Subject matter
Providing Fomatic as a live operations workspace for high-touch events.
Last updated: June 3, 2026
This Data Processing Addendum ("DPA") is Fomatic's standard customer data-processing addendum. It applies only when it is incorporated into an order form, master services agreement, cloud services agreement, online terms, or other written agreement between Fomatic and a customer.
If a signed agreement between Fomatic and a customer includes a different data-processing addendum, that signed addendum controls for the covered customer account.
For personal data submitted to Fomatic by or on behalf of a customer, the customer is generally the controller, business, or equivalent decision-maker, and Fomatic is generally the processor, service provider, or equivalent service provider. Fomatic may act as an independent controller for limited account, website, billing, security, and business operations data as described in our Privacy Policy.
Fomatic will process customer personal data only to provide, secure, support, and improve the service; operate customer-enabled integrations; comply with law; and follow documented customer instructions in the applicable agreement. The customer is responsible for ensuring it has the rights, notices, permissions, and lawful bases required to provide personal data to Fomatic.
Providing Fomatic as a live operations workspace for high-touch events.
The term of the applicable customer agreement, plus any lawful retention or deletion period.
Customer users, sponsor contacts, attendees, companions, vendors, event staff, and other people included in customer event records.
Names, contact details, organization and role information, event participation, lodging and activity selections, dietary or accommodation details, billing metadata, files, support messages, audit records, and integration metadata.
Hosting, storing, transmitting, displaying, securing, supporting, analyzing, troubleshooting, deleting, exporting, and otherwise processing customer data to provide Fomatic.
| Subject matter | Providing Fomatic as a live operations workspace for high-touch events. |
|---|---|
| Duration | The term of the applicable customer agreement, plus any lawful retention or deletion period. |
| Data subjects | Customer users, sponsor contacts, attendees, companions, vendors, event staff, and other people included in customer event records. |
| Personal data | Names, contact details, organization and role information, event participation, lodging and activity selections, dietary or accommodation details, billing metadata, files, support messages, audit records, and integration metadata. |
| Processing activities | Hosting, storing, transmitting, displaying, securing, supporting, analyzing, troubleshooting, deleting, exporting, and otherwise processing customer data to provide Fomatic. |
Fomatic will require personnel who access customer personal data to protect it in confidence. Fomatic will maintain reasonable technical and organizational measures designed to protect customer personal data against unauthorized access, loss, misuse, alteration, and disclosure. More detail is available on our Security page.
Customer authorizes Fomatic to use subprocessors to provide the service. Fomatic remains responsible for its subprocessors' performance of Fomatic's obligations under this DPA. Our current public list is available on the Subprocessors page.
Where required by an applicable agreement, Fomatic will provide notice of material subprocessor changes and an opportunity to object as stated in that agreement.
Taking into account the nature of the processing and the information available to Fomatic, Fomatic will provide reasonable assistance with customer obligations related to data-subject requests, security, breach notifications, data protection impact assessments, and regulator consultations where required by applicable law and the customer agreement.
On written request after termination or expiration of the applicable agreement, Fomatic will delete or return customer personal data within a reasonable period, unless retention is required by law, needed for legitimate business records, or maintained in backups until ordinary backup expiration.
Fomatic will provide reasonable information needed to demonstrate compliance with this DPA. Any customer audit must be scoped, confidential, scheduled in advance, and conducted in a way that does not compromise Fomatic security, other customers' data, or normal service operations.
Fomatic operates from the United States and may use subprocessors in the United States and other countries. Where transfer safeguards are required by applicable data protection law, the parties will use the applicable standard contractual clauses or other legally recognized transfer mechanism.
If this DPA conflicts with the applicable customer agreement, this DPA controls only for the processing of covered personal data. The applicable customer agreement controls all other matters.
To request a signed DPA or discuss a customer-specific data-processing requirement, contact hello@fomatic.ai.