Data Processing Agreement
An annex to the Terms of Service under Article 28 GDPR. It covers how we handle the personal data a band puts into Pulse.
1. Who, with whom, and why
This agreement is entered into between:
- the controller – the band (or other ensemble) created in Pulse by one of its users and represented by its admins, and
- the processor – DxO Systems s.r.o., Gallandova 1232/1, 163 00 Prague 6, Czech Republic, company no. 22438505.
It is entered into automatically when a band is created and forms an integral annex to the Terms of Service. It lasts for as long as the band uses Pulse.
It is needed because a band puts personal data about its members and other people into Pulse. The band decides on that; we only process the data on the band’s instructions.
2. What we process and why
| Subject matter | providing the Pulse service to the band |
| Purpose | running a band: events, availability, line-ups, repertoire, logistics, equipment, finances and communication |
| Nature | storing, structuring, displaying, amending, exporting and deleting data to the extent the service allows |
| Duration | for as long as the service is used, and 30 days after the band is deleted |
Categories of data subjects: band members, deps, guests, external crew and contact persons entered into Pulse by the band.
Categories of data: identification and contact details, profile data and photographs, availability and attendance, membership and permissions, financial data (agreed pay, payouts, expenses, bank details for QR payment), message content and uploaded files. Where members fill them in, also special category data – medical notes and allergies.
3. Our obligations
We undertake to:
- process personal data only on the controller’s documented instructions; using the service and choosing its settings counts as such an instruction. If the law required us to process data otherwise, we will say so in advance unless that same law forbids it;
- bind everyone with access to confidentiality, and limit access to those who need it for their work;
- put in place and maintain the technical and organisational measures in clause 4;
- engage no further processor without meeting the conditions in clause 5;
- assist the controller in handling data subject requests and in meeting its obligations under Articles 32 to 36 GDPR, to the extent appropriate to the nature of the processing and the information available to us;
- delete the data when the service ends, as set out in clause 7;
- make available the information needed to demonstrate compliance and allow audits as set out in clause 8.
4. Security
The measures in place include:
- Encryption in transit – all traffic runs over HTTPS.
- No passwords – signing in uses a link, a one-time code or a passkey. Because there are no passwords, none can be guessed or stolen from the database.
- Access control in the database – the permissions a band’s admins set are enforced at database level, not only in the application, so a member of one band cannot reach another band’s data.
- Specially protected data – medical notes, emergency contacts and bank details are visible only to the person concerned and to members with an explicit permission.
- Backups – encrypted and stored in the European Union.
- Records – sign-ins and any staff action in the administration area are written to an append-only audit log.
- Separated environments – production is separate from development and testing, and live data is not used for development.
We may change these measures over time, but never so as to lower the level of security.
5. Sub-processors
The controller gives general authorisation for us to engage sub-processors. As at the effective date these are:
| Who | For what | Where |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | running servers, database and storage | EU data centres |
| Microsoft Ireland Operations Ltd. (Microsoft 365, Exchange Online) | sending e-mail from the service | EU |
| Stripe Payments Europe, Ltd. | payment processing, tax calculation, invoices | EU; transfers to the USA under standard contractual clauses |
We impose on every sub-processor the same obligations we have under this agreement, and we remain liable for their performance as for our own.
We will give notice of any change to this list at least 30 days in advance, by e-mail to the band’s admins or by notice in the app. The controller may object within that period; if it maintains the objection and no agreement is reached, it may delete the band without penalty and the service is settled pro rata.
6. Transfers outside the EU
We process data in the European Union. A transfer to a third country occurs only for payments through Stripe, on the basis of the European Commission’s standard contractual clauses together with supplementary measures. We make no other transfers outside the EU.
7. What happens to the data at the end
After a band is deleted the data is kept for 30 days so the band can be restored, and is then permanently deleted, including copies in backups, within 90 days at the latest (the remaining time is the rotation of encrypted backups). The controller can download an export in the app at any time beforehand.
The exception is data we must keep by law, typically accounting documents. Those are stored separately and only for the period the law requires.
8. Audits
On request we will provide the information needed to demonstrate compliance with this agreement. The controller has the right to an audit, at most once a year, on at least 30 days’ notice, during business hours and in a way that does not disrupt the service or other bands’ privacy. The controller bears the cost of the audit unless it reveals a material breach of this agreement.
9. Personal data breaches
If we become aware of a personal data breach we will notify the controller without undue delay and no later than 48 hours after becoming aware of it. The notice will describe what happened, which data and how many people are affected, the likely consequences, and what we have done or propose to do. Notifying the supervisory authority and the data subjects is the controller’s obligation; we will help with the information needed.
10. Liability
Liability is governed by Article 82 GDPR and by the Terms of Service. The limitations of liability agreed in the Terms do not apply to claims by data subjects or to fines imposed by a supervisory authority.
11. Finally
This agreement is governed by the law of the Czech Republic. If any provision conflicts with the GDPR, the GDPR applies. Where this agreement and the Terms of Service conflict on a question of personal data processing, this agreement prevails.
Contact: support@bandpulse.cloud