Data Security & Privacy Addendum
This addendum forms part of the service agreement between Spacevio (“Provider”) and the subscribing organisation (“Client”).
Index
1. Parties
Spacevio (“Provider”) and the subscribing organisation (“Client”).
2. Data We Collect
The Provider collects and processes only the data necessary to deliver the facility and event management service. This includes:
- Booking data — event name, date, time, room selection, add-on preferences, and any notes submitted through the booking form.
- Contact information — names, email addresses, and phone numbers of guests, event coordinators, staff members, and vendors added to the platform by the Client.
- Payment metadata — transaction amounts, booking references, and payout records. The Provider does not store, process, or have access to credit or debit card numbers at any point. All payment card data is handled exclusively by Stripe, Inc., which is PCI DSS Level 1 certified — the highest level of payment security certification available.
- Communication records — messages exchanged between admins, guests, and vendors through the platform's messaging system.
- Usage data — login timestamps, booking status changes, and admin actions, used for audit trail purposes and platform improvement.
The Provider does not collect or store sensitive personal data including national identification numbers, health information, financial account credentials, or biometric data.
3. How Data Is Stored and Protected
3.1 Encryption in Transit
All traffic to and from Spacevio is encrypted using TLS 1.2/1.3 with modern cipher suites. HTTP connections are automatically redirected to HTTPS, and HSTS is enforced to prevent downgrade attacks.
3.2 Encryption at Rest
Data is encrypted at rest using AES-256, covering the database, file storage, and configuration secrets via disk-level encryption. Database connections are secured with enforced SSL.
3.3 Data Classification and Retention
Data is classified by sensitivity (personal, financial, operational) and defined retention periods are applied accordingly. Data no longer needed is securely deleted, and Client's users may request erasure of their personal data at any time, subject to Section 7 below.
3.4 Access Control
- Role-Based Access Control (RBAC): Spacevio enforces RBAC to ensure users only access data and features permitted by their assigned role.
- Multi-Factor Authentication (MFA): available for all users as an additional layer of security beyond standard username/password authentication.
- SSO/SAML support: planned for a future release, to allow users to authenticate using their existing corporate credentials via SAML 2.0.
3.5 Infrastructure
- Cloud provider: Spacevio is hosted on Amazon Web Services (AWS), leveraging AWS's enterprise-grade physical and network security controls, independently audited under SOC 2, ISO 27001, and other industry certifications.
- Network security: access to infrastructure is restricted through security groups and firewall rules, limiting exposure to only the services required for the application to function.
- Storage encryption: storage volumes and backups are encrypted at rest using AWS-managed encryption (AES-256), consistent with Section 3.2 above.
3.6 Monitoring
System activity, access patterns, and application logs are monitored to help detect unusual or unauthorized behavior, supporting the incident response commitments in Section 5.
3.7 Additional Safeguards
- Access to the production database is restricted to authorised personnel only. No third-party contractor or vendor has unrestricted access to Client data.
- Payment processing is handled entirely by Stripe, Inc. Card details are captured directly by Stripe's secure form elements and transmitted to Stripe's servers. They never pass through the Provider's servers or databases.
- Digital contract signing is handled by DocuSeal, which maintains its own security standards and audit trail for signed documents.
- Email communications are sent via Postmark, which maintains SOC 2 Type II certification.
4. Who Has Access to Client Data
The Provider commits to the following access controls:
- Client data is accessible only to authorised members of the Provider's engineering team on a need-to-know basis for the purpose of maintaining and supporting the platform.
- The Provider will not sell, rent, license, or share Client data with any third party for commercial purposes.
- The Provider will not use Client data for any purpose other than delivering the agreed service.
- Sub-processors — third-party services used to deliver the platform — are limited to Stripe (payments), Postmark (email), and DocuSeal (document signing). Each sub-processor has been evaluated for security and operates under their own data protection commitments.
- The Provider will provide the Client with advance written notice (e.g., via email) at least thirty (30) days prior to the addition or removal of any sub-processor, giving the Client a reasonable opportunity to review and object to such changes.
5. Security Incident Response
In the event of a confirmed or reasonably suspected security incident affecting Client data, the Provider commits to:
- Notifying the Client's designated contact within 72 hours of becoming aware of the incident.
- Providing a written summary of the nature of the incident, the data affected, and the steps taken or planned in response.
- Cooperating with the Client in any reasonable investigation or remediation effort.
- Taking prompt steps to contain, investigate, and remediate the incident.
6. Client Responsibilities
The Client is responsible for:
- Maintaining the security of admin account credentials. The Provider is not liable for unauthorised access resulting from compromised credentials held by the Client.
- Ensuring that any personal data entered into the platform has been collected with appropriate consent from the individuals concerned.
- Notifying the Provider promptly if any admin account credentials are believed to have been compromised.
7. Data Retention and Deletion
The Provider retains Client data for the duration of the active subscription and for a period of 90 days following termination of the service agreement, to allow for data export or dispute resolution.
Upon written request following the termination period, the Provider will permanently delete Client data from all production systems within 30 days.
Backups containing Client data are rotated and permanently deleted within 90 days of the termination date.
8. Scalability and Availability
The Provider commits to maintaining platform availability suitable for the Client's operational needs. Specifically:
- The platform is hosted on cloud infrastructure designed to scale automatically with demand. The Client's performance is not degraded by activity from other clients on the platform.
- The Provider targets a minimum uptime of 99% measured monthly, excluding scheduled maintenance windows communicated in advance.
- Scheduled maintenance will be communicated to the Client's designated contact no less than 24 hours in advance and will be scheduled outside of peak booking hours where possible.
9. Security Certifications
The Provider's sub-processors — Stripe, AWS, Postmark, and DocuSeal — operate under rigorous independent security certifications including PCI DSS Level 1, SOC 2 Type II, and ISO 27001 respectively. The Provider benefits from these certifications by virtue of using these services for all sensitive data handling.
The Provider is committed to pursuing independent SOC 2 Type II certification as the platform scales and client volume warrants the investment. The Provider will communicate progress on this commitment to the Client annually.
10. Governing Law
This addendum is governed by the laws of the State of California. Any dispute, claim, or controversy arising under or relating to this addendum will be resolved exclusively by binding arbitration, rather than in court. The arbitration will be conducted in Sacramento County, California, in accordance with the applicable commercial arbitration rules, and judgment on the arbitration award may be entered in any court having jurisdiction thereof.
11. Amendments
The Provider may update this addendum from time to time to reflect changes in the platform, applicable law, or industry practice. The Client will be notified of material changes no less than 30 days in advance. Continued use of the platform following notification constitutes acceptance of the updated addendum.