Supplier GDPR
Supplier GDPR Agreement
Ultima actualizare: 19 iunie 2026
Operational agreement covering personal data received by suppliers through EventBroker.ro for quoting, orders, invoicing and complaints.
1. Purpose and GDPR roles
This Supplier GDPR Agreement governs how suppliers use client data received through EventBroker.ro for quoting, orders, invoicing and complaints.
The parties may act as independent controllers or, for specific flows, as controller and processor. The exact role must be confirmed based on the technical and contractual workflow.
2. Permitted use
Suppliers may receive names, email addresses, telephone numbers, event type, date, location, guest count, budget, requested services and operational notes.
Data may be used only for the relevant quote, service delivery, invoicing, operational communication and complaint handling. It may not be sold, reused for unrelated marketing or used to bypass EventBroker.ro.
3. Security and retention
Suppliers must restrict access to people who need it, use reasonably secure systems and delete or anonymise data when it is no longer necessary, subject to legal retention duties.
Any security incident affecting client data received through EventBroker.ro must be reported without undue delay to contact@eventbroker.ro.
4. International transfers and review
Transfers to subcontractors or countries outside the EEA require an appropriate legal mechanism and security safeguards.
The controller/processor role, retention periods, subprocessors, incident deadline and transfer safeguards should be reviewed by legal counsel or a DPO before international launch.