Article 28 processing terms
Data Processing Agreement
Article 28 data-processing terms covering processing that Brockhaus Ventures UG (haftungsbeschränkt) i. G. performs on documented instructions for a professional Workspace customer. This DPA becomes binding when incorporated into and accepted as part of the Workspace Contract.
- Version
- 1.0
- Last updated
- 2026-08-28
Related documents
Parties
- NOCTRA
- NOCTRA Intelligence / Brockhaus Ventures UG (haftungsbeschränkt) i. G.
Falgerstraße 7 · 48147 Münster · Germany - Customer / controller where applicable
- The professional Workspace customer identified in the accepted Order and the applicable signature or valid acceptance evidence.
Main agreement
1. Parties and scope
This DPA supplements the accepted Workspace Contract between the professional Workspace customer and Brockhaus Ventures UG (haftungsbeschränkt) i. G., operating the NOCTRA Intelligence product. It applies only where NOCTRA processes personal data on behalf of the customer within the meaning of Article 28 GDPR.
The customer is the controller where it determines the purposes and means of the covered processing; NOCTRA is the processor only for the activities listed in Annex 1. Mixed payment, legal-compliance, public-site, security and independent business activities remain outside this customer-processing annex and follow their applicable role and legal basis.
2. Documented instructions
NOCTRA processes covered customer personal data only on documented instructions, including the Order, this DPA, authorized Workspace configuration and documented support requests, unless Union or Member State law requires processing. Where legally permitted, NOCTRA will inform the customer of such a requirement before processing.
If NOCTRA considers an instruction to infringe applicable data-protection law, it will inform the customer and may pause the affected instruction while the issue is resolved.
3. Customer responsibilities
The customer is responsible for the lawfulness of its instructions, the legal basis for customer-controlled processing, required information notices, controller-side decisions on data-subject requests, appropriate Workspace roles and permissions, and avoiding personal data that is unnecessary for the instructed purpose. The customer must use Campaign and contact functions lawfully and must not treat this DPA as a legal basis for outreach.
4. Special-category data
The NOCTRA Platform is not designed for routine processing of special categories of personal data under Article 9 GDPR unless the parties expressly agree the purpose, instructions and safeguards. The customer must avoid unnecessary sensitive information in free-text fields. If the customer intentionally instructs such processing, it is responsible for an applicable legal basis and required safeguards. This clause does not claim that the Platform technically blocks such entries.
5. Confidentiality and security
NOCTRA ensures that persons authorized to process covered data are bound by confidentiality or an appropriate statutory duty. Taking account of the state of the art, implementation costs, scope and risk, NOCTRA maintains the repository-evidenced measures described in Annex 2 and reviews them as the service changes.
6. Subprocessors
The customer grants NOCTRA general written authorization to use subprocessors for covered processing. NOCTRA will engage a subprocessor under a written agreement imposing the data-protection obligations required by Article 28 GDPR for the relevant processing and remains responsible for that subprocessor’s performance as required by applicable law. The canonical current disclosure is maintained on the public Subprocessors page.
Before adding or replacing a subprocessor for customer personal data, NOCTRA will provide notice through the applicable contract or billing contact or a designated Platform notice channel with enough advance time, where practicable, for the customer to object on objectively justified data-protection grounds relating to the proposed processing. The parties will first seek a reasonable solution where practicable. Urgent security, legal or provider circumstances may require shorter notice. This clause creates no automatic penalty or suspension remedy.
7. Data-subject rights assistance
Taking account of the nature of processing, NOCTRA will assist the customer through appropriate technical and organizational measures, insofar as possible, with requests to exercise data-subject rights. NOCTRA will forward requests relating to customer-controlled data and will not respond on the customer’s behalf unless instructed or legally required.
8. Security, breach, DPIA and consultation assistance
Taking account of the information available and the nature of processing, NOCTRA will assist the customer with applicable security obligations, personal-data-breach assessment and notification, data-protection impact assessments and prior consultation. NOCTRA will notify the customer without undue delay after becoming aware of a personal-data breach affecting covered customer data and provide available relevant information in stages where necessary.
9. Deletion or return
After Platform Contract termination, the customer may request return through an available export and/or deletion as applicable. NOCTRA deletes or returns covered customer personal data according to the customer’s documented instruction and deletes existing active copies unless applicable law requires storage. The timing follows the technically available process and the nature of the instructed data; no universal post-termination access period is promised.
Legally required financial, tax, refund, correction, security, contract, audit or dispute evidence may be retained outside active processing. Retained data is restricted to the applicable retention or legal purpose and must not become ordinary active product data. Each evidence category follows its applicable statutory role and retention obligation; no single period applies to every category.
Deletion from backup or provider-held copies follows the technically applicable deletion process; no universal backup-deletion period is promised. Data awaiting deletion remains protected and is not restored to ordinary active use except where necessary for recovery, security or legal obligations.
10. Information and audits
NOCTRA will first make available existing compliance and security documentation reasonably necessary to demonstrate the Article 28 processor obligations. If that evidence is insufficient, the customer may conduct an audit itself or through an independent auditor bound by confidentiality, generally no more than once in any 12-month period. This frequency limit does not apply after a relevant incident, on a competent authority’s request, or where there is credible evidence of a material breach.
Audits require reasonable advance notice, take place during normal business hours, remain proportionate in scope and must not provide access to other customers’ data or compromise security. The customer bears its own audit costs. Extraordinary, demonstrable NOCTRA costs caused by a customer audit may be allocated to the customer where legally permissible, unless the audit identifies a material breach by NOCTRA. Statutory supervisory and authority rights remain unaffected.
11. International transfers
NOCTRA will not make covered customer data available in a third country except on documented instructions and with a transfer basis and safeguards required by applicable law. Provider entities, processing regions and transfer mechanisms are not asserted until verified in the public Subprocessors disclosure and the applicable provider contracts.
12. Liability and precedence
Liability under this DPA follows the liability framework in the effective Platform Contract and mandatory data-protection law. For covered processor obligations, the executed DPA prevails over conflicting Platform Terms; the Order prevails only where it expressly and lawfully modifies the relevant provision.
Annex 1 — Processing description
Accounts and team data
- Data subjects
- Workspace owners, administrators, members and invited users.
- Personal-data categories
- Names, email addresses, account identifiers, role and permission assignments, invitations, membership and access status.
- Purposes
- Authenticate users and administer customer-authorized Workspace access.
- Processing operations
- Collect, record, organize, retrieve, display, update, restrict, revoke and delete where implemented or instructed.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Workspace and organizer operational data
- Data subjects
- Customer representatives, organizers, staff, promoters, contractors and business contacts recorded by the customer.
- Personal-data categories
- Contact, role, organizer, Event, Venue, staffing, operational note, task, schedule, branding and configuration data where it relates to a person.
- Purposes
- Operate the customer’s Workspace, Events, external Event locations and managed Venue workflows.
- Processing operations
- Store, structure, display, update, associate with Events or Venues, report and export where implemented.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Guestlist and Door data
- Data subjects
- Guests, VIPs, attendees, promoters, staff, external Door operators and pass holders.
- Personal-data categories
- Names, list category, affiliation, notes entered by the customer, pass and invitation identifiers, check-in, denial, revocation and access-event data.
- Purposes
- Prepare and operate Guestlist, access and Door workflows for the customer’s Event.
- Processing operations
- Import or enter, organize, display, search, validate, record access events, restrict, revoke and report.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Ticket purchaser and attendee data
- Data subjects
- Ticket purchasers, billing contacts, ticket holders, attendees and transfer recipients.
- Personal-data categories
- Name, email, billing contact data, purchase and ticket references, ticket quantities and categories, protected access and transfer references.
- Purposes
- Support ticket ordering, delivery, validation, transfer and customer-authorized attendee operations.
- Processing operations
- Collect, record, associate, disclose to authorized customer users and service providers, deliver, validate, transfer, restrict and retain as required.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Reservation, order, ticket and refund data
- Data subjects
- Purchasers, attendees, refund recipients and customer users performing ticket or refund actions.
- Personal-data categories
- Reservation status, order and payment references, line items, gross amounts and currency, ticket status, refund reasons and references, invoice or correction evidence and action metadata.
- Purposes
- Administer the customer’s ticket transactions, fulfilment, refund decisions and related records.
- Processing operations
- Create, validate, reconcile, update status, issue documents, communicate, refund and preserve immutable or versioned evidence where implemented.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Campaign customer data
- Data subjects
- Customer contacts, prospective attendees and audience records entered or selected by an authorized Workspace user.
- Personal-data categories
- Contact, audience, segmentation, campaign configuration, status and performance data where a campaign feature is used.
- Purposes
- Configure and operate customer-directed Campaign workflows where available and enabled.
- Processing operations
- Import or enter, organize, segment, select, display, update and report. This annex does not establish a legal basis for customer outreach.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Event and report evidence
- Data subjects
- Customer users and persons represented in operational, commercial or access data aggregated into an Event or periodic report.
- Personal-data categories
- User attribution, Event operations, attendance, ticketing, revenue, cost, performance, version and generation metadata where personally identifiable.
- Purposes
- Generate, present and preserve customer-requested operational and performance reports and their evidence history.
- Processing operations
- Aggregate, calculate, structure, render, version, export where implemented and preserve completed evidence.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Support and security data
- Data subjects
- Customer users, contacts and persons whose data appears in a customer-authorized support or security request.
- Personal-data categories
- Contact details, request content, relevant Workspace records, technical event data, access or revocation status and pseudonymized abuse signals where NOCTRA handles them on the customer’s behalf.
- Purposes
- Resolve customer-authorized support issues and protect the customer’s Workspace and workflows.
- Processing operations
- Receive, inspect, retrieve, diagnose, communicate, restrict, revoke and record resolution evidence.
- Duration
- For the relevant Workspace service and thereafter only until instructed deletion or return is completed through the technically available process, subject to applicable legal retention.
Separate and mixed controller activities
Activities outside the customer-processing annex
- NOCTRA’s own Platform account, contract, invoicing and business-contact administration.
- Platform security, fraud or abuse prevention and defence of legal claims where NOCTRA determines the relevant purposes and means.
- Public-site, workspace-access inquiry and consent-gated analytics activity described in the Privacy Notice.
- Stripe payment and Connect activities, legally required transaction evidence and other mixed-role processing until each role is contractually verified.
Annex 2 — Technical and Organizational Measures
This technical inventory describes controls evidenced in the repository. It is not a certification, audit report or guarantee of a particular security standard.
Authentication and access control
Authentication
Supabase Auth supports user identity and sessions; protected server flows resolve the authenticated user through server-managed authentication rather than trusting a client-supplied identity.
Scoped authorization
Workspace-scoped authorization, owner/admin/member roles, module permissions and database RLS or guarded RPC paths restrict application operations to authorized scopes.
Privileged credentials
The Supabase service-role client and other privileged credentials are confined to server-only modules and are not intentionally exposed to browser code.
Access and revocation controls
Workspace membership, invitations, Door access and selected pass or transfer authorities have implemented revocation or expiry controls; account flows support scoped sign-out and session revocation.
Data and transaction protection
Protected tokens and abuse signals
Selected checkout and transfer authorities are stored or compared as SHA-256 hashes; public rate limiting derives a pseudonymized signal with HMAC instead of storing the available raw request-origin signal in the limiter key.
Time-limited file access
Where implemented for Event covers and organizer branding, stored files are presented through time-limited signed URLs rather than permanent public application URLs.
Webhook verification
Stripe Connect webhook events are constructed only after signature verification against the configured webhook secret.
Idempotent transaction controls
Ticket checkout, refund and transactional-email paths use scoped idempotency keys or persisted provider references to reduce accidental duplicate operations.
Versioned and immutable evidence
Implemented legal formation, report, financial, tax, refund and correction records use versioned snapshots or append-only and immutable database guards for completed evidence paths.
Operational security and change control
Rate limiting
Upstash Redis supports server-side limits for selected public reservation and refund operations; limiter analytics is disabled in the current configuration.
Secure development and dependency control
The repository uses a dependency lockfile and a read-only CI quality gate that installs locked dependencies and runs linting, TypeScript checks, deterministic tests and a production build for pull requests and pushes to the main branch.
Deployment and change controls
Repository guidance separates Production and Preview configuration, prohibits Production credentials in Preview, and represents database schema changes through versioned forward migrations. These controls do not constitute a certification or an availability commitment.
Security incident contact and notification
NOCTRA publishes a dedicated security contact. Section 8 requires notification without undue delay after NOCTRA becomes aware of a personal-data breach affecting covered customer data and permits relevant information to follow in stages where necessary.
Annex 3 — Subprocessors
The canonical public provider disclosure is maintained on the Subprocessors page. It includes technical classifications and explicitly unresolved provider facts instead of duplicating them in this Annex.
The customer grants general written authorization for subprocessors subject to the change-notice and justified-objection process in section 6. The current Workspace subprocessors are listed in the public Subprocessor Disclosure.
Subprocessors