Legal
Data processing
Who is responsible for what data on Exhibitio, the subprocessors we use, and how to get a signed DPA.
Last updated July 21, 2026
1. Roles
When an organizer sells through Exhibitio, two roles apply. For buyer and applicant data collected for the organizer's event, the organizer is the controller and Exhibitio processes that data on the organizer's behalf: to deliver tickets, record orders, run the door, and show the organizer their revenue. For organizer account data and for running the platform itself, Exhibitio is the controller, as described in our privacy policy.
2. Subprocessors
We use these providers to process data, each under contract:
- Stripe: payment processing, connected accounts, payouts, and refunds.
- Supabase: database hosting, file storage, and authentication.
- Vercel: application hosting.
- SendGrid (Twilio): transactional email such as ticket delivery and receipts.
- Anthropic: AI processing for the optional service agent, when an organizer turns it on.
If we add or replace a subprocessor that touches organizer or buyer personal data, we will update this list.
3. Security and deletion
Data is encrypted in transit and at rest, access is restricted by role, and card details never touch Exhibitio at all: they go directly to Stripe. When a workspace closes, we delete or de-identify its data on the schedule described in the privacy policy, keeping only what financial law requires us to retain.
4. Getting a signed DPA
Organizers who need a signed data processing agreement, for example to satisfy their own GDPR obligations, can request one at hello@exhibitio.co and we will provide our current standard instrument.