Data Processing Agreement
Last updated: October 6, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Controller”) and MERAF Digital Solutions (the “Processor”). It applies whenever we process personal data on your behalf (“Customer Personal Data”). It is designed to meet Article 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR and the Philippine Data Privacy Act of 2012, where they apply.
On this page
1. When this DPA applies
QRSVP, QRSVP Pro and the add-ons run on your own WordPress website. Your guest lists, registrations and check-ins stay there, and our licensing service receives only your licence key, your website’s address and its server’s IP address, which we process as a controller under our Privacy Policy.
We process Customer Personal Data only when you give us some of it — for example an export, or access to your website, so that we can help you with a support request — and through any future service of ours that says it relies on this DPA.
2. Details of the processing
- Nature and purpose: receiving, looking into and solving the support requests you send us.
- Data subjects: your guests, the people who register for your events, and your staff.
- Personal data: what your request contains, such as names, email addresses, phone numbers, party details, ticket and door codes, and check-in times.
- Special categories of data: QRSVP can record allergies and emergency contacts, which may reveal health information. Send them to us only when we cannot help you without them.
- Duration: as long as we need to answer your request, and then until the data is deleted under section 11.
3. Your instructions
We process Customer Personal Data only on your documented instructions — these Terms, this DPA and your support request — unless the law requires otherwise; in that case we will tell you first, unless the law forbids it. We will tell you if we believe an instruction breaks data protection law.
4. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality.
5. Security measures
We maintain appropriate technical and organisational measures, including:
- encryption in transit (HTTPS);
- access limited to the people working on your request;
- your data kept apart from other customers’ data, and never used for any other purpose;
- deletion once your request is solved (section 11).
6. Sub-processors
You authorise us to use sub-processors, currently our hosting provider and our email provider. We impose data protection obligations on them that are at least as protective as this DPA, and we remain responsible for them. We will tell you before we add or replace a sub-processor; if you object on reasonable data protection grounds and we cannot address your objection, you may stop sending us Customer Personal Data and cancel your subscription. An up-to-date list is available on request.
7. Assistance
Taking into account the information available to us, we will help you answer requests from data subjects, and meet your security obligations and your data protection impact assessments.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information we have, and we will help you meet your obligations to notify authorities and data subjects.
9. International transfers
We process Customer Personal Data in the Philippines and in the countries where our sub-processors operate. Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), apply and are incorporated by reference, with the general written authorisation option for sub-processors, the law and courts of the EU Member State where you are established, and the UK International Data Transfer Addendum for transfers subject to the UK GDPR. If they conflict with this DPA, the Standard Contractual Clauses prevail.
10. Information and audits
We will make available the information needed to demonstrate compliance with this DPA. You, or an auditor you appoint, may audit our compliance once a year, with at least 30 days’ notice, during business hours, at your cost and under confidentiality — and more often if an authority requires it or after a breach. We may first answer with existing documentation.
11. Return and deletion
We delete the Customer Personal Data you sent us within 30 days after your request is solved, or sooner if you ask, except where the law requires us to keep it.
12. Liability and precedence
The limitations of liability in the Terms of Service apply to this DPA to the extent permitted by law. For the processing of Customer Personal Data, this DPA prevails over the Terms of Service.
Contact
Questions about this page, or about your personal data? Write to MERAF Digital Solutions at support@merafsolutions.com.