Partyfiy

Legal & policies
Partyfiy
Partyfiy

Data Processing Addendum

Last updated: September 3, 2026

This Data Processing Addendum (“DPA”) sets out the terms under which Partyfiy Inc. (“Partyfiy” or “Processor”) processes personal information on behalf of vendors and other business users (“Controllers”) who use the Service to operate their business. It supplements our Terms of Service and Privacy Policy and aligns with PIPA and PIPEDA.

1. Roles & scope

When a vendor uses Partyfiy to manage bookings, leads, and client information, the vendor is the Controller of that client personal information and Partyfiy acts as Processor. This DPA applies to the personal information processed to provide the Service.

2. Purpose limitation

Partyfiy processes personal information only on documented instructions from the Controller and as needed to provide the Service, except where required by law. We will not use the information for our own commercial purposes beyond operating and improving the Service.

3. Categories of data

  • Client contact details (name, email, phone) shared for quotes and bookings.
  • Event details (type, date, location, guest count, special requests).
  • Communication content and booking/payment records.

4. Confidentiality & personnel

Access to personal information is limited to authorized personnel who are bound by confidentiality obligations and trained on privacy and security practices.

5. Security measures

  • Encryption of data in transit and at rest where technically feasible.
  • Access controls, authentication, and least-privilege permissions.
  • Payment data handled solely by certified processors; not stored by Partyfiy.
  • Monitoring, logging, and incident response procedures.

6. Sub-processors

We engage sub-processors (e.g. hosting and payment providers) under written agreements that require equivalent protection. We remain responsible for their performance. A list of key sub-processor categories is available on request.

7. Data subject rights & assistance

Where applicable law requires, Partyfiy will assist Controllers in responding to requests from individuals regarding access, correction, or deletion, taking into account the nature of processing and the information available to us.

8. Breach notification

If a security breach affecting personal information occurs, Partyfiy will notify the affected Controller without undue delay and provide reasonable information to help meet any legal notification obligations.

9. Return & deletion

Upon request or termination, and subject to legal retention requirements, Partyfiy will return or delete personal information processed on behalf of the Controller, unless law requires retention.

10. Audits & international transfers

Controllers may audit our compliance as reasonably agreed in advance. Personal information is stored and processed primarily in Canada; where any cross-border transfer occurs, we apply appropriate safeguards consistent with applicable law.

Data-protection questions? Contact us.