Legal
Data Processing Agreement
Last updated: 24 June 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between Function Desk (“we”, “us”, the “Processor”) and the customer that agrees to those terms (“you”, the “Customer”, the “Controller”). It applies whenever we process personal data on your behalf as part of providing the Function Desk service. By accepting the Terms of Service, you agree to this DPA. No separate signature is required, though we will sign a copy on request.
1. Roles and definitions
You are the controller of the personal data you put into the service (your enquiries, contacts, proposals, event details and connected-inbox email). You decide why and how it is processed. We are the processor: we handle that data on your behalf, on your instructions, to provide the service.
“Personal data”, “data subject”, “processing” and “controller / processor” have the meanings given under applicable data protection law. Australia’s Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) do not use the controller / processor labels, but the concepts apply: you are the APP entity accountable for the information, and we handle it for you under this DPA. Where you have data subjects in the UK or EU, the UK GDPR / EU GDPR also apply and this DPA is intended to satisfy Article 28.
2. Scope of processing
The details required by Article 28(3) and APP 8 are set out in Annex A (subject matter, duration, nature and purpose, types of personal data, and categories of data subjects).
3. Our obligations as processor
We commit to the following for as long as we process your personal data:
- Documented instructions only. We process your personal data only to provide the service and on your documented instructions (which include your use of the product’s features and settings), unless we are required to do otherwise by law, in which case we will tell you first where permitted. We do not use your data for our own purposes, and we do not use it to train AI models (see section 7).
- Confidentiality. Everyone we authorise to access your personal data is bound by a duty of confidentiality, and we limit access to those who need it to operate the service.
- Security. We implement and maintain appropriate technical and organisational measures to protect your data, described in Annex C.
- Sub-processors. You give general authorisation for us to engage the sub-processors listed in Annex B to help deliver the service. We impose data protection obligations on each sub-processor that are no less protective than this DPA, and we remain responsible for their performance. We will give you at least 30 days’ notice (by email or an in-product or website update) before adding or replacing a sub-processor, during which you may object on reasonable data protection grounds; if we cannot resolve the objection, you may terminate the affected part of the service.
- Assistance with data subject rights. Taking into account the nature of the processing, we assist you with responding to requests from data subjects to access, correct, delete, or export their data, including through the export and deletion tools in the app.
- Breach notification. We notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations (including, in Australia, the Notifiable Data Breaches scheme). We also assist you with security, breach notification, and data protection impact assessments where required.
- Return or deletion. You can export your data as CSV at any time while your account is active. On termination, at your choice we will return or delete your personal data, and delete existing copies within 90 days, unless we are required by law to retain it.
- Audit and information. We make available the information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits, including by providing documentation of our security measures and (where available) third-party reports. On-site audits may be subject to reasonable scope, notice, and confidentiality terms.
4. Your obligations as controller
You are responsible for ensuring you have a lawful basis to collect and provide the personal data you put into the service, that your instructions to us are lawful, and that you have given any notices and obtained any consents required from your own clients and contacts. You must not put special-category or unusually sensitive data into the service beyond what the service is designed to handle.
5. International transfers
Some of our sub-processors operate outside Australia (see Annex B). Where we or a sub-processor handle your data overseas, we take reasonable steps to ensure it is protected to a standard consistent with the APPs, as required by APP 8. Where the UK or EU GDPR applies to a transfer, the relevant Standard Contractual Clauses (and the UK International Data Transfer Addendum, if applicable) are incorporated into this DPA by reference, with the parties and details taken from this DPA and its Annexes.
6. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
7. AI processing
The service uses AI to read and classify inbound email, score engagement, and draft and send replies on your behalf. This processing happens only to deliver the service to you. We do not use your data, or your clients’ data, to train, fine-tune, or improve AI models for ourselves or for other customers. Our AI sub-processor processes inputs to return a result and does not train its models on that content.
8. Changes and contact
We may update this DPA as the product and our sub-processors evolve, and will notify active subscribers of material changes. Questions, or to request a signed copy, email support@fillyourvenue.com.
Annex A - Details of processing
- Subject matter: provision of the Function Desk CRM and workflow service for private event venues.
- Duration: for the term of your subscription, plus the retention period in section 3 (Return or deletion).
- Nature and purpose: storing and organising enquiries and deals; sending and receiving email through your connected mailbox; AI classification, scoring, drafting and sending of replies; generating proposals, contracts and invoices; collecting deposit payments via Stripe; and reporting.
- Types of personal data: names, email addresses, phone numbers, event details (date, type, guest count), email and message content, proposal and payment records (card details are handled by Stripe, not stored by us), and any custom fields you add.
- Categories of data subjects: your enquirers and clients (for example couples and corporate bookers), and your own staff and team members who use the service.
Annex B - Sub-processors
We use the following sub-processors to deliver the service. We keep this list current and notify customers of changes as described in section 3.
- Supabase - database, authentication, file storage and edge functions (USA, AWS us-west-2)
- Stripe - deposit and payment processing (USA / Ireland)
- Resend - transactional and notification email delivery (USA)
- Anthropic - AI processing for email classification, scoring and drafting (USA; does not train on your content)
- Vercel - application hosting (USA)
- Cloudflare - content delivery and edge networking (global)
- Sentry - error monitoring and performance diagnostics (EU / Germany)
- PostHog - product analytics and usage telemetry, including identifying logged-in users (USA)
Your connected Gmail or Outlook account is operated by Google or Microsoft under your own agreement with them and is not our sub-processor; we access it on your instruction to send and read email for your deals.
Annex C - Security measures
- Encryption of personal data in transit (TLS) and at rest
- Per-tenant data isolation enforced by database row-level security, so each venue can only access its own data
- Role-based access controls and least-privilege access for our personnel
- Secure secret and credential storage; secrets are never exposed to the browser
- Error monitoring, logging, and alerting on application and security events
- Managed, regularly backed-up infrastructure provided by reputable cloud providers
- Regular dependency and security updates