Data Processing Agreement
Data Processing Agreement
Data Processing Agreement
Home » Data Processing Agreement
Annex to the Wisembly General Terms of Service, forming an integral part of the Contract
This document is an English translation provided for convenience. The Contract is governed by French law. In the event of any discrepancy or dispute over interpretation, the French version prevails.
1. Purpose
This agreement (the “DPA“) sets out the terms under which MEDIACTIVE EVENTS SOLUTIONS, trading as Wisembly (“Wisembly” or the “Processor“), undertakes to carry out, on behalf of the Client (the “Controller“), the personal data processing operations described below, in accordance with Article 28 of Regulation (EU) 2016/679 of 27 April 2016 (“GDPR“) and French Act No. 78-17 of 6 January 1978, as amended (“French Data Protection Act“).
Terms defined in the General Terms of Service have the same meaning in this DPA. The terms “processing,” “personal data,” “data breach” and “data subject” have the meaning given to them by the GDPR.
In their contractual relationship, the parties undertake to comply with applicable law regarding the processing of personal data, and in particular the GDPR.
2. Description of the Processing
2.1 Nature of the Operations
Collection, recording, storage, consultation, alteration, import/export, disclosure to the Controller, temporary copying, backup and restoration, replication, erasure, and any use related to maintenance and support obligations.
2.2 Purposes of the Processing
- Enabling the creation, management and running of the Controller’s Events (Participant registration, invitations, ticketing, access control, interactive features);
- Enabling emails to be sent to Participants and tracking such emails under the conditions set out in Section 8;
- Enabling, where applicable, the receipt and publication of SMS contributions sent by Participants, where that feature is enabled for an Event;
- Measuring usage and audience of the Services and producing the statistics provided to the Controller;
- Ensuring the maintenance, support and security of the Platform.
2.3 Categories of Data Processed
- Identity and contact data: name, email address, phone number;
- Professional data: company, job title;
- Connection and usage data: IP address, connection logs;
- Participation and interaction data: registrations, attendance, messages, questions, votes, survey and questionnaire responses;
- Files and images that may be submitted by Participants through Platform features, where enabled;
- Any other data collected through form fields freely configured by the Controller, at its sole responsibility.
Special categories of data. The Platform is not, by default, intended for the processing of special categories of data within the meaning of Article 9 of the GDPR. If the Controller chooses to collect such data through the form fields it configures (for example, accessibility requirements or dietary information), it does so at its sole responsibility and warrants that it holds a valid legal basis and, where required, the explicit consent of the data subjects.
2.4 Categories of Data Subjects
- Participants in the Controller’s Events;
- Contacts imported by the Controller into the Platform.
2.5 Duration of Processing
Processing takes place for the duration of the Contract, and until data is deleted in accordance with Section 10.
3. Wisembly’s General Obligations
Wisembly undertakes to:
- process data solely for the purposes described in Section 2.2;
- process data in accordance with the Controller’s documented instructions, as set out in the Contract, in the Controller’s configuration of the Platform, and in any additional written instruction. If Wisembly considers that an instruction infringes the GDPR or any other provision of EU or Member State data protection law, it will immediately inform the Controller;
- inform the Controller, prior to processing, of any legal requirement obliging it to transfer data to a third country or international organization, unless the applicable law prohibits such notification on important grounds of public interest;
- ensure the confidentiality of data processed under the Contract;
- ensure that persons authorized to process the data are bound by confidentiality obligations, whether contractual or statutory, and receive appropriate data protection training;
- take into account, with respect to its tools, products, applications and services, the principles of data protection by design and by default.
4. Sub-processors
4.1 Authorized Sub-processors
The Controller authorizes Wisembly to engage the following sub-processors:
| Sub-processor | Activity | Location | Conditions |
|---|---|---|---|
| Mediactive Network (Mediactive Group) | Hosting of the Platform and its data, on a highly available infrastructure spread across 3 data centers | Île-de-France, France | Permanent |
| Mailjet (Sinch Group) | Delivery of emails sent through the Platform | France | Except where Wisembly implements the Client’s own sending service as part of a bespoke engagement (Section 8.3) |
| Esendex | Receipt and delivery of inbound SMS sent by Participants | United Kingdom (EU adequacy decision) | Only where the SMS contribution feature is enabled for an Event |
| Stripe | Processing of online payments | European Union | Only in the event of online payment; payment data is processed by Stripe under the terms of its own contractual documentation |
4.2 Additional Sub-processors
Wisembly may engage other sub-processors to carry out specific processing activities. In that case, it will inform the Controller in advance and in writing of any intended addition or replacement of a sub-processor, indicating the processing activities concerned and the identity and contact details of the sub-processor.
The Controller has fifteen (15) days from receipt of that information to raise reasoned objections. The new sub-processing arrangement may only be implemented if the Controller has not objected within that period.
4.3 Liability
Sub-processors are subject to obligations equivalent to those set out in this DPA. Wisembly is responsible for ensuring they provide sufficient guarantees regarding the implementation of appropriate technical and organizational measures. Where a sub-processor fails to fulfil its data protection obligations, Wisembly remains fully liable to the Controller for that sub-processor’s performance of its obligations.
5. Data Location and Transfers
Platform data is hosted and stored in France, on the servers of Mediactive Network. Wisembly ensures that any transfer of personal data outside the European Economic Area, in particular to sub-processors established in third countries, is subject to appropriate safeguards in accordance with Chapter V of the GDPR, such as standard contractual clauses or a European Commission adequacy decision.
6. Security
Wisembly undertakes to implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, including:
- measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- measures to restore the availability of and access to data in a timely manner in the event of a physical or technical incident, including regular backups;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures, including an annual security audit.
7. Data Subject Rights
7.1 Information to Data Subjects
It is the Controller’s responsibility to provide the information required under Articles 13 and 14 of the GDPR to data subjects at the time of data collection, in particular through the registration forms it configures.
7.2 Assistance with the Exercise of Rights
Wherever possible, Wisembly assists the Controller in fulfilling its obligation to respond to requests from data subjects seeking to exercise their rights: right of access, rectification, erasure, objection, restriction of processing, data portability, and the right not to be subject to a decision based solely on automated processing.
The Platform provides the Controller with tools to directly view and edit certain Participant data (except for the email address and consent data, which cannot be edited by the organizer), to facilitate the handling of rights requests it receives.
Where a data subject exercises their rights directly with Wisembly, Wisembly will forward the request to the Controller as soon as reasonably possible, except where Wisembly is required to respond directly under Section 10.3.
8. Emails, Open Tracking and SMS
8.1 Compiling Recipient Lists
The Controller is solely responsible for compiling the recipient lists for emails sent through the Platform. It warrants that it holds the consent of data subjects, or another valid legal basis, for these communications. An unsubscribe link is automatically included in every email sent through the Platform.
8.2 Open Tracking
Emails delivered by the sub-processor Mailjet may include a tracking pixel to measure open and interaction rates. This tracking is disabled by default for each Participant. The Platform allows the Controller to include, in its emails, a mechanism inviting the Participant to expressly consent to having their opens tracked. Tracking is only enabled for a given Participant once this explicit consent has been obtained, and may be withdrawn by the Participant at any time.
Including this consent mechanism, and configuring the emails that depend on it, constitute a processing instruction given by the Controller within the meaning of Section 3. The Controller remains solely responsible for the compliance of this mechanism and for complying with applicable law, in accordance with Article 82 of the French Data Protection Act and CNIL Recommendation No. 2026-042 of 12 March 2026.
8.3 Client’s Own Sending Service
As part of a bespoke engagement, Wisembly may configure the Platform so that emails are delivered through the Controller’s own sending service (SMTP server or equivalent), without Mailjet’s involvement. That service is then the Controller’s sole responsibility, and it is for the Controller to enter into any agreement required by applicable law with its provider. In that case, no tracking pixel is embedded by Wisembly in the emails delivered this way.
8.4 Anonymous Participation Mode
The Platform allows the Controller to enable an anonymous participation mode for an Event. When this mode is enabled, Participants’ contributions (messages, votes, responses) are not linked to their identity on the Platform: no name or email address is attached to these contributions. Technical data inherently linked to any connection (IP address, session data) may nonetheless be collected, without enabling Wisembly to individually identify the Participants concerned.
9. Data Breach Notification
Wisembly notifies the Controller of any personal data breach without undue delay, and no later than forty-eight (48) hours after becoming aware of it, by any written means, including email.
This notification is accompanied by all relevant documentation (nature of the breach, categories and approximate number of individuals and records affected, likely consequences, measures taken or proposed) to enable the Controller, where necessary, to notify the breach to the competent supervisory authority within the seventy-two (72) hour period provided for in Article 33 of the GDPR and, where applicable, to inform data subjects.
10. Retention Periods and Fate of Data
10.1 During the Contract
Data is retained for the duration of the Contract, for the purposes of providing the Services.
10.2 Automatic Deletion of Participant Data
Participants’ personal data is automatically deleted two (2) years after their last activity on the Platform.
10.3 Deletion Requests
Since a given Participant may be registered for Events organized by separate entities, each acting as an independent data controller, a Participant’s data cannot be deleted at the request of a single organizer.
Deletion of a Participant’s data occurs:
- upon direct request from the data subject to Wisembly (dpo@wisembly.com); or
- automatically, upon expiry of the two (2) year period of inactivity referred to in Section 10.2.
The Controller retains the ability to delete, for its own Events, the registration and participation data attached to them.
10.4 At the End of the Contract
At the end of the Contract, the Controller has one (1) month to export its data under the terms of the General Terms of Service. Upon expiry of that period, Wisembly will delete data processed on the Controller’s behalf, without prejudice to applicable legal retention obligations and to Section 10.2 for Participant data linked to other controllers.
11. Data Protection Impact Assessments and Prior Consultation
Wisembly provides the Controller, taking into account the nature of the processing and the information available to it, with reasonable assistance in carrying out data protection impact assessments (Article 35 of the GDPR) and, where applicable, in the prior consultation of the supervisory authority (Article 36 of the GDPR).
12. Record of Processing Activities
Wisembly maintains a written record of all categories of processing activities carried out on behalf of its clients, including: the name and contact details of the Controller, of sub-processors and, where applicable, of the data protection officer; the categories of processing carried out; where applicable, transfers of data to a third country; and, where possible, a general description of the technical and organizational security measures implemented.
13. Audit
Wisembly makes available to the Controller the documentation necessary to demonstrate compliance with its obligations under this DPA, and allows for and contributes to audits, including inspections, carried out by the Controller or an auditor it has appointed.
Any audit is carried out no more than once (1) per twelve (12) month period, subject to thirty (30) days’ written notice, during business hours, at the Controller’s expense, and without disrupting Wisembly’s operations. The auditor may not be a competitor of Wisembly and is subject to appropriate confidentiality obligations. Neither the Controller nor the auditor may access Wisembly’s trade secrets, strategic information, or data relating to other clients.
14. Controller’s Obligations
The Controller undertakes to:
- only provide to Wisembly, and only collect through the Platform, data whose collection and processing are based on a valid legal basis;
- provide data subjects with the information required by the GDPR at the time of collection;
- document in writing any additional instructions regarding Wisembly’s processing of data;
- ensure, both before and throughout the processing, compliance with the obligations set out in the GDPR;
- oversee the processing, including, where applicable, by carrying out audits and inspections under Section 13.
15. Contact
For any question regarding this DPA or the protection of personal data, the Controller and data subjects may contact Wisembly:
- by email: dpo@wisembly.com
- by post: Wisembly (MEDIACTIVE EVENTS SOLUTIONS), 4 cité Paradis, 75010 Paris, France
