Legal

Data Processing Addendum

Draft — not in effect This document has no version in force and no effective date. It has not been reviewed by a qualified professional and must not be relied on.

Effective date: [TO BE SET AT PUBLICATION] Version: 0.1.0

This Data Processing Addendum (“DPA”) forms part of the TicketQuill Terms of Service between the customer identified in the applicable TicketQuill account or Discord installation (“Customer”) and Black Tide Studio (“TicketQuill”).

This DPA applies only to personal information that TicketQuill processes on Customer’s behalf as a processor, service provider, or equivalent role under applicable data-protection law (“Customer Data”). It does not govern information TicketQuill processes for its own independent purposes, such as its own security, billing, legal, support, or account-administration records.

1. Roles

For Customer Data, Customer is the controller/business or equivalent party and TicketQuill is the processor/service provider to the extent required by applicable law.

Customer determines the purposes and means of processing Customer Data and gives TicketQuill documented instructions through the Service configuration, these Terms, this DPA, and reasonable support requests consistent with the Service.

2. Subject matter and duration

TicketQuill processes Customer Data to provide, maintain, secure, troubleshoot, and support the TicketQuill Service for the duration of Customer’s use of the Service and for limited post-termination periods necessary for deletion, backup expiry, legal compliance, or security.

3. Nature and purpose of processing

Processing may include collection, organization, storage, retrieval, transmission, display, configuration, support, security monitoring, deletion, and other processing reasonably necessary to operate the Service.

4. Categories of data and data subjects

Customer may instruct TicketQuill to process identifiers, Discord identifiers, ticket operational metadata, form responses, configuration information, and other information submitted through the Service.

Data subjects may include Discord server members, customers, staff, moderators, administrators, and other individuals whose information Customer places into the Service.

Customer must not intentionally instruct TicketQuill to process highly sensitive information prohibited by the Terms unless TicketQuill has expressly agreed in writing after appropriate legal and technical review.

5. Customer responsibilities

Customer will:

6. TicketQuill obligations

TicketQuill will:

7. Subprocessors

Customer gives general authorization for TicketQuill to use subprocessors reasonably necessary to provide the Service.

Current subprocessors that process Customer Data are listed in the TicketQuill Privacy Policy. TicketQuill will provide notice of intended additions or replacements where required by applicable law. Customer may object on reasonable data-protection grounds within the period required by applicable law.

If an objection cannot reasonably be resolved, TicketQuill may offer a commercially reasonable alternative where available or allow Customer to stop using the affected processing feature.

8. Security measures

TicketQuill maintains safeguards appropriate to its size, architecture, and risk profile. Current measures include:

Backup files are currently access-restricted rather than encrypted at rest. TicketQuill does not represent that data is encrypted at rest.

TicketQuill may update these measures as its architecture changes, provided the overall security of processing is not materially reduced.

9. Security incidents

If TicketQuill confirms a security incident involving Customer Data, TicketQuill will notify Customer without undue delay where notification is required by applicable law or reasonably necessary for Customer to meet its own obligations.

To the extent reasonably available, the notice will describe the nature of the incident, categories of information affected, known or suspected impact, and mitigation measures. TicketQuill will provide reasonable updates as material information becomes available.

Customer remains responsible for notifying affected individuals or regulators where Customer is legally required to do so, except to the extent TicketQuill has an independent legal obligation.

10. Data-subject requests

If TicketQuill receives a request from an individual concerning Customer Data for which Customer is controller, TicketQuill may direct the individual to Customer and will reasonably assist Customer where required by applicable law.

TicketQuill will not independently respond to or disclose Customer Data except as instructed by Customer, required by law, or necessary to protect rights, security, or the Service.

11. Government requests

If TicketQuill receives a legally binding request from a governmental authority for Customer Data, TicketQuill will, where legally permitted, notify Customer before disclosure and provide reasonable assistance to challenge or narrow the request. TicketQuill will disclose only the information legally required.

12. International transfers

Where Customer Data is subject to EU/EEA transfer restrictions, the parties will use an applicable lawful transfer mechanism.

Where required for a transfer to a non-EEA country, the parties may rely on the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with any supplementary measures required by applicable law.

For UK restricted transfers, the parties will use the applicable UK transfer mechanism, including the UK International Data Transfer Agreement, UK Addendum, adequacy regulations, or another lawful mechanism as applicable.

13. Deletion and return

At Customer’s request following termination, TicketQuill will delete Customer Data within the periods described in the Privacy Policy, subject to legal retention requirements and the normal expiration of backups on their rolling schedule.

Where the Service architecture does not provide a practical export mechanism, TicketQuill is not required to create a custom export at no charge, but will provide reasonable assistance available through normal Service functionality.

14. Audits and compliance information

Customer may request information reasonably necessary to demonstrate TicketQuill’s compliance with applicable processor obligations. Where legally required and where a reasonable documentary review is insufficient, Customer may request a remote audit or other proportionate assessment, subject to reasonable notice, confidentiality, security restrictions, and protection of other customers’ information.

Audits must not unreasonably interfere with TicketQuill operations or expose security-sensitive information, trade secrets, or information belonging to other customers.

15. Conflict and precedence

If this DPA conflicts with the TicketQuill Terms of Service concerning the processing of Customer Data, this DPA controls for that specific processing matter.

If applicable law imposes a mandatory requirement that cannot be contractually changed, that requirement controls.

16. Liability

The liability provisions of the TicketQuill Terms apply to this DPA unless applicable law requires otherwise.

Nothing in this DPA is intended to limit a party’s liability to the extent such limitation is prohibited by applicable law.

17. Contact

Privacy and DPA requests: privacy@ticketquill.com Security incidents: security@ticketquill.com