Legal

Data-processing agreement

Part of your Cashbox agreement, for every plan that processes personal data on your organisation’s instructions.

Document version: 2026-10-01.1

Parties and scope

This agreement forms part of the terms between the subscribing organisation (Customer) and PixelPulse OÜ, Ahtri tn 12, 15551 Tallinn, Estonia (Processor). It applies on every plan, including trials, when Cashbox processes personal data for the Customer. The Customer acts as controller or, where authorised, as processor for its own controller. This agreement prevails over conflicting general terms on data protection; mandatory GDPR rights and liabilities remain unaffected.

Processing details

The subject and purpose are hosting and operating event financial management on the Customer’s instructions: collection, storage, organisation, calculation, retrieval, authorised disclosure, export and deletion. Processing lasts for the service relationship and the return/deletion period. Data subjects may include users, staff, contractors, suppliers, artists, sponsors and business contacts. Data includes identity/contact details, roles, approvals, financial transactions, tax identifiers, documents, communications and activity records entered by the Customer. Special-category and criminal-conviction data are excluded unless separately agreed in writing with suitable safeguards.

Instructions and confidentiality

We process Customer personal data only on documented instructions, including this agreement, authorised product actions and written requests to our contact address. We notify the Customer if an instruction appears unlawful. If Union or Member State law requires other processing, we notify the Customer before processing unless that law prohibits notice. Authorised personnel must be bound by confidentiality and access only what their duties require. The Customer determines lawful purposes, provides required notices and ensures its instructions and disclosures are lawful.

Security measures

We will maintain measures appropriate to risk under Article 32 GDPR: encrypted transport and managed encrypted storage; authenticated, organisation-scoped access; role and event-assignment checks; server-controlled financial writes; protected invoice retrieval; activity logs; access restriction for staff; and procedures for recovery, incident response and regular security evaluation. We may improve measures without materially reducing protection. The Customer controls user invitations, access assignments, uploaded content and the security of its devices. Details and evidence may be requested for compliance review.

Subprocessors and transfers

The Customer generally authorises Google Cloud/Firebase (authentication, database, storage), Vercel (hosting), Resend (service email), Sentry (error diagnostics where enabled) and Google Gemini (only for requested AI import assistance) for their relevant processor activities. We remain responsible for their performance and must impose equivalent data-protection obligations in written contracts. We will give owners at least 30 days’ advance notice of additions or replacements, including purpose and processing location. Customers may object on reasonable data-protection grounds during that period; we will seek a solution or allow termination of the affected service if unresolved. Transfers outside the EEA require a valid Chapter V mechanism and any necessary supplementary safeguards. We provide provider and transfer details on request; no EU-only processing guarantee is made.

Assistance, incidents and audits

Taking account of the nature of processing and information available, we will assist the Customer with data-subject rights, security obligations, breach notifications, impact assessments and prior consultation under Articles 32–36. We notify the Customer without undue delay after becoming aware of a personal-data breach, provide available details of its nature, affected data/people, likely consequences, contact point and mitigation, and supplement information as it becomes available. We make compliance information available and allow and contribute to audits, including inspections by the Customer or its mandated auditor. Reasonable scheduling and confidentiality protect other customers but must not prevent required audits. We forward data-subject requests and do not respond on the Customer’s behalf without instructions unless legally required.

Return, deletion and contact

At the Customer’s choice on termination, we will return or delete personal data and delete existing copies unless Union or Member State law requires retention. The Customer may export first and instruct immediate workspace deletion, or use the switching/retrieval process in the terms. Residual backup copies must be isolated from ordinary use until erased; restoration must not reintroduce deleted workspaces. We will explain any legally required retention and confirm completion of the applicable deletion scope. This does not delete independent personal sign-in accounts or records we lawfully process as controller under the privacy policy. Send instructions, audit requests and security/privacy enquiries to hello@cashbox.events. Acceptance is recorded with the Customer’s identity, authorised representative, document versions and server timestamp.