Data Processing Addendum
Effective 24 August 2026
In plain English
When your vendors give you their details through Captain Expo, you decide what happens to that information and we carry out your instructions. In data protection terms you are the controller and we are your processor.
This document is what you can point at when somebody asks whether your booking software is covered. It forms part of the Terms of Service and applies automatically - there is nothing to sign.
This summary is here to orient you. The numbered clauses below are the agreement.
1.Roles
This addendum applies where Captain Expo processes personal data on behalf of an organizer in the course of providing the service. For that data the organizer is the controller and Captain Expo is the processor.
Captain Expo is a controller in its own right for a narrow set of data described in the Privacy Policy - organizer account records, billing, and security logs. This addendum does not govern those.
Where the law of a particular jurisdiction uses different words for these roles - “business” and “service provider”, for instance - the equivalent role applies.
2.Details of the processing
- Subject matter. Providing booth mapping, vendor applications, booking and payment coordination for the organizer’s events.
- Duration. For as long as the organizer’s account is open, plus the deletion window in clause 9.
- Nature and purpose. Collection, storage, organization, retrieval and transmission of vendor details so the organizer can sell booths, decide applications, and communicate with vendors about their events.
- Categories of data subjects. Vendors who apply for or purchase a booth at the organizer’s events, and any contact the organizer imports.
- Types of personal data. Name, email address, phone number, Instagram handle, city, state, selling categories, the booths taken and amounts paid, the date and text of the rules accepted, and correspondence sent through the service.
- Special category data. None. The service does not ask for it and organizers should not put it in free-text fields.
3.Processing on your instructions
We process vendor personal data only on the organizer’s documented instructions. Using the product is an instruction: creating an event, approving an application, issuing a refund, sending an announcement.
We will not use vendor personal data for our own purposes, and specifically we will not use it to market to vendors, to build a cross-organizer vendor directory, or to train machine learning models. If we are required by law to process it otherwise, we will tell the organizer first unless the law forbids that.
4.Confidentiality
Everyone we permit to access vendor personal data is bound by confidentiality obligations, and access is limited to those who need it to operate or support the service.
5.Security measures
We maintain technical and organizational measures appropriate to the risk, including:
- encryption of all traffic in transit;
- tenant isolation enforced in the data layer - every tenant-owned record carries an organization identifier, and queries are constrained to one organization by a seam the build will not compile without;
- authenticated encryption of any third-party credential an organizer stores, with the key held outside the database;
- no card data in scope - payment details are captured by Stripe and never reach our systems;
- IP addresses hashed with a secret salt before storage, so no raw address is retained;
- booking access links treated as credentials - never logged and never placed in outbound web addresses.
6.Subprocessors
The organizer authorises Captain Expo to engage subprocessors. Each is bound by data protection obligations no less protective than these, and we remain responsible for their performance.
- Stripe (United States) - payment processing and connected account onboarding.
- Clerk (United States) - organizer authentication and organization membership.
- Resend (United States) - transactional and announcement email.
- Vercel (United States) - application hosting and floor plan image storage.
- Neon (United States) - managed Postgres database.
- Anthropic (United States) - automatic floor plan detection. Receives only the venue plan image an organizer submits for a detection run, and no vendor personal data.
We will give at least 30 days’ notice before adding or replacing a subprocessor that processes vendor personal data. An organizer who objects on reasonable data protection grounds may terminate the affected part of the service.
7.Data subject requests
The product gives the organizer direct access to the vendor data it holds, so most requests can be answered without involving us.
If a vendor comes to us directly, we will not respond substantively on the organizer’s behalf. We will tell them to contact the organizer and, where we can identify the organization, pass the request on. Where an organizer needs help to respond, we will provide reasonable assistance.
8.Security incidents
We will notify the organizer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting their vendor data. The notice will describe what we know, what we are doing, and what we recommend.
We will also give reasonable assistance with data protection impact assessments and with any consultation of a supervisory authority that follows from one.
9.Deletion and return
The organizer can export their vendor roster at any time while the account is open.
On termination, we delete vendor personal data within 90 days, except where retention is required by law. Backups age out on their own schedule and are not restored except to recover from a failure.
10.Information and audits
We will make available the information reasonably necessary to demonstrate compliance with this addendum, and will contribute to audits carried out by the organizer or an auditor they mandate. Audits are at the organizer’s expense, no more than once in any twelve months absent a security incident, on reasonable notice, and conducted so as not to disrupt the service or expose another organizer’s data.
11.Location of processing
The service and all of the subprocessors in clause 6 operate in the United States, and vendor personal data is processed there.
Captain Expo is built for United States markets. An organizer selling to vendors in a jurisdiction with a consent-in regime - the EU, the UK, or Canada, for example - is responsible for satisfying the requirements that apply to them, including the transfer mechanism and any consent their vendors must give before being contacted. Tell us if you need standard contractual clauses and we will discuss it.
12.Term and precedence
This addendum forms part of the Terms of Service and lasts as long as we process vendor personal data for the organizer. Where it conflicts with the Terms of Service on the processing of personal data, this addendum governs.
Questions, or a request for standard contractual clauses, go to legal@captainexpo.com.