Legal · DPA

Data Processing Addendum

This DPA supplements the Ventra Terms of Service and governs how we process personal data on behalf of our customers under UK GDPR, EU GDPR and (where applicable) the EU Standard Contractual Clauses.

Version 2.4 · Ready to counter-sign on request

1. Roles

The Customer is the Controller of personal data uploaded to Ventra. Ventra is the Processor. For account-level data (billing contacts, admin identities) Ventra acts as an independent Controller.

2. Scope & purpose

Ventra processes personal data only to provide the Service as described in the Agreement, respond to Customer instructions, meet legal obligations, and secure the platform.

3. Categories of data & data subjects

Customer contact records (guests, suppliers, staff, partners) including names, emails, phone numbers, dietary or accessibility notes, and photos where uploaded. Data subjects include the Customer's employees, contractors, guests and business partners.

4. Sub-processors

Current sub-processors: AWS (hosting, EU/UK regions), Stripe (payments), Postmark (transactional email), OpenAI (AI features, zero-retention), Sentry (error monitoring, EU region). New sub-processors are announced at least 30 days in advance. Customers may object to a new sub-processor by contacting dpa@theventra.co.

5. International transfers

Customer data is stored and processed in the UK and EU. Any transfer outside that boundary relies on the UK IDTA or the EU Standard Contractual Clauses with a transfer risk assessment on file.

6. Security

Ventra maintains ISO 27001-aligned controls including AES-256 encryption at rest, TLS 1.3 in transit, least-privilege access, mandatory 2FA for staff, quarterly penetration testing, and continuous vulnerability scanning. Detail lives in the Trust Centre.

7. Data-subject rights

Ventra assists the Customer in responding to data-subject requests through in-product tooling (export, delete) and by responding to Customer support tickets within five working days.

8. Breach notification

Ventra will notify the Customer of any personal-data breach affecting Customer data without undue delay and in any event within 72 hours of confirmation.

9. Return & deletion

On termination Ventra will delete all Customer data within 60 days, or export it in machine-readable form on request before deletion.

10. Audit

The Customer may audit Ventra's compliance annually with reasonable notice. Ventra provides SOC 2 Type II and ISO 27001 reports on request under NDA to satisfy most audit needs.