For ShowRunner customers
Data Processing Addendum
- Version
- 2.0
- Effective
- August 15, 2026
- Last updated
- July 26, 2026
This Data Processing Addendum (this DPA) is part of the agreement between ShowRunner LLC, a Minnesota limited liability company (ShowRunner), and the business subscribing to the Service (Customer). It is incorporated into the Terms of Service and takes effect the first time Customer uploads or collects personal data through the Service.
It carries the contract terms state comprehensive privacy laws require between a controller and its processor, and the service-provider terms required by the California Consumer Privacy Act and comparable statutes. Defined terms follow the Terms of Service.
1.1. Scope and roles of the parties
This DPA governs ShowRunner's processing of Contact Data — the contact, registrant, Guest, appointment, message, and outcome records Customer uploads to or generates within the Service.
- Customer is the controller of Contact Data and, under the California Consumer Privacy Act, the business. It determines the purposes and means of processing and is responsible for the lawfulness of the data it brings.
- ShowRunner is the processor and, under that Act, the service provider. It processes Contact Data only on Customer's documented instructions and only to provide, secure, support, and maintain the Service.
- Each tenant is separate. ShowRunner does not make one Customer's Contact Data available to another and is not a joint controller.
ShowRunner is a controller in its own right for data that is not Contact Data — account and billing details, authentication records, product telemetry, support correspondence, security logs — as described in the Privacy Policy. Data a Guest submits through a Registration Page is Contact Data of the Customer hosting that seminar; disclosures to Guests are in the Guest Privacy Notice.
2.2. Definitions
- Applicable Privacy Law
- — United States law governing privacy, data protection, or commercial messaging that applies to the processing of Contact Data, including the operative state comprehensive privacy statutes, the Telephone Consumer Protection Act, the CAN-SPAM Act, and consumer health data statutes.
- Contact Data
- — Personal data Customer or its Authorized Users upload to, collect through, or generate within the Service, as described in Annex I. It excludes Customer's own account, billing, and authentication records.
- Authorized User, Guest, Registration Page, Service
- — As defined in the Terms of Service.
- Subprocessor
- — A third party ShowRunner engages to process Contact Data, as listed on the Subprocessor List.
- Security Incident
- — A confirmed breach of ShowRunner's security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Contact Data in its control. Unsuccessful attempts that compromise nothing — scans, blocked logins, rate-limited traffic — are not Security Incidents.
- Consumer Rights Request
- — A data subject's request to exercise a right under Applicable Privacy Law: to know, access, correct, delete, port, opt out of sale, sharing, or targeted advertising, or withdraw consent.
3.3. Processing instructions
ShowRunner processes Contact Data only on Customer's documented instructions, including as to transfers to third parties, unless law requires otherwise. Those instructions consist of, and are limited to:
- The Terms of Service, this DPA, and the policies they incorporate, including the Acceptable Use Policy and Messaging Policy.
- The configuration choices Customer and its Authorized Users make — creating a seminar, publishing a Registration Page, importing a list, scheduling a message, connecting a Google account, enabling an optional feature.
- Any further written instruction an Authorized User gives support, to the extent ShowRunner agrees to act on it and it fits how the Service is designed to work.
The nature and purpose of the processing, the types of personal data, the categories of data subjects, and the duration are in Annex I. ShowRunner will not process Contact Data for any other purpose, nor for its own commercial purposes except as Section 12 permits.
Rights and obligations of the parties. ShowRunner must process only on instruction, secure the data, keep it confidential, engage Subprocessors only under written flow-down terms, assist with rights requests and incidents, evidence its compliance, and delete or return the data. Customer must give lawful instructions, establish a lawful basis, provide notices, obtain consents, keep prohibited data out, secure its credentials, and respond to data subjects as controller.
If ShowRunner reasonably believes an instruction violates Applicable Privacy Law, it will notify Customer promptly and may suspend that instruction without liability until resolved. It has no duty to audit Customer's instructions, and does not.
4.4. Customer obligations as controller
The Service is a set of tools. Whether Customer's use of them is lawful turns on facts only Customer knows: where the list came from and what the person was told and agreed to. Customer therefore represents and agrees:
- Lawful basis. Customer has a lawful basis to collect Contact Data and have ShowRunner process it for the purposes in Annex I, and obtained it lawfully, including where purchased from a list vendor.
- Notices. Customer maintains a privacy notice accurately describing its use of Contact Data, its use of a service provider, and data subject rights, and provides it where law requires.
- Consent for messaging. Customer has obtained and can evidence the consent the Telephone Consumer Protection Act, the CAN-SPAM Act, and state law require before any SMS or email is sent, on the terms of the Messaging Policy, and honors opt-outs received outside the Service.
- Consumer health data. Where a seminar topic, condition tag, or note reveals or infers health status or treatment interest, Customer complies with the Consumer Health Data Privacy Policy, including any separate consent required.
- Prohibited data. Customer does not upload, enter, or cause the Service to collect anything listed in Section 13, and removes it promptly if found.
- Accuracy of instructions. Customer's instructions are complete, accurate, lawful, and will not require either party to violate Applicable Privacy Law. ShowRunner may rely on them without verification, and nothing here shifts a controller obligation to it.
- Authorized Users. Customer provisions and deprovisions Authorized Users promptly, protects credentials, and is responsible for activity under its account.
- Responding to data subjects. Customer receives, evaluates, and answers Consumer Rights Requests within statutory deadlines, with the assistance in Section 8.
- Consent evidence. Customer keeps the consent, opt-out, and suppression records the Service generates for as long as law and prudent defense of a messaging claim require, and will not ask ShowRunner to alter them.
5.5. Confidentiality of personnel
ShowRunner treats Contact Data as Customer's confidential information and applies these controls to the people who can reach it.
- Everyone authorized to process Contact Data is bound by a written confidentiality obligation or equivalent statutory or professional duty.
- Those obligations survive the individual's engagement and this DPA.
- Access is need-to-know — principally support, incident response, and operation of the Service.
- Personnel are instructed on their obligations and the handling rules before access is granted.
- Access is revoked promptly on role change or departure, and elevated access is reviewed periodically.
- Cross-tenant access requires an explicit per-user, per-organization allowlist entry and is written to an append-only operator action log (Annex II).
6.6. Security measures
ShowRunner maintains technical and organizational measures designed to protect Contact Data against a Security Incident, appropriate to the data and the risks of the processing. Those in place as of the effective date are in Annex II. ShowRunner may change them, but not in a way that materially reduces the overall level of protection.
- ShowRunner protects Contact Data in transit and at rest, isolates each tenant, restricts and logs privileged access, and applies change management to the code handling it.
- ShowRunner assists Customer, given the nature of the processing and the information available to it, in meeting Customer's own obligation to maintain reasonable security practices.
- Customer configures the Service for its own risk, enables the account-security features available, limits Authorized User access to those who need it, and keeps out the data listed in Section 13.
7.7. Subprocessors
Customer gives ShowRunner a general authorization to engage Subprocessors. Each one, what it does, the data it receives, and where it processes are published on the Subprocessor List, incorporated here as Annex III. The objection window below is 30 days rather than the 7 common elsewhere, so a privacy reviewer has a working month.
- Written flow-down. Before a Subprocessor receives Contact Data, ShowRunner enters a written contract imposing data-protection obligations no less protective than those in this DPA.
- Responsibility. ShowRunner remains responsible to Customer for each Subprocessor's performance of those obligations to the same extent as if it performed the processing itself, subject to Section 15.
- Notice of change. ShowRunner posts any new or replacement Subprocessor to the Subprocessor List, with an updated effective date, before it processes Contact Data. Subscribers to change notices also receive an email.
- Objection window. Customer may object on reasonable data-protection grounds by written notice to privacy@showrunnercrm.com within 30 days of posting.
- Resolution. On a timely objection ShowRunner will work in good faith to offer a reasonable alternative — a configuration change, a feature exclusion, or a different provider. If it cannot within a reasonable period, Customer may terminate the affected portion of the Service without penalty and receive a pro-rata refund of prepaid Fees for that portion of the term.
- Emergency replacement. If a Subprocessor ceases operating, fails on security, or must be replaced urgently to keep the Service running, ShowRunner may engage a replacement immediately, posting and notifying as soon as practicable, with the objection window running from that notice.
8.8. Assistance with consumer rights requests
Customer, as controller, is responsible for responding to Consumer Rights Requests. ShowRunner assists as follows, given the nature of the processing and the information available to it.
- Self-service tooling. Where the Service provides a feature to locate, export, correct, suppress, or delete a contact record and its messages, consent records, and appointment history, Customer uses it. Self-service is the primary channel.
- Reasonable assistance. Where no self-service feature exists, ShowRunner assists on written request, promptly and in time for Customer to meet its statutory deadline, provided the request identifies the data subject and the right exercised.
- Requests received by ShowRunner. If a Guest or other data subject contacts ShowRunner directly, ShowRunner will not respond substantively on Customer's behalf. It routes the request to the relevant Customer and may confirm to the individual that it has done so, identifying the Customer as responsible for responding.
- Opt-outs. An opt-out received through the Service — an SMS stop keyword, an unsubscribe link, a suppression entry — is applied automatically and recorded on the suppression list. Customer remains responsible for opt-outs received by any other channel.
- Cost. Assistance is free unless requests are repetitive, voluminous, or manifestly unfounded, in which case ShowRunner may charge reasonable costs after notice.
On reasonable written request ShowRunner will also provide information it holds that Customer needs for a data protection assessment required by law.
9.9. Security incidents
ShowRunner will notify Customer of a Security Incident affecting its Contact Data without undue delay and in any event within 72 hours of confirming it, by notice to the administrative contact and, where practicable, in the product.
- The initial notice describes, to the extent known, the nature of the incident, the categories and approximate volume of Contact Data involved, the likely consequences, the measures taken or proposed, and a contact point.
- Because the clock runs from confirmation rather than the end of an investigation, an initial notice may be incomplete. ShowRunner will update it as material facts emerge.
- ShowRunner will take reasonable steps to contain the incident, mitigate its effects, and preserve evidence and logs.
- ShowRunner will cooperate reasonably with Customer's investigation and any regulatory notification Customer must make, providing information Customer needs for it.
- Customer determines whether the incident triggers notification to data subjects, regulators, or attorneys general, and makes it. ShowRunner will not notify them on Customer's behalf unless required by law or separately agreed in writing.
10.10. Deletion and return of Contact Data
At the end of the provision of the Service, ShowRunner deletes or returns Contact Data at Customer's direction, on these terms.
- Export window. For 30 days after termination or expiration, Customer may export its Contact Data through the Service or request a copy in a structured, machine-readable format.
- Deletion. After that window, ShowRunner deletes Contact Data from active production systems on written request. Absent one, deletion follows its ordinary retention schedule.
- Backups. Contact Data in encrypted backups or point-in-time snapshots is deleted as those backups age out on their ordinary cycle rather than on demand, and stays subject to this DPA until deleted.
- Legal hold. ShowRunner may retain Contact Data where required by law or reasonably necessary to preserve evidence for a pending or anticipated claim, investigation, or regulatory inquiry involving either party. Only what the hold requires is kept, and it is deleted when the hold lifts.
- Compliance records. The records described below are retained as evidence of compliance and are not deleted on request.
- Confirmation. Completion of deletion is confirmed in writing on request.
In-term record deletion is subject to the same three exceptions. Suppression is what stops future contact; deleting the record does not erase the proof that the individual once consented or later opted out.
11.11. Demonstrating compliance and assessments
ShowRunner will make available the information it holds that is reasonably necessary to demonstrate compliance, and will allow and cooperate with reasonable assessments by Customer or its designated assessor, on these terms.
- Documentation first. ShowRunner demonstrates compliance documentarily: a completed security questionnaire, a current description of the Annex II measures, the Subprocessor List, and any current third-party report it holds. Where that reasonably addresses the inquiry, ShowRunner has satisfied this section and no on-site or hands-on assessment is required.
- Frequency. Where documentation does not reasonably address the inquiry, Customer may assess no more than once in any 12-month period, except after a Security Incident affecting its Contact Data or where a regulator with jurisdiction demands one.
- Notice and timing. At least 30 days advance written notice to legal@showrunnercrm.com describing scope, with the assessment in normal business hours on an agreed date.
- Scope and conduct. An assessment covers only information and systems relevant to ShowRunner's processing of Customer's Contact Data. It must not disrupt ShowRunner's business or the Service for other tenants, must not reach another Customer's data or systems, and must not include penetration testing, vulnerability scanning, or other active testing of production without ShowRunner's prior written consent.
- Confidentiality. Customer and any assessor must be bound by written confidentiality obligations at least as protective as those in the Terms of Service before receiving information. ShowRunner may withhold anything whose disclosure would breach a third-party duty, waive a privilege, or compromise the Service or another tenant.
- Assessor. Any assessor must be independent, suitably qualified, and not a competitor. ShowRunner may reasonably object, in which case Customer may propose another.
- Expense. Assessments are conducted at Customer's expense, and Customer reimburses ShowRunner's reasonable costs of preparing for and supporting them, including personnel time at then-current rates, estimated before work begins.
- Results. Results are confidential to both parties. Customer will share findings and allow a reasonable opportunity to remediate before escalating to a regulator, unless law requires otherwise.
Where Applicable Privacy Law offers, as an alternative, arranging a qualified independent assessor to evaluate the processor's policies and measures, the parties agree the documentation-first route above is the method they will use. ShowRunner will arrange such an assessor only where law requires it and documentation will not suffice; that assessment will use an accepted control standard, and the report is provided on request, subject to confidentiality.
13.13. Prohibited data
The Service is not built, secured, or certified for the categories below, and the Terms of Service prohibit them. Nothing here authorizes ShowRunner to process them, and no instruction will be read as directing it to.
- Protected health information as defined by the Health Insurance Portability and Accountability Act, and any clinical record, diagnosis, treatment note, or prescription.
- Government identifiers: Social Security, driver licence, passport, and state identification numbers.
- Financial account and payment card numbers, and credentials granting access to a financial account.
- Biometric identifiers, including fingerprints, voiceprints, and facial-geometry templates.
- Personal data of individuals known or reasonably believed to be under 18 years of age.
- Any other category identified as prohibited in the Acceptable Use Policy.
Seminar-topic interest tags are not prohibited. A tag showing that someone registered for a seminar about knee, shoulder, back, or systemic conditions is an interest signal, not a clinical record, and the Service is designed to hold it. Customer should still treat it as sensitive: under several state statutes it may qualify as consumer health data, per the Consumer Health Data Privacy Policy.
If prohibited data reaches the Service, Customer must remove it promptly. ShowRunner may remove or restrict access to prohibited data it identifies, and will notify Customer.
14.14. International transfers
All processing of Contact Data under this DPA takes place in the United States, as does that of every Subprocessor on the Subprocessor List.
ShowRunner does not currently offer the Service for processing personal data subject to the General Data Protection Regulation or the UK GDPR. The European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and the equivalent Swiss mechanism are not incorporated, and no representation of compliance with those laws is made. Customer agrees not to use the Service to process personal data of individuals in the European Economic Area, the United Kingdom, or Switzerland in a way that would subject either party to them.
If that changes, ShowRunner will publish a transfer addendum with the appropriate mechanism and notify Customers first.
15.15. Liability
Each party's liability arising out of or related to this DPA, in contract, tort, or any other theory, is subject to the limitations of liability, exclusions of damages, and liability cap in the Terms of Service. This DPA creates no separate cap, does not raise it, and creates no cumulative basis of recovery for the same loss.
Where one set of facts gives rise to claims under both documents, aggregate recovery is limited to the single cap in the Terms of Service. The indemnities there, including Customer's indemnity for messaging and consent claims, apply here and are not modified.
16.16. Term, changes, and order of precedence
This DPA takes effect on the date shown above, or when Customer first uses the Service if later, and continues while ShowRunner processes Contact Data on Customer's behalf. Section 5, Section 10, Section 12, and Section 15 survive while ShowRunner retains any Contact Data.
ShowRunner may update this DPA to reflect changes in Applicable Privacy Law, the Service, or its Subprocessors. Material changes are announced with the notice period the Terms of Service provides; Subprocessor List changes follow Section 7 instead.
Order of precedence. If this DPA conflicts with the Terms of Service, this DPA prevails on data protection and privacy matters only. On every other matter — fees, term and termination, warranties, disclaimers, indemnities, limitation of liability, governing law, venue, and dispute resolution — the Terms of Service prevail. A negotiated agreement signed by both parties prevails over both. If any provision here is unenforceable, the rest continues and that provision is narrowed as little as needed.
Questions go to privacy@showrunnercrm.com; contract requests to legal@showrunnercrm.com.
17.Annex I — Details of the processing
A. Parties
Controller (business): the Customer identified in the ShowRunner account. Processor (service provider): ShowRunner LLC, a Minnesota limited liability company, at www.showrunnercrm.com. Contact: privacy@showrunnercrm.com.
B. Categories of data subjects
- The Customer's contacts and prospects.
- Seminar registrants and the guests who accompany them.
- The Customer's Authorized Users.
C. Categories of personal data
- Name.
- Postal address and geocoded coordinates derived from it.
- Email address and email-verification status.
- Mobile and alternate phone numbers.
- Age, birth month and year, gender, and income band, where supplied by a list vendor.
- Health-interest indicators: seminar-topic condition tags such as knee, shoulder, back, or systemic.
- Marketing consent status, with the verbatim consent record, timestamp, IP address, and user agent.
- Event registration, seating, attendance, and party size.
- Appointment times, outcomes, and sale amounts.
- Message logs: SMS bodies, email subject lines, and delivery status.
- Free-text notes entered by the Customer.
D. Special or sensitive categories
The Service is not intended for special-category or clinical data, and Section 13 prohibits it. Seminar-topic interest may still constitute consumer health data under certain state laws, addressed in the Consumer Health Data Privacy Policy. No other sensitive category is processed.
E. Nature and purpose of the processing
- Hosting a customer relationship management system of record for contacts, seminars, appointments, and outcomes.
- Hosting public Registration Pages and receiving registrations.
- Delivering SMS and email the Customer initiates, and handling replies, opt-outs, and delivery events.
- Scheduling appointments and reading calendar availability where a calendar is connected.
- Reporting within the Customer's own tenant.
- Support, troubleshooting, and incident response.
F. Duration and frequency
Continuous for the subscription term, plus the export window and retention described in Section 10, plus the ongoing retention of the compliance records identified there.
18.Annex II — Technical and organizational measures
Each measure below is a control that exists as of the effective date. This annex describes controls, not certifications; aspirational measures are omitted, and an absence should be read as an absence.
Encryption
- In transit. Traffic between browsers, mobile clients, the application, and infrastructure providers is protected with TLS.
- At rest. Contact Data in the database and file storage is encrypted using provider-managed encryption.
- Connected-account credentials. Stored Google OAuth refresh tokens are additionally encrypted at the application layer with AES-256-GCM, using a random initialization vector and an authentication tag per encryption operation.
Tenant isolation and access control
- Multi-tenant isolation. Separation between Customers is enforced in the database by PostgreSQL row-level security policies keyed to organization membership on every tenant table, so a query for one organization cannot return another's rows.
- Least privilege. Administrative capability is gated behind platform-administrator roles, and cross-account access requires an explicit allowlist entry for a specific user and organization, not a general override.
- Operator action log. Cross-tenant activity by ShowRunner personnel is written to an append-only log.
- Sensitive-read logging. Human reads of sensitive contact records are logged by record identifier and count only, so access is auditable without copying contact details into a second store.
- Segregated credentials. Production credentials are segregated from development and testing credentials.
Data integrity and evidence
- Append-only consent ledger. Consent events are written to an append-only ledger recording the verbatim consent text, timestamp, IP address, and user agent, so a record cannot be silently edited.
- Suppression records. Opt-out and unsubscribe events are recorded and applied to future sends.
Platform and application controls
- Rate limiting and bot protection. Public forms, including Registration Pages, are protected by rate limiting and bot protection.
- Change management. Changes run through version control; deployment is gated on a required test, lint, type-check, and build pass.
19.Annex III — Approved subprocessors
The subprocessors approved under Section 7 are those published on the Subprocessor List, incorporated by reference. That page states, for each, what it does, the personal data it receives, and its processing location.
It is a live page rather than a copy so one authoritative version exists. Changes follow only Section 7.
Related policies
- Terms of Service
The agreement between ShowRunner LLC and the businesses that subscribe to ShowRunner. Covers accounts and seats, ownership of Customer Data, messaging and consent obligations, the prohibition on protected health information, fees, warranties, liability limits, indemnities, and binding individual arbitration under Minnesota law.
- Privacy Policy
How ShowRunner LLC handles personal information for the businesses that use our CRM, the guests who register for their seminars, and visitors to our website — what we collect, who receives it, how long we keep it, and how to exercise your rights.
- Acceptable Use Policy
What Customers may and may not send, collect, claim and do with ShowRunner: prohibited content, list-sourcing rules, data restrictions, health-claim limits, geofencing limits, and how ShowRunner investigates and enforces.
- Messaging Terms
The consent, record-keeping, opt-out, A2P 10DLC registration, carrier, email and do-not-call obligations that apply to every Customer who sends SMS, MMS or email through ShowRunner.
- Subprocessor List
The third-party providers ShowRunner uses to deliver the Service, what each one does, the personal data each receives, and where each processes it.
- Consumer Health Data Policy
The standalone notice required by Washington's My Health My Data Act: the categories of consumer health data ShowRunner processes, where it comes from, who receives it, and how to exercise your rights to confirm, access, withdraw consent, delete, and appeal.
- Guest Privacy Notice
A plain-language explanation for people who registered for a seminar dinner: what the form asked for, how it is used, how to stop text messages and email, who can see your information, and how to have it deleted.