Data processing agreement.
Version 2026-09.2 · Last updated: 15 September 2026
This agreement applies to anyone organising events on OffTrail Events. When you publish an event and collect registrations, you are the controller of your participants' data; OffTrail processes it on your behalf, on your instructions. This is the written agreement Article 28(3) GDPR requires between us, and you accept it when you create an organiser account.
Who is who
The controller is the organisation that creates the account and publishes the event. It decides what the registration form asks, why, and who on its team can see the answers.
The processor is OffTrail, published by Ricardo Costa, contact [email protected]. We provide the platform and process participant data only to run it, never for purposes of our own.
Outside this agreement is the organiser account's own data (name, email, authentication, plan billing): there OffTrail is the controller, and the Events privacy policy applies.
Subject matter, duration, nature and purpose
We process participant data to run your events' registrations: receiving and storing registrations, generating payment references, recording payment and check-in state, sending registration emails, making the roster available to your team, allowing exports, and — when the event uses it — showing live position during the event. Processing lasts while your account exists and the event is on the platform.
What data, and whose
Data subjects: the participants registered for your events, and people on a waiting list.
Data: name, email and phone (always); the answers to the questions the controller adds to the form and any files it asks for; the accepted terms version; payment reference and state and any proof the participant uploads; ticket and add-ons chosen and the total; language; check-in state; and, if the event uses live position, coordinates during the event.
The form's questions are yours. They may include special categories of data if you configure them that way. We do not vet them one by one: the controller warrants, in the Events terms, that it has a lawful basis, informs participants, and obtains any consent required.
Our instructions are yours
We process participant data only on the controller's documented instructions, which are: this agreement, the Events terms, and normal use of the platform (what you do in the dashboard and the event's settings). If we receive an instruction that appears to us to infringe data protection law, we tell you, and we may pause that part of the processing until it's resolved.
Confidentiality
Anyone on our side who can access this data is bound by confidentiality and accesses it only as far as needed to run, support and protect the platform.
Security
We keep technical and organisational measures appropriate to the risk: encryption in transit, hosting on managed infrastructure with encryption at rest, password plus two-step verification on the organiser console, access to an event's roster limited to the organisation that published it, and our own operator access restricted and justified.
Sub-processors
The controller authorises OffTrail to use the following sub-processors for participant data:
- Cloudflare — platform hosting, database, and storage of registration files.
- Amazon Web Services (SES, EU region) — sending registration emails.
We only use sub-processors that are themselves bound, under their own data processing terms, to data protection obligations equivalent to those in this agreement. We give reasonable notice before adding or replacing a sub-processor, and the controller may object; if the objection makes the service unworkable, either party may terminate.
If you connect your own payment provider, that provider is your processor, not ours: the money and the payment data flow between you and them.
We help with requests and obligations
Participants' requests (access, correction, deletion, objection) are answered by the controller. We give you the tools to do it and help where they fall short. If a request reaches us directly, we pass it on and do not answer on your behalf.
We also help, as far as we reasonably can, with security of processing, breach notification, and impact assessments.
Data breaches
If there is a personal data breach affecting your participants' data, we notify the controller without undue delay after becoming aware, with what we know: what happened, which data and people are affected, the likely consequences, and the measures taken. Notifying the authorities and the participants, where required, is the controller's responsibility.
Deletion and return at the end
The controller can export registrations at any time and delete them on the platform. When the agreement ends, we delete participant data within a reasonable period, except where law requires us to keep it. Backups are superseded by their normal cycle.
Audits
We make available to the controller the information needed to demonstrate compliance with these obligations, and we answer reasonable requests for clarification, including about sub-processors.
International transfers
Participant data is processed in the European Union wherever our sub-processors allow it. Where processing may occur outside the European Economic Area, we rely on the safeguards the law requires, including the standard contractual clauses in our providers' agreements.
Term and changes
This agreement runs while the organiser account exists. When we change it materially, we give notice and publish the new version here; the version you accepted is recorded with its date. If it conflicts with the Events terms, this agreement prevails as to the processing of participant data.
Contact
Questions about this agreement: [email protected].