This Data Processing Agreement ("Agreement" or "DPA") is entered into between Outzone Sagl ("Outzone", "we") and the Organizer registered on the Outzone platform ("Organizer", "you"), and governs the processing of the personal data of Users who buy tickets through the Outzone platform for the Events published by the Organizer. It forms an integral part of, and an annex to, the Organizer Terms & Conditions and is accepted together with them.
Outzone and the Organizer act as separate and independent controllers, each for its own purposes. This Agreement is not a controller-processor mandate under Art. 28 GDPR / Art. 9 revFADP: it is a transparency and allocation-of-responsibility arrangement between independent controllers who share personal data through the platform, drafted in the spirit of Art. 26 GDPR and of Arts. 5 and 30–31 of the Swiss Federal Act on Data Protection (revFADP, in force since 01.09.2023) and its Ordinance (DPO/OPDa).
In the event of any discrepancy between the Italian and the English versions of this Agreement, the Italian version prevails.
1. Subject matter, scope and definitions
1.1 Subject matter and scope
This Agreement applies to the personal data of ticket-buying Users that is shared, made accessible or otherwise processed between Outzone and the Organizer in the context of ticket sales and Event management via the Outzone platform.
This Agreement does not govern:
- data the Organizer collects directly from Users outside the platform (e.g. forms, guest lists, direct communications): for these, the Organizer is a fully independent controller;
- the Organizer's merchant-identification / KYC data, processed directly by Stripe when the Organizer uses Stripe Connect; that onboarding is not required for Outzone-managed Events;
- Outzone's processing toward Users as an independent controller (account, feed, security), described in the Privacy Policy.
1.2 Definitions
The definitions of the revFADP and the GDPR apply. In addition:
- "Personal data": any information relating to an identified or identifiable natural person (here: the ticket-buying Users).
- "Processing": any operation performed on personal data.
- "Data subject" / "User": the natural person who buys a ticket.
- "Independent controller": each Party that independently determines, for its own purposes, the means and modalities of processing.
- "Merchant of record": the seller on whose Stripe account the charge is created, which appears on the card statement and is responsible for refunds, disputes and chargebacks: the Organizer or Outzone Sagl, according to the model shown for the Event.
- "Personal data breach": a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
- "Sub-processor": the third party engaged by Outzone to process personal data on its behalf and on its instructions.
2. Essence of the arrangement and roles of the parties
2.1 Payment models and merchant of record
- Organizer sale: the charge is associated with the Organizer's Stripe Connect account. The Organizer is seller and merchant of record and receives the payment-linked name from Stripe.
- Outzone-managed sale: the charge is made on Outzone Sagl's Stripe account. Outzone is seller and merchant of record and processes payment, refund and dispute data. The Organizer receives no payment data from Stripe, but receives from the Platform only the data strictly needed to run the Event and admit the attendee.
Under both models the Organizer remains an independent controller for data processed for Event organization, security and admission.
2.2 Essence of the arrangement (allocation of roles)
Outzone and the Organizer are independent controllers, each for its own purposes. The table below summarizes the allocation of responsibilities and is made available to Users through the Privacy Policy and these public documents.
| Activity | Outzone | Organizer |
|---|---|---|
| Technical platform operation, User accounts, authentication | Controller | Not involved |
| Ticket sale and processing | Controller; also seller/MoR for Outzone-managed sales | Controller; also seller/MoR for Organizer sales |
| Receiving payment data from Stripe | Controller for Outzone-managed sales | Controller for Organizer sales |
| Attendee admission and operational Event management | Not involved | Independent controller |
| Refunds, disputes and chargebacks | Technical execution; financially responsible for Outzone-managed sales | Financially responsible for Organizer sales; always cooperates on Event facts |
| Direct communications to the User about the Event (changes, cancellations) | Only if related to the Outzone service | Independent controller for Event purposes |
| Direct marketing toward Users | Only with User consent collected by Outzone | Permitted only with explicit consent collected directly by the Organizer |
| Aggregate statistics for the Organizer | Controller (generates anonymous/aggregate data with a k=5 threshold) | Recipient of anonymous/aggregate data |
| Single contact point for User rights | info@outzone.app (routing and cooperation, §7) | Cooperates for the data it holds |
2.3 Single contact point for data-subject rights
Although they are independent controllers, the Parties designate info@outzone.app as the single contact point to which Users can address requests concerning their rights. Outzone routes the request to the competent Party and cooperates under §7. This does not deprive the User of the right to address each Party and the supervisory authority.
3. Categories of data subjects and personal data
3.1 Data subjects
The Users who buy tickets through the Outzone platform for the Organizer's Events.
3.2 Categories of personal data
For each ticket, the categories of data shared or made accessible are:
- Identifying data: username and data needed for admission; for Organizer sales, also the name received from Stripe as merchant of record (see §2.1).
- Contact data: the email address associated with the receipt/ticket, where applicable.
- Ticket data: unique identifier, type, quantity, price, currency, any VAT, purchase date, check-in status.
- Any additional data requested by the Organizer and disclosed on the Event page (e.g. accessibility needs), if and when Outzone enables such collection.
- Purchase reports: free text entered by the User in a complaint, which may contain personal data.
Merchant-of-record carve-out. Card data, IBAN and sensitive identifiers are processed by Stripe and are not transmitted to the Organizer. Only for Organizer sales does it see the payment-linked name in its Stripe dashboard; for Outzone-managed sales it receives no payment data from Stripe.
3.3 Data Outzone does NOT transmit to the Organizer via the platform
By design, the immutable sale snapshot stored by Outzone contains no buyer name or email. Outzone does not transmit a payment-data list to the Organizer: it sees data strictly needed for the Event and aggregate metrics; for Organizer sales it may additionally see the payment-linked name through Stripe. The obligations in §5 apply to data the Organizer actually receives or exports.
4. Purposes and legal bases
4.1 Outzone's purposes (controller)
| Purpose | GDPR legal basis | revFADP position |
|---|---|---|
| Technical intermediation, generation and delivery of the digital ticket | Art. 6(1)(b) – contract | Lawful (contract) |
| Technical payment facilitation (via Stripe) | Art. 6(1)(b) contract + 6(1)(f) legitimate interest | Lawful (contract / overriding interest) |
| Service communications about the ticket | Art. 6(1)(b) – contract | Lawful (contract) |
| Accounting and tax obligations | Art. 6(1)(c) – legal obligation | Law (Art. 31) |
| Security, abuse/fraud prevention, audit | Art. 6(1)(f) – legitimate interest | Overriding interest |
| Aggregate/anonymous statistics (k=5 threshold) for the Organizer | Art. 6(1)(f) – legitimate interest | Overriding interest / statistical purpose |
4.2 Organizer's purposes (controller)
| Purpose | GDPR legal basis | revFADP position |
|---|---|---|
| Attendee admission and operational Event management | Art. 6(1)(b) – contract | Lawful (contract) |
| Direct Event communications (changes, cancellations) | Art. 6(1)(b) – contract | Lawful (contract) |
| Managing refunds, disputes and chargebacks when merchant of record; cooperating on Event facts under either model | Art. 6(1)(b) contract + 6(1)(c) legal obligation | Lawful (contract + law) |
| Security and legal obligations connected to the Event | Art. 6(1)(c) – legal obligation | Law |
| Direct marketing toward Users | Art. 6(1)(a) – explicit and separate consent of the User | Consent |
| Retention of the Event's financial/tax records | Art. 6(1)(c) – legal obligation | Law |
The Organizer may not process the received data for further purposes incompatible with those above.
5. Obligations of the parties
5.1 Outzone's obligations
Outzone undertakes to:
- provide Users with a complete notice via the Privacy Policy;
- make accessible to the Organizer only the data strictly necessary to manage the Event;
- implement adequate technical and organizational measures (§8) and host the data in Switzerland (§9);
- engage only sub-processors bound by adequate obligations (§7) and notify changes;
- cooperate with the Organizer on the exercise of User rights and on breach handling (§7, §10);
- maintain a record of processing under Art. 12 revFADP / Art. 30 GDPR.
5.2 Organizer's obligations
The Organizer, as an independent controller and, only for Organizer sales, merchant of record, undertakes to:
- process the received data solely for the stated purposes (§4.2) and in a compatible manner;
- not carry out direct marketing toward Users without the User's explicit and separate consent, collected and documented directly by the Organizer;
- not assign, sell or share the data with unauthorized third parties, nor combine it with external databases for purposes other than Event management;
- implement risk-appropriate technical and organizational measures (Art. 8 revFADP / Art. 32 GDPR);
- appoint a Data Protection Officer (DPO) where required by applicable law — note that a Data Protection Officer (DPO) is a distinct role from a processor;
- retain the data only as long as necessary and for legal obligations, and erase or anonymize it afterward, subject to retention obligations (§6);
- handle refunds, disputes and chargebacks when it is merchant of record and cooperate with Outzone by providing Event information when Outzone is merchant of record;
- notify Outzone, without delay, of breaches involving data received via the platform (§10);
- cooperate with Outzone and with Users on the exercise of rights (§7);
- maintain its own record of processing where required;
- indemnify Outzone per §11.
6. Retention and erasure
Each Party retains the data for as long as necessary for its purposes and legal obligations. Indicatively, for the data covered by this Agreement:
| Category | Retention period |
|---|---|
| Identifying and contact data of the buyer received to manage the Event | For as long as needed to manage the Event and related matters (refunds, disputes), then erased/anonymized |
| Financial, tax and ticketing records (incl. disputes/chargebacks) | For the period required by law (Swiss Code of Obligations, ~10 years) |
| Purchase reports / complaints | For as long as needed to handle the complaint and any defense |
| Aggregate/anonymous statistics (k=5) | Indefinitely (not personal data) |
| Proof of consent, audit/erasure logs (Outzone side) | As proof of compliance, as required by law |
On termination of the relationship, each Party ceases processing for the purposes of the relationship and erases or anonymizes the data, subject to legal retention obligations. The clauses on confidentiality, liability, residual legally-required processing and governing law survive termination.
7. Sub-processors and cooperation on rights
7.1 Outzone's sub-processors
Outzone engages the following sub-processors (processing data on Outzone's behalf and instructions) and relevant independent controllers in the ticketing flow. The current list is available on request at info@outzone.app.
| Provider (entity) | Role | Purpose | Location / transfer |
|---|---|---|---|
| Infomaniak Network SA | Sub-processor | Application and backup hosting | Switzerland – no extra-CH transfer |
| MinIO self-hosted | Sub-processor (Outzone infrastructure) | Object storage (images) | Switzerland |
| Stripe (Stripe Payments Europe Ltd / Stripe Technology Company Ltd, IE; Stripe, Inc./LLC, US) | Independent controller (fraud/AML/compliance) and processor (payment facilitation) | Payments, payouts, disputes, subscriptions | Ireland + USA – DPF / SCCs (§9) |
| Resend (Plus Five Five, Inc.) | Sub-processor | Transactional emails and receipts, email OTP | USA – DPF / SCCs |
| Meta Platforms (WhatsApp Business Platform) | Sub-processor (for Cloud-API OTP messages) | OTP via WhatsApp | USA + EU – DPF / SCCs |
| Sentry (Functional Software, Inc.) | Sub-processor | Error/crash diagnostics | USA – DPF / SCCs |
| OpenRouter, Inc. (and downstream LLM providers) | Sub-processor | Analysis of public Instagram business content to import events (not buyer data) | USA/distributed – SCCs; does not retain prompts by default |
| Google "Sign in with Google" (Google Ireland Ltd / Google LLC) | Independent controller | Authentication | Google infrastructure – own mechanisms (SCCs/DPF) |
| Apple "Sign in with Apple" (Apple Inc. / Apple Distribution International Ltd) | Independent controller | Authentication | Apple infrastructure – own mechanisms |
7.2 Sub-processor changes and right to object
Outzone notifies the Organizer of material changes to the sub-processor list with 30 days' notice, during which the Organizer may raise reasoned objections. If a reasonable objection cannot be resolved, the Organizer may terminate the relationship under the Organizer Terms & Conditions.
7.3 Cooperation on the exercise of rights
Users have the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent (revFADP / GDPR). The Parties cooperate in good faith:
- a request received by one Party but requiring the other's action is forwarded within 7 days to the other Party (or to info@outzone.app);
- the Parties respond to the User within the legal deadlines (as a rule, within 30 days).
8. Technical and organizational measures
The Parties implement and maintain risk-appropriate measures (Art. 8 revFADP / Art. 32 GDPR), including:
- encryption in transit (TLS/HTTPS); encryption at rest where appropriate;
- access control (authentication, least-privilege principle, RBAC, logging);
- backup and disaster recovery with restore testing;
- monitoring, logging and incident handling;
- staff training on privacy and security;
- periodic compliance reviews.
On the Outzone side, in particular: passwords protected with bcrypt, sessions using JWT and revocable refresh tokens, rate limiting and anti-abuse protections, parameterized queries, hosting exclusively in Switzerland with Swiss backups. Card data never transits Outzone's servers (Stripe-side tokenization).
The Organizer guarantees measures appropriate to the nature of the data it receives and to its activity, and reviews them periodically.
9. Cross-border transfers
Data managed by Outzone is hosted in Switzerland (Infomaniak + self-hosted MinIO, with Swiss backups). Some providers are located outside Switzerland. The destination countries are Switzerland (CH), the European Union/EEA, and the United States (US).
- CH↔EU/EEA flows are free thanks to mutual adequacy recognition.
- The United States is not considered generally adequate under the revFADP. For US providers we rely, where available, on EU‑U.S. and Swiss‑U.S. Data Privacy Framework (DPF) certification; otherwise, on Standard Contractual Clauses (SCCs) with the Swiss addendum (Art. 16(2) revFADP / Art. 46 GDPR).
The Organizer guarantees equivalent protections for any transfers it makes on its own initiative and informs Outzone thereof.
10. Personal data breaches — cooperation
Each Party notifies the other of any breach involving the data covered by this Agreement without undue delay and, where possible, within 48 hours of discovery. The notice contains, to the extent available: the nature of the breach, the categories and approximate number of data subjects and data records involved, the likely consequences, and the measures taken/proposed.
The Parties cooperate in managing the breach and in any notifications to the supervisory authority (FDPIC and, where applicable, the competent EU authority) and to data subjects, under applicable law (as a rule within 72 hours of discovery for notification to the competent authority, where required). Each Party remains responsible for the notifications incumbent on it as a controller.
11. Liability and indemnity
Each Party is responsible for its own breaches of this Agreement, the revFADP and the GDPR, and answers to data subjects for the processing within its remit.
The Organizer is responsible for Event delivery and for processing the data received for that purpose. It is also responsible for refunds, disputes and chargebacks when it is merchant of record. The Organizer indemnifies and holds Outzone harmless from claims, penalties, damages and costs (including reasonable legal fees) arising from:
- unlawful or non-compliant processing of the data by the Organizer;
- use of the data for purposes other than those stated;
- failure to adopt adequate security measures;
- unauthorized disclosure of the data to third parties;
- direct marketing toward Users without their explicit consent;
- failure to handle refunds/disputes/chargebacks when it is merchant of record, or failure to cooperate on facts concerning delivery of the Event.
Outzone is responsible for the processing within its remit, within the limits set out in the Organizer Terms & Conditions. Nothing in this Agreement limits liability that mandatory law does not permit to be excluded.
12. Audit
Each Party may request from the other, with reasonable notice (as a rule 30 days) and no more than once a year (save for justified unforeseen events), information and documentation useful to verify compliance with this Agreement. Reviews are conducted without interfering with operations and respecting confidentiality; where justified, the Parties may agree to independent third-party audits. Costs are borne by the requesting Party, unless the audit reveals significant breaches, in which case they are borne by the audited Party.
13. Term, amendments, governing law and forum
13.1 Term
This Agreement takes effect upon acceptance of the Organizer Terms & Conditions and lasts for the duration of the relationship between the Parties. The clauses indicated in §6 survive termination.
13.2 Amendments
Outzone may amend this Agreement to reflect legal, organizational or operational changes. Material changes are communicated with 30 days' notice; continued use of the platform constitutes acceptance and, in case of non-acceptance, the Organizer may terminate within the notice period.
13.3 Governing law and forum
This Agreement is governed by Swiss law, subject to the mandatory provisions of the GDPR and of data-subject-protection law where applicable. Exclusive forum: Lugano (Switzerland).
13.4 Supervisory authority
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch
- European Union/EEA: the competent supervisory authority of the data subject's Member State.
Outzone Sagl · Via Grumo 31, 6929 Gravesano, Ticino, Switzerland · Sagl (CO art. 772 et seq.) · capital CHF 20'000 · CHE-251.077.155 (Ticino Commercial Register) · Managers: Jornod Jeremy and Bovino Simone (sole signature) info@outzone.app · www.outzone.app
This DPA is annexed to the Organizer Terms & Conditions and must be read together with the Privacy Policy, the Ticket Sale & Refund Terms and the Community Guidelines.