Skip to main content
← REVOLUTION.FANPrivacy Policy →

PENDING ATTORNEY REVIEW · Working draft, formal legal review scheduled prior to first commercial transaction.

Legal

Data Processing Agreement

Version 1.0 · 8 August 2026

Token Events, Inc. (“Company”) · privacy@revolution.fan · enterprise@revolution.fan

1. Parties, scope and incorporation

This Data Processing Agreement (“DPA”) is entered into between Token Events, Inc., a Delaware corporation operating the revolution.fan platform (the “Company”), and the organisation registering for access to the revolution.fan Data Marketplace (the “Buyer”).

The Buyer accepts this DPA at registration. Acceptance is recorded with a timestamp and the originating IP address against the Buyer’s account, and API credentials will not authenticate until it has been accepted. This DPA is incorporated into, and forms part of, the Terms of Service. Where this DPA and the Terms of Service conflict on the handling of personal data, this DPA governs.

2. Roles of the parties

In respect of the personal data of platform users (fans, artists, venue operators), the Company is the controller. Data made available through the Data Marketplace is disclosed by the Company to the Buyer, and the Buyer determines the purposes and means of its own subsequent processing. The parties therefore act as independent controllers in respect of marketplace data, not as controller and processor, and each is responsible for its own compliance.

Where the Company processes personal data on behalf of the Buyer, for example, data the Buyer supplies for audience matching, the Company acts as processor and sections 5 to 10 apply to that processing.

3. Subject matter, duration, nature and purpose

Subject matter: provision of aggregated and anonymised behavioural attributes derived from live-event and platform activity, delivered through the marketplace query API.
Duration: for as long as the Buyer holds an active marketplace account, and thereafter for any retention period required by section 9.
Nature and purpose: audience analysis, market research, campaign planning and measurement.
Categories of data subject: platform users who have expressly opted in to marketplace inclusion.
Types of data: behavioural attributes such as event attendance patterns, genre and venue affinity, and geographic region at a coarse level. Direct identifiers, name, email address, telephone number, payment credentials, precise location, are never made available through the marketplace.

4. Technical controls the Company applies

The following are implemented in the platform today, not aspirations:

k-anonymity at k=5. Query results are suppressed where a cohort contains fewer than five distinct data subjects. This applies to both individual-record and aggregated query paths, and the threshold is enforced in the query engine rather than by policy.

Sensitivity ceiling. Attributes are classified by regulatory sensitivity. The buyer-facing API refuses any request above the pii_medium tier, so the highest-sensitivity classification is unreachable through the marketplace even if an attribute were misclassified.

Opt-in only. A user’s attributes enter the marketplace only where that user has explicitly opted in. Opting out removes them from subsequent queries.

Credential and access controls. API keys are stored only as salted hashes and are shown once at issuance; each key may be restricted to an IP allowlist; and every query is written to an audit log recording the requesting account, the filters used and the row count returned.

5. Buyer obligations

The Buyer shall: (a) process data received only for the purposes in section 3 and in accordance with applicable data protection law; (b) not attempt to re-identify any data subject, and not combine marketplace data with other datasets for the purpose of re-identification; (c) not resell, sublicense or otherwise redistribute marketplace data to third parties without the Company’s prior written consent; (d) apply security measures appropriate to the risk, no less protective than those in section 7; (e) ensure that personnel with access are bound by confidentiality; and (f) delete data received once the purpose for which it was obtained has been fulfilled.

Attempted re-identification is a material breach and grounds for immediate termination of access.

6. Sub-processors

The Company uses the following sub-processors in operating the platform. Each is engaged under terms imposing data protection obligations, and this list reflects the services actually in use:

Stripe (payments and payouts) · Google / Firebase (authentication, file storage) · Cloudflare (live video ingest, delivery, CDN) · SendGrid (transactional email) · Sentry (error monitoring) · Vercel (web hosting) · Railway (application and database infrastructure) · Coinbase Commerce (digital-asset payments) · OpenAI (content moderation and transcription).

The Company will give notice of any intended addition or replacement of a sub-processor, and the Buyer may object on reasonable data protection grounds.

7. Security measures

The Company maintains measures appropriate to the risk, including: encryption of data in transit; credentials stored as hashes rather than plaintext; role-based access control with least privilege; audit logging of administrative and marketplace access; network-level restriction of database access; and separation of production from non-production environments.

The Company does not currently hold a SOC 2 or ISO 27001 certification, and makes no representation that it does.

8. Personal data breach

The Company will notify the Buyer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting data disclosed to the Buyer. Notice will describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed.

Each party will provide the other with reasonable assistance in meeting its own notification obligations to supervisory authorities and data subjects.

9. Data subject rights, retention and deletion

The Company operates an account erasure process that removes or irreversibly anonymises a user’s personal data across platform systems on request, subject to records the Company is required to retain (for example, transaction records retained for tax and accounting purposes, and moderation records retained to substantiate enforcement decisions).

Where a data subject exercises a right of erasure or objection, the Company will cease including that subject’s attributes in future marketplace queries. Because marketplace results are aggregated and k-anonymised, historical result sets already delivered to the Buyer cannot be recalled by the Company; the Buyer will delete or re-derive affected data on notice.

On termination, the Buyer will delete marketplace data in its possession within 30 days, except where retention is required by law.

10. Audit, international transfers, and governing law

The Company will make available information reasonably necessary to demonstrate compliance with this DPA, and will respond to a reasonable audit request no more than once in any twelve-month period, on reasonable notice and subject to confidentiality.

Platform infrastructure is operated in the United States. Where personal data of data subjects in the European Economic Area or the United Kingdom is transferred, the parties will put in place an appropriate transfer mechanism, including the applicable Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference on execution.

This DPA is governed by the laws of the State of Delaware, without prejudice to any mandatory data protection law applicable to a data subject.

11. Contact

Questions about this DPA, requests for a countersigned copy, and requests for the Standard Contractual Clauses should be directed to privacy@revolution.fan.