LineupBack to Lineup

Organiser data processing terms

Lineup Organiser Data Processing Terms

Version dated 7 September 2026

These reusable terms apply whenever Lineup processes personal data for an Organiser through a Space or agreed import. They also apply where an account holder uses a private workspace for professional or business purposes and is a controller under data-protection law.

Lineup: Carlos Montenegro, sole proprietorship, KVK 96085819, Tuigerstraat 60, 1033 PH Amsterdam, the Netherlands, carlos.montenegrovela@gmail.com, operator of lineupapp.nl.

Organiser: The person or organisation identified in an addendum, order, Space setup or recorded electronic acceptance as responsible for a Space or other controller-managed use.

Space: A distinct organiser-managed area within Lineup for a community, group, project, network or another supported purpose.

Member: A person who is invited, applies, joins or otherwise participates in a Space.

Effective date: The date the Organiser signs an addendum or otherwise accepts these terms.

1. How these terms fit together

These terms form the data processing agreement (the DPA) between Lineup and the Organiser. If documents conflict, this DPA controls general data-protection obligations; an addendum controls Organiser-specific processing instructions and arrangements to the extent it does not reduce protection required by this DPA or law; and the Lineup Terms of Service control everything else. The service limitations and liability provisions in the Terms apply to this DPA to the fullest extent permitted by law.

2. Who controls which data

Space Data. The Organiser is controller for personal data submitted, imported, made available or created for its Space, including membership and access records, information made available by Members, Organiser-provided data, content, communications and activity within that Space. Within the available service settings and agreed scope, the Organiser decides the Space's purposes, who may participate, what information is requested and how it may be used or accessed. Lineup acts as processor for Space Data under this DPA, handles it on the Organiser's documented instructions and does not use it for unrelated independent purposes.

Controller status describes the Organiser's GDPR responsibilities and decision-making for its Space; it does not give the Organiser ownership of a Member's personal data or reduce the Member's legal rights.

Where an Organiser makes a Space discoverable, people using Lineup may find it and choose to join. Browsing shares no personal data with the Organiser and does not make the person a Member. Before joining, Lineup shows what information will be shared. Once the person confirms, that information becomes separate Space Data for that Space; its Organiser is controller and Lineup acts as processor. Nothing is transferred from another Space.

An account holder is also controller where they use a private workspace to keep information about other people for professional or business purposes and data-protection law applies. No Space Organiser receives rights over those private records unless they were separately provided for that Organiser's Space.

In this DPA, Organiser-controlled data means Space Data and any controller-managed private-workspace data within the scope of these terms.

Lineup's limited service-administration responsibility. The Organiser remains controller of Organiser-controlled data and Lineup remains processor for it. Separately, for the limited personal data needed to operate Lineup, Lineup acts as controller only where it independently determines the purposes and essential means. This covers accounts and authentication, account-wide preferences, Member-directed Space discovery and navigation, security and misuse prevention, support, essential service administration and Lineup's own legal obligations. This limited data is Service Administration Data. The role gives Lineup no ownership or control over Organiser-controlled data and no permission to reuse it for an unrelated purpose. Lineup may improve the service using information that has been anonymised or aggregated so that it no longer identifies individuals.

Classification follows who determines the purposes and essential means of each processing activity. The same information may be Service Administration Data for one limited purpose and Space Data for another; storing or handling it in one account, database or technical system does not by itself change that classification. The parties are not joint controllers merely because they use the same service or handle some of the same information for separate purposes. If they begin jointly determining a new purpose and its essential means, they will review and record the arrangement required by law.

3. Instructions and Organiser duties

The Organiser gives instructions through the available Space and data-management settings, an addendum, or other written requests that Lineup accepts within the agreed service scope.

  • The Organiser will have a lawful basis, give people the required privacy information, collect only accurate data needed for its stated purposes, and give Lineup lawful retention instructions.
  • The Organiser will not knowingly provide children's data, special-category data or criminal-offence data unless the parties first agree appropriate safeguards in writing.

4. Lineup's processor commitments

For Organiser-controlled data, Lineup will:

  • process it only on documented instructions. This restriction also applies if Organiser-controlled data would be handled outside the EEA; such handling is permitted only as section 7 allows. If EU or Dutch law requires other processing, Lineup will tell the Organiser before processing unless the law prohibits this;
  • immediately tell the Organiser if an instruction appears to breach applicable data-protection law and may pause it while the parties clarify it;
  • ensure authorised people are bound to confidentiality and use the security measures in Appendix 2;
  • use subprocessors only as section 6 permits and impose equivalent data-protection duties on them;
  • promptly forward a rights request concerning Organiser-controlled data to the Organiser, and respond only on the Organiser's instructions or where law requires;
  • taking account of the processing and insofar as reasonably possible, help the Organiser with all data-subject rights under Chapter III GDPR and with its obligations under Articles 32–36 GDPR;
  • return or delete the data as section 8 provides; and
  • provide the compliance information and audits in section 9.

5. Security and personal-data breaches

Lineup will maintain security measures appropriate under Article 32 GDPR. Appendix 2 describes the measures currently used and may be updated as the service changes, provided the measures remain appropriate.

Lineup will notify the Organiser without undue delay after becoming aware of a personal-data breach affecting Organiser-controlled data. It will provide available information, mitigation steps and reasonable updates as the investigation develops. The Organiser remains responsible for any notification it must make as controller.

6. Subprocessors

The Organiser gives general written authorisation for subprocessors needed to provide the service. Lineup's current direct providers are:

  • Supabase — database and backend infrastructure; the primary project database region is Frankfurt.
  • Netlify, Inc. — application hosting, delivery and operational request logs.
  • Plus Five Five, Inc. (Resend) — delivery of authentication and other service email; a United States provider used under data-processing terms and the safeguards described in section 7.

Lineup will keep an up-to-date register of subprocessors used for Organiser-controlled data, including their identity, function and processing location, and make it available to the Organiser. On reasonable request, Lineup will explain the safeguards used where a provider handles data outside the EEA. Lineup will give reasonable advance written notice before adding or replacing a direct subprocessor, with enough information for the Organiser to object before the change takes effect on reasonable, documented data-protection grounds. Lineup will consider the objection in good faith and may choose a reasonable alternative, allow the Organiser to end the affected service before the change, or proceed where the objection cannot reasonably be resolved and applicable law permits.

Lineup will impose equivalent duties on each subprocessor and remains responsible for its performance.

7. Safeguards for providers outside the EEA

Lineup's primary database is hosted in Frankfurt, Germany. Lineup will not have Organiser-controlled data handled outside the EEA except where a service provider authorised under section 6 needs to do so to provide the service. In that case, Lineup will comply with Chapter V GDPR and use the applicable transfer mechanism, such as an adequacy decision or Standard Contractual Clauses, together with supplementary measures where required after assessing the transfer. Lineup will identify the provider, location and safeguard on reasonable request.

8. Retention, return and deletion

  • During the service, the Organiser may use available standard exports, reasonably request an administrative export of all personal data processed on its behalf for the Space that is reasonably needed to fulfil its controller duties, and give lawful correction, restriction or deletion instructions. The export will be provided in a reasonably usable format and excludes account credentials, security-sensitive information, another Organiser's data and Service Administration Data unrelated to the Space.
  • When processing ends, the Organiser may choose return through such an export followed by deletion of Lineup's copies, or deletion without return. Lineup will delete active copies within 30 days and confirm deletion on request unless law requires retention.
  • Until deletion is complete, the data remains protected under this DPA. Backup copies remain protected, are put beyond normal use following a deletion instruction, and are deleted under documented retention schedules, whether managed by Lineup or its authorised providers. If a backup is restored before deletion, Lineup will reapply the deletion instruction.
  • Leaving or ending membership in one Space does not automatically delete a person's Lineup account, Service Administration Data or data in another Space. Those records follow the Privacy Notice or the instructions of the relevant controller.

9. Compliance information and audits

Lineup will provide information reasonably needed to demonstrate compliance and will allow and contribute to proportionate audits, including inspections, by the Organiser or an independent auditor. Existing documentation and remote evidence will be used first where sufficient.

Reasonable notice, confidentiality and non-disruption requirements apply. Unless required by a regulator, a personal-data breach or documented reasonable grounds to suspect material non-compliance, the Organiser may conduct one audit in any twelve-month period. An independent auditor must be bound to confidentiality and must not be a Lineup competitor. Remote evidence will be used first; an on-site inspection is required only where remote evidence cannot reasonably demonstrate compliance. The Organiser covers reasonable, pre-agreed costs of audits or assistance beyond Lineup's standard service capabilities, unless caused by a material Lineup breach and to the extent charging is legally permitted.

10. Duration and changes

This DPA applies while Lineup processes Organiser-controlled data. No material amendment applies to existing processing until Lineup has directly notified the Organiser and the Organiser has accepted it in writing or electronically. A change required by law may apply after direct notice, but only to the extent necessary. Lineup may update technical or operational security measures without separate acceptance, provided they remain appropriate under section 5, do not materially reduce overall protection and do not change the agreed processing purposes or instructions. Sections 6 and 7 and the material-amendment requirements above continue to apply.

Appendices

The following appendices are part of this DPA. They record the processing and security information required for a controller-processor agreement. The Organiser does not need to complete or sign them separately.

Appendix 1 — What Lineup processes for Organisers

Service and duration: Hosting and operation of organiser-managed Spaces, agreed imports and controller-managed private workspaces for the service term, followed by the deletion period in section 8.

What Lineup may do: Receive or import, validate, store, organise, make available to authorised people, enable participation and communication, analyse or connect information as instructed, export, correct, restrict, return and delete data to provide the Organiser's configured use of the service. This covers current and future functionality only where it supports the Organiser's documented purposes and instructions.

People whose data may be included: Members, prospective Members, invitees, applicants, contributors, survey respondents, Organiser personnel, professional or business contacts, and other adults the Organiser lawfully includes. Children are outside scope unless agreed in writing.

Types of data: Identity, contact and profile information; professional, organisational or participation information; Space membership, roles, access and visibility settings; content, communications, preferences, connections and activity within a Space; Organiser-provided or imported records; private professional or business records; and other data categories expressly agreed in writing and supported by the service. Special-category and criminal-offence data are outside scope unless agreed in writing.

What the Organiser can decide and request: The Organiser may determine its Space purposes and participation rules, give lawful instructions, manage access within its scope, receive all personal data processed for its Space that is reasonably needed for its controller duties, obtain compliance information, object to subprocessors on documented grounds, and require correction, restriction, return or deletion within the agreed scope. These rights do not extend to account credentials, security-sensitive information, unrelated Service Administration Data or another Organiser's Space.

Appendix 2 — How Lineup protects Organiser-controlled data

These are the practical safeguards Lineup currently uses. They may change with the service, but Lineup must keep protection appropriate under section 5.

  • Account access: Authentication and role-based access controls appropriate to the service and the sensitivity of the data.
  • Separation: Space-based controls designed to keep private Space Data separate, plus owner-only controls for controller-managed private workspaces.
  • Secure connections and infrastructure: TLS encryption in transit and managed hosting and database services. Production secrets are not exposed in public client code and access to them is restricted.
  • Limited access: Access is limited to people and providers who need it, with confidentiality duties for authorised people.
  • Availability and recovery: Backup and recovery measures appropriate to the service are operated by Lineup or its authorised providers.
  • Security maintenance and incidents: Lineup maintains dependencies, follows incident-response procedures and reviews security where changes or incidents materially affect the processing.
  • Rights and deletion support: Technical or operational processes support lawful access, correction, export, restriction and deletion instructions.
Lineup
PrivacyTermsProcessing termsContact
Made by Carlos Montenegro