← Back to Lovebug's Jump House

Data Processing Addendum

This Data Processing Addendum ("DPA") describes how Lovebug's Jump House (the "Business") handles personal information collected through this website on behalf of, and in the course of serving, its guests. It supplements our Privacy Policy and Terms & Conditions. Where a written agreement between the Business and a corporate customer, partner, or vendor requires a formal data-processing agreement, this DPA sets out the baseline terms.

Roles of the parties

For personal information submitted by guests, the Business acts as the controller (it decides why and how the information is used). The software platform that operates this website, and the service providers listed below, act as processors that handle personal information only on the Business's documented instructions.

Categories of data and data subjects

Purpose and duration of processing

Personal information is processed to register guests; manage passes, memberships, visits, waivers, purchases, and bookings; communicate with guests; operate and secure the website; keep business records; and, where a guest opts in, send marketing. Processing continues for as long as needed to provide these services and to meet legal, accounting, and recordkeeping obligations, after which information is deleted or anonymized.

Sub-processors

The Business engages service providers to help operate the website. Each receives only the information needed to perform its function on the Business's behalf and is bound by confidentiality and data-protection obligations. These operational disclosures do not authorize a provider to use personal information for its own marketing. In particular, mobile phone numbers, text-message opt-ins, and messaging consent data are not shared, sold, rented, or provided to third parties or affiliates for marketing or promotional purposes. Typical sub-processors include:

Security measures

The platform applies reasonable technical and organizational safeguards, including encrypted transport (HTTPS), hashed administrator credentials, role-based staff access, an append-only audit trail of sensitive actions, rate-limited sign-in, CSRF protection on forms, and access controls on uploaded documents. No online system can be guaranteed completely secure.

Data subject requests

Guests may request access to, correction of, or deletion of their personal information, and may withdraw marketing consent at any time. The Business honours verified deletion requests by removing the guest's record and associated visits, waivers, payments, and marketing data, subject to information that must be retained by law. Requests can be made using the contact details below.

International transfers

Where personal information is processed or stored in a country other than the guest's own, the Business and its sub-processors rely on appropriate safeguards permitted by applicable law for any such transfer.

Data breach notification

If the Business becomes aware of a personal-data breach affecting guest information, it will assess the incident without undue delay and notify affected individuals and any competent authority where required by applicable law.

Contact

Questions about this DPA, or requests concerning personal information, can be sent to hello@lovebugsjumphouse.com or mailed to 123 Bounce Blvd.