Legal

Data Processing Addendum

Effective date: September 23, 2026 · Version 2026-09-23

1. The parties

This addendum is between El Boiler Speakeasy, LLC, a limited liability company organized in Delaware, United States, with its address at 131 Continental Dr, Suite 305, Newark, DE 19713, which provides the service under the Revenight brand and acts as the processor, and the company that holds the Revenight account, which acts as the controller and is called “the Client” here.

The Client’s details are the ones on its account and its venue, as they stand in Revenight on the day it accepts this addendum. Nothing needs filling in: accepting it in the app records who accepted, from which account, from which IP address, when, and which version of this text, and that record is the proof of the contract.

This addendum is part of the Terms of Service. If the terms and this addendum disagree on data protection, this addendum wins.

2. What we process and why

The Client instructs us to process personal data of its own customers (here, “guests”) for the sole purpose of providing the Revenight service.

Categories of data subjects

  • People who join the venue’s Circle through its QR code or link.
  • People who book at the venue, online, by phone or over WhatsApp.
  • People who come in and are checked in at the door.
  • People the Client imports from its own list.

Types of data

  • Identification and contact: name, email, phone and language.
  • Relationship with the venue: bookings, visits, notes written by staff, tags, and day and month of birth if the person gives it.
  • Permissions: whether they agreed to receive email or WhatsApp messages, when, with what wording and from which hashed IP address, and whether they unsubscribed.
  • Messages: the content of the campaigns and automations the Client sends, and whether they were delivered, opened or clicked.
  • WhatsApp conversations: only if the Client turns on the booking assistant.

We do not process special categories of data (health, beliefs, origin, orientation) and the Client undertakes not to enter them, including in free-text notes.

Nature and duration: processing is automated and lasts for the duration of the subscription, plus the return or deletion periods in section 8.

3. Instructions and prohibited uses

We process the data only on the Client’s instructions. Those documented instructions are this addendum, the terms, and whatever the Client does or configures inside the app.

  • We do not use guest data for our own purposes.
  • We do not mix it across venues: each venue sees only its own, and the database enforces that, not just the app.
  • We do not sell it, share it or use it to train artificial intelligence models.
  • If an instruction looks to us like a breach of data protection law, we will say so and may suspend that part of the processing.
  • If a law forces us to process the data differently, we will tell the Client first, unless that same law forbids it.

The Client’s own account data (its name, its email, its billing, how it uses the product) is a separate matter: for that we are the controller, and it is explained in the privacy policy.

4. Security (art. 32)

These are the measures in place today, not a wish list:

  • Venue isolation: every row carries its venue and the database only allows the account holder to read its own, with column-level permissions for the sensitive ones.
  • Access: named accounts, service keys only on the server, and staff access limited to what support requires.
  • Encryption: in transit over TLS and at rest by the database provider.
  • Door: check-in sits behind a PIN, with lockout after repeated failed attempts.
  • Permissions: each consent is stored with its date, wording and source, and every campaign carries one-click unsubscribe.
  • Logs: we keep technical send and error traces so incidents can be investigated.

What we do not have yet, said plainly so nobody assumes it: we are not certified under ISO 27001 or SOC 2, there is no appointed data protection officer, and we do not run annual third-party audits. If any of that changes, it will be said here.

5. Subprocessors

The Client gives general authorization for the providers below. They are the same ones listed in the privacy policy, with their country and role:

  • Supabase (United States, servers in Oregon): database and authentication.
  • Vercel (United States): application hosting and technical logs.
  • Resend (United States): delivery of the Client’s emails to its guests.
  • Anthropic (United States): summaries and insights generated with artificial intelligence.
  • Meta (Ireland and United States): only if the Client turns on the WhatsApp booking assistant.
  • n8n: our automations, on a server we manage ourselves.

If we change a subprocessor or add a new one, we will tell the Client 30 days in advance by email and update this page. If the Client objects on reasonable data protection grounds, it can cancel the service without penalty before the change takes effect.

We have a contract with each subprocessor imposing obligations equivalent to this addendum, and we remain liable to the Client for what they do.

6. Transfers outside the European Economic Area

Our main providers are in the United States, so data leaves the European Economic Area. Those transfers rely on the Standard Contractual Clauses approved by the European Commission and, where the provider is certified, on the EU-US Data Privacy Framework.

The Client and we incorporate by reference the Standard Contractual Clauses, module two (controller to processor), for anything this addendum does not cover. If the Client needs them signed separately, we will provide them: write to hello@revenight.com.

7. Helping the Client

  • Guest rights: if a guest writes to us directly, we will point them to the venue and tell the Client. When the Client asks, we will help it handle access, rectification, erasure, objection, restriction and portability, with the product’s own tools or, where those fall short, by hand.
  • Security breaches: if there is a breach affecting its guests’ data, we will tell the Client without undue delay and within 48 hours at most of becoming aware, with what we know: what happened, how many people are affected, what the consequences are and what we are doing. Notifying the authority and the individuals is the Client’s job, as controller.
  • Impact assessments: we will give the Client the information we hold so it can carry out an impact assessment or a prior consultation, if it needs one.

8. What happens when it ends

When the subscription ends, the Client chooses whether we return the data or delete it. If it says nothing within 30 days, we delete it.

  • It has 30 calendar days from the end of the contract to export its data from the app or ask us for a copy in CSV or JSON.
  • After that, we delete its guests’ data from the live systems.
  • Backups are overwritten on their normal rotation; until then they stay covered by this addendum and are not used for anything.
  • We keep what the law requires us to keep, such as invoices, which are the Client’s data and not its guests’.

At any time, not only at the end, the Client can ask us to delete one specific person’s data. We delete it and confirm what was deleted.

9. Information and audits

We will make available to the Client the information it needs to show we comply with this addendum. It may audit us once a year, with 30 days’ notice, during business hours, without disrupting the service and at its own cost, unless the audit finds a breach on our side. A written questionnaire counts as an audit if the Client accepts it.

10. Confidentiality

Anyone on our side with access to the data is bound by confidentiality, by contract or by law, and that obligation survives the end of the relationship.

11. Governing law

For clients established in the European Economic Area, the United Kingdom or Switzerland, this addendum is governed by Spanish law and the parties submit to the courts of the city of Barcelona. For everyone else, the Terms of Service apply. For personal data of people resident in the European Economic Area, the General Data Protection Regulation applies whatever the law of the contract.

12. How it is accepted and recorded

This addendum is accepted in the app, with a button, no signature and no paper. On acceptance we record the account that accepted, the date and time, the version of this text and the IP address as a hash. That record is given to the Client on request, and it is what evidences the contract to a supervisory authority.

If we change this addendum, we give 30 days’ notice and the Client will be asked to accept again in the app. If it would rather sign a separate copy, we will send the same text as a PDF: write to hello@revenight.com. Current version: 2026-09-23.