DPA between TentPole LLC (Processor) and the Customer (Controller).
Effective: September 2, 2026 · Version: 1.1
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer" or "Controller") and TentPole LLC ("TentPole" or "Processor") for use of the TentPole Service. It applies where TentPole processes Personal Data on behalf of the Customer that is subject to applicable data protection laws including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).
Capitalized terms not defined here have the meanings in the Terms of Service or applicable data protection law. "Personal Data," "Processing," "Data Subject," "Controller," and "Processor" have the meanings given in GDPR.
TentPole acts as Processor for Personal Data submitted by Customer or its end users through the Service. Customer is the Controller and is responsible for the lawfulness of collection, the legal basis for Processing, and providing required notices to Data Subjects.
| Item | Details |
|---|---|
| Subject matter | Provision of the TentPole vendor event management platform |
| Duration | For the term of the Agreement plus the data retention periods in our Privacy Policy |
| Nature & purpose | Hosting, displaying, transmitting, and processing data to provide platform functionality |
| Categories of Data Subjects | Customer's staff, vendors, attendees, event applicants |
| Categories of Personal Data | Identifiers (name, email, phone), business information, profile data, application content, messages, payment metadata, IP address, device info |
| Sensitive data | None expected. Customer must not submit special categories of Personal Data without prior written agreement |
TentPole will:
See Annex II for details. Summary: TLS 1.2+ encryption in transit, encryption at rest for database storage, row-level security, access controls, regular reviews, incident response procedures.
TentPole will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer's data. TentPole will provide information reasonably available to it so Customer can meet its own notification obligations, including:
Customer authorizes TentPole to engage the sub-processors listed below. TentPole will provide at least 30 days' notice of new sub-processors via email or a public sub-processor page. Customer may object on reasonable data protection grounds.
| Sub-processor | Service | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, edge functions | United States |
| Square, Inc. | Payment processing | United States |
| Anthropic, PBC | AI feature processing | United States |
| Resend Inc. | Transactional email delivery | United States |
| Functional Software, Inc. (Sentry) | Error and performance monitoring | United States |
| Netlify, Inc. | Static asset hosting and CDN | United States |
| Intuition Machines, Inc. | Security challenges (hCaptcha) | United States |
TentPole stores Personal Data primarily in the United States. A restricted transfer from the EEA, UK, or Switzerland must be covered by an executed or otherwise valid transfer mechanism appropriate to the parties and transfer. The EU Standard Contractual Clauses, UK International Data Transfer Addendum, or another recognized safeguard applies only when completed and incorporated into the parties' agreement; this web page does not by itself complete missing selections, annexes, signatures, or transfer assessments.
Once per year (or in the event of a Personal Data Breach), Customer may request reasonable information demonstrating TentPole's compliance. TentPole may satisfy this by providing copies of relevant SOC reports, security questionnaires, or third-party audit summaries when available.
Customer warrants that:
This DPA continues for the term of the Agreement. Upon termination, TentPole will, at Customer's written choice and subject to the Service's export capabilities, delete or return Customer Personal Data and delete remaining copies when they are no longer reasonably required, except for protected backups and records retained for legal, security, fraud-prevention, accounting, or dispute purposes.
Each party's liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits liability that cannot be excluded under applicable law.
Controller (Data Exporter): Customer as identified in the Service account.
Processor (Data Importer): TentPole LLC, a North Carolina limited liability company, with email at dpo@thetentpole.com.
See Section 8 above. Current list maintained at thetentpole.com/legal/dpa.html.
Data Protection inquiries: dpo@thetentpole.com