PulseTry it free

Data Processing Agreement

Version 1.0 · Effective from 1 October 2026

An annex to the Terms of Service under Article 28 GDPR. It covers how we handle the personal data a band puts into Pulse.

1. Who, with whom, and why

This agreement is entered into between:

It is entered into automatically when a band is created and forms an integral annex to the Terms of Service. It lasts for as long as the band uses Pulse.

It is needed because a band puts personal data about its members and other people into Pulse. The band decides on that; we only process the data on the band’s instructions.

2. What we process and why

Subject matter providing the Pulse service to the band
Purpose running a band: events, availability, line-ups, repertoire, logistics, equipment, finances and communication
Nature storing, structuring, displaying, amending, exporting and deleting data to the extent the service allows
Duration for as long as the service is used, and 30 days after the band is deleted

Categories of data subjects: band members, deps, guests, external crew and contact persons entered into Pulse by the band.

Categories of data: identification and contact details, profile data and photographs, availability and attendance, membership and permissions, financial data (agreed pay, payouts, expenses, bank details for QR payment), message content and uploaded files. Where members fill them in, also special category data – medical notes and allergies.

3. Our obligations

We undertake to:

4. Security

The measures in place include:

We may change these measures over time, but never so as to lower the level of security.

5. Sub-processors

The controller gives general authorisation for us to engage sub-processors. As at the effective date these are:

Who For what Where
Microsoft Ireland Operations Ltd. (Azure) running servers, database and storage EU data centres
Microsoft Ireland Operations Ltd. (Microsoft 365, Exchange Online) sending e-mail from the service EU
Stripe Payments Europe, Ltd. payment processing, tax calculation, invoices EU; transfers to the USA under standard contractual clauses

We impose on every sub-processor the same obligations we have under this agreement, and we remain liable for their performance as for our own.

We will give notice of any change to this list at least 30 days in advance, by e-mail to the band’s admins or by notice in the app. The controller may object within that period; if it maintains the objection and no agreement is reached, it may delete the band without penalty and the service is settled pro rata.

6. Transfers outside the EU

We process data in the European Union. A transfer to a third country occurs only for payments through Stripe, on the basis of the European Commission’s standard contractual clauses together with supplementary measures. We make no other transfers outside the EU.

7. What happens to the data at the end

After a band is deleted the data is kept for 30 days so the band can be restored, and is then permanently deleted, including copies in backups, within 90 days at the latest (the remaining time is the rotation of encrypted backups). The controller can download an export in the app at any time beforehand.

The exception is data we must keep by law, typically accounting documents. Those are stored separately and only for the period the law requires.

8. Audits

On request we will provide the information needed to demonstrate compliance with this agreement. The controller has the right to an audit, at most once a year, on at least 30 days’ notice, during business hours and in a way that does not disrupt the service or other bands’ privacy. The controller bears the cost of the audit unless it reveals a material breach of this agreement.

9. Personal data breaches

If we become aware of a personal data breach we will notify the controller without undue delay and no later than 48 hours after becoming aware of it. The notice will describe what happened, which data and how many people are affected, the likely consequences, and what we have done or propose to do. Notifying the supervisory authority and the data subjects is the controller’s obligation; we will help with the information needed.

10. Liability

Liability is governed by Article 82 GDPR and by the Terms of Service. The limitations of liability agreed in the Terms do not apply to claims by data subjects or to fines imposed by a supervisory authority.

11. Finally

This agreement is governed by the law of the Czech Republic. If any provision conflicts with the GDPR, the GDPR applies. Where this agreement and the Terms of Service conflict on a question of personal data processing, this agreement prevails.

Contact: support@bandpulse.cloud