GDPR Article 28 agreement between Pistaclub (processor) and event organizers (controller) for rider personal data received through the platform. Forms an integral part of the Organizer Terms.
Last updated: 2026-07-16
This Data Processing Agreement ("DPA") supplements the Organizer Terms between Pistaclub (Pistaclub s.r.o., pending incorporation, "Pistaclub", "Processor") and the event organizer named in the organizer account ("Organizer", "Controller"). It reflects the parties' respective obligations under Regulation (EU) 2016/679 (GDPR) and, where applicable, the UK GDPR and Swiss nFADP.
Subject-matter. Pistaclub processes personal data relating to riders on the Controller's behalf for the sole purpose of enabling the Controller to receive, manage, and communicate with rider registrations for its events.
Duration. Processing continues for the term of the Organizer Terms and ends when the Controller's organizer status is terminated, subject to legally required retention (§9).
Nature and purpose. Collection via the platform's registration flow; storage on Pistaclub's infrastructure; onward disclosure to the Controller via the organizer dashboard and participant-list exports; associated support and troubleshooting.
Data subjects: riders who register for the Controller's events via the platform, and (where the rider chose to include one) the rider's emergency contact.
Categories of personal data:
Controller / processor split (rider-facing table). The controller/processor split is set out in the Privacy Policy and is binding as between the parties.
Pistaclub processes rider personal data only on documented instructions from the Controller. The Organizer Terms, the platform configuration the Controller sets in the organizer dashboard (registration form fields, event visibility, chat settings, ticket resale policy), and this DPA together constitute those documented instructions.
If Pistaclub is legally required by EU or Member State law to process rider data beyond those instructions (for example, in response to a lawful court order), we will inform the Controller of that requirement before processing, unless the law prohibits disclosure on important grounds of public interest.
Pistaclub ensures that persons authorised to process rider data are bound by a duty of confidentiality of at least equivalent scope to this DPA.
Pistaclub implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
The full technical control set is available on request to enterprise organizers under NDA. The Controller is responsible for implementing its own equivalent measures in respect of rider data once it has been exported or downloaded from the platform.
The Controller gives its general written authorisation for Pistaclub to engage the sub-processors listed below. We will inform the Controller of any intended additions or replacements at least 30 days in advance through the organizer dashboard; the Controller may object on reasonable data-protection grounds and, in that case, either party may terminate the affected part of the Organizer Terms without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Base44 (Wix.com Ltd. group) | Application hosting, database, authentication, storage, and integrations backend. Runs the platform code, stores all entity data, and serves user requests. | European Union / United States |
| Stripe Payments Europe, Ltd. | Card-payment processing for in-app event bookings (destination charges to the organizer’s Stripe Connect account) and Premium subscription billing. | Ireland (EU) |
| Google Cloud Platform (EU regions — via Base44) | Underlying cloud infrastructure and object storage for platform data; Google Gemini API for AI-assisted content translation. | European Union |
| Transactional email provider (Base44-integrated) | Sending booking confirmations, reminders, moderation notifications, organizer team invites, and other operational email. | European Union |
Pistaclub imposes on every sub-processor written data-protection obligations that provide sufficient guarantees to meet GDPR Art. 28 requirements and remains fully liable to the Controller for the performance of the sub-processor's obligations. The public, always-current list — including data categories reaching each sub-processor and the specific safeguards in place — is on the Sub-processors page.
Where a sub-processor processes rider data outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses (Decision 2021/914) or an adequacy decision. Details are available on request.
Where a rider exercises a right under GDPR Art. 15–22 in respect of data held by the Controller, Pistaclub assists the Controller — at the Controller's cost for non-routine requests — by:
On termination of the Organizer Terms, Pistaclub will, at the Controller's choice made within 30 days:
In either case, Pistaclub may retain data for as long as required by EU or Member State law (accounting: up to 10 years for payment transactions; DSA Art. 15 statement-of-reasons records; hash-chain integrity ledger entries), and such retained data continues to be protected under this DPA.
The Controller may audit Pistaclub's compliance with this DPA no more than once every 12 months, or more often after a personal-data breach, subject to reasonable notice, working-hours execution, and protection of Pistaclub's confidential information and other organizers' data. In lieu of an on-site audit, Pistaclub may provide the Controller with an SOC 2 / ISO 27001 report or an equivalent third-party attestation once available. Reasonable audit costs are borne by the Controller.
Pistaclub notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal-data breach that affects rider data processed on the Controller's behalf. The notification will describe the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, measures taken and proposed to address it, and contact points for further information. The Controller is responsible for its own notifications to the supervisory authority (GDPR Art. 33) and to data subjects (Art. 34), unless the parties agree otherwise in writing.
Each party's liability under this DPA is subject to the liability cap in the Organizer Terms (§13), save that neither party's liability for its own gross negligence, wilful misconduct, or death or personal injury caused by it is limited by that cap or by this DPA.
In case of conflict between this DPA and the Organizer Terms on any matter of personal-data processing, this DPA prevails. This DPA is governed by the laws of the Czech Republic and subject to the jurisdiction of the courts of Prague, aligned with the Organizer Terms §15. Amendments follow the process in Organizer Terms §16.
Data-protection queries: privacy@pistaclub.app
DPO: dpo@pistaclub.app
Legal / contract: legal@pistaclub.app