Jade powered by mci group
Home Legal Center Log in

Legal Documents

Terms of Use Privacy Policy AI Use & Transparency Acceptable Use Data Processing Addendum Security & Trust Cookie Policy Government Use GDPR Addendum

Data Processing Agreement

Jade Event Operating Platform|Last Updated: June 25, 2026

This Data Processing Agreement ("DPA") governs the processing of Personal Data by MCI USA Operating Co. on behalf of the Client in compliance with the EU General Data Protection Regulation (GDPR), UK GDPR, and the Swiss Federal Act on Data Protection (FADP).

I. Subject of the Agreement

The purpose of this DPA is to define the conditions under which MCI USA Operating Co. (the "Data Processor") undertakes to carry out personal data processing operations on behalf of the Client (the "Data Controller").

As part of their contractual relationship, the parties undertake to comply with the regulations in effect applicable to personal data processing and in particular, Regulation (EU) 2016/679 (the "GDPR"), UK GDPR, and Swiss Federal Act on Data Protection (FADP).

Definitions

Under the terms of this DPA, the following terms are defined as per Article 4 of the EU GDPR and Article 5 of FADP:

  • "Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
  • "Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
  • "Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
  • "Sub-processor" means the natural person or legal entity contracted by the Data Processor to process personal data for the purpose of carrying out a specific processing activity on behalf of the Data Controller.

MCI as Data Controller for Certain Processing

MCI remains as data controller for processing for which MCI itself determines the purposes and means. This is particularly the case when MCI reuses, on its own behalf and with the consent of the participant, personal data for later compatible purposes, including:

  • Management of commercial prospecting for information purposes (newsletter) of participants and invitations to subsequent events;
  • Organization of the event in relation with exhibitors and sponsors, including the communication of personal contact data of participants;
  • Management of related services offered to participants, such as hotel reservations.

MCI acknowledges that its own processing operations comply with European data protection regulations, including concerning the integrity and confidentiality of the data communicated, the exercise of individuals' rights and compliance with their retention periods and initial processing purposes.

II. Description of the Processing

The Data Processor is authorized to process personal data on behalf of the Data Controller that are necessary to provide the Jade platform services.

The details of the processing carried out by the Data Processor are specified in Annex I.A below.

III. Data Processor's Obligations

The Data Processor undertakes to:

1. Process data solely for the purpose(s) of the subcontracting

MCI shall process Personal Data only for the purposes set out in this DPA and the Agreement.

2. Process data in accordance with documented instructions

MCI shall process Personal Data only in accordance with the Data Controller's documented instructions, which include:

  • this DPA and any related agreements;
  • the Agreement and any Order Forms;
  • the Data Controller's configuration and use of the Services; and
  • any other written instructions provided by the Data Controller and acknowledged by MCI.

If MCI considers that an instruction constitutes an infringement of the GDPR or any other provision of European Union law or the law of Member States on data protection, it must inform the Data Controller within a reasonable time.

3. Data processing location and transfers

Unless otherwise specifically and expressly authorized by the Data Controller, MCI processes data within the territory of an EEA Member State, Switzerland, UK, or the United States. MCI undertakes not to disclose, make accessible or transfer any of the Data Controller's data, even for routing purposes, to any processing organization or data processor based in a country located outside the EEA, except with the Data Controller's prior written consent.

In the event of a transfer outside the EEA, the Data Controller acknowledges authorizing the transfer. Such transfer may only take place within the strict limits necessary for the performance of the services, and provided said transfer is towards a State whose legislation has been recognized by the European Commission as offering an equivalent level of protection, or is governed by standard contractual clauses issued by the European Commission (Annex II), or is carried out on the basis of any other alternative arrangements recognized by the GDPR.

4. Guarantee confidentiality of personal data

MCI shall ensure that all personnel authorized to process Personal Data:

  • undertake to respect confidentiality or are subject to an appropriate statutory confidentiality obligation;
  • receive the necessary training in respect of personal data protection;
  • have access limited to only that which is necessary to perform the Services.

5. Data protection by design and by default

MCI takes into account data protection principles and data protection by default from the design stage onwards of tools, products, applications and services.

IV. Subcontracting

The Data Processor has the Data Controller's general authorization for the engagement of sub-processors from an agreed list (see Annex I.C).

The Data Processor shall specifically inform in writing the Data Controller of any intended changes of that list through the addition or replacement of sub-processors at least one month in advance, thereby giving the Data Controller sufficient time to be able to object to such changes prior to the engagement of the concerned sub-processor(s).

Where the Data Processor engages a sub-processor for carrying out specific processing activities (on behalf of the Data Controller), it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the Data Processor in accordance with this DPA.

The Data Processor shall ensure that the sub-processor complies with the obligations to which the Data Processor is subject pursuant to this DPA and to Regulation (EU) 2016/679.

At the Data Controller's request, the Data Processor shall provide a copy of such a sub-processor agreement and any subsequent amendments to the Data Controller. To the extent necessary to protect business secret or other confidential information, including personal data, the Data Processor may redact the text of the agreement prior to sharing the copy.

The Data Processor shall remain fully responsible to the Data Controller for the performance of the sub-processor's obligations in accordance with its contract with the Data Processor. The Data Processor shall notify the Data Controller of any failure by the sub-processor to fulfil its contractual obligations.

The Data Processor shall agree a third party beneficiary clause with the sub-processor whereby - in the event the Data Processor has factually disappeared, ceased to exist in law or has become insolvent - the Data Controller shall have the right to terminate the sub-processor contract and to instruct the sub-processor to erase or return the personal data.

V. Data Subjects' Right to Information

Depending on the choice of the parties, the Data Controller, or the Data Processor through the MCI Privacy Statement, is responsible for providing information to those affected by processing operations when data are collected.

In the case that the Data Controller itself informs the data subjects, the Data Controller agrees and acknowledges to inform the data subjects of the processing operations that the Data Processor may carry out for its own behalf, as described in Section I of this DPA. This information may be provided by means of a hyperlink to the Data Processor's privacy statement.

VI. Exercise of Individual Rights

So far as possible, the Data Processor must help the Data Controller to fulfil its obligation to respond to requests to exercise their rights by data subjects, including:

  • rights of access, correction, deletion and opposition;
  • right to restriction of processing;
  • right to data portability; and
  • right not to be the subject to an automated individual decision (including profiling).

Where the Services provide self-service functionality for the Data Controller to respond to data subject requests, the Data Controller shall use such functionality. MCI shall provide additional assistance upon request.

VII. Notification of Breaches of Personal Data

The Data Processor must notify the Data Controller of any personal data breach without undue delay after becoming aware of it, by e-mail to the data protection officer.

Said notification must be accompanied by any documentation that may be useful in enabling the Data Controller to inform the relevant regulatory authority of the breach, if applicable.

The Data Processor will also provide all reasonable assistance to the Data Controller in the case of a notification in respect of any action the latter may be obliged or may choose to take in respect of a personal data breach.

The Data Processor shall cooperate and provide the Data Controller with the necessary assistance in respect of any complaint formulated by a data subject or any investigation or request issued by a regulatory authority with regard to the GDPR or any other applicable regulation.

Notification shall include, where possible:

  • a description of the nature of the personal data breach, including the categories and approximate number of data subjects and records concerned;
  • the name and contact details of MCI's data protection officer (Privacy@mci-group.com);
  • a description of the likely consequences of the personal data breach; and
  • a description of the measures taken or proposed to address the breach and mitigate its effects.

VIII. Assistance from the Data Processor

The Data Processor shall cooperate with the Data Controller and use its best endeavours to help the Data Controller prove that it is compliant with all its legislative and regulatory obligations, notably in respect of the GDPR.

In particular, the Data Processor shall, where relevant, assist the Data Controller with:

  • carrying out data protection impact assessments; and
  • carrying out a prior consultation with the regulatory authority, to the extent required under applicable law and taking into account the nature of the processing and the information available to MCI.

IX. Security Measures

The Data Processor undertakes to implement technical and organisational means to ensure the security of the processing of personal data carried out on behalf of the Data Controller, in accordance with Article 32 of the GDPR.

The details of the security measures are specified in Annex I.B below.

X. Retention of Data

Once the provision of services relating to the processing of these data is complete, the Data Processor undertakes to:

  • Destroy all personal data; or
  • At any time, at the Data Controller's written request and at the latest, within 15 calendar days of the end of the Contract, return the Data Controller's personal data in a legible or interoperable form agreed between the Parties and to destroy all copies (paper or electronic) of the Data Controller's personal data that it may hold.

The return of all files, data, programmes, documentation, etc. is included in the price for the provision of the Service.

The Data Processor must confirm the actual destruction of the Data Controller's personal data within 15 calendar days of the Data Controller's request or the end of the Contract.

The Data Controller reserves the right to carry out any checks it deems necessary to confirm the performance of these obligations.

MCI may retain Personal Data to the extent required by applicable law. Any retained Personal Data shall continue to be protected in accordance with this DPA.

XI. Register of Categories of Processing Activities

The Data Processor declares that it holds a written record of all categories of processing activities carried out on behalf of the Data Controller as required by Article 30(2) of the GDPR, including:

  • the name and contact details of the Data Controller on behalf of whom it is acting, any data processors and, if applicable, the data protection officer;
  • the categories of processing activities carried out on behalf of the Data Controller;
  • if applicable, any transfers of personal data to a third country or international organisation, including the identification of said third country or international organisation and, in the case of transfers referred to in Article 49, paragraph 1, second subparagraph of the GDPR, documents attesting to the existence of appropriate guarantees;
  • as far as possible, a general description of technical and organisational security measures.

XII. Documentation

The Data Processor shall provide the Data Controller with the necessary documentation to demonstrate compliance with all its obligations and to enable audits and inspections to be carried out by the Data Controller or another auditor appointed by it, and to contribute to said audits.

XIII. Audit

Throughout the term of the Contract, the Data Controller may carry out tests and audits of all or some of the services, either itself or through an independent third party at its expense – subject to five (5) working days' notice – including at the premises of authorized data processors, in order to ensure compliance with the stipulations of the Contract in terms of:

  • compliance with Security Policies;
  • quality of service;
  • maintenance of appropriate security measures, in particular to ensure the integrity and confidentiality of the Data Controller's data.

Where the services involve the processing of personal data, the audit may also relate to the verification of the GDPR and the verification of:

  • locations used for the processing and/or storage of personal data;
  • transfers of personal data outside the European Economic Area;
  • measures taken to ensure the security of personal data and combat breaches of personal data.

The Data Processor undertakes to authorize the Data Controller, or the companies appointed by the latter and tasked with carrying out the audit, to access the necessary information to carry out their mission properly and access the sites where the services are delivered.

The Data Processor will cooperate fully (and, where data processors and representatives are concerned, ensure their cooperation) with the Data Controller and the audit representatives of the Data Controller, including giving them access to the premises, personnel, physical and technical environments, equipment, software, documentation, data, registers and systems relating to the services, and any useful information that might reasonably be necessary in carrying out the audit.

An audit report must be sent to the Data Processor.

Should it become apparent, following the audit and testing measures, that the security measures implemented by the Data Processor are not appropriate or sufficient, or if said audits or tests reveal any gaps or examples of non-compliance with the requirements set out in this Contract and/or the legal requirements applicable, the Data Processor will implement corrective actions within a time frame to be agreed between the Parties, depending on the severity of the failure observed and in any case, not longer than 15 days.

Where available, MCI may satisfy audit requests by providing relevant third-party certifications, audit reports (such as SOC 2), or security questionnaire responses.

XIV. Data Controller's Obligations

The Data Controller undertakes, throughout the term of the contract, to:

  1. provide the Data Processor with the data referred to in Section II;
  2. document in writing any additional instructions regarding the processing of data by the Data Processor;
  3. ensure, prior to and during the period of processing, compliance with its obligations set out in the GDPR;
  4. supervise the processing, including carrying out audits and inspections at the Data Processor's premises in accordance with the provisions of this DPA.

XV. International Data Transfers

To the extent that the processing of Personal Data involves the transfer of Personal Data from the EEA or UK to a country outside the EEA that has not received an adequacy decision from the European Commission, the parties agree that:

  • the Standard Contractual Clauses (Module 4: Processor to Controller) approved by European Commission Decision 2021/914 are incorporated by reference in Annex II and apply to such transfers;
  • for transfers from the UK, the UK Addendum to the EU SCCs (as approved by the UK Information Commissioner) shall apply;
  • MCI shall implement supplementary measures as necessary to ensure an essentially equivalent level of protection.

The Data Processor shall ensure that its own processors sign and comply with the requirements of the Standard Contractual Clauses.

Standard Contractual Clauses Details

For the purposes of the SCCs (where applicable):

  • Module 4 (Processor to Controller) applies where the Data Processor in the United States processes Personal Data on behalf of a Data Controller located in the EEA or UK.
  • The Data Controller is the Data Exporter.
  • The Data Processor (MCI USA Operating Co.) is the Data Importer.
  • For Clause 14 (Governing law), the SCCs shall be governed by the laws of the country where the Data Controller is established.
  • For Clause 15 (Choice of forum and jurisdiction), disputes shall be resolved by the courts of the country where the Data Controller is established.

XVI. Liability

Each party's liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement, except that such limitations shall not apply to:

  • liability for personal data breaches caused by a party's gross negligence or willful misconduct;
  • fines or penalties imposed by a supervisory authority that are directly attributable to a party's breach of this DPA; or
  • any liability that cannot be limited under applicable data protection law.

XVII. Cooperation with Supervisory Authorities

The Data Processor shall cooperate, on request, with any supervisory authority in the performance of its tasks, to the extent required by the GDPR or other applicable data protection law.

XVIII. Conflict and Precedence

In the event of any conflict between this DPA and other agreements between the parties, this DPA shall prevail to the extent of the conflict with respect to the processing of Personal Data subject to applicable data protection law. In the event of any conflict between this DPA and the Standard Contractual Clauses, the SCCs shall prevail.

XIX. Contact

For questions about this Data Processing Agreement or to exercise data protection rights, please contact:

Data Protection Officer

MCI USA Operating Co.

5717 Legacy Drive, Ste 250

Plano, TX 75024

United States

Email: privacy@mci-group.com

Legal: legal@wearemci.com


ANNEX I

ANNEX I.A - Description of Processing

Categories of data subjects whose personal data is processed

Personal Data processed may concern the following categories of data subjects:

  • Event attendees and registrants
  • Exhibitors, sponsors, and vendors
  • Speakers and presenters
  • Suppliers and supplier representatives participating in sourcing or contracting workflows
  • Hotel personnel accessing rooming lists
  • Organizer employees and representatives
  • Housing guests and travelers
  • Lead contacts, appointment participants, support contacts, and mobile app users
  • Other event participants as configured by the Data Controller

Categories of personal data processed

Personal Data processed may include:

  • Identifiers: name, email address, phone number, mailing address
  • Professional information: employer, job title, organization
  • Registration details: event preferences, session selections, badge information
  • Housing information: check-in/check-out dates, room preferences, guest details, rooming lists
  • Speaker submissions, survey responses, continuing-education credit records, attendance/check-in records, wallet pass details, mobile app activity, appointments, exhibitor/company profile details, lead scans, lead qualifiers, prospect invitations, support communications, and sourcing/contract records where configured
  • Dietary and accessibility requirements (where provided)
  • Travel documentation (where required for visa letters or compliance)
  • Payment and transaction records (payment card data is handled by third-party payment processors and not stored by MCI in full card-number form)
  • Communications: support requests, correspondence
  • Technical data: IP addresses, device information, usage logs

Sensitive data processed (if applicable)

The Data Controller may choose to collect special categories of Personal Data (such as health information for accessibility needs or dietary restrictions). Where such data is collected, the Data Controller is responsible for ensuring a valid legal basis and providing appropriate notices.

Applied restrictions or safeguards for sensitive data include:

  • Strict purpose limitation
  • Access restrictions (including access only for staff having followed specialized training)
  • Keeping a record of access to the data
  • Restrictions for onward transfers
  • Additional security measures

Purpose of processing

The Data Processor processes Personal Data to provide the Jade platform services authorized by the Data Controller, including:

  • Event registration, ticketing, and credentialing workflows
  • Housing and accommodation workflows, including rooming list management
  • Approvals, pricing rules, discounts, recommendation features, surveys, speaker management, exhibitor management, lead retrieval, mobile app, badge, certificate, onsite, support, sourcing, contract, and reporting workflows
  • Payment processing facilitation through third-party processors (including Stripe) and card-guarantee vaulting where configured (including Basis Theory)
  • Customer support and communications
  • Reporting, analytics, and integrations
  • Security and fraud prevention
  • AI-enabled features (data validation, data normalization, recommendations, setup assistance, support, report generation, document analysis, and content drafting)

Nature of the operations carried out on the data

Operations include: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, restriction, erasure, and destruction.

Period of data retention

Personal Data is retained for the duration of the Agreement and thereafter:

  • as required by applicable law;
  • for legitimate business purposes (e.g., establishment, exercise, or defense of legal claims); or
  • as specified in the Data Controller's data retention instructions.

Processor's DPO contact details

privacy@mci-group.com

For transfers to sub-processors

See Annex I.C for the list of authorized sub-processors and the subject matter, nature, and duration of processing by each sub-processor.


ANNEX I.B - Technical and Organizational Measures

In addition to any measures already agreed to by the Data Controller, the Data Processor undertakes to institute and maintain the following data protection measures to ensure the security of Personal Data:

Access Control to Personal Data

The Data Processor commits that the persons entitled to use any data processing system in relation to the Personal Data are only able to access the Personal Data within the scope and to the extent covered by the respective access permission (authorization).

This shall in particular be accomplished by:

  • Establishing access authorizations for employees and third parties, including the respective documentations
  • Code card passes and restrictions on keys
  • All required internal regulations
  • Identification of the persons having access authority
  • Securing any and all data processing equipment and personal computers
  • Locking of terminals
  • Allocation of individual terminals and/or terminal user and identification characteristics exclusive to specific functions
  • Functional and/or time restricted use of terminals and/or terminal users and identification characteristics
  • Regulations for user authorization and obligation to comply with data secrecy
  • User codes and differentiated access regulations (e.g. partial blocking)
  • Regulations for the organisation of files
  • Logging and analysis of use of the files
  • Controlled destruction of Personal Data, when relevant
  • Work instructions for templates for the registration of Personal Data
  • Checking, adjustment and controlling systems

Transmission Control

The Data Processor shall be obliged to enable the verification and tracing of the locations/destinations to which the data subject's Personal Data are transferred by the utilization of the Data Processor's data communication equipment/devices.

Measures include:

  • All Personal Data is encrypted in transit using TLS 1.2 or higher
  • Personal Data at rest is encrypted using AES-256 encryption
  • Encryption keys are managed using secure key management practices
  • Comprehensive logging of data transmissions

Organization Control

The Data Processor shall maintain its internal organisation in a manner that meets the requirements of this Agreement. This shall be accomplished by:

  • Internal data processing policies and procedures, guidelines, work instructions, process descriptions and regulations for programming, testing and release, insofar as they relate to the Personal Data
  • Formulation of a data security concept
  • Industry standard system and program examination
  • Formulation of an emergency plan (backup contingency plan)
  • Binding policies and procedures for the Data Processor's employees
  • Secure software development lifecycle (SDLC) practices and change management procedures

Physical Security

  • Use of reputable cloud and managed-service providers with documented physical security controls
  • Physical access restrictions and environmental controls appropriate to the selected provider facilities
  • Customer-specific audit reports or certifications are provided where available and governed by the applicable written agreement

Network and Infrastructure Security

  • Firewalls and network segmentation
  • Intrusion detection and prevention systems
  • DDoS protection and mitigation
  • Secure configuration management
  • Regular security assessments and penetration testing
  • Vulnerability scanning and timely patch management

Business Continuity and Availability

  • Regular automated backups with encryption
  • Geographically distributed backup storage
  • Documented disaster recovery procedures
  • Regular testing of recovery capabilities
  • High availability architecture with redundancy

Personnel Security

  • Background checks for personnel with access to Personal Data
  • Confidentiality agreements and data protection training
  • Security awareness training programs
  • Defined responsibilities and acceptable use policies

Incident Response

  • Documented incident response procedures
  • Designated incident response team
  • Breach notification procedures compliant with GDPR requirements
  • Post-incident review and remediation processes

ANNEX I.C - List of Sub-processors

The Data Controller has authorized the use of the following sub-processors:

Sub-processors located in the EEA or in an adequate third-country

NameAddress/LocationDescription of Processing
Mailjet / MailgunEU/United StatesEmail delivery and messaging services for transactional and event-related communications

Sub-processors not located in the EEA nor in an adequate third-country

The following sub-processors are located in the United States and are subject to Standard Contractual Clauses and/or other appropriate safeguards:

NameAddress/LocationDescription of Processing
Microsoft AzureUnited StatesCloud hosting and infrastructure services for the Jade platform
Amazon Web Services (AWS)United StatesCloud hosting and infrastructure services for certain platform components
MongoDB AtlasUnited StatesDatabase hosting and management services
StripeUnited StatesPayment processing services (payment card data is processed directly by Stripe, not stored by MCI)
Basis TheoryUnited StatesCard vaulting for guarantee-only payment instruments where configured
OpenAIUnited StatesAI-powered features for data validation, recommendations, setup assistance, report generation, document analysis, content drafting, and customer support (Customer Data and Attendee/Exhibitor personal data is not used to train general-purpose AI models)

Note: MCI will notify the Data Controller at least 30 days in advance of any intended changes to this list through the addition or replacement of sub-processors.


ANNEX II - Standard Contractual Clauses

Where transfers of Personal Data from the EEA or UK to the United States occur, the Standard Contractual Clauses approved by European Commission Decision 2021/914 apply and are incorporated by reference using the module appropriate to the parties' roles under the Agreement.

Key Terms

  • Data Exporter: The Data Controller (Client), as identified in the Agreement
  • Data Importer: MCI USA Operating Co., 5717 Legacy Drive, Ste 250, Plano, TX 75024, United States
  • Module: For the standard Jade controller-to-processor relationship, Module 2 (Controller to Processor) applies where MCI (as Processor/Data Importer) in the United States processes Personal Data on behalf of a Controller (Data Exporter) located in the EEA or UK, unless the Agreement specifies a different role configuration
  • Competent Supervisory Authority: Determined in accordance with Clause 13 of the SCCs, based on the establishment or location of the Data Exporter

Clause 7 (Optional Docking Clause)

The optional docking clause is included, allowing entities not party to these Clauses to join them at a later stage.

Clause 14 (Governing Law)

These Clauses shall be governed by the law of the country where the Data Exporter is established, allowing for third-party beneficiary rights.

Clause 15 (Choice of Forum and Jurisdiction)

Any dispute arising from these Clauses shall be resolved by the courts of the country where the Data Exporter is established.

UK Transfers

For transfers from the UK, the UK Addendum to the EU Standard Contractual Clauses (as approved by the UK Information Commissioner's Office) shall apply in addition to the EU SCCs.

Supplementary Measures

In addition to the Standard Contractual Clauses, MCI implements the technical and organizational measures described in Annex I.B to ensure an essentially equivalent level of protection for Personal Data transferred outside the EEA or UK.

Jade powered by mci groupJade by MCI USA Operating Co.
HomeLegalPrivacyTermsContact