1.Purpose and scope
This Controller Addendum forms part of the collaboration agreement between Happenings Group A/S, CVR 40979956, Aarhus, Denmark ("Happenings") and the association, school, business or other organisation identified in that agreement (the "Organisation"). It governs the parties' processing of personal data relating to users of the Happenings platform (the "Platform").
This addendum records the parties' responsibilities for processing they each determine for their own purposes and for the limited processing they determine jointly. It does not make Happenings a processor for its operation of the Platform. If a separate service is expressly agreed to be performed solely on the Organisation's documented instructions, the parties must identify that service and enter into a data processing agreement under GDPR Article 28 for that processing only.
2.Roles are assessed per processing activity
The terms controller, joint controller and processor have the meanings given in GDPR Articles 4(7), 4(8), 26 and 28. The actual purposes and essential means of each processing activity determine the parties' roles; a contractual label does not override the facts.
As a starting point, Happenings and the Organisation are separate, independent controllers. They are joint controllers only where they jointly determine the purposes and essential means of a specific processing activity. One party acts as processor only where it processes personal data solely on behalf of, and on documented instructions from, the other party.
3.Happenings as independent controller
Happenings is an independent controller for processing carried out for its own Platform purposes, including:
• creating and administering user accounts;
• providing access to events, memberships, communities, local deals and other Platform content;
• ticketing, purchases, payments, invoicing and settlement;
• creating and using identity or eligibility verification records for Platform access, integrity and security;
• operating, securing, maintaining and developing the Platform;
• general service analytics and product improvement;
• advertising, ad delivery and Happenings' own marketing;
• communications from Happenings to users; and
• bookkeeping, tax compliance, fraud prevention and enforcement of Platform rules.
Happenings determines the purposes and essential means of this processing, including relevant data categories, access controls, recipients and retention periods, subject to applicable law.
4.The Organisation as independent controller
The Organisation is an independent controller for its own activities, including:
• creating and managing its events, memberships, offers, pages and content;
• deciding eligibility and access requirements for its own activities;
• administering its own member, participant, customer, student or staff records;
• administering accounts in its own systems, including school or workplace identity systems;
• its communications with members, participants and users;
• the personal data it uploads to or exports from the Platform; and
• its independent use of information made available through the Platform.
The Organisation is responsible for its own legal basis, transparency information, data accuracy, access management and retention. It is not the controller for unrelated activity on a user's Happenings account and has no right to access unrelated user data.
5.Independent accounts and eligibility verification
A user creates a direct account with Happenings. The account exists independently of any Organisation and may give the user access to local deals, other events, memberships, communities and other Platform functions.
Where a user verifies an affiliation, student status, membership or other eligibility, Happenings may attach a verification record to that existing account. Happenings determines the technical verification method and normally retains only the information needed to evidence the result, such as a provider-specific identifier, the relevant Organisation, verification status and timestamps. Happenings does not access an Organisation's directory or receive a bulk export unless this is separately and expressly agreed.
Happenings is the controller for the verification record and its use across the Platform. The Organisation remains controller for its source systems and for its decision that verified eligibility is required for its own content or activities. If the parties jointly determine the purposes and essential means of a particular verification flow, joint controllership is limited to that flow and must be documented accordingly.
6.Disclosures between independent controllers
When either party discloses personal data to the other for the recipient's independently determined purposes, the disclosure is between independent controllers. The disclosing party must have a lawful basis and provide any required information about the disclosure. The recipient must establish its own lawful basis, purpose, retention period and safeguards.
The source or amount of personal data does not by itself determine the parties' roles. If the Organisation instead instructs Happenings to process a defined dataset solely on the Organisation's behalf, that separate activity must be covered by a GDPR Article 28 data processing agreement before processing begins.
7.Joint controllership for Organisation Insights
The parties are joint controllers under GDPR Article 26 only for Organisation-specific statistics and analytics that they jointly determine ("Insights Data"). This may include Platform events such as views, clicks, registrations, participation or purchase signals, relevant page or event identifiers, timestamps and aggregated metrics made available to the Organisation. Special-category data is not intended to form part of Insights Data.
The joint purpose is to measure and understand engagement with the Organisation's activities on the Platform. Happenings' general product analytics, security monitoring and analytics that are not made available for the Organisation's purposes remain Happenings' independent processing.
8.Responsibilities for Insights Data
For Insights Data, Happenings is responsible for establishing a legal basis for its collection and aggregation, the technical collection and aggregation, Platform security, providing the primary privacy information, handling requests received through Happenings and acting as the primary contact point.
The Organisation is responsible for establishing a legal basis for its use of Insights Data, describing that use in its own privacy information where required, protecting any data it exports and forwarding relevant data-subject requests to Happenings without undue delay and no later than seven calendar days after receipt.
The parties will cooperate on data-subject requests, supervisory-authority enquiries, impact assessments and incidents. This allocation does not limit a data subject's right under GDPR Article 26(3) to exercise rights against either joint controller. The essence of this arrangement is made available through this addendum.
9.Transparency and data-subject rights
Each party is responsible for the information obligations and data-subject rights relating to processing under its control. Requests concerning a Happenings account, Platform verification record or Insights Data may be sent to privacy@happenings.dk. Requests concerning the Organisation's own records and independent use of Platform data should be sent to the Organisation using the contact details in its privacy information.
If a party receives a request that primarily concerns the other party's processing, it will forward the request without undue delay. The Organisation is not authorised to respond on behalf of Happenings or to request disclosure of unrelated Happenings user data.
10.Security and personal data breaches
Each party must implement appropriate technical and organisational measures for the processing under its control and comply with its own obligations under GDPR Articles 32–34.
For Insights Data and any other documented joint processing, Happenings monitors the Platform and coordinates the initial technical investigation. If an incident is likely to affect the other party's obligations, the party that becomes aware of it will inform the other without undue delay and share the information reasonably required for assessment and notification. Each party remains responsible for deciding whether it must notify a supervisory authority or affected data subjects.
11.Duration, changes and governing law
This addendum applies while the collaboration agreement is in force and afterwards for as long as either party retains personal data covered by it. Material changes will be communicated in accordance with the collaboration agreement and applicable law. Changes do not alter the parties' factual roles for processing that has already taken place.
This addendum is governed by Danish law. Disputes are subject to the courts of Aarhus, Denmark, unless mandatory law requires otherwise. If a provision is unenforceable, the remaining provisions continue to apply. Mandatory data-protection law and the rights of data subjects always take precedence.
Legal entity
- Legal entity
- Happenings Group A/S
- CVR
- 40979956
- Address
- Klostergade 56B, 8000 Aarhus C
- Office
- Aarhus, Denmark
- Contact
- privacy@happenings.dk
- General
- legal@happenings.dk