Jade powered by mci group
Home Legal Center Log in

Legal Documents

Terms of Use Privacy Policy AI Use & Transparency Acceptable Use Data Processing Addendum Security & Trust Cookie Policy Government Use GDPR Addendum

Data Processing Addendum (DPA)

Jade Event Operating Platform|Last Updated: June 25, 2026

1. Parties and Scope

This Data Processing Addendum ("DPA") is between MCI USA Operating Co. ("Processor") and the customer identified in the applicable order form or master agreement ("Customer" or "Controller"). This DPA applies to the extent Processor processes Personal Data on behalf of Controller in connection with the Services.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable individual and includes "personal information" as defined under applicable privacy laws.
  • "Process" means any operation performed on Personal Data, such as collection, storage, use, disclosure, deletion.
  • "Subprocessor" means a third party engaged by Processor to Process Personal Data.
  • "Applicable Laws" include U.S. state privacy laws (including, where applicable, California CPRA/CCPA and similar laws in other states) and, if and when applicable, GDPR/UK GDPR.

3. Roles of the Parties

Controller is the Controller (or equivalent) of Personal Data and Processor is the Processor (or equivalent) processing Personal Data on behalf of Controller.

4. Details of Processing

4.1 Subject Matter and Duration

Processor will Process Personal Data to provide the Services for the term of the Agreement and as needed for support, security, and compliance.

4.2 Nature and Purpose

Processing includes hosting, storage, transmission, analytics, support, fraud prevention, integrations, payment facilitation, wallet pass generation, API/webhook delivery, and AI-assisted processing as configured for event operations.

4.3 Categories of Data Subjects

May include Controller's employees, contractors, Attendees, Exhibitors, speakers, sponsors, suppliers, hotel personnel, support contacts, lead contacts, and other event participants.

4.4 Categories of Personal Data

May include identifiers (name, email, phone, address), registration details, housing details, speaker submissions, survey responses, attendance/check-in records, mobile app activity, appointments, exhibitor/company details, lead details, sourcing and contract details, support communications, accessibility/dietary information, government ID/travel documentation if collected for an event, and transactional records. Payment card data is processed by Payment Processors and is not stored by Processor in full card-number form.

4.5 Special Categories / Sensitive Data

Controller may choose to collect sensitive data (e.g., accessibility needs). Controller is responsible for ensuring a lawful basis and providing required notices and consents.

5. Processor Obligations

Processor will:

  • Process Personal Data only on documented instructions from Controller (including configuration and use of the Services);
  • ensure personnel are bound by confidentiality;
  • implement appropriate technical and organizational measures to protect Personal Data;
  • not sell or share Personal Data for cross-context behavioral advertising;
  • notify Controller of any legally binding request for disclosure, unless prohibited by law;
  • assist Controller with data subject requests as described below.

6. Controller Obligations

Controller will:

  • ensure it has the right to disclose Personal Data to Processor and to instruct Processor to Process it;
  • provide notices and obtain consents where required (including for minors where applicable);
  • maintain the accuracy, quality, and legality of Personal Data;
  • configure the Services appropriately for its compliance needs.

7. Subprocessors

7.1 Authorized Subprocessors

Controller authorizes Processor to engage Subprocessors necessary to provide the Services, including:

  • Microsoft Azure — Cloud hosting and infrastructure
  • Amazon Web Services (AWS) — Cloud hosting and infrastructure (as applicable)
  • MongoDB Atlas — Database hosting
  • Stripe — Payment processing
  • Basis Theory — Card vaulting for guarantee-only payment instruments where configured
  • Mailjet / Mailgun — Email delivery and messaging
  • OpenAI — AI-assisted platform features where configured
  • Apple Wallet / Google Wallet providers — Wallet pass issuance where configured

7.2 Subprocessor Terms

Processor will impose data protection obligations on Subprocessors consistent with this DPA.

7.3 Changes to Subprocessors

Processor may add or replace Subprocessors. Processor will provide notice (e.g., via a published list or written notice). Controller may object on reasonable data protection grounds within a specified period (e.g., 10 business days), and the parties will work in good faith to resolve the objection. If unresolved, Controller may terminate the affected Services without penalty as its sole remedy.

8. Security Measures

Processor will maintain a written information security program and implement measures appropriate to the risk, including:

  • encryption in transit and at rest (where supported);
  • logical access controls and least-privilege;
  • logging and monitoring;
  • vulnerability management and incident response;
  • backups and resilience controls;
  • vendor risk management.

Processor may update security measures over time, provided they do not materially decrease overall security.

9. Personal Data Breach Notification

Processor will notify Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. Notifications will include, to the extent available, nature of breach, categories of data, likely consequences, and measures taken or proposed.

10. Assistance with Data Subject Requests

Taking into account the nature of processing, Processor will provide commercially reasonable assistance to Controller to respond to verified requests from individuals (access, deletion, correction) as required by Applicable Laws. Where the Services provide self-service tools, Controller is responsible for using those tools.

11. Audits and Assessments

Upon reasonable request, Processor will provide information necessary to demonstrate compliance with this DPA (such as security summaries) and may allow audits:

  • no more than once annually (unless a breach occurs);
  • subject to confidentiality and reasonable scope;
  • performed by Controller or an independent auditor.

Processor may satisfy audit requests by providing third-party reports, certifications, or summaries where available.

12. Data Return and Deletion

Upon termination of the Services, Processor will, at Controller's choice and to the extent supported by the Services:

  • return Controller Personal Data; or
  • delete Controller Personal Data.

Processor may retain Personal Data as required by law or for legitimate business purposes (e.g., security logs) and will continue to protect it.

13. International Transfers (Future)

At launch, Services are hosted in the United States. If Controller requires processing in other regions (e.g., EU), the parties will implement appropriate safeguards (including, where applicable, Standard Contractual Clauses) as described in the Future GDPR Addendum.

14. US State Privacy Law Terms (Service Provider / Processor)

To the extent Applicable Laws require, Processor acts as a "service provider" / "contractor" / "processor" and agrees that it will:

  • process Personal Data only to provide the Services and as permitted by the Agreement;
  • not retain, use, or disclose Personal Data outside that relationship except as permitted by law;
  • not sell or share Personal Data;
  • allow and cooperate with reasonable assessments of compliance.

15. Order of Precedence

In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to data protection obligations.

16. Signatures

This DPA is incorporated into the Agreement and is effective as of the effective date of the Agreement.

Processor: MCI USA Operating Co.
Controller: [Customer Legal Name]

Jade powered by mci groupJade by MCI USA Operating Co.
HomeLegalPrivacyTermsContact