Skip to content
Volt
Book Services
Explore more →
Join Volt
Volt Volunteer Volt Eventstaff Volt Career
Volt Partner City Charging About Contact
Market
Language
Market
Language
Explore more →
Volt Volunteer Volt Eventstaff Volt Career
Volt Partner City Charging About Contact

Data Processing Agreement

Standard terms under Article 28(3) of the General Data Protection Regulation. Last updated: 08/10/2026.

Volt supplies lockers, charging and SOUNDBOKS batteries to festivals and permanent installations. Whether Volt is a data controller or a data processor depends on who owns the customer relationship with the guest. This page explains the roles, our standard terms when we act as processor, and the list of sub-processors that applies to all customers. The agreement signed by the parties is always the binding one.

1. Who is the data controller

The party that owns the customer relationship with the guest is the data controller. Both situations can occur at the same festival, and the data is kept separate according to where it comes from.

Situation Data controller Volt's role
Permanent installations where a venue offers lockers to its own guests Venue Processor under this page and the signed agreement
Festival where the guest books and pays directly with Volt (pre-order with Volt or purchase on site) Volt Independent controller. See Volt's Privacy Policy
Festival where the festival or its partners handle pre-orders and send the data to Volt so we can deliver the service The festival Processor for the data received

Volt receives payments in its own name through Stripe and Vipps MobilePay. For payment, transaction and accounting data, Volt is therefore always an independent controller.

2. What we process for the customer

When Volt acts as processor, we process data in order to deliver and operate our solution for the customer:

  • Booking and rental of lockers, charging and SOUNDBOKS batteries
  • Access codes, opening and locking of lockers, including remote unlock
  • Sending booking confirmations, access codes and receipts by email and SMS
  • Customer support to guests on the customer's behalf
  • Operation, troubleshooting and monitoring of hardware and software
  • Reports and statistics for the customer

This typically covers name, email, phone number, booking data, access data and support enquiries. We do not process national ID numbers or special categories of data. The exact scope is set out in Annex A of the individual agreement.

3. Our standard terms as processor

The terms are based on the Danish Data Protection Agency's standard contractual clauses. These are the main points.

Instructions. We process personal data only on the customer's documented instructions. If we believe an instruction infringes data protection law, we say so immediately.

Confidentiality. Only employees who need access for their work and are bound by confidentiality have access to the data.

Security. We implement appropriate technical and organisational measures under Article 32. Data is encrypted in transit and at rest, daily backups are taken with restore testing, and administrative actions are logged.

Sub-processors. The customer gives general authorisation for the sub-processors listed in section 4. Changes are notified in writing at least 14 days in advance so the customer can object. We impose the same obligations on sub-processors and remain fully liable to the customer for them.

Transfers outside the EU. Data is stored in the EU. Where a sub-processor with a US parent company has access, this is based on the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses.

Assistance. We help the customer respond to data subject requests for access, rectification, erasure, restriction, data portability and objection, and with impact assessments and consultation of the Danish Data Protection Agency.

Personal data breaches. We notify the customer without undue delay and no later than 48 hours after becoming aware of a breach, and assist with notification to the Danish Data Protection Agency within 72 hours.

Retention and deletion. Name, email and phone number are deleted 90 days after the end of the booking period. Booking data is then kept in pseudonymised form for 24 months so a purchase can be traced via the purchase ID on the bank statement. On termination of the agreement we return the data and delete it. Data covered by the Danish Bookkeeping Act is kept for five years.

Audit. The customer can obtain the information needed to demonstrate compliance with the terms and can carry out audits and inspections themselves or through an authorised auditor.

4. Sub-processors

The list was reviewed and confirmed on 08/10/2026 and applies to all customers where Volt is a processor.

Sub-processor Processing activity Location and transfer basis
DigitalOcean, LLC, USA Hosting of the platform's servers, database and backups Data centre in Frankfurt. Any support access from the USA covered by DPF or SCC
AC PM, LLC (Postmark), USA Transactional emails: booking confirmations, access codes and receipts Postmark's EU server. Any transfer to the USA covered by DPF or SCC
Twilio Ireland Limited, Ireland SMS with access codes and booking information EU (Ireland). Account and usage data with Twilio Inc. in the USA covered by DPF or SCC
Functional Software, Inc. (Sentry), USA Error and crash logging EU region (Frankfurt). Any residual transfers covered by DPF or SCC
650 Industries, Inc. (Expo), USA Push notifications via Expo's push service and distribution of app updates, including device information and push tokens USA, DPF or SCC
Apple Inc., USA Delivery of push notifications to iOS devices (APNs) via Expo USA, DPF or SCC
Google Cloud EMEA Limited (Google Workspace), Ireland Email and documents in connection with support to the customer's staff. Does not include guest data EU data region. Any transfer covered by DPF or SCC
Planday A/S, Denmark Shift planning and time registration for paid staff working at the customer's event. Does not include guest data EU (Denmark)
Crewstack (HEAP), Denmark Volunteer planning: sign-up, shifts and attendance for volunteers working at the customer's event. Does not include guest data EU

Payments. Stripe and Vipps MobilePay process the payment as independent controllers and are not sub-processors. Volt is the merchant and independent controller for payment and accounting data.

Locks. Remote unlock is controlled by Volt's own backend. The lock supplier only receives the lock's technical ID and open/close commands and receives no personal data.

5. Contact

Questions about data protection go to privacy@getvolt.dk. The customer's own contact person is named in the signed agreement.

Volt ApS · CVR 42439916 · Smallegade 52E, 2000 Frederiksberg · privacy@getvolt.dk

Volt

Festival tech made easy. We power charging, lockers and sound at 80+ festivals across Europe.

Company
  • Become Volt
  • About Volt
  • Contact Us
  • Accessibility
Legal
  • Terms & Conditions
  • Privacy Policy
  • Volunteer Terms
  • Data Processing Agreement
Business
  • Volt for Business
  • Technology
We are social!
  • Facebook
  • Instagram
  • TikTok
  • LinkedIn
© 2026 Volt ApS · CVR DK42439916 Made for Festival

Select your market

Choose a country to explore festivals, events and local pricing.