legal · dpa · art. 28 gdpr
Data processing agreement
last updated · 2026-09-23
This Data Processing Agreement ("DPA") applies between the Customer as controller and Till Antonio Mahler, trading as Digital Music Services, Am Berlin Museum 12, 10969 Berlin, Germany, as processor ("we"), for all personal data we process on the Customer's behalf when providing eventflow. It forms part of the contract under our terms of service and is accepted by the Customer when concluding that contract or using the Service. Terms defined in the GDPR have the same meaning here.
1 · subject matter and duration
The subject matter is the provision of the eventflow Service as described in the terms. This DPA applies for the term of the contract and afterwards until we have returned or deleted the Customer's personal data under section 10.
2 · nature, purpose, data and data subjects
We process personal data only to provide, secure and support the Service for the Customer. The nature and purpose of the processing, the categories of personal data and the categories of data subjects are set out in Annex 1.
3 · instructions
We process personal data only on documented instructions from the Customer. The contract, this DPA and the Customer's use and configuration of the Service are the Customer's complete instructions at the time of conclusion. Further instructions must be given in text form. We inform the Customer without delay if we consider that an instruction infringes data protection law, and may suspend it until it is confirmed or changed. If Union or German law requires us to process data otherwise, we inform the Customer before processing, unless the law prohibits this.
The Customer instructs us to turn the Customer's own corrections to invoice checks into short guidance for future invoice checks. This guidance is stored in the Customer's workspace, used only for that workspace, visible to its members and deleted with the workspace. We do not use it for other customers. Messages a Customer's users send to our support chat are processed by us as controller, as described in our privacy policy; they are answered first by an AI model from Anthropic, which acts as our processor for that processing, and guidance learned from them is visible only to us.
4 · confidentiality
We ensure that every person authorised to process the personal data is bound to confidentiality or is under an appropriate statutory obligation of confidentiality.
5 · security of processing
We implement the technical and organisational measures in Annex 2 to ensure a level of security appropriate to the risk (Art. 32 GDPR). We may adapt them to technical progress, provided the level of protection is not reduced.
6 · sub-processors
The Customer gives general authorisation for the sub-processors listed in Annex 3, which is also published on the sub-processor page. We inform the Customer by email at least 30 days before adding or replacing a sub-processor. The Customer may object in text form within that period on reasonable data protection grounds. If we cannot resolve the objection, the Customer may terminate the affected part of the contract with effect before the change, and we refund fees paid in advance for the period after termination.
We impose on each sub-processor, by contract, data protection obligations that are materially the same as in this DPA. The contract is concluded directly with the sub-processor or, where Annex 3 names an intermediary, through that intermediary. We remain responsible to the Customer for the performance of our sub-processors' obligations (Art. 28(4) GDPR).
7 · transfers outside the eu
We transfer personal data to a country outside the EU or the EEA only where the requirements of Chapter V GDPR are met, in particular on the basis of an adequacy decision such as the EU-U.S. Data Privacy Framework or the EU Standard Contractual Clauses. Annex 3 states the safeguard for each sub-processor.
8 · assistance
Taking into account the nature of the processing, we assist the Customer with appropriate measures in responding to requests from data subjects (Chapter III GDPR). Most data can be viewed, corrected and deleted by the Customer directly in the Service. If a data subject contacts us directly about Customer Data, we forward the request to the Customer without delay and do not answer it ourselves unless instructed. We also assist the Customer, with the information available to us, in meeting its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation.
9 · personal data breaches
We notify the Customer of a personal data breach affecting Customer Data without undue delay and at the latest within 48 hours of becoming aware of it. The notification describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information we do not yet have follows as soon as it is available. We take the measures necessary to secure the data and limit possible adverse consequences.
10 · deletion and return
On request made before the end of the contract or within 30 days after it, we provide the Customer with an export of the Customer's personal data in a common, machine-readable format. 30 days after the end of the contract we delete the personal data from our active systems, unless Union or German law requires us to retain it. Backup copies are overwritten or expire in their regular backup cycle and are used only to restore the Service. On request we confirm the deletion in text form.
11 · information and audits
We make available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR, in the first place by written answers and documentation, including the data protection and security documentation of our sub-processors. Where this is not sufficient, we allow audits, including inspections, by the Customer or an auditor it mandates who is bound to confidentiality and is not a competitor of ours. Audits must be announced at least 30 days in advance, take place during business hours without disrupting operations, and, unless there is a concrete reason, not more than once a year. The Customer bears its own costs of an audit.
12 · responsibilities of the customer
The Customer is responsible for the lawfulness of the processing, in particular for having a legal basis for the personal data it enters or collects through the Service, and for informing data subjects. The Customer does not enter special categories of personal data (Art. 9 GDPR) unless this is necessary and lawful. The Customer informs us without delay if it finds errors or irregularities in the processing.
13 · liability
Liability towards data subjects is governed by Art. 82 GDPR. Between the parties, the liability provisions of the terms of service (section 16) apply, to the extent permitted by law.
14 · final provisions
In matters of data protection this DPA prevails over the terms of service. Changes to this DPA follow section 19 of the terms. German law applies; the place of jurisdiction is determined by section 20 of the terms.
annex 1 · details of processing
Nature of processing: hosting and storage, organisation and structuring, retrieval and display, transmission by email and through links, AI-assisted analysis, translation and drafting, export and deletion.
Purpose: providing the Service to the Customer: planning and running events, booking intake, artist briefings, guest lists and door check-in, invoice collection and checking (including turning the Customer's written invoice instructions into the requirements the check applies), preparation of payouts, communications, design exports and public event pages, and the related support and security; and quality control of the invoice check, in which a scheduled second model re-checks stored invoice checks and we, as the operator of eventflow, review its results in our internal dashboard to improve our prompts. These results are not shown to the Customer and do not change a check or a status.
Categories of personal data: names, stage names and roles; business contact data (email, phone, address); account and login data; booking terms and fees; data on invoices, including tax numbers, VAT IDs and bank details; guest names, optional email addresses, number of additional guests and check-in times; message content and delivery and open events; uploaded files such as invoices, artwork and fonts; event, lineup and timetable data; technical request data.
Categories of data subjects: the Customer's users and team members; artists and their agents, managers and other representatives; curators, promoters and collectives; guests; door staff; business contacts; recipients of messages sent from the Service.
Special categories: not intended. See section 12.
annex 2 · technical and organisational measures
- EU hosting: the database, authentication and file storage run in Frankfurt, Germany; application server functions are pinned to the Frankfurt region.
- Encryption: all connections use TLS; stored data is encrypted at rest by the hosting providers.
- Workspace isolation: row-level security policies in the database limit every read and write to the workspaces a user belongs to.
- Role-based access: workspace roles determine what each member can see and do; door staff see only the door.
- Public links: long random tokens that cannot be guessed, scoped to one purpose and rate-limited; public forms use bot protection.
- Operator access: access to production systems is limited to the operator; administrative actions in the application are recorded in an audit log.
- Access logging: authentication events and administrative actions are logged.
- Backups: daily database backups; a restore was tested in September 2026. A periodic off-site copy of the database backup is kept with a second provider.
- Monitoring: error monitoring and system health checks with sanitised telemetry; no session recordings.
- Secrets and change management: credentials are kept in environment configuration, never in source code; changes are reviewed and pass automated checks before deployment.
- AI requests: sent only for the function in use; requests through our AI gateway run with payload logging switched off and a zero data retention request. Guidance learned from a Customer's corrections stays in that Customer's workspace.
- Deletion: as described in section 10.
annex 3 · sub-processors
- Supabase, Inc. (Supabase)
Purpose: Database, user authentication, file storage (for example uploaded invoices, logos and fonts) and daily database backups.
Data: All Customer Data stored in a workspace, account data and login metadata.
Location: EU, Frankfurt (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU Standard Contractual Clauses. - Vercel Inc. (Vercel)
Purpose: Hosting of the eventflow application and this website. Application server functions run in the Frankfurt region; this website uses Vercel Web Analytics only with consent.
Data: Request data (IP address, user agent, URL, time) and any Customer Data processed while serving a request.
Location: Server functions in Frankfurt (Germany); content delivery through Vercel's global edge network.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - Cloudflare, Inc. (Cloudflare)
Purpose: Edge service at worker.event-flow.ai that dispatches email and routes AI requests; Workers AI inference; AI Gateway, through which we reach OpenAI and some Anthropic models under Cloudflare's billing; Browser Rendering, which turns timetables into PDF files and designs into images; Turnstile bot protection on public forms; DNS.
Data: Request data, email content and recipients handed to the email provider, AI prompts and outputs (including invoice documents), timetable and design content sent for rendering, anti-abuse signals.
Location: Cloudflare's global network; processing location varies by request.
Transfer safeguard: Listed in the EU-U.S. Data Privacy Framework; we also rely on EU Standard Contractual Clauses. - Twilio Inc. (Twilio SendGrid)
Purpose: Sending transactional email and the messages a Customer sends from eventflow (for example artist briefings), and reporting delivery and open events.
Data: Recipient names and email addresses, message content, delivery and open events.
Location: USA.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - Stripe Payments Europe, Ltd. (Stripe)
Purpose: Checkout, subscription billing, invoices, tax calculation and the billing portal.
Data: Billing contact, billing address, VAT ID, payment method and transaction data.
Location: Ireland, with processing in the USA.
Transfer safeguard: EU-U.S. Data Privacy Framework (the provider is certified under it). - OpenAI (OpenAI models, reached through Cloudflare AI Gateway)
Purpose: The invoice check (reading an uploaded invoice and comparing it with the agreed booking), turning a workspace's written invoice instructions into the list of requirements the check applies, reading invoices an operator uploads to prefill them, and the assistant that helps write communication templates. Requests run with payload logging switched off at the gateway and with a zero data retention request.
Data: Invoice documents, including payee names, addresses, tax numbers and bank details; extracted invoice data; event and booking facts needed for the check; a workspace's written invoice instructions; template drafts; instructions and outputs.
Location: USA.
How engaged: Through Cloudflare, Inc.: requests are billed and routed by Cloudflare under Cloudflare's contract with the provider; we hold no direct contract or API key with OpenAI.
Transfer safeguard: EU Standard Contractual Clauses. - Anthropic Ireland, Limited (Claude models)
Purpose: Fallback for the invoice check when the primary check fails; a scheduled second check of stored invoice checks, whose results we as the operator review to improve our prompts; translation of communication templates, briefing page headlines, invoice instructions and invoice check results; parsing of imported lineups; and turning corrections into short guidance (section 3 of the Data Processing Agreement). Separately, Anthropic writes the first automatic reply in our support chat; for that we are the controller and Anthropic is our processor, not a sub-processor of Customer Data.
Data: Invoice documents, including payee names, addresses, tax numbers and bank details; event and booking facts; support chat messages; template, headline and message text; lineup text a Customer imports; corrections to AI output; instructions and outputs.
Location: USA.
How engaged: Through our own API contract with Anthropic (direct API calls) and, for the scheduled invoice verification and template translation, through Cloudflare AI Gateway.
Transfer safeguard: EU Standard Contractual Clauses. - PostHog, Inc. (PostHog (EU Cloud, eu.i.posthog.com))
Purpose: Counting page views in aggregate, in the signed-in application and on the public pages /sign-in, /sign-up, /forgot-password, /intake/<workspace>, /submit and /help. It is cookieless: nothing is stored on the device, and each page load gets a fresh anonymous identifier held only in memory. No automatic click capture, no session recording, no person profiles. Not loaded on personal link pages such as guest lists, briefings, invoices, the door or outreach pages.
Data: The anonymous per-page-load identifier, the page path with identifiers removed, and the time. The IP address of the request reaches PostHog as part of the connection.
Location: EU, Frankfurt (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it). - Functional Software, Inc. (Sentry)
Purpose: Error and performance monitoring for the application. Default personal data collection is switched off and events are sanitised before sending.
Data: Error reports, sanitised URLs, technical request and device metadata.
Location: EU data region (Germany).
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it). - Backblaze, Inc. (Backblaze B2)
Purpose: Periodic off-site copy of the database backup, kept in a private bucket.
Data: A copy of the database, which contains Customer Data.
Location: EU.
Transfer safeguard: Data is hosted in the EU. For any access from outside the EU: EU-U.S. Data Privacy Framework (the provider is certified under it).