Data Processing Agreement
Schwarz Events, Inc. d/b/a Rockoly · Last Updated: September 10, 2026
This Data Processing Agreement (this “DPA”) forms part of the Event Terms and Conditions (the “Agreement”) between Schwarz Events, Inc., a corporation doing business as Rockoly (“Rockoly”), and the client identified in the applicable proposal, invoice, or booking confirmation (“Client”).
It applies whenever Rockoly processes personal data on Client’s behalf to provide the Services — for example, participants’ names and email addresses for invitations, delivery addresses for ingredient kits, and dietary requirements for menu planning — and sets out each party’s data protection obligations, including those that Article 28 of the GDPR and U.S. state privacy laws require in a contract between a business and its service provider.
This DPA takes effect when Client enters into the Agreement; no separate signature is required. Client may request a countersigned copy at info@rockoly.com.
1. DEFINITIONS
Capitalized terms not defined in this DPA have the meanings given in the Agreement. In this DPA:
- “Client Personal Data” means Personal Data that Rockoly processes on Client’s behalf in providing the Services, as described in Annex I.
- “Data Protection Laws” means all laws that apply to the processing of Client Personal Data under the Agreement, which may include the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its regulations (the “CCPA”) and other U.S. state privacy laws; the EU General Data Protection Regulation 2016/679 (the “GDPR”); the GDPR as it forms part of the law of the United Kingdom, together with the UK Data Protection Act 2018 (the “UK GDPR”); and the Swiss Federal Act on Data Protection (the “FADP”), each as amended or replaced.
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Supervisory Authority” have the meanings given in the GDPR, and “Business,” “Service Provider,” “Sell,” and “Share” have the meanings given in the CCPA. Equivalent terms in other Data Protection Laws have corresponding meanings.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Client Personal Data while it is processed by Rockoly or its Subprocessors.
- “Subprocessor” means any third party that Rockoly engages to process Client Personal Data on its behalf, including service providers and the independent chefs, instructors, Zoom hosts, and event helpers who deliver Events.
- “Standard Contractual Clauses” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, and the “UK Addendum” means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner.
2. ROLES AND SCOPE
2.1 Roles of the Parties
For Client Personal Data, Client is the Controller and Rockoly is its Processor. Where Client acts on behalf of another controller — for example, an affiliate whose employees attend an Event — Client is a Processor, Rockoly is its Subprocessor, and Client confirms that it is authorized to give the instructions in this DPA.
Under the CCPA and similar U.S. state laws, Client is the Business (or controller) and Rockoly is its Service Provider (or processor).
2.2 Client’s Instructions
Rockoly processes Client Personal Data only on Client’s documented instructions, unless applicable law requires otherwise — in which case Rockoly will inform Client before processing, unless that law prohibits it. Client’s instructions are the Agreement, this DPA, the applicable proposal, the choices Client’s organizer makes in Rockoly’s member area (such as whether Rockoly may message participants about their delivery or ask them to review the Event), and any further reasonable instructions Client gives in writing, including by email to its Rockoly event planner.
Rockoly will inform Client promptly if, in its opinion, an instruction infringes Data Protection Laws.
2.3 Client’s Responsibilities
Client is responsible for the lawfulness of the Client Personal Data it provides and for giving any notices and obtaining any consents that Data Protection Laws require for Rockoly to process it — including when Client shares participants’ contact details so that Rockoly can invite them to an Event or deliver to them.
Client should share only the Client Personal Data an Event needs. Rockoly does not need, and Client should not send, government identification numbers, financial account or payment card numbers, or health information beyond the dietary requirements and allergies described in Annex I.
2.4 Processing Outside this DPA
This DPA does not cover personal data that Rockoly processes as an independent controller for its own business purposes: inquiries and sales conversations with the people who contact Rockoly or book with it; its accounting and tax records; the operation, analytics, and security of its public website; feedback and reviews that people choose to give Rockoly about its services; and names, images, and recordings used under the Marketing and Likeness terms of the Agreement. That processing is described in Rockoly’s Privacy Policy.
2.5 Details of Processing
The subject matter, duration, nature, and purpose of the processing, and the types of Client Personal Data and categories of Data Subjects, are described in Annex I.
3. ROCKOLY’S OBLIGATIONS
3.1 Confidentiality and Access
Rockoly limits access to Client Personal Data to the personnel and contractors who need it to deliver the Services, gives each of them only the data their part in an Event requires, and ensures that each is bound by an appropriate obligation of confidentiality.
3.2 Security
Rockoly implements and maintains appropriate technical and organizational measures to protect Client Personal Data against a Personal Data Breach, taking into account the nature of the data and the risks of the processing. Those measures are described in Annex II.
3.3 Service Provider Commitments
Rockoly will not:
- Sell or Share Client Personal Data;
- retain, use, or disclose Client Personal Data for any purpose other than providing the Services, or as Data Protection Laws otherwise permit;
- retain, use, or disclose Client Personal Data outside its direct business relationship with Client;
- combine Client Personal Data with personal data it receives from or on behalf of anyone else, or collects from its own interactions with individuals, except as Data Protection Laws permit; or
- use Client Personal Data to market Rockoly’s services to participants or for targeted advertising.
Rockoly will comply with the obligations that Data Protection Laws place on it as a Service Provider or Processor, provide the level of privacy protection they require, and notify Client if it determines that it can no longer meet those obligations. Client may take reasonable and appropriate steps to ensure that Rockoly uses Client Personal Data consistently with Client’s own obligations, and to stop and remediate any unauthorized use. Rockoly certifies that it understands and will comply with the restrictions in this Section.
3.4 Aggregated Information
Rockoly may create aggregated or de-identified information from its provision of the Services — such as the number of participants in a workshop — that does not identify Client or any individual, and may use it to operate and improve its business. Rockoly will keep such information in de-identified form and will not attempt to re-identify it.
4. SUBPROCESSORS
4.1 Authorization
Client gives Rockoly general written authorization to engage Subprocessors. The Subprocessors Rockoly uses are listed in Annex III, together with the independent chefs, instructors, Zoom hosts, and event helpers it engages for individual Events.
4.2 Subprocessor Obligations
Before a Subprocessor processes Client Personal Data, Rockoly will ensure that it is bound by written data protection terms no less protective than this DPA, to the extent relevant to the service it provides. Rockoly remains responsible to Client for its Subprocessors’ performance of those obligations.
4.3 Changes to Subprocessors
Rockoly will update Annex III on this page at least fourteen (14) days before a new Subprocessor begins processing Client Personal Data, and will also notify by email any Client that has asked to receive notice of these changes by writing to info@rockoly.com.
Client may object to a new Subprocessor on reasonable data protection grounds by notifying Rockoly in writing within that period. The parties will discuss the objection in good faith. If they cannot resolve it, Rockoly will either deliver the affected Services without that Subprocessor or allow Client to cancel the affected Services and refund the amounts Client has prepaid for Services not yet performed, less costs already incurred.
If a Subprocessor must be replaced urgently — for example, because it has failed or stopped providing its service — Rockoly may make the change immediately and will give notice as soon as practicable.
4.4 Deliveries
To deliver ingredients, kits, and supplies, Rockoly gives the business fulfilling each delivery — a retailer or grocery delivery service, a kit maker, a carrier, or a licensed alcohol distributor (for example, Whole Foods Market, Amazon, Instacart, UPS, or Bevvi) — the participant’s name, delivery address, phone number, and delivery instructions. Dietary information is not included in delivery instructions. Retailers, carriers, and alcohol distributors handle deliveries under their own terms and privacy policies, and a delivery outside the United States is fulfilled by a business in the destination country.
5. INTERNATIONAL TRANSFERS
5.1 Location of Processing
Rockoly is based in the United States and processes Client Personal Data there. Its Subprocessors process Client Personal Data in the locations listed in Annex III.
5.2 Transfers from the European Economic Area
Where Rockoly processes Client Personal Data that is subject to the GDPR, and the transfer to Rockoly is not covered by an adequacy decision or another valid transfer mechanism, the Standard Contractual Clauses are incorporated into this DPA and apply as follows:
- Module Two (controller to processor) applies where Client is a Controller, and Module Three (processor to processor) applies where Client is a Processor;
- Client is the data exporter and Rockoly is the data importer, and each is deemed to have signed the Standard Contractual Clauses, including their Annexes, by entering into the Agreement;
- the optional docking clause in Clause 7 applies;
- in Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 4.3;
- the optional language in Clause 11 does not apply;
- in Clause 13, the competent Supervisory Authority is the one determined in accordance with that Clause;
- in Clauses 17 and 18, the Standard Contractual Clauses are governed by the laws of Ireland, and disputes arising from them are resolved by the courts of Ireland;
- the audits described in Clause 8.9 are carried out in accordance with Section 9 of this DPA, and the certification of deletion described in Clauses 8.5 and 16(d) is provided on Client’s written request; and
- Annexes I, II, and III of the Standard Contractual Clauses are completed with the information in Annexes I, II, and III of this DPA.
5.3 Transfers from the United Kingdom
For Client Personal Data subject to the UK GDPR, the UK Addendum is incorporated into this DPA. Table 1 is completed with the parties’ details in the Agreement and Annex I; Table 2 with the modules and options in Section 5.2; and Table 3 with Annexes I to III. For Table 4, either party may end the UK Addendum as its Section 19 permits.
5.4 Transfers from Switzerland
For Client Personal Data subject to the FADP, the Standard Contractual Clauses apply as set out in Section 5.2, with these changes: references to the GDPR are to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent Supervisory Authority; and the term “Member State” does not prevent Data Subjects in Switzerland from bringing claims in their place of habitual residence.
6. PERSONAL DATA BREACHES
Rockoly will notify Client without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach. The notice will go to Client’s event organizer or another contact Client designates in writing, and will describe, to the extent then known, the nature of the breach; the categories and approximate number of Data Subjects and records concerned; its likely consequences; the measures Rockoly has taken or proposes to take to address it; and a contact for more information. Where Rockoly cannot provide all of that information at once, it will provide it in phases as it becomes available.
Rockoly will promptly take reasonable steps to contain and investigate the breach and to mitigate its effects, and will cooperate with Client so that Client can meet any obligation to notify Supervisory Authorities or Data Subjects. Rockoly will not notify them about a breach of Client Personal Data without Client’s prior written approval, unless the law requires it to.
Notifying Client of a Personal Data Breach is not an acknowledgement of fault or liability. Unsuccessful attempts that do not compromise the security of Client Personal Data — such as failed sign-in attempts or blocked automated traffic — are not Personal Data Breaches.
7. ASSISTANCE TO CLIENT
7.1 Data Subject Requests
If Rockoly receives a request from a Data Subject to exercise their rights over Client Personal Data — for example, to access or delete it — Rockoly will promptly forward it to Client and will not respond to it except as Client instructs or the law requires. Rockoly may, however, act directly on a participant’s own request to correct their delivery details or to stop receiving text messages, as the Agreement describes.
Taking into account the nature of the processing, Rockoly will assist Client by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests, including by correcting or deleting Client Personal Data at Client’s request.
7.2 Impact Assessments and Regulators
Using the information available to it, Rockoly will give Client reasonable assistance with any data protection impact assessment or prior consultation with a Supervisory Authority that Data Protection Laws require of Client in relation to the Services, and will cooperate with Supervisory Authorities as the law requires.
8. RETURN AND DELETION
Rockoly keeps Client Personal Data only for as long as it is needed for the purposes described in Annex I, including answering questions about an Event and keeping accurate records of the Services. Participants’ delivery addresses are deleted automatically from Rockoly’s delivery records thirty (30) days after the Event.
At Client’s written request — at any time after an Event, or when the Agreement ends — Rockoly will, within thirty (30) days, delete the Client Personal Data it holds or, if Client prefers, return it and then delete it, and will confirm the deletion in writing on request.
Rockoly may keep information it must retain by law, such as invoices and tax records, and copies in encrypted backups until those backups are deleted on their normal schedule. Order records that retailers and carriers hold for deliveries under Section 4.4 are kept under their own terms. Anything Rockoly keeps remains protected by this DPA and is used for no other purpose.
9. AUDITS AND INFORMATION
Rockoly will make available to Client the information reasonably necessary to demonstrate its compliance with this DPA, including by responding to Client’s reasonable written security and privacy questionnaires.
If that information is not sufficient to demonstrate compliance, or a Supervisory Authority requires it, Client may audit Rockoly’s compliance with this DPA, itself or through an independent auditor bound by confidentiality, no more than once in any twelve (12) month period unless following a Personal Data Breach. Client will give at least thirty (30) days’ written notice, and audits will take place during business hours, at Client’s expense, without unreasonably disrupting Rockoly’s operations, and without access to other clients’ data.
10. LIABILITY
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent that Data Protection Laws or the Standard Contractual Clauses do not permit it to be limited.
11. TERM
This DPA applies for as long as Rockoly processes Client Personal Data, and survives the end of the Agreement until that data has been deleted or returned under Section 8.
12. GENERAL
12.1 Order of Precedence
If there is a conflict concerning Client Personal Data, the Standard Contractual Clauses (where they apply) prevail over this DPA, and this DPA prevails over the rest of the Agreement.
12.2 Governing Law
Except where the Standard Contractual Clauses provide otherwise, this DPA is governed by the laws of the Commonwealth of Massachusetts, and disputes under it are resolved as the Agreement provides.
12.3 Changes to this DPA
Rockoly may update this DPA from time to time — for example, to reflect changes in Data Protection Laws or in its Subprocessors — by posting the updated version on this page with a new “Last Updated” date. An update will not reduce the overall level of protection this DPA gives to Client Personal Data already provided under a confirmed booking.
12.4 Severability
If any provision of this DPA is found unenforceable, the remaining provisions remain in full force and effect.
12.5 Contact
Questions about this DPA, requests for a countersigned copy, and requests for notice of Subprocessor changes go to:
Schwarz Events, Inc. d/b/a Rockoly · 4 Majestic Way, Salem, MA 01970 · info@rockoly.com
Annex I: Details of Processing
- Parties
-
Data exporter: Client, as identified in the applicable proposal, invoice, or booking confirmation; its contact is the organizer named there. Data importer: Schwarz Events, Inc. d/b/a Rockoly, 4 Majestic Way, Salem, MA 01970, United States (info@rockoly.com), acting as Processor.
- Subject matter
-
The planning and delivery of the virtual, in-person, and in-office events described in the Agreement and the applicable proposal.
- Duration
-
For the term of the Agreement, and afterwards until the Client Personal Data is deleted or returned under Section 8.
- Nature and purpose
-
Collecting, storing, organizing, using, and deleting Client Personal Data, and disclosing it to Subprocessors and delivery partners, in order to: plan, staff, and run the Event; send invitations, event details, and joining links; collect delivery addresses and deliver ingredients, kits, and supplies; send delivery updates by email and, to participants who opt in, by text message; prepare food around dietary requirements and allergies; after the Event, share event photos and ask participants to review it where Client’s organizer permits; and invoice Client.
- Data Subjects
-
- Client’s event organizers and other contacts, such as assistants and billing contacts.
- Participants and guests whom Client invites to an Event, such as its employees, contractors, and customers.
- Personal data
-
- Organizers and contacts: name, business email address, phone number, company, the event details and preferences they give Rockoly (for example, in its event questionnaire), and billing contact details. Card payments are made directly to Rockoly’s payment processor; Rockoly does not receive or store card numbers.
- Participants: name and email address; and, where the Event requires them, delivery address and delivery instructions, phone number, dietary requirements and allergies, event choices (such as a menu or drink option, or a character in a murder mystery game), their preferences about delivery messages, the name, audio, and video they share in a virtual Event, and photographs taken during the Event.
- Sensitive data
-
Dietary requirements and allergies can reveal information about a participant’s health or religious beliefs. Rockoly collects them only to prepare food and kits safely and shares them only with the people preparing that food or kit: chefs receive them as counts, without names, and they are never included in delivery instructions. Rockoly does not ask for any other special category of personal data.
- Frequency
-
Continuous, for each Event booked under the Agreement.
- Retention
-
As set out in Section 8.
- Supervisory Authority
-
Where the Standard Contractual Clauses apply, the one determined under their Clause 13.
Annex II: Security Measures
Rockoly maintains the following technical and organizational measures for Client Personal Data. Rockoly may change them over time, provided the overall level of protection does not decrease.
Encryption
- All connections to Rockoly’s website and systems are encrypted in transit using HTTPS (TLS).
- Participants’ delivery details, event records, questionnaire answers, text-message records, and organizer account details are encrypted by Rockoly with AES-256-GCM before they are stored, using keys held separately from the data.
- Event photos and documents are kept in private storage that its provider encrypts at rest, and database backups are encrypted with a separate key.
Access Control
- Staff, contractors, and organizers sign in to Rockoly’s systems with their own individual accounts. Passwords are stored only as salted scrypt hashes, and sessions use signed, secure cookies.
- Sign-in to Rockoly’s administrative systems requires a one-time code, sent by email or text message, in addition to the password.
- Access is role-based: each staff member can see or change only the sections their role needs, and a change to a person’s access ends their existing sessions.
- Chefs, instructors, Zoom hosts, and event helpers see only the Events they are assigned to, and never participants’ contact details or delivery addresses.
Pages That Collect Personal Data
- The pages where participants and organizers enter their details — the delivery address form and its murder mystery RSVP, the event questionnaire, kick-off booking, and the member area — load no third-party advertising or analytics tags.
- Personal links to those forms, the questionnaire, and kick-off booking carry long random tokens, and those pages tell browsers not to pass their address on to other sites.
Monitoring and Integrity
- Administrative actions are recorded in an audit log.
- Automated alerts notify Rockoly if a delivery address is ever stored without encryption, and of other failures in its data stores.
- Messages from Rockoly’s payment, text-message, and email providers are authenticated before they are accepted, public forms are protected against automated abuse, and responses containing personal data are marked not to be cached.
Payments
- Card payments are made directly to Stripe, a PCI DSS Level 1 certified payment processor. Card numbers never reach Rockoly’s systems.
People and Vendors
- Personnel and contractors receive only the information their work on an Event requires, and are required to keep client and participant details confidential.
- Subprocessors are bound by written data protection terms, as described in Section 4.
Annex III: Subprocessors
Client authorizes Rockoly to engage the following Subprocessors, under Section 4. Rockoly updates this list before a new Subprocessor begins processing Client Personal Data.
| Subprocessor | What it does for Rockoly | Client Personal Data involved | Location |
|---|---|---|---|
| Vercel Inc. | Hosts Rockoly’s website, forms, and server functions. | All Client Personal Data submitted through Rockoly’s website or handled by its systems. | United States |
| Upstash, Inc. | Database for event records, delivery details, and questionnaires. | Event and organizer details, participants’ delivery details, and questionnaire answers, encrypted by Rockoly before storage; names and email addresses in activity logs. | United States |
| GitHub, Inc. | Stores Rockoly’s code and some operational records. | Organizer account records; text-message records; delivery order notes, which can include a participant’s name, phone number, and allergy notes. | United States |
| Cloudflare, Inc. | File storage for event photos, event documents, and backups. | Photographs taken at Events; event documents, such as agreements and menus; encrypted backups of the database. | United States |
| Zoho Corporation | Business email, event and delivery emails (ZeptoMail), internal team messaging (Cliq), and website chat (SalesIQ). | Organizer and participant names and email addresses; the content of event emails and delivery updates; participants’ replies to text messages, passed to the team. | United States |
| Twilio Inc. | Text messages about deliveries. | Mobile numbers of participants who opt in to delivery updates, and the text of those messages. | United States |
| Google LLC | Address checking and autocomplete (Google Maps Platform); documents and forms used by Rockoly’s office. | Delivery addresses, without names or contact details; event details in office documents. | United States |
| Zoom Communications, Inc. | Video meetings for virtual Events and kick-off calls. | Meeting details, such as the company and workshop; the names, audio, and video that people share in a meeting. | United States |
| Stripe, Inc. | Invoices and card payments. | Billing contact name, email address, phone number, and company. Card details are entered directly with Stripe. | United States |
Independent chefs, instructors, Zoom hosts, and event helpers, engaged for individual Events and located in the United States, are also Subprocessors. They receive only the details of the Events they work — such as the organizer’s name, company, headcount, and venue, and participants’ dietary needs as counts without names — and Rockoly will identify the people assigned to Client’s Event on request.
Deliveries of ingredients, kits, and supplies are fulfilled as described in Section 4.4.