gigiii

gigiii is a private B2B marketplace. Not a consumer event platform.

Help·Contact·Privacy·Terms·Cookies

Data Processing Agreement

Last updated: August 3, 2026

Introduction

This Data Processing Agreement (DPA) governs the processing of personal data by Moore World Wide Enterprises, LLC (Data Processor) on behalf of gigiii marketplace users (Data Controllers) in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws.

Definitions

Data Controller
The entity (venue operator or entertainer) that determines the purposes and means of processing personal data.

Data Processor
Moore World Wide Enterprises, LLC, which processes personal data on behalf of the Controller.

Data Subject
The identified or identifiable natural person whose personal data is processed.

Personal Data
Any information relating to an identified or identifiable natural person as defined by GDPR Article 4(1).

Scope and Purpose

This DPA applies to the processing of personal data necessary to provide gigiii marketplace services, including:

  • Profile data of entertainers and venue operators
  • Booking and calendar information
  • Contact details and communication records
  • Agreement generation and signature metadata

Processing Instructions

The Processor shall process personal data only on documented instructions from the Controller, including transfers of personal data to third countries or international organizations, unless required by EU or Member State law. The Processor shall immediately inform the Controller if instructions violate GDPR or other data protection provisions.

Security Measures

The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and penetration testing
  • Incident detection and response procedures
  • Staff training on data protection and security

Sub-processors

The Processor engages sub-processors to assist in providing services. The Controller consents to the use of sub-processors listed on our Sub-processors page. The Processor shall notify the Controller of any intended changes concerning addition or replacement of sub-processors at least 30 days in advance.

View the complete list of sub-processors: Sub-processors List

Data Subject Rights

The Processor shall assist the Controller in fulfilling obligations to respond to data subject requests exercising their rights under GDPR, including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

Data Breach Notification

The Processor shall notify the Controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting the Controller's data. The notification shall include available information about the nature of the breach, affected data categories and subjects, likely consequences, and measures taken or proposed.

Data Retention and Deletion

The Processor shall retain personal data only for as long as necessary to provide services or as required by law. Upon termination of services or upon Controller request, the Processor shall delete or return all personal data and delete existing copies unless storage is required by applicable law.

International Data Transfers

Where processing involves transfer of personal data outside the European Economic Area (EEA), the Processor shall ensure such transfers are protected by appropriate safeguards including Standard Contractual Clauses (SCCs), adequacy decisions, or other mechanisms approved under GDPR Chapter V.

Audit Rights

The Controller has the right to audit the Processor's compliance with this DPA and GDPR obligations. The Processor shall make available all information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller upon reasonable notice.

Termination

This DPA remains in effect for as long as the Processor processes personal data on behalf of the Controller. Upon termination, the Processor shall cease all processing, delete or return all personal data, and delete existing copies unless retention is required by law.

Contact Information

For questions about this DPA or data protection matters, contact:

Moore World Wide Enterprises, LLC
2102 Quail Hollow Dr
Bryan, Texas 77802
United States
Email: hello@moorewwe.com

gigiii
Request early access