Data Processing Agreement

Pursuant to Art. 28(3) GDPR · Version 1.0 — August 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer using the Kivvo platform (the “Controller”) and INOVA LAB SHPK, Bulevardi Gjergj Fishta, Shk 2, Nd 146, Ap 19, Kodi Postar 1001, Tiranë, Albania (the “Processor”), and governs the processing of personal data the Processor carries out on the Controller’s behalf.

§ 1 Subject matter and duration

The subject matter of this DPA is the processing of personal data in connection with the provision of the Kivvo event-management platform: registration, payments, participant apps, check-in, schedules, communication and related features. The DPA applies for as long as the main agreement is in force and until all personal data has been deleted or returned in accordance with § 10.

§ 2 Nature and purpose of processing, data categories, data subjects

Processing comprises the collection, storage, organization, display, transmission and deletion of personal data as required to run the Controller’s events. Categories of data include: names, email addresses, phone numbers, country and unit, date of birth, answers to the Controller’s custom registration forms (which may include dietary or accessibility information the Controller chooses to collect), payment status (never card data), check-in and attendance records, uploaded files and photos, chat messages and posts, goals, feedback and poll responses, and device push tokens. Data subjects are the Controller’s event participants, registrants, organizers and volunteers.

§ 3 Obligations of the Processor

The Processor shall:

  • process personal data only on the Controller’s documented instructions, including with regard to transfers to third countries, unless required to do so by law;
  • ensure that persons authorized to process the data have committed themselves to confidentiality;
  • implement appropriate technical and organizational measures, including encryption of data in transit (TLS) and at rest, database hosting exclusively within the European Union, field-level encryption for answers the Controller marks as masked, role-based access with per-participant privacy tiers, and push notifications that are content-free by design;
  • engage sub-processors only under a written contract imposing the same data protection obligations, and inform the Controller of any intended changes with the opportunity to object.

The Controller grants general authorization for the following sub-processors:

ProviderPurposeLocation
Hetzner Online GmbHCloud infrastructure: application hosting, PostgreSQL database, file storageGermany (EU)
Stripe Payments Europe, Ltd.Payment processing for registration fees (card data is held by Stripe, never by Kivvo)Ireland (EU)
Google Ireland Ltd. (Firebase Cloud Messaging)Push notification delivery — payloads are content-free by design and carry no personal dataIreland (EU); Google LLC (USA) under Standard Contractual Clauses
Google Ireland Ltd. (Google Maps Platform)Map display in the participant app - serves map tiles and processes the device IP address and visible map area; user location is shown on-device onlyIreland (EU); Google LLC (USA) under Standard Contractual Clauses
Sendinblue SAS (Brevo)Transactional email delivery (sign-in codes, registration and waitlist emails)France (EU)

§ 4 Assistance with data subject rights

Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The platform provides self-service tools for data export and deletion; requests received directly by the Processor are forwarded to the Controller without undue delay.

§ 5 Personal data breach notification

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing at least: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.

§ 6 Data protection impact assessment

The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities pursuant to Art. 35 and 36 GDPR, insofar as they relate to processing under this DPA.

§ 7 Obligations of the Controller

The Controller is responsible for the lawfulness of the processing, in particular for an adequate legal basis for the data collected through its registration forms, for the content it distributes through the platform, and for responding to data subjects. The Controller shall indemnify the Processor against third-party claims arising from unlawful instructions or unlawfully collected data.

§ 8 Audit and inspection rights

The Processor makes available all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with reasonable prior notice and during normal business hours.

§ 9 International data transfers

Customer data is hosted exclusively within the European Union. Where personal data is accessed from outside the EU/EEA — including administrative and support access by the Processor from Albania, or processing by a sub-processor’s non-EU affiliates — such transfers are safeguarded by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or another valid transfer mechanism.

§ 10 Termination and deletion

Upon termination of the main agreement, the Processor deletes all personal data processed on the Controller’s behalf, unless storage is required by law. Before deletion, the Controller may request an export of its data in a commonly used, machine-readable format (CSV and file archives).

§ 11 Liability

Liability is governed by Art. 82 GDPR. The Processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the Controller’s lawful instructions.

Questions about this DPA: contact@kivvo.app · INOVA LAB SHPK, NUIS/NIPT M02214016J, Tiranë, Albania.