |
| Sendinblue SAS (Brevo) | 9-17 rue Salneuve, 75017 Paris, France | Sending transactional email (form notifications, account mail) | Name, email address, message content | EU (France and Belgium) | No transfer outside the EU |
| Stripe Payments Europe, Limited | Dublin, Ireland | Payment processing: card payments and subscription billing | Name, email address, billing address, payment and transaction data (card details are entered with Stripe directly) | EU and USA | EU–US Data Privacy Framework and Standard Contractual Clauses |
Statutory recipient (not a sub-processor). Invoices issued by Marik Péter EV. are reported to the Hungarian Tax and Customs Administration (Nemzeti Adó- és Vámhivatal, NAV) through its Online Számla system, as Hungarian VAT law requires (Act CXXVII of 2007 on VAT and Decree 23/2014 (VI. 30.) NGM). NAV receives this data as a public authority under a legal obligation, not on the Controller’s instructions.
Any future appointment shall remain subject to the authorisation procedure set out in this Annex and the data processing agreement.
4. Information to be maintained
For each authorised sub-processor, the Processor shall maintain and make available to the Controller sufficient information to identify the sub-processor and describe the processing delegated to it, including at least the sub-processor's identity, contact details or registered address, the nature of the outsourced processing, and the relevant processing location.
5. International processing
Where a sub-processor processes personal data outside the European Economic Area, the Processor shall ensure that such transfer or onward transfer is subject to a valid transfer mechanism under Chapter V GDPR and that any supplementary safeguards required under applicable law are implemented.
6. Change control
The Processor shall keep this Annex, or an equivalent maintained sub-processor list incorporated by reference in the data processing agreement, up to date. The Processor shall notify the Controller of any intended addition, replacement, or removal of a sub-processor in accordance with the notice procedure agreed between the parties.
7. Signature note
This Annex may be completed either by listing all approved sub-processors individually or by attaching the Processor's current sub-processor register, provided that such register forms part of the data processing agreement and is subject to the Controller's applicable approval rights.