StudioKontrol — Data Processing Addendum (DPA)

Last updated: August 1, 2026 Effective date: August 1, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between StudioKontrol, LLC ("StudioKontrol," "Processor," "we," or "us") and the customer entity that accepts the Agreement ("Customer," "Controller," or "you"). It governs the processing of Personal Data that Customer uploads to or processes through the StudioKontrol platform (the "Service").

If there is any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that Customer processes through the Service — for example, information about Customer's own clients, artists, or collaborators.
  • "Processing" means any operation performed on Personal Data (collection, storage, use, disclosure, deletion, etc.).
  • "Controller" means the party that determines the purposes and means of Processing (here, the Customer).
  • "Processor" (or "Service Provider" under U.S. state law) means the party that Processes Personal Data on behalf of the Controller (here, StudioKontrol).
  • "Subprocessor" means a third party engaged by StudioKontrol to Process Personal Data.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Applicable Data Protection Laws" means all privacy and data-protection laws applicable to the Processing, including the CCPA/CPRA and other U.S. state privacy laws, and, where applicable, the EU/UK GDPR and Latin American data-protection laws.

2. Roles of the Parties

The parties agree that, with respect to Personal Data that Customer uploads to the Service, Customer is the Controller and StudioKontrol is the Processor / Service Provider. StudioKontrol Processes Personal Data only on behalf of and under the documented instructions of Customer, as set out in this DPA and the Agreement.

For clarity, StudioKontrol does not "sell" or "share" Personal Data (as those terms are defined under the CCPA/CPRA), will not retain, use, or disclose it for any purpose other than performing the Service, and will not combine it with data from other sources except as permitted by law to provide the Service.

3. Scope and Purpose of Processing

  • Subject matter: Provision of the StudioKontrol platform.
  • Duration: For the term of the Agreement, plus any limited retention period described in Section 9.
  • Nature and purpose: Hosting, storing, organizing, transmitting, securing, and otherwise Processing Personal Data as necessary to provide the Service and support to Customer.
  • Types of Personal Data: As determined by Customer — typically names, contact details, project and scheduling information, and files that Customer chooses to store.
  • Categories of Data Subjects: Customer's clients, artists, collaborators, and personnel.

4. Customer's Obligations

Customer represents and warrants that it has a lawful basis and any required consents to collect and Process the Personal Data it uploads, that its instructions comply with Applicable Data Protection Laws, and that it has provided any required notices to its Data Subjects. Customer is responsible for the accuracy and legality of the Personal Data it uploads.

5. StudioKontrol's Obligations

StudioKontrol will:

  • Process Personal Data only on Customer's documented instructions, including as set out in the Agreement, unless required by law (in which case we will notify Customer where legally permitted);
  • Ensure that personnel authorized to Process Personal Data are bound by confidentiality obligations;
  • Implement and maintain appropriate technical and organizational security measures (Section 7);
  • Assist Customer, taking into account the nature of the Processing, in responding to Data Subject requests (Section 6) and in meeting Customer's security, breach-notification, and impact-assessment obligations; and
  • Make available information reasonably necessary to demonstrate compliance with this DPA.

6. Data Subject Requests

If StudioKontrol receives a request from a Data Subject to exercise rights (access, correction, deletion, portability, or objection) relating to Personal Data Processed on Customer's behalf, StudioKontrol will, where legally permitted, direct the Data Subject to Customer and/or promptly notify Customer. StudioKontrol will provide reasonable assistance to enable Customer to respond to such requests, taking into account the nature of the Processing.

7. Security

StudioKontrol maintains technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and accidental loss, destruction, or damage, including: encryption of data in transit; access controls and authentication; use of reputable infrastructure providers; logical separation of Customer data; and regular review of security practices. StudioKontrol may update these measures provided the level of protection is not materially reduced.

8. Subprocessors

Customer authorizes StudioKontrol to engage Subprocessors to Process Personal Data to provide the Service. Current Subprocessors include:

SubprocessorPurposeLocation
Stripe, Inc.Payment processingUnited States
SupabaseDatabase, authentication, and file storage hostingUnited States
ResendTransactional email deliveryUnited States

StudioKontrol will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA and remains responsible for its Subprocessors' performance. We will provide Customer with a means to be notified of new Subprocessors and an opportunity to object on reasonable data-protection grounds. To request the current list or notifications, contact legal [at] studiokontrol [dot] com.

9. Return and Deletion of Data

Upon termination of the Agreement, StudioKontrol will, at Customer's choice and where technically feasible, make Personal Data available for export for a limited period and then delete or de-identify it, except where retention is required by law. Backups are deleted or overwritten in the ordinary course within a limited period.

10. Data Breach Notification

If StudioKontrol becomes aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data Processed on Customer's behalf, StudioKontrol will notify Customer without undue delay after becoming aware, and provide information reasonably available to help Customer meet its own notification obligations.

11. International Transfers

StudioKontrol Processes Personal Data primarily in the United States. Where Personal Data is transferred from a jurisdiction that restricts international transfers (such as the EEA or UK), the parties will cooperate to implement an appropriate transfer mechanism (such as Standard Contractual Clauses) where required by Applicable Data Protection Laws.

12. Audits

Upon reasonable written request, and no more than once per year (unless required by a supervisory authority or following a security incident), StudioKontrol will make available information necessary to demonstrate compliance with this DPA. Any audit will be conducted during business hours, subject to confidentiality, and in a manner that does not disrupt StudioKontrol's operations.

13. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.

14. Term

This DPA takes effect when Customer accepts the Agreement and remains in force for as long as StudioKontrol Processes Personal Data on Customer's behalf.

15. Contact

StudioKontrol, LLC 1500 NW 79th Ave, Doral, FL 33126, USA Email: legal [at] studiokontrol [dot] com