NOCTRA

Article 28 processing terms

Data Processing Agreement

Article 28 data-processing terms covering processing that Brockhaus Ventures UG (haftungsbeschränkt) i. G. performs on documented instructions for a professional Workspace customer. This DPA becomes binding when incorporated into and accepted as part of the Workspace Contract.

Version
1.0
Last updated
2026-08-28

Parties

NOCTRA
NOCTRA Intelligence / Brockhaus Ventures UG (haftungsbeschränkt) i. G.
Falgerstraße 7 · 48147 Münster · Germany
Customer / controller where applicable
The professional Workspace customer identified in the accepted Order and the applicable signature or valid acceptance evidence.

Main agreement

1. Parties and scope

This DPA supplements the accepted Workspace Contract between the professional Workspace customer and Brockhaus Ventures UG (haftungsbeschränkt) i. G., operating the NOCTRA Intelligence product. It applies only where NOCTRA processes personal data on behalf of the customer within the meaning of Article 28 GDPR.

The customer is the controller where it determines the purposes and means of the covered processing; NOCTRA is the processor only for the activities listed in Annex 1. Mixed payment, legal-compliance, public-site, security and independent business activities remain outside this customer-processing annex and follow their applicable role and legal basis.

2. Documented instructions

NOCTRA processes covered customer personal data only on documented instructions, including the Order, this DPA, authorized Workspace configuration and documented support requests, unless Union or Member State law requires processing. Where legally permitted, NOCTRA will inform the customer of such a requirement before processing.

If NOCTRA considers an instruction to infringe applicable data-protection law, it will inform the customer and may pause the affected instruction while the issue is resolved.

3. Customer responsibilities

The customer is responsible for the lawfulness of its instructions, the legal basis for customer-controlled processing, required information notices, controller-side decisions on data-subject requests, appropriate Workspace roles and permissions, and avoiding personal data that is unnecessary for the instructed purpose. The customer must use Campaign and contact functions lawfully and must not treat this DPA as a legal basis for outreach.

4. Special-category data

The NOCTRA Platform is not designed for routine processing of special categories of personal data under Article 9 GDPR unless the parties expressly agree the purpose, instructions and safeguards. The customer must avoid unnecessary sensitive information in free-text fields. If the customer intentionally instructs such processing, it is responsible for an applicable legal basis and required safeguards. This clause does not claim that the Platform technically blocks such entries.

5. Confidentiality and security

NOCTRA ensures that persons authorized to process covered data are bound by confidentiality or an appropriate statutory duty. Taking account of the state of the art, implementation costs, scope and risk, NOCTRA maintains the repository-evidenced measures described in Annex 2 and reviews them as the service changes.

6. Subprocessors

The customer grants NOCTRA general written authorization to use subprocessors for covered processing. NOCTRA will engage a subprocessor under a written agreement imposing the data-protection obligations required by Article 28 GDPR for the relevant processing and remains responsible for that subprocessor’s performance as required by applicable law. The canonical current disclosure is maintained on the public Subprocessors page.

Before adding or replacing a subprocessor for customer personal data, NOCTRA will provide notice through the applicable contract or billing contact or a designated Platform notice channel with enough advance time, where practicable, for the customer to object on objectively justified data-protection grounds relating to the proposed processing. The parties will first seek a reasonable solution where practicable. Urgent security, legal or provider circumstances may require shorter notice. This clause creates no automatic penalty or suspension remedy.

7. Data-subject rights assistance

Taking account of the nature of processing, NOCTRA will assist the customer through appropriate technical and organizational measures, insofar as possible, with requests to exercise data-subject rights. NOCTRA will forward requests relating to customer-controlled data and will not respond on the customer’s behalf unless instructed or legally required.

8. Security, breach, DPIA and consultation assistance

Taking account of the information available and the nature of processing, NOCTRA will assist the customer with applicable security obligations, personal-data-breach assessment and notification, data-protection impact assessments and prior consultation. NOCTRA will notify the customer without undue delay after becoming aware of a personal-data breach affecting covered customer data and provide available relevant information in stages where necessary.

9. Deletion or return

After Platform Contract termination, the customer may request return through an available export and/or deletion as applicable. NOCTRA deletes or returns covered customer personal data according to the customer’s documented instruction and deletes existing active copies unless applicable law requires storage. The timing follows the technically available process and the nature of the instructed data; no universal post-termination access period is promised.

Legally required financial, tax, refund, correction, security, contract, audit or dispute evidence may be retained outside active processing. Retained data is restricted to the applicable retention or legal purpose and must not become ordinary active product data. Each evidence category follows its applicable statutory role and retention obligation; no single period applies to every category.

Deletion from backup or provider-held copies follows the technically applicable deletion process; no universal backup-deletion period is promised. Data awaiting deletion remains protected and is not restored to ordinary active use except where necessary for recovery, security or legal obligations.

10. Information and audits

NOCTRA will first make available existing compliance and security documentation reasonably necessary to demonstrate the Article 28 processor obligations. If that evidence is insufficient, the customer may conduct an audit itself or through an independent auditor bound by confidentiality, generally no more than once in any 12-month period. This frequency limit does not apply after a relevant incident, on a competent authority’s request, or where there is credible evidence of a material breach.

Audits require reasonable advance notice, take place during normal business hours, remain proportionate in scope and must not provide access to other customers’ data or compromise security. The customer bears its own audit costs. Extraordinary, demonstrable NOCTRA costs caused by a customer audit may be allocated to the customer where legally permissible, unless the audit identifies a material breach by NOCTRA. Statutory supervisory and authority rights remain unaffected.

11. International transfers

NOCTRA will not make covered customer data available in a third country except on documented instructions and with a transfer basis and safeguards required by applicable law. Provider entities, processing regions and transfer mechanisms are not asserted until verified in the public Subprocessors disclosure and the applicable provider contracts.

12. Liability and precedence

Liability under this DPA follows the liability framework in the effective Platform Contract and mandatory data-protection law. For covered processor obligations, the executed DPA prevails over conflicting Platform Terms; the Order prevails only where it expressly and lawfully modifies the relevant provision.

Annex 1 — Processing description

01

Accounts and team data

Data subjects
Workspace owners, administrators, members and invited users.
Personal-data categories
Names, email addresses, account identifiers, role and permission assignments, invitations, membership and access status.
Purposes
Authenticate users and administer customer-authorized Workspace access.
Processing operations
Collect, record, organize, retrieve, display, update, restrict, revoke and delete where implemented or instructed.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
02

Workspace and organizer operational data

Data subjects
Customer representatives, organizers, staff, promoters, contractors and business contacts recorded by the customer.
Personal-data categories
Contact, role, organizer, Event, Venue, staffing, operational note, task, schedule, branding and configuration data where it relates to a person.
Purposes
Operate the customer’s Workspace, Events, external Event locations and managed Venue workflows.
Processing operations
Store, structure, display, update, associate with Events or Venues, report and export where implemented.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
03

Guestlist and Door data

Data subjects
Guests, VIPs, attendees, promoters, staff, external Door operators and pass holders.
Personal-data categories
Names, list category, affiliation, notes entered by the customer, pass and invitation identifiers, check-in, denial, revocation and access-event data.
Purposes
Prepare and operate Guestlist, access and Door workflows for the customer’s Event.
Processing operations
Import or enter, organize, display, search, validate, record access events, restrict, revoke and report.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
04

Ticket purchaser and attendee data

Data subjects
Ticket purchasers, billing contacts, ticket holders, attendees and transfer recipients.
Personal-data categories
Name, email, billing contact data, purchase and ticket references, ticket quantities and categories, protected access and transfer references.
Purposes
Support ticket ordering, delivery, validation, transfer and customer-authorized attendee operations.
Processing operations
Collect, record, associate, disclose to authorized customer users and service providers, deliver, validate, transfer, restrict and retain as required.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
05

Reservation, order, ticket and refund data

Data subjects
Purchasers, attendees, refund recipients and customer users performing ticket or refund actions.
Personal-data categories
Reservation status, order and payment references, line items, gross amounts and currency, ticket status, refund reasons and references, invoice or correction evidence and action metadata.
Purposes
Administer the customer’s ticket transactions, fulfilment, refund decisions and related records.
Processing operations
Create, validate, reconcile, update status, issue documents, communicate, refund and preserve immutable or versioned evidence where implemented.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
06

Campaign customer data

Data subjects
Customer contacts, prospective attendees and audience records entered or selected by an authorized Workspace user.
Personal-data categories
Contact, audience, segmentation, campaign configuration, status and performance data where a campaign feature is used.
Purposes
Configure and operate customer-directed Campaign workflows where available and enabled.
Processing operations
Import or enter, organize, segment, select, display, update and report. This annex does not establish a legal basis for customer outreach.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
07

Event and report evidence

Data subjects
Customer users and persons represented in operational, commercial or access data aggregated into an Event or periodic report.
Personal-data categories
User attribution, Event operations, attendance, ticketing, revenue, cost, performance, version and generation metadata where personally identifiable.
Purposes
Generate, present and preserve customer-requested operational and performance reports and their evidence history.
Processing operations
Aggregate, calculate, structure, render, version, export where implemented and preserve completed evidence.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
08

Support and security data

Data subjects
Customer users, contacts and persons whose data appears in a customer-authorized support or security request.
Personal-data categories
Contact details, request content, relevant Workspace records, technical event data, access or revocation status and pseudonymized abuse signals where NOCTRA handles them on the customer’s behalf.
Purposes
Resolve customer-authorized support issues and protect the customer’s Workspace and workflows.
Processing operations
Receive, inspect, retrieve, diagnose, communicate, restrict, revoke and record resolution evidence.
Duration
For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.

Separate and mixed controller activities

Activities outside the customer-processing annex

  • NOCTRA’s own Platform account, contract, invoicing and business-contact administration.
  • Platform security, fraud or abuse prevention and defence of legal claims where NOCTRA determines the relevant purposes and means.
  • Public-site, workspace-access inquiry and consent-gated analytics activity described in the Privacy Notice.
  • Stripe payment and Connect activities, legally required transaction evidence and other mixed-role processing until each role is contractually verified.

Annex 2 — Technical and Organizational Measures

This technical inventory describes controls evidenced in the repository. It is not a certification, audit report or guarantee of a particular security standard.

Authentication and access control

Authentication

Supabase Auth supports user identity and sessions; protected server flows resolve the authenticated user through server-managed authentication rather than trusting a client-supplied identity.

Scoped authorization

Workspace-scoped authorization, owner/admin/member roles, module permissions and database RLS or guarded RPC paths restrict application operations to authorized scopes.

Privileged credentials

The Supabase service-role client and other privileged credentials are confined to server-only modules and are not intentionally exposed to browser code.

Access and revocation controls

Workspace membership, invitations, Door access and selected pass or transfer authorities have implemented revocation or expiry controls; account flows support scoped sign-out and session revocation.

Data and transaction protection

Protected tokens and abuse signals

Selected checkout and transfer authorities are stored or compared as SHA-256 hashes; public rate limiting derives a pseudonymized signal with HMAC instead of storing the available raw request-origin signal in the limiter key.

Time-limited file access

Where implemented for Event covers and organizer branding, stored files are presented through time-limited signed URLs rather than permanent public application URLs.

Webhook verification

Stripe Connect webhook events are constructed only after signature verification against the configured webhook secret.

Idempotent transaction controls

Ticket checkout, refund and transactional-email paths use scoped idempotency keys or persisted provider references to reduce accidental duplicate operations.

Versioned and immutable evidence

Implemented legal formation, report, financial, tax, refund and correction records use versioned snapshots or append-only and immutable database guards for completed evidence paths.

Operational security and change control

Rate limiting

Upstash Redis supports server-side limits for selected public reservation and refund operations; limiter analytics is disabled in the current configuration.

Secure development and dependency control

The repository uses a dependency lockfile and a read-only CI quality gate that installs locked dependencies and runs linting, TypeScript checks, deterministic tests and a production build for pull requests and pushes to the main branch.

Deployment and change controls

Repository guidance separates Production and Preview configuration, prohibits Production credentials in Preview, and represents database schema changes through versioned forward migrations. These controls do not constitute a certification or an availability commitment.

Security incident contact and notification

NOCTRA publishes a dedicated security contact. Section 8 requires notification without undue delay after NOCTRA becomes aware of a personal-data breach affecting covered customer data and permits relevant information to follow in stages where necessary.

Annex 3 — Subprocessors

The canonical public provider disclosure is maintained on the Subprocessors page. It includes technical classifications and explicitly unresolved provider facts instead of duplicating them in this Annex.

The customer grants general written authorization for subprocessors subject to the change-notice and justified-objection process in section 6. The current Workspace subprocessors are listed in the public Subprocessor Disclosure.

Subprocessors
Back to NOCTRA