
Data Processing Addendum
Last updated: September 3, 2026
This Data Processing Addendum (“DPA”) sets out the terms under which Partyfiy Inc. (“Partyfiy” or “Processor”) processes personal information on behalf of vendors and other business users (“Controllers”) who use the Service to operate their business. It supplements our Terms of Service and Privacy Policy and aligns with PIPA and PIPEDA.
1. Roles & scope
When a vendor uses Partyfiy to manage bookings, leads, and client information, the vendor is the Controller of that client personal information and Partyfiy acts as Processor. This DPA applies to the personal information processed to provide the Service.
2. Purpose limitation
Partyfiy processes personal information only on documented instructions from the Controller and as needed to provide the Service, except where required by law. We will not use the information for our own commercial purposes beyond operating and improving the Service.
3. Categories of data
- Client contact details (name, email, phone) shared for quotes and bookings.
- Event details (type, date, location, guest count, special requests).
- Communication content and booking/payment records.
4. Confidentiality & personnel
Access to personal information is limited to authorized personnel who are bound by confidentiality obligations and trained on privacy and security practices.
5. Security measures
- Encryption of data in transit and at rest where technically feasible.
- Access controls, authentication, and least-privilege permissions.
- Payment data handled solely by certified processors; not stored by Partyfiy.
- Monitoring, logging, and incident response procedures.
6. Sub-processors
We engage sub-processors (e.g. hosting and payment providers) under written agreements that require equivalent protection. We remain responsible for their performance. A list of key sub-processor categories is available on request.
7. Data subject rights & assistance
Where applicable law requires, Partyfiy will assist Controllers in responding to requests from individuals regarding access, correction, or deletion, taking into account the nature of processing and the information available to us.
8. Breach notification
If a security breach affecting personal information occurs, Partyfiy will notify the affected Controller without undue delay and provide reasonable information to help meet any legal notification obligations.
9. Return & deletion
Upon request or termination, and subject to legal retention requirements, Partyfiy will return or delete personal information processed on behalf of the Controller, unless law requires retention.
10. Audits & international transfers
Controllers may audit our compliance as reasonably agreed in advance. Personal information is stored and processed primarily in Canada; where any cross-border transfer occurs, we apply appropriate safeguards consistent with applicable law.
Data-protection questions? Contact us.