Data Processing Addendum
Last updated: 2 September 2026
Contact: hello@hallway.events
This Data Processing Addendum ("DPA") supplements our Terms of Service and describes the commitments Hallway makes when it processes, on an event organiser's behalf, personal data about the people that organiser coordinates through the Service - their speakers and form respondents ("participant data"). Hallway is a product of Venn Labs LLC, a Missouri, USA limited liability company ("Hallway", "we", "us", or "our").
These are commitments we choose to make to every organiser, framed to be jurisdiction-neutral. They are substantive protections rather than an acceptance of any single country's regulatory regime; where your local data protection law gives you stronger rights, those rights apply. Where this DPA and the Terms of Service conflict on the processing of participant data, this DPA prevails.
Definitions
- "Controller" - the party that determines the purposes and means of processing personal data.
- "Processor" - the party that processes personal data on behalf of the controller.
- "Participant data" - personal data an organiser enters, imports, or collects about their speakers and form respondents through the Service.
- "Data protection laws" - all data protection and privacy laws that apply, including US state privacy laws (such as CCPA/CPRA and comparable state laws) and any other applicable international data protection laws.
- "Security incident" - a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, participant data.
- "Sub-processor" - a third party we engage to process participant data on the organiser's behalf.
Relationship of the parties
For participant data, the organiser is the controller and decides the purposes and means of the processing and the basis for it. Hallway is the processor, acting on the organiser's behalf and on its instructions.
Hallway is responsible in its own right only for its own surfaces - user accounts and authentication, the cookieless analytics beacon, operational and security logs, and the public directory of event listings. Those are described in our Privacy Policy and fall outside this DPA.
Processing on the organiser's instructions
We process participant data only to:
- provide the Service as described in the Terms of Service;
- follow the organiser's documented instructions, given through the Service's features and this DPA; and
- comply with applicable law - and if the law requires us to process the data otherwise, we will tell the organiser first unless the law forbids it.
We will tell the organiser if we believe an instruction breaks data protection laws. Processing continues for as long as the organiser uses the Service and for up to 30 days after termination, as needed to complete deletion and meet legal obligations.
Confidentiality
We ensure that personnel authorised to process participant data are bound by an appropriate duty of confidentiality and access it only as needed to operate and support the Service.
Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS) and encrypted backups;
- passwords and other secrets stored only as salted hashes, never in readable form;
- role-based access controls limiting who can see participant data, with sensitive fields masked in the interface until a permitted user reveals them;
- signed, HTTP-only session cookies for authentication;
- rate limiting and abuse detection; and
- error monitoring and security-incident response procedures.
No system is perfectly secure, but we work to protect this data and to respond promptly to incidents. A fuller plain-language description of our security posture is on our Security page.
Sub-processors
The organiser authorises us to engage the sub-processors below to process participant data on the organiser's behalf. We impose data protection obligations on each sub-processor no less protective than those in this DPA. This list covers only the sub-processors that touch participant data.
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Application hosting and database | United States (us-west2 region) |
| Cloudflare (R2) | Object storage for images and encrypted backups | United States |
| Resend | Transactional email delivery | United States |
| Anthropic | Detecting personal data in CFP submissions, called directly (not through any router), so it can be masked for blind review - only when the organiser has switched this on in their CFP settings (off by default) | United States |
| Sentry | Error monitoring and diagnostics | United States |
| Arcjet | Rate limiting and abuse protection | United States |
Sentry and Arcjet - how participant data can reach them. Sentry receives diagnostic data about uncaught errors. Before an error report leaves our systems we scrub it: request bodies, cookies, query strings, and non-operational headers are removed, and IP addresses and email addresses are stripped from the user context, so submitted field values are not transmitted. A report can still incidentally include participant data that appears in a request path. Arcjet receives the IP address and request metadata of people interacting with the Service, including form respondents when they submit their answers, so it can detect and block abuse. Both are configured to process only what their function needs, and neither is used to enrich, profile, or market to participants.
Special category data. Some form answers an organiser collects - in particular dietary requirements and accessibility needs - can constitute special category or health data. We recognise this: such fields default to the private visibility tier (never public), are masked in the interface until a permitted user reveals them, and are deleted on the same schedule as all other participant data.
Enrichment of public content happens outside this addendum. Hallway also sends the public content of conference and CFP web pages to language model providers (via OpenRouter) to structure the public directory. That processing concerns published event-listing content, not participant data, so it falls outside this DPA. The full roster of enrichment providers - including several providers based in China, scoped to public content only - is described in our Privacy Policy; none of those providers is a sub-processor of participant data and none appears in the table above.
CFP PII masking - provider changes are notice-worthy. The CFP PII-masking path is the one place organiser-adjacent personal data is deliberately sent to a language model, it runs only for events whose organiser has enabled it (off by default), and it uses Anthropic directly. Any change to the provider used for CFP PII masking will always receive the standard 30-day sub-processor change notice described below. Changing the model version within the same provider does not require notice, because the provider - and therefore where the data is processed and under whose terms - is unchanged. Specific model versions are operational detail and are not named on these legal pages.
We will give the organiser at least 30 days advance notice, by email or through the Service, before adding or replacing a sub-processor, including a change to the CFP PII-masking provider. The organiser has 14 days from that notice to object on reasonable data-protection grounds. If the organiser objects, we will work with them in good faith to find an alternative - for example a configuration change, or keeping the affected feature on the previous arrangement where feasible - before any other remedy applies. If an objection cannot be resolved, the organiser may stop using the affected feature or terminate as set out in the Terms.
Assisting the organiser
Taking account of the nature of the processing, we assist the organiser with requests from individuals to exercise their rights (access, correction, erasure, portability, restriction, and objection), and with the organiser's own security and incident-handling responsibilities, using the tools built into the Service and reasonable support on request. If we receive such a request directly, we will notify the organiser promptly and will not respond to it without the organiser's instructions unless legally required to.
Security incidents
If we become aware of a security incident affecting an organiser's participant data, we will notify the affected organiser without undue delay, and in any event within 72 hours of becoming aware of it - matching the deadline the organiser may itself face as controller. Our notice will describe, so far as we know it:
- the nature of the incident, including where possible the categories and approximate number of individuals and records affected;
- the likely consequences of the incident; and
- the measures taken or proposed in response, including measures to mitigate its adverse effects,
and we will provide further information as it becomes available.
International transfers
Hallway is operated from the United States, and our production environment runs in Railway's us-west2 region. Participant data may be transferred to and processed in the United States and other countries where our sub-processors operate. By using the Service and agreeing to this DPA, the organiser acknowledges and consents to those transfers, and remains responsible as controller for ensuring an appropriate basis for any transfer from another country; we will provide reasonable assistance and information to support it.
For organisers subject to European Union data protection law, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two, controller-to-processor) are incorporated into this DPA by reference and apply automatically to transfers of participant data out of the EEA, with the organiser as data exporter and Venn Labs LLC as data importer. For the purposes of the SCCs: the annex describing the transfer is constituted by this DPA's descriptions of the parties, the participant data categories, and the sub-processor list above; the competent supervisory authority is that of the organiser's establishment; and the governing law and forum for the SCCs are those of an EU member state permitted by Clause 17/18 (Ireland, unless the parties agree otherwise in writing). Where this DPA and the SCCs conflict, the SCCs prevail for the transfers they govern.
For organisers subject to United Kingdom data protection law, the UK International Data Transfer Addendum (IDTA) to the SCCs, as issued by the UK Information Commissioner, is likewise incorporated by reference and applies automatically to transfers of participant data out of the UK, on the same basis.
A countersigned standalone copy of either instrument is available on written request for organisers whose procurement processes require one - but no request is needed for the protections to apply.
Audit
On reasonable written request, and no more than once in any 12-month period unless a regulator or a suspected breach requires otherwise, we will make available the information reasonably necessary to demonstrate our compliance with this DPA. Any audit must be on at least 30 days written notice, during normal business hours, and must not unreasonably disrupt our operations; the organiser bears its costs except where the audit reveals material non-compliance by us.
Return and deletion
On termination of the organiser's use of the Service, or on the organiser's written request, we delete the participant data we hold as processor for that organiser within 30 days - except where we are required by law to retain it or where it sits in routine backups, which expire on their normal 30-day cycle.
On request, we will provide an export of the organiser's event data in a machine-readable format at any time during the organiser's use of the Service, not only before deletion, and written confirmation once deletion is complete. A self-serve export from the organiser dashboard is a planned feature.
We do not sell participant data and do not use it to train, fine-tune, or otherwise modify any AI model.
Changes
We may update this DPA from time to time. When we make a material change - in particular one that reduces our commitments to organisers - we will give organisers at least 30 days advance notice, by email or through the Service, before the change takes effect. For other changes we will update the "Last updated" date above and, where appropriate, notify organisers through the Service. Continuing to use Hallway as an organiser after a change takes effect means you accept the revised DPA.
Contact
Questions about this DPA, or a request to exercise any right under it, can be sent to hello@hallway.events.