← Legal

Data Processing Agreement

Last updated: July 27, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the event host ("Controller") and Knight Ops LLC, operating the Headliner platform ("Processor"), for the processing of personal data in connection with the Headliner event management platform.

1. Definitions

  • "Controller" means the event host who determines the purposes and means of processing attendee personal data through the Headliner platform.
  • "Processor" means Knight Ops LLC, which processes personal data on behalf of the Controller through the Headliner platform.
  • "Personal Data"means any information relating to an identified or identifiable natural person processed through the Platform in connection with the Controller’s events.
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

2. Scope and Purpose

This DPA applies to the processing of attendee personal data by the Processor on behalf of the Controller for the purpose of providing event management services through the Headliner platform, including:

  • Event registration and ticketing
  • Attendee profile management
  • Session scheduling and check-in
  • Communication between hosts and attendees
  • Networking and matchmaking features
  • Payment processing facilitation
  • Event analytics and reporting

3. Processing Details

3.1 Types of Personal Data

  • Names (first and last)
  • Email addresses
  • Phone numbers
  • Profile data (company, title, bio, social links, photos)
  • Event activity data (registrations, session attendance, messages, posts)
  • Transaction records (amounts, dates, confirmation IDs — no payment card data)

3.2 Categories of Data Subjects

  • Event attendees
  • Speakers and presenters
  • Affiliates and promotional partners

3.3 Purpose of Processing

Personal data is processed solely for the purpose of providing event management, ticketing, communication, and networking services as described in the Controller’s service agreement with Knight Ops LLC.

4. Processor Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits such notification.
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, as described in Section 6.
  • Assist the Controller in responding to requests from data subjects exercising their rights under applicable data protection law (access, rectification, erasure, portability, objection).
  • Assist the Controller in ensuring compliance with obligations related to security of processing, notification of data breaches, data protection impact assessments, and prior consultation with supervisory authorities.
  • At the Controller’s choice, delete or return all Personal Data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage of the Personal Data.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA.

5. Sub-processors

The Controller grants general authorization for the Processor to engage sub-processors. As of the date of this DPA, the following sub-processors are authorized:

  • Supabase Inc.— Database hosting, authentication, and row-level security enforcement. Data location: United States.
  • Stripe Inc.— Payment processing and transaction management. Data location: United States.
  • Vercel Inc.— Application hosting, edge delivery, and serverless compute. Data location: United States (with global edge nodes).
  • Resend Inc.— Transactional email delivery. Data location: United States.

The Processor shall provide the Controller with at least 30 days’ written notice before engaging any new sub-processor, giving the Controller the opportunity to object. If the Controller objects on reasonable grounds related to data protection, and the Processor cannot reasonably accommodate the objection, either party may terminate the affected services.

The Processor shall impose data protection obligations on each sub-processor no less protective than those set out in this DPA.

6. Security Measures

The Processor implements the following technical and organizational security measures:

  • Encryption in transit: All data transmitted between clients and the Platform is encrypted using TLS 1.2 or higher.
  • Encryption at rest: All data stored in the database is encrypted at rest using AES-256.
  • Row-Level Security (RLS):Database-level tenant isolation ensures that each host’s data is accessible only to authorized users within that tenant. RLS policies are enforced by Supabase PostgreSQL.
  • AES-256-GCM for sensitive credentials: API keys, webhook secrets, and other sensitive configuration values stored on behalf of hosts are encrypted using AES-256-GCM before storage.
  • Access control: Role-based access control limits access to personal data to authorized personnel only.
  • SOC 2 compliance (planned): Knight Ops is working toward SOC 2 Type II certification. Sub-processors Supabase, Stripe, and Vercel each maintain their own SOC 2 certifications.

7. Data Breach Notification

In the event of a personal data breach, the Processor shall notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach. The notification shall include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and records affected.
  • The name and contact details of the Processor’s point of contact for further information.
  • A description of the likely consequences of the breach.
  • A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

8. International Transfers

Where Personal Data is transferred from the European Economic Area, United Kingdom, or Switzerland to the United States (where the Platform infrastructure is located), such transfers shall be governed by Standard Contractual Clauses (SCCs) as approved by the European Commission. The Controller and Processor agree to execute the applicable SCCs upon request.

9. Audit Rights

The Controller may audit the Processor’s compliance with this DPA, subject to the following conditions:

  • The Controller must provide at least 30 days’ written notice before conducting an audit.
  • Audits may be conducted no more than once per year, unless a data breach has occurred or a supervisory authority requires an additional audit.
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor’s operations.
  • The Controller shall bear the costs of the audit, unless the audit reveals a material breach of this DPA by the Processor.

10. Return and Deletion of Data

Upon termination of the service agreement, the Processor shall, at the Controller’s election, either return all Personal Data to the Controller in a structured, commonly-used, machine-readable format, or delete all Personal Data, within 30 days of termination.

The Processor shall provide written confirmation of deletion upon request. The Processor may retain Personal Data only to the extent required by applicable law, and shall inform the Controller of any such retention requirement.

11. Term

This DPA shall remain in effect for the duration of the service agreement between the Controller and the Processor. It co-terminates with the service agreement. Obligations relating to confidentiality, data deletion, and breach notification survive termination.

12. Contact

Knight Ops LLC (Processor)

Email: hello@knightops.biz

Website: headliner.space