Data Processing Agreement
Pursuant to Art. 28(3) GDPR · Version 1.3 — October 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer using the Kivvo platform (the “Controller”) and INOVA LAB SHPK, Bulevardi Gjergj Fishta, Shk 2, Nd 146, Ap 19, Kodi Postar 1001, Tiranë, Albania (the “Processor”), and governs the processing of personal data the Processor carries out on the Controller’s behalf.
§ 1 Subject matter and duration
The subject matter of this DPA is the processing of personal data in connection with the provision of the Kivvo event-management platform: registration, payments, attendee apps, check-in, schedules, communication and related features. The DPA applies for as long as the main agreement is in force and until all personal data has been deleted or returned in accordance with § 10.
§ 2 Nature and purpose of processing, data categories, data subjects
Processing comprises the collection, storage, organization, display, transmission and deletion of personal data as required to run the Controller’s events. Categories of data include: names, email addresses, phone numbers, country and unit, date of birth, answers to the Controller’s custom registration forms (which may include dietary or accessibility information the Controller chooses to collect), payment status (never card data), check-in and attendance records, uploaded files and photos, chat messages and posts, goals, feedback and poll responses, and device push tokens. Data subjects are the Controller’s event attendees, registrants, organizers and volunteers.
§ 3 Obligations of the Processor
The Processor shall:
- process personal data only on the Controller’s documented instructions, including with regard to transfers to third countries, unless required to do so by law;
- ensure that persons authorized to process the data have committed themselves to confidentiality;
- implement appropriate technical and organizational measures, including encryption of data in transit (TLS) and at rest, database hosting exclusively within the European Union, nightly database backups to EU object storage (Scaleway, Paris) with 30-day retention and automated server-image backups (Hetzner, Germany), field-level encryption for answers the Controller marks as masked and for stored payment credentials, with the encryption key held in an EU key management service (Scaleway Key Manager, Paris) and never stored in plaintext, audit logging of privileged access changes, security events and server access with automated alerting, role-based access with per-attendee privacy tiers, and push notifications that are content-free by design;
- engage sub-processors only under a written contract imposing the same data protection obligations, and inform the Controller of any intended changes with the opportunity to object.
The Controller grants general authorization for the following sub-processors:
Intended additions or replacements are announced in the “Changes” section at the end of this DPA at least 30 days before the new sub-processor begins processing. Controllers may object within that period on reasonable data protection grounds; Controllers who wish to be notified by email can request this at contact@kivvo.app.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure: application hosting, PostgreSQL database and automated server-image backups | Germany (EU) |
| Scaleway SAS | Object storage for uploaded files and photos, nightly database backups with 30-day retention (S3-compatible, encrypted at rest), and key management (Key Manager) for the encryption key that protects stored credentials and masked answers; Key Manager holds no personal data | France (EU) — Paris |
| Stripe (payment processing) | Payment processing for registration fees when the Controller's events accept card payments (card data is held by Stripe, never by Kivvo) | The contracting Stripe entity follows the merchant account's country: Stripe Payments Europe, Ltd. (Ireland, EU) for EU/EEA accounts; Stripe, Inc. (USA) under Standard Contractual Clauses for US accounts |
| Google Ireland Ltd. (Firebase Cloud Messaging) | Push notification delivery — payloads are content-free by design and carry no personal data | Ireland (EU); Google LLC (USA) under Standard Contractual Clauses |
| Google Ireland Ltd. (Google Maps Platform) | Map display in the attendee app - serves map tiles and processes the device IP address and visible map area; user location is shown on-device only | Ireland (EU); Google LLC (USA) under Standard Contractual Clauses |
| Brevo SAS (formerly Sendinblue) | Transactional email delivery (sign-in codes, registration and waitlist emails) | France (EU) |
| Cloudflare, Inc. (Turnstile) | Bot protection on public forms (registration, sign-up, demo and report forms) — processes the visitor's IP address and browser environment signals to tell humans from bots; no advertising or cross-site tracking | USA — EU–U.S. Data Privacy Framework and Standard Contractual Clauses |
| Google Ireland Ltd. (Google Analytics 4) | Aggregate usage statistics for the public website, including public event and community pages. Loads only after the visitor accepts the cookie banner; declined or undecided visitors load nothing. IP anonymization is enabled and no advertising features are used. Listed for transparency: it operates on the visitor's own consent rather than on the Controller's instructions | Ireland (EU); Google LLC (USA) under Standard Contractual Clauses |
§ 4 Assistance with data subject rights
Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organizational measures in fulfilling requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). The platform provides self-service tools for data export and deletion; requests received directly by the Processor are forwarded to the Controller without undue delay.
§ 5 Personal data breach notification
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing at least: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where this information is not available at once, it is provided in phases as it becomes available. Where the Controller’s agreement with the Processor sets a specific notification period, that period applies.
§ 6 Data protection impact assessment
The Processor provides reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities pursuant to Art. 35 and 36 GDPR, insofar as they relate to processing under this DPA.
§ 7 Obligations of the Controller
The Controller is responsible for the lawfulness of the processing, in particular for an adequate legal basis for the data collected through its registration forms, for the content it distributes through the platform, and for responding to data subjects. The Controller shall indemnify the Processor against third-party claims arising from unlawful instructions or unlawfully collected data.
§ 8 Audit and inspection rights
The Processor makes available all information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with reasonable prior notice and during normal business hours.
§ 9 International data transfers
Customer data is hosted exclusively within the European Union. Where personal data is accessed from outside the EU/EEA — including administrative and support access by the Processor from Albania, or processing by a sub-processor’s non-EU affiliates — such transfers are safeguarded by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR or another valid transfer mechanism.
§ 10 Termination and deletion
Upon termination of the main agreement, the Processor deletes all personal data processed on the Controller’s behalf, unless storage is required by law. Copies in backups are not restored after deletion and expire with the backup rotation — at most 30 days for database backups and within the server-image backup cycle. Before deletion, the Controller may request an export of its data in a commonly used, machine-readable format (CSV and file archives).
§ 11 Liability
Liability is governed by Art. 82 GDPR. The Processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the Controller’s lawful instructions.
Changes
- Version 1.3 — October 2026: minor changes: the Scaleway SAS entry now also covers key management (Key Manager) for the key that protects stored credentials and masked answers, with no personal data held there; the technical measures describe encryption of stored payment credentials, key management and security audit logging with alerting; breach notifications may be provided in phases, and a notification period agreed in a Controller’s contract applies. No new sub-processors.
- Version 1.2 — July 2026: added Scaleway SAS (object storage for uploaded files, Paris), Cloudflare, Inc. (Turnstile bot protection) and Google Ireland Ltd. (consent-gated Google Analytics 4) to the sub-processor list; narrowed Hetzner Online GmbH to application hosting and database; renamed Sendinblue SAS to Brevo SAS; clarified the Stripe contracting entity; added this change log and the 30-day advance-notice process for sub-processor changes; documented the backup regime (nightly EU database backups with 30-day retention, server-image backups).
- Version 1.1 — February 2026: clarified the processing descriptions and technical measures; no sub-processor changes.
- Version 1.0 — January 2026: initial version.
Questions about this DPA: contact@kivvo.app · INOVA LAB SHPK, NUIS/NIPT M02214016J, Tiranë, Albania.