Last Updated - Oct. 3, 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the HoneyBee Terms and Conditions (the "Terms") between HoneyBee Innovations LLC ("HoneyBee") and the Customer that has accepted them. It applies whenever HoneyBee processes Customer Personal Data subject to Data Protection Laws on the Customer's behalf. No separate signature is required.

1. Definitions

Terms not defined here have the meanings given in the Terms or in Data Protection Laws.

  • "Customer Personal Data" means personal data within Customer Data, as defined in the Terms, that HoneyBee processes on the Customer's behalf.

  • "Data Protection Laws" means all laws that apply to the processing of Customer Personal Data under the Terms, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and US state privacy laws such as the California Consumer Privacy Act ("CCPA").

  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.

  • "Subprocessor" means any third party HoneyBee engages to process Customer Personal Data.

  • "Controller," "processor," "data subject," "personal data," and "processing" have the meanings given in the GDPR.

2. Roles and scope

The Customer is the controller of Customer Personal Data, and HoneyBee is its processor. Annex 1 describes the subject matter, nature, purpose, and duration of the processing, the types of personal data, and the categories of data subjects. The Customer is responsible for the lawfulness of the Customer Personal Data it provides and for any consents and notices Data Protection Laws require.

3. Processing on instructions

HoneyBee processes Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise, in which case HoneyBee will tell the Customer before processing unless the law prohibits it. The Terms, this DPA, and the Customer's configuration and use of the Services are the Customer's complete instructions. HoneyBee will tell the Customer promptly if it believes an instruction infringes Data Protection Laws.

4. Confidentiality

HoneyBee ensures that everyone it authorizes to process Customer Personal Data is bound by an obligation of confidentiality and accesses the data only as needed to provide the Services.

5. Security

HoneyBee implements and maintains the technical and organizational measures described in Annex 2 to protect Customer Personal Data, taking into account the state of the art, the costs of implementation, the nature of the processing, and the risks to data subjects. HoneyBee may update these measures over time, provided the overall level of protection does not decrease.

6. Subprocessors

The Customer authorizes HoneyBee to engage the Subprocessors listed in Annex 3 and new Subprocessors under this section. HoneyBee will bind each Subprocessor by written contract to data protection obligations no less protective than this DPA, and remains responsible for each Subprocessor's performance.

HoneyBee will email the Customer's account owner at least 30 days before engaging a new Subprocessor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services, and HoneyBee will refund any prepaid fees for the unused part of the term.

7. Data subject requests

Taking into account the nature of the processing, HoneyBee will help the Customer respond to requests from data subjects exercising their rights under Data Protection Laws. The Services let the Customer view, edit, export, and delete client records directly. When the Customer passes an access or deletion request to HoneyBee, HoneyBee will complete it within 24 hours. If HoneyBee receives a request directly, it will forward it to the Customer without undue delay and will not respond on the Customer's behalf unless instructed.

8. Personal Data Breaches

HoneyBee will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. HoneyBee will provide further information as it becomes available and take reasonable steps to contain and remedy the breach.

9. Other assistance

HoneyBee will provide reasonable assistance with the Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to HoneyBee's processing and the information is not otherwise available to the Customer.

10. Deletion and return

After the Customer's subscription ends, the Customer may export Customer Personal Data for 30 days. HoneyBee then permanently deletes it from its live systems, and remaining copies in backups are deleted on the providers' rolling backup schedules, unless the law requires HoneyBee to keep them.

11. Audits

HoneyBee will make available the information reasonably necessary to demonstrate compliance with this DPA, including its security policies and compliance materials at trust.withhoneybee.com. If that information is not sufficient, or a supervisory authority requires it, the Customer may conduct an audit, itself or through an independent auditor bound by confidentiality, no more than once a year, with at least 30 days' written notice, during business hours, and at the Customer's expense.

12. International transfers

HoneyBee and its Subprocessors process Customer Personal Data in the United States. To the extent Customer Personal Data is transferred from the European Economic Area to HoneyBee in a country without an adequacy decision, the SCCs are incorporated into this DPA as follows:

  • Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is itself a processor.

  • The Customer is the data exporter and HoneyBee is the data importer.

  • In Clause 7, the docking clause applies.

  • In Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 6 of this DPA.

  • In Clause 11, the optional language does not apply.

  • In Clause 13, the competent supervisory authority is the one for the Member State where the Customer is established or, if the Customer is not established in the EU, where HoneyBee's EU representative is established (Austria).

  • In Clauses 17 and 18, the governing law is the law of Ireland and disputes are resolved by the courts of Ireland.

  • Annexes I, II, and III of the SCCs are completed by Annexes 1, 2, and 3 of this DPA.

For transfers subject to the UK GDPR, the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner applies, completed with the information in this DPA. For transfers subject to the FADP, the SCCs apply with references to the GDPR read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority.

13. US state privacy laws

Where the CCPA or similar US state laws apply, HoneyBee acts as the Customer's service provider or processor. HoneyBee will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Services, or combine it with personal data from other sources except as those laws permit. HoneyBee will notify the Customer if it can no longer meet these obligations.

14. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms, except where Data Protection Laws or the SCCs do not permit such a limitation.

15. Order of precedence

If there is a conflict, the SCCs prevail over this DPA, and this DPA prevails over the rest of the Terms, in each case only for the processing of Customer Personal Data.

16. Term

This DPA remains in effect for as long as HoneyBee processes Customer Personal Data on the Customer's behalf, including during the 30-day export period after the Customer's subscription ends. HoneyBee may update this DPA by posting a new version and emailing the Customer's account owner at least 30 days before a material change takes effect, provided the update does not reduce the protection of Customer Personal Data.

Annex 1: Description of processing

Data exporter: the Customer, as identified in its HoneyBee account. Role: controller (or processor, where the Customer acts on behalf of another controller).

Data importer: HoneyBee Innovations LLC, 11133 Shady Trail PMB 133, Dallas, TX 75229, United States; info@withhoneybee.com; +1 844-638-1741. Role: processor. EU representative: Prighter, Schellinggasse 3/10, 1010 Vienna, Austria.

Categories of data subjects: the Customer's clients and prospective clients, event attendees, and the Customer's staff users.

Categories of personal data: names and contact details; demographic details such as age, location, and occupation; photos; relationship preferences, intake form answers, and notes the Customer records; event registrations, check-ins, and match selections; messages sent through the Services; and event ticket transaction records (card details are held by Stripe only).

Special categories of data: depending on what the Customer chooses to collect, data revealing sexual orientation, religious beliefs, racial or ethnic origin, or health. Safeguards include encryption at rest and in transit, tenant isolation through row-level security, access limited to what is needed to provide the Services, and the measures in Annex 2.

Frequency of transfer: continuous, for as long as the Customer uses the Services.

Nature of processing: hosting, storage, organization, retrieval, display, transmission (including text messages and emails sent at the Customer's direction), payment collection for events, and deletion.

Purpose: to provide, maintain, secure, and support the Services for the Customer under the Terms.

Duration and retention: for the term of the Customer's subscription plus the 30-day export period in Section 10, after which the data is deleted.

Transfers to Subprocessors: as listed in Annex 3, for the same nature, purpose, and duration.

Annex 2: Technical and organizational measures

HoneyBee's full technical and organizational measures are available on request and at trust.withhoneybee.com. In summary:

  • Encryption: TLS 1.2 or higher in transit, and AES-256 encryption at rest for databases, backups, and stored files.

  • Access control: multi-factor authentication on all administrative accounts, least-privilege access, and tenant isolation enforced by row-level security policies.

  • Logging and monitoring: account activity, storage access, network, and application logs, with automated threat detection and error alerting.

  • Availability: daily database backups and 30-day versioning of stored photos.

  • Retention and deletion: customer-instructed deletions completed within 24 hours, and all Customer Personal Data deleted 30 days after a subscription ends.

  • Vulnerability management: dependency and supply-chain scanning before release.

  • Incident response: documented procedures, external breach counsel, and Customer notification within 48 hours.

  • Organizational measures: security policies reviewed annually, confidentiality obligations for anyone with data access, and annual security training.

Annex 3: Subprocessors

The current list is maintained at trust.withhoneybee.com. As of the date of this DPA, HoneyBee uses the following Subprocessors:

  • Supabase: database and authentication. Location: United States.

  • Vercel: application hosting. Location: United States.

  • Amazon Web Services: photo storage and delivery, serverless functions, and security monitoring. Location: United States.

  • HighLevel: CRM marketing features, for Customers who use them. Location: United States.

  • Stripe: event ticket payment processing. Location: United States.

  • Resend: transactional email sending, receiving, and processing, for Customers who use them. Location: United States

  • Surge: transactional SMS sending, receiving, and processing, for Customers who use them. Location: United States.

  • Prighter: EU and UK representative and data subject request portal. Location: Austria.

Demo Icon 1

Book a demo or get started with events today.

Demo Icon 1

Book a demo or get started with events today.