Effective Date: July 5, 2026
This Data Processing Agreement ("DPA") forms part of the ExpoPilot Terms of Service, Master Subscription Agreement, or other written agreement (the "Agreement") between ExpoPilot ("Processor," "we," "our," or "us") and the customer identified in the Agreement ("Controller," "Customer," or "you").
This DPA governs the processing of Personal Data by ExpoPilot on behalf of the Customer in connection with the Services.
For purposes of this DPA:
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means ExpoPilot, which processes Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
Processing means any operation performed on Personal Data, including collection, storage, organization, use, disclosure, transmission, analysis, retrieval, deletion, or destruction.
Subprocessor means a third party engaged by ExpoPilot to process Personal Data on behalf of the Customer.
Security Incident means a confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Customer Personal Data processed by ExpoPilot.
Applicable capitalized terms not defined herein have the meanings assigned in the Agreement.
ExpoPilot processes Personal Data solely for the purpose of providing, supporting, securing, and improving the Services in accordance with the Agreement and the Customer's documented instructions.
The Customer determines the categories of Personal Data submitted to the Services and is responsible for ensuring that it has an appropriate legal basis to collect, use, and disclose such information.
ExpoPilot acts only as a Processor and does not determine the purposes for which Customer Personal Data is collected.
Depending on how the Services are used, Customer Personal Data may include:
Unless expressly agreed in writing, the Customer should not upload special categories of Personal Data or sensitive information that requires additional legal protections under applicable law.
ExpoPilot processes Customer Personal Data solely to:
ExpoPilot will never sell Customer Personal Data or use it for unrelated commercial purposes.
The Customer is responsible for:
ExpoPilot agrees to:
ExpoPilot maintains an information security program designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, or destruction.
Security measures may include:
Our security program is regularly reviewed and may evolve to reflect changes in technology, threats, and industry best practices.
Customer authorizes ExpoPilot to engage subprocessors necessary to provide the Services.
Subprocessors may include providers of:
ExpoPilot remains responsible for ensuring that all subprocessors are contractually required to protect Customer Personal Data in a manner consistent with this DPA.
Upon reasonable written request, ExpoPilot will provide Customers with a current list of material subprocessors.
Where Customer Personal Data is transferred across national borders, ExpoPilot will implement appropriate safeguards required under applicable data protection laws.
These safeguards may include:
If ExpoPilot receives a request directly from an individual regarding Personal Data processed on behalf of a Customer, ExpoPilot will promptly notify the Customer unless legally prohibited from doing so.
The Customer remains responsible for responding to all data subject requests, including requests for:
ExpoPilot will provide reasonable assistance where technically feasible.
ExpoPilot will notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.
To the extent information is available, the notification will include:
Notification of a Security Incident does not constitute an admission of fault or liability.
Customer Personal Data is retained only as long as necessary to:
Upon termination of the Agreement and written request from the Customer, ExpoPilot will return or securely delete Customer Personal Data where technically feasible and legally permissible.
Certain information may be retained where required by applicable law or legitimate business obligations.
Upon reasonable written request and subject to appropriate confidentiality obligations, ExpoPilot will provide documentation describing its security controls and privacy practices sufficient to demonstrate compliance with this DPA.
Customer audit requests:
ExpoPilot shall ensure that employees, contractors, and subprocessors authorized to process Customer Personal Data are subject to confidentiality obligations appropriate to the sensitivity of the information they process.
These obligations survive termination of employment or contractual relationships.
The limitation of liability provisions contained in the Agreement apply equally to this DPA unless otherwise required by applicable law.
Nothing in this DPA limits either party's liability where such limitation is prohibited by law.
If there is any conflict between this DPA and the Agreement regarding the processing of Personal Data, the provisions of this DPA shall control solely with respect to data protection and privacy obligations.
All other provisions of the Agreement remain in full force and effect.
This DPA shall be governed by the same governing law specified in the Agreement unless otherwise required by applicable data protection laws.
If you have questions regarding this Data Processing Agreement or our data protection practices, please contact us.
ExpoPilot is committed to maintaining a secure, transparent, and privacy-focused platform for organizations managing conferences, trade shows, and events worldwide.