At AddEvent, we’re committed to the
security and privacy of your data.
Our Trust Center connects you to our privacy, security and compliance programs, so you have all of the information you need to manage your data.
Meet global standards for
privacy and security
AddEvent adheres to GDPR, CCPA and other privacy and security regulations. We also have policies and controls for you to manage security threats, keep your data safe and help you meet your compliance obligations.
Compliance certifications and attestations
SOC 2
(Type II)
Trust Services Principles
GDPR
Compliant
CCPA
Compliant
Accessibility Conformance Report
WAI WCAG 2.2 A/AA. VPAT® 2.5Rev INT
(the international VPAT edition covering WCAG, U.S. Section 508, and the European EN 301 549 standard)
FAQ
Trust & Compliance FAQ
SOC 2 is an independent audit framework developed by the AICPA that evaluates how an organization protects customer data, based on the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
SOC 2 Type II (Type 2) is an audit report that assesses both the design of controls and how effectively those controls operated over a defined review period (not just at a point in time).
Yes. We maintain a SOC 2 Type II report that covers key controls related to security and data protection.
Note: Note: If your email program doesn’t open automatically, please copy the text below and email it to security@addevent.com.
We undergo SOC 2 Type II audits on a recurring basis and refresh our report annually. The most current report is available upon request.
Our SOC 2 scope covers the systems and services used to deliver our core product(s). If you need confirmation that a specific product, deployment option, or environment is in scope, contact us and we’ll clarify.
Customer data is hosted on Amazon Web Services (AWS) in the EU (Ireland) region.
We follow a data-minimization approach and retain customer data only as needed to provide the service, meet contractual requirements, and comply with legal obligations. Retention periods can vary by product configuration and customer requirements.
We use encryption in transit (e.g., TLS) and encryption at rest (e.g., industry-standard encryption) along with access controls, monitoring, and secure key management practices.
Yes. We offer a DPA for customers who require it, covering our role as a processor/service provider and
outlining data protection obligations and subprocessors.
Go to Data Processing Agreement (DPA)
We support GDPR requirements through privacy-by-design practices, security controls, appropriate contractual terms, and documented processes to protect personal data and respect data subject rights.
Where international transfers are required, we use recognized transfer mechanisms (such as Standard Contractual Clauses) and apply appropriate safeguards (including technical and organizational measures) to protect personal data.
No. We do not sign a HIPAA Business Associate Agreement (BAA) because our service is not intended to process, store, or transmit sensitive patient data (PHI).
We maintain a formal security program with documented policies and procedures that are reviewed and updated regularly. Our governance includes risk management, access management, incident response, and ongoing security monitoring.
We assess vendors and subprocessors based on risk and maintain oversight through due diligence, contractual
controls, and periodic reviews.
List of sub-data processors.
We maintain an incident response process to detect, respond to, and remediate security incidents. Where required, we notify affected customers and regulators in accordance with contractual and legal obligations.
For any security or compliance questions, please contact us at security@addevent.com. We’re happy to help with security reviews, questionnaires, audit documentation (e.g., SOC 2 reports under NDA if applicable), and coordination on customer due diligence requests.
AddEvent’s calendar experiences have been evaluated against WCAG 2.2 Level AA within the scope documented in our Accessibility Conformance Report. This includes the applicable calendar pages, embeddable calendars, and event-list experiences identified in the report.
AddEvent event and calendar pages can include RSVP functionality. Applicable RSVP experiences have been evaluated for accessibility within the product scope and testing conditions documented in our Accessibility Conformance Report.
Yes. AddEvent offers embeddable calendars, individual event pages, and event lists. The surrounding website, implementation, configuration, and customer-created event content must also be accessible for the complete experience to conform.
Yes. Organizations can use AddEvent to publish public meetings, school events, academic deadlines, community programs, training sessions, and other important dates through hosted pages or embedded calendar experiences.