The agreement, in readable form.
When you run events on ewent, you are the controller of your attendees’ data and we are the processor. This sets out what that means in practice.
1. Roles
The organizer (or the partner platform, where they hold the customer relationship) is the data controller. ewent.ai, operated by TheWORKCompany, is the processor and acts only on documented instructions from the controller.
2. Subject matter and duration
Processing runs for as long as the controller uses the service, plus the retention window needed to complete event follow-up. On termination we delete or return the data at the controller’s choice.
3. Nature and purpose
Hosting registration records; generating per-attendee checklists; scheduling and sending transactional event email; recording checklist progress and attendance; reporting aggregate results back to the controller.
4. Categories of data and data subjects
- Data subjects: people who registered for the controller’s events, and the controller’s own staff.
- Data: email address, name where collected, timezone, registration and ticket reference, checklist step state, message delivery and open events, attendance status, and any free text an attendee voluntarily submits through a feedback or support form.
- No special categories. ewent is not designed to process health, biometric, political or similar data, and controllers should not send it.
5. Our obligations
- Process only on documented instructions, including on international transfers.
- Ensure personnel with access are bound by confidentiality.
- Apply appropriate technical and organisational measures — summarised on the security page.
- Assist the controller with data subject requests, impact assessments and regulator enquiries.
- Notify the controller without undue delay on becoming aware of a personal data breach.
- Delete or return the data at the end of the engagement.
- Make available the information needed to demonstrate compliance.
6. Subprocessors
The controller gives general authorisation for the subprocessors listed at /subprocessors. We give notice before adding or replacing one, and the controller may object. Each subprocessor is bound by terms no less protective than these.
7. International transfers
Where data moves outside its region of origin, we rely on Standard Contractual Clauses or an equivalent lawful mechanism, with the transfer and its basis recorded in the subprocessor list.
8. Data subject rights
Attendees can exercise access, correction, deletion and objection directly with us via the contact form. Where a request belongs to the controller we forward it promptly and assist. We never charge the controller for this assistance.
9. Audit
Controllers may request the information reasonably necessary to verify compliance. For on-site audits we ask for reasonable notice and scope, and we will not unreasonably refuse.
10. Security incidents
We notify the controller without undue delay, with what we know, what we are doing, and what we recommend. We do not wait for a complete picture before telling you something happened.
Last reviewed 20 September 2026. Related: Subprocessors · Security · Privacy policy
ewent