Data Processing Agreement
Under GDPR art. 28 · version [DATE]
This Agreement governs the processing of personal data that [LEGAL ENTITY] (“Processor”, epk.show) carries out on behalf of the customer (“Controller”) when providing the epk.show service, and forms part of the Terms of service.
1. Subject matter, nature and purpose
The Processor processes personal data only to provide the epk.show service (EPK publishing, tracked sends, contracting intelligence, notifications and billing) following the Controller’s documented instructions.
2. Duration
Processing lasts for the duration of the service relationship, plus the retention and deletion periods set out in this Agreement.
3. Categories of data subjects and data
- Data subjects: send recipients (promoters and professional contacts) and people who submit booking requests.
- Data: contact data (name, organization, email); send-engagement data (event type, timestamp, hashed IP, user agent, approximate country/city, dwell time); booking request content.
- No special categories of data (art. 9 GDPR) are processed.
4. Processor obligations
- Process data only on the Controller’s documented instructions, including as to international transfers, unless legally required otherwise.
- Ensure the confidentiality of persons authorized to process the data.
- Implement the technical and organizational measures of art. 32 (see Annex II).
- Assist the Controller in responding to data subject rights requests.
- Assist the Controller in complying with arts. 32–36 (security, breach notification and impact assessments).
- Notify the Controller without undue delay of any security breach it becomes aware of.
- At the Controller’s choice, delete or return the data at the end of the service, unless legally required to retain it.
- Make available to the Controller the information needed to demonstrate compliance and allow reasonable audits.
5. Sub-processors
The Controller authorizes the sub-processors listed in Annex I. The Processor will give reasonable prior notice of any addition or replacement so the Controller can object on justified grounds. The Processor will impose on sub-processors obligations equivalent to those in this Agreement.
6. International transfers
Personal data at rest is hosted in the European Union. Where a sub-processor processes data outside the EEA, the transfer relies on Standard Contractual Clauses or another adequate GDPR safeguard.
7. Deletion
When the account is deleted, real deletion of the data (files included) is performed after a 30-day grace period. Tracking events are retained according to the configured retention window and deleted automatically on expiry.
Annex I — Sub-processors
| Sub-processor | Function | Location |
|---|---|---|
| Supabase | Database and authentication | European Union |
| Cloudflare | CDN, edge, storage (R2) and cache (KV) | Global (edge) |
| Stripe | Payments and billing | EU / US (adequate safeguards) |
| Resend | Transactional email | US (adequate safeguards) |
| Google (YouTube Data API) | Public metrics | Global |
Annex II — Security measures (art. 32)
- Encryption in transit (HTTPS/TLS) across the platform.
- IP addresses always stored hashed with a salt; never in the clear.
- Role-based access control and per-account isolation at the database level (RLS).
- Signed session cookies; secrets managed outside the codebase.
- Personal data hosted in the European Union; backups managed by the database provider.
- Audit logging of privileged administrative actions.
[Name and signature]
[Date]
[Name and signature]
[Date]