← Back to TentPole

Data Processing Agreement

DPA between TentPole LLC (Processor) and the Customer (Controller).

Effective: September 2, 2026 · Version: 1.1

1. Background

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer" or "Controller") and TentPole LLC ("TentPole" or "Processor") for use of the TentPole Service. It applies where TentPole processes Personal Data on behalf of the Customer that is subject to applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

2. Definitions

Capitalized terms not defined here have the meanings in the Terms of Service or applicable data protection law. "Personal Data," "Processing," "Data Subject," "Controller," and "Processor" have the meanings given in GDPR.

3. Scope and Roles

TentPole acts as Processor for Personal Data submitted by Customer or its end users through the Service. Customer is the Controller and is responsible for the lawfulness of collection, the legal basis for Processing, and providing required notices to Data Subjects.

4. Processing Details

ItemDetails
Subject matterProvision of the TentPole vendor event management platform
DurationFor the term of the Agreement plus the data retention periods in our Privacy Policy
Nature & purposeHosting, displaying, transmitting, and processing data to provide platform functionality
Categories of Data SubjectsCustomer's staff, vendors, attendees, event applicants
Categories of Personal DataIdentifiers (name, email, phone), business information, profile data, application content, messages, payment metadata, IP address, device info
Sensitive dataNone expected. Customer must not submit special categories of Personal Data without prior written agreement

5. Processor Obligations

TentPole will:

6. Security Measures

See Annex II for details. Summary: TLS 1.2+ encryption in transit, encryption at rest for database storage, row-level security, access controls, regular reviews, incident response procedures.

7. Personal Data Breach Notification

TentPole will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer's data. TentPole will provide information reasonably available to it so Customer can meet its own notification obligations, including:

8. Sub-processors

Customer authorizes TentPole to engage the sub-processors listed below. TentPole will provide at least 30 days' notice of new sub-processors via email or a public sub-processor page. Customer may object on reasonable data protection grounds.

Sub-processorServiceLocation
Supabase, Inc.Database, authentication, file storage, edge functionsUnited States
Square, Inc.Payment processingUnited States
Anthropic, PBCAI feature processingUnited States
Resend Inc.Transactional email deliveryUnited States
Functional Software, Inc. (Sentry)Error and performance monitoringUnited States
Netlify, Inc.Static asset hosting and CDNUnited States
Intuition Machines, Inc.Security challenges (hCaptcha)United States

9. International Transfers

TentPole stores Personal Data primarily in the United States. A restricted transfer from the EEA, UK, or Switzerland must be covered by an executed or otherwise valid transfer mechanism appropriate to the parties and transfer. The EU Standard Contractual Clauses, UK International Data Transfer Addendum, or another recognized safeguard applies only when completed and incorporated into the parties' agreement; this web page does not by itself complete missing selections, annexes, signatures, or transfer assessments.

10. Audits

Once per year (or in the event of a Personal Data Breach), Customer may request reasonable information demonstrating TentPole's compliance. TentPole may satisfy this by providing copies of relevant SOC reports, security questionnaires, or third-party audit summaries when available.

11. Customer Obligations

Customer warrants that:

12. Term and Termination

This DPA continues for the term of the Agreement. Upon termination, TentPole will, at Customer's written choice and subject to the Service's export capabilities, delete or return Customer Personal Data and delete remaining copies when they are no longer reasonably required, except for protected backups and records retained for legal, security, fraud-prevention, accounting, or dispute purposes.

13. Liability

Each party's liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits liability that cannot be excluded under applicable law.

14. Annex I — Parties

Controller (Data Exporter): Customer as identified in the Service account.
Processor (Data Importer): TentPole LLC, a North Carolina limited liability company, with email at dpo@thetentpole.com.

15. Annex II — Technical and Organizational Measures

16. Annex III — List of Sub-processors

See Section 8 above. Current list maintained at thetentpole.com/legal/dpa.html.

17. Contact

Data Protection inquiries: dpo@thetentpole.com