Transparent Data Processing
We process your personal data with the highest standards of security and transparency. Learn about our lawful basis for processing, your rights, and how we protect your information throughout the PartyPad platform.
This data processing policy is effective as of January 1, 2025
Last Updated
January 1, 2025
Review Schedule
Updated annually or as needed
Notice: We may update this data processing policy from time to time to reflect changes in our processing activities, legal requirements, or business practices. We will notify you of any material changes by updating the "Last Updated" date and providing notice through our platform or via email as required by law.
Data Processing Policy Details
Comprehensive information about how PartyPad processes personal data in compliance with GDPR and other privacy regulations.
PartyPad acts as the data controller for personal data processed through our platform. As the controller, we determine the purposes and means of processing your personal data.
Controller Details
- Company Name: PartyPad, Inc.
- Legal Structure: Texas S-Corporation
- Contact: admin@gopartypad.com
- Data Protection Officer: admin@gopartypad.com
Controller Responsibilities
- Determine purposes and means of data processing
- Ensure lawful basis for all processing activities
- Implement appropriate technical and organizational measures
- Respond to data subject rights requests
- Maintain records of processing activities
We process personal data only when we have a lawful basis under GDPR Article 6. Different processing activities rely on different legal bases.
Contract Performance (Article 6(1)(b))
- Account creation and management
- Service delivery and platform functionality
- Payment processing and billing
- Contractor matching and coordination
- Customer support and dispute resolution
Legitimate Interest (Article 6(1)(f))
- Platform security and fraud prevention
- Business analytics and service improvement
- Network and information security
- Internal administration and operations
- Legal compliance and regulatory reporting
Consent (Article 6(1)(a))
- Marketing communications and newsletters
- Non-essential cookies and tracking
- Optional features and enhancements
- Third-party integrations and sharing
Legal Obligation (Article 6(1)(c))
- Tax reporting and financial compliance
- Anti-money laundering checks
- Regulatory reporting requirements
- Court orders and legal proceedings
We process various categories of personal data depending on your role and how you use our platform.
Identity Data
- Name, email address, phone number
- Business name and registration details
- Profile information and preferences
- Account credentials and authentication data
Business Data
- Event details and rental information
- Customer contact information
- Inventory and pricing data
- Task assignments and scheduling
Contractor Data
- Contact details and account credentials
- Any qualifications you choose to record about them
- Performance ratings you record about them
- Location data and availability
Technical Data
- IP address and device information
- Browser type and operating system
- Usage patterns and analytics data
- Cookies and tracking identifiers
Financial Data
- Payment method information (tokenized)
- Transaction history and billing records
- Tax identification numbers
- Banking details for contractor payments
We process personal data for specific, explicit, and legitimate purposes related to operating the PartyPad platform.
Platform Operations
- User account management and authentication
- Service delivery and platform functionality
- Payment processing and financial transactions
- Customer support and technical assistance
Contractor Coordination
- Delivering task assignments to the contractors you manage
- Recording job status, photos and completion times
- Performance ratings you record about your own contractors
- Location data while a job is active
Business Intelligence
- Usage analytics and platform optimization
- Market research and trend analysis
- Service improvement and feature development
- Business performance monitoring
Legal and Compliance
- Regulatory compliance and reporting
- Fraud prevention and security monitoring
- Dispute resolution and legal proceedings
- Record keeping and audit requirements
We share personal data with specific categories of recipients only when necessary for our business operations and with appropriate safeguards.
Service Providers
- Payment Processor: Stripe for secure transactions
- Hosting: Linode for our servers and database
- File Storage: Cloudinary for images and documents you upload
- Analytics Providers: Google Analytics 4 and Google Tag Manager, on our public marketing pages only — not on your dashboard
- Push Notifications: Firebase Cloud Messaging and Expo for mobile alerts
- Communication Tools: SendGrid for notifications
Platform Users
- Business contact information shared with assigned contractors
- Contractor profiles and ratings visible to businesses
- Event details shared for service delivery purposes
- Performance feedback and reviews (anonymized when possible)
Legal and Regulatory
- Law enforcement agencies (when legally required)
- Regulatory authorities for compliance purposes
- Legal advisors and professional service providers
- Courts and tribunals in legal proceedings
Data Processing Agreements: All service providers are bound by data processing agreements that ensure appropriate protection of your personal data.
Some of our service providers are located outside the European Economic Area (EEA). We ensure appropriate safeguards are in place for all international transfers.
Transfer Mechanisms
- Adequacy Decisions: Transfers to countries with adequate protection
- Standard Contractual Clauses: EU-approved contract terms
- Certification Schemes: Privacy Shield successors and equivalents
- Binding Corporate Rules: For multinational service providers
Primary Transfer Destinations
- United States: Cloud infrastructure and analytics services
- Canada: Customer support and data processing
- United Kingdom: Business intelligence and reporting
- Australia: Technical support and development
Additional Safeguards
- Encryption in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and audits
- Incident response and breach notification procedures
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations.
Account Data
- Active Accounts: Duration of account plus 30 days
- Closed Accounts: 7 years for tax and legal compliance
- Authentication Logs: 2 years for security purposes
- Profile Information: Until account deletion requested
Business Data
- Event Records: 7 years for business and tax purposes
- Customer Information: 3 years after last interaction
- Financial Transactions: 7 years for regulatory compliance
- Communication Records: 3 years for dispute resolution
Contractor Data
- Verification Documents: 7 years after contractor departure
- Performance Records: 5 years for quality assurance
- Task and Job Records: Retained for the life of the account
- Location Data: 30 days unless longer retention consented
Technical Data
- Server Logs: 1 year for security and troubleshooting
- Analytics Data: 2 years for business intelligence
- Cookies: As specified in our Cookie Policy
- Backup Data: 90 days in encrypted backups
Under GDPR and other privacy laws, you have specific rights regarding your personal data. We provide mechanisms to exercise these rights easily and efficiently.
Right of Access (Article 15)
- Request a copy of your personal data we hold
- Information about processing purposes and legal basis
- Details of data sharing and retention periods
- Available through account dashboard or data request form
Right to Rectification (Article 16)
- Correct inaccurate or incomplete personal data
- Update profile information and preferences
- Modify business details and contact information
- Most updates can be made directly in your account
Right to Erasure (Article 17)
- Request deletion of your personal data
- Account closure and data removal
- Subject to legal retention requirements
- Some data may be anonymized rather than deleted
Right to Data Portability (Article 20)
- Receive your data in a structured, machine-readable format
- Transfer data to another service provider
- Available for data processed based on consent or contract
- Export functionality available in account settings
Right to Object (Article 21)
- Object to processing based on legitimate interest
- Opt out of direct marketing communications
- Object to automated decision-making
- We will stop processing unless we have compelling legitimate grounds
Right to Restrict Processing (Article 18)
- Limit how we process your data in certain circumstances
- During disputes about accuracy or lawfulness
- When you object to processing pending our response
- Data will be stored but not actively processed
We implement comprehensive technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction.
Technical Safeguards
- Encryption: AES-256 encryption for data at rest and TLS 1.3 in transit
- Access Controls: Role-based permissions and multi-factor authentication
- Network Security: Firewalls, intrusion detection, and monitoring
- Data Backup: Encrypted backups with geographic redundancy
Organizational Measures
- Staff Training: Regular privacy and security awareness training
- Access Management: Principle of least privilege and regular reviews
- Incident Response: Documented procedures for security breaches
- Vendor Management: Due diligence and contractual protections
Compliance and Auditing
- Regular security assessments and penetration testing
- SOC 2 Type II compliance for service providers
- ISO 27001 information security management
- Annual third-party security audits
Security by Design: We implement privacy and security considerations from the earliest stages of system design and throughout the development lifecycle.
We have established procedures to detect, investigate, and respond to personal data breaches in compliance with GDPR requirements.
Breach Detection
- 24/7 security monitoring and alerting systems
- Automated anomaly detection and threat intelligence
- Regular security assessments and vulnerability scanning
- Staff training on identifying potential breaches
Response Timeline
- Immediate (0-1 hours): Contain the breach and assess impact
- 72 hours: Notify supervisory authority if high risk
- Without undue delay: Notify affected individuals if high risk
- Ongoing: Document incident and implement improvements
Notification Content
- Nature of the breach and categories of data affected
- Likely consequences and potential impact
- Measures taken to address the breach
- Recommendations for individuals to protect themselves
Prevention Measures
- Regular security training and awareness programs
- Continuous monitoring and threat detection
- Incident response plan testing and updates
- Post-incident analysis and system improvements
We use automated systems to enhance our services, including contractor matching and fraud detection. You have rights regarding automated decision-making.
Automated Systems We Use
- Contractor Matching: Algorithm matches businesses with suitable contractors
- Fraud Detection: Automated systems identify suspicious activities
- Risk Assessment: Evaluate contractor performance and reliability
- Pricing Optimization: Dynamic pricing based on demand and availability
Human Oversight
- All automated decisions can be reviewed by human operators
- Appeals process for disputed automated decisions
- Regular auditing of algorithmic fairness and accuracy
- Manual override capabilities for exceptional circumstances
Your Rights
- Right to human review of automated decisions
- Right to contest and appeal automated decisions
- Right to explanation of the logic involved
- Right to opt out of certain automated processing
Algorithmic Transparency: We are committed to ensuring our automated systems are fair, transparent, and free from discriminatory bias.
We may update our data processing activities from time to time. We will notify you of any material changes that affect your rights or our processing.
Types of Changes
- New processing purposes or legal bases
- Additional categories of personal data
- Changes to data sharing arrangements
- Updates to retention periods or security measures
Notification Process
- Email notification for material changes
- Platform notifications and dashboard alerts
- Updated policy posted with effective date
- 30-day notice period for significant changes
Your Options
- Review changes and update your preferences
- Withdraw consent for new processing activities
- Object to processing based on legitimate interest
- Close your account if you disagree with changes
Record Keeping
- Maintain records of all processing activities
- Document legal basis and data subject consents
- Track data sharing agreements and transfers
- Regular review and update of processing records
Data Processing Questions & Rights
Need help with data processing or want to exercise your data subject rights? Contact our Data Protection Officer and privacy team for assistance.
Exercise Your Data Subject Rights
Under GDPR and other privacy laws, you have specific rights regarding your personal data. Each button below opens an email to us naming the right you want to exercise — add your account email and send it. A person handles these, and the law gives us one month to respond, though we aim to be quicker.
Additional Data Rights
You have additional rights under GDPR and other privacy laws. Contact us to exercise these rights or learn more.
Withdraw Consent
We rely on consent for very little: analytics run on our public marketing pages only, never once you are signed in, and we set no advertising cookies at all. There is nothing here to withdraw. If we ever add processing that needs your consent, we will ask for it first.
Supervisory Authority
If you're not satisfied with our response to your data protection concerns, you have the right to lodge a complaint with the relevant supervisory authority.
Response Time
We typically respond to data subject rights requests within 30 daysas required by GDPR. Complex requests may take up to 60 days, and we will notify you of any delays and the reasons for them.
Additional Resources: For general privacy information, visit our Privacy Policy. For cookie information, see our Cookie Policy. For terms of service, visit our Terms of Service.
Important Legal Notice
This contact information is specifically for data processing and GDPR-related inquiries. For general support, please use our Support Center. We may require identity verification before processing data subject rights requests to protect your personal information.