Data Processing Agreement
Last updated: August 14, 2026
01Parties & How to Enter Into This DPA
This Data Processing Agreement ("DPA") is made between:
- The Customer — the account holder identified in the CueSync account, acting as controller; and
- to be confirmed — write to contact@cuesync.live, of to be confirmed — write to contact@cuesync.live (to be confirmed — write to contact@cuesync.live), trading as CueSync, acting as processor.
How to put it in place
You do not need to negotiate this document to have it apply. It forms part of the Studio Terms and applies automatically to the personal data we process on your behalf in Studio.
If your organisation needs a countersigned record — most procurement processes do — email privacy@cuesync.live from the address on the account, with the subject line "DPA acceptance", naming your legal entity, its registered address, and the version date shown at the top of this page. We will reply confirming acceptance, and that exchange is the executed agreement. Keep our reply: it is your copy.
Whether we also offer a signature workflow (a PDF counterpart, or an e-signature platform) is a commercial decision that has not been made yet. If your process requires one, say so in the same email and we will tell you what we can do.
Data protection contacts
No DPO appointed. Privacy enquiries: privacy@cuesync.live
- EU Article 27 representative: to be confirmed — write to contact@cuesync.live
- UK Article 27 representative: to be confirmed — write to contact@cuesync.live
- Security contact: security@cuesync.live
02Subject Matter, Duration, Nature & Purpose
Subject matter. Our provision of CueSync Studio, the hosted collaboration workspace in which the Customer builds a show with the people it invites.
Duration.From the moment the Customer first puts personal data into Studio until the later of (a) the end of the Customer's Studio entitlement and (b) the expiry of the retention windows set out in the Data Retention Schedule, subject to the deletion clause below.
Nature of the processing.Collection through the Customer's own use of the service; storage; structuring; retrieval; transmission to the collaborators the Customer has invited; automated derivation of waveform data from audio the Customer uploads; backup; and erasure.
Purpose.Solely to provide, secure and support the service under the Studio Terms. We do not process the Customer's personal data for our own purposes, we do not sell or share it for advertising, and we do not use it to train machine-learning models.
The categories of data subject and of personal data are set out in Annex 1.
03Roles of the Parties
For the personal data the Customer puts into Studio — principally its collaborators' and crew's data — the Customer is the controller and CueSync is the processor. The Customer is responsible for having a lawful basis for putting that data into the service and for telling the people concerned that it has done so.
For a separate and narrower set of data — the account holder's own registration and billing details, our security and anti-abuse telemetry, and the analytics on our public website — CueSync acts as a controller in its own right. That processing is described in the Privacy Policy and is not governed by this DPA.
Where a person is both a collaborator on a Customer's project and a CueSync account holder in their own right, both roles apply to the respective data sets; neither displaces the other.
04Processing on Documented Instructions
We process the Customer's personal data only on the Customer's documented instructions, including as to international transfers, unless we are required to do otherwise by law to which we are subject. Where the law requires it, we will inform the Customer before processing unless that law forbids us to on important grounds of public interest.
The Customer's documented instructions consist of:
- This DPA and the Studio Terms
- The Customer's own configuration and use of the service — creating projects, inviting collaborators, assigning roles and disciplines, uploading content, exporting and deleting
- Any further written instruction the Customer sends to privacy@cuesync.live and that we accept
We will tell the Customer if, in our opinion, an instruction infringes the GDPR or other applicable data protection law. An instruction that would require material work outside the scope of the service may be chargeable, and we will say so before doing it rather than after.
05Confidentiality of Personnel
We ensure that every person authorised to process the Customer's personal data is bound by an obligation of confidentiality, whether contractual or statutory, and that the obligation survives the end of their engagement.
Access is granted on a need-to-know basis and is limited to what a specific task requires. The administrative surfaces that can reach customer records are gated behind an explicit operator allowlist, an enrolled authenticator app, and a fresh re-authentication challenge — see Annex 2 — and administrative actions are written to the tamper-evident audit log.
06Security of Processing (Art. 32)
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing.
The measures actually in place are listed in Annex 2 rather than described in general terms here, because a list a customer can check is worth more than an assurance it cannot. We may change a measure for an equivalent or better one; we will not reduce the overall level of security during the term.
Report a suspected vulnerability or incident to security@cuesync.live.
07Sub-processors
The Customer gives general written authorisationfor us to engage sub-processors. The complete current list, with each one's purpose, the categories of data it receives, and its location, is published and kept up to date at https://www.cuesync.live/legal/subprocessors.
Change notification
We will give notice before a new or replacement sub-processor starts processingthe Customer's personal data — not afterwards. Notice is given by updating the sub-processor page and emailing the subscribers to its change notifications; the page explains how to subscribe.
The Customer may object on reasonable data-protection grounds within 30 days of the notice. We will work with the Customer in good faith to find a solution — a configuration that avoids the sub-processor, or an alternative provider. If none is available, the Customer may terminate the affected part of the service, and we will refund fees paid for the period after termination.
Terms and liability
We impose on each sub-processor data-protection obligations no less protective than those in this DPA. For most of the sub-processors listed, those obligations come from the data processing terms incorporated into that provider's own contract; we are in the process of verifying and dating each one, and until that is complete we are not going to claim a signed instrument we have not confirmed. We remain fully liable to the Customer for a sub-processor's performance of its data-protection obligations regardless — that liability does not depend on the state of our own paperwork, and it is the commitment the Customer is actually relying on here.
08Assistance with Data-Subject Requests
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to fulfil the Customer's obligation to respond to requests to exercise rights under Chapter III of the GDPR — access, rectification, erasure, restriction, portability and objection.
In practice, the Customer can satisfy most requests itself: a project owner or admin can read, correct and delete the content and membership records in their own projects, and any member can export a project in a machine-readable show file. Where a request cannot be satisfied through the product, write to privacy@cuesync.live and we will assist without undue delay.
If a data subject contacts us directly about data we process on the Customer's behalf, we will not respond to the substance of the request ourselves. We will tell them to contact the Customer, and tell the Customer promptly so it can respond within its own one month deadline.
09Assistance with Articles 32 to 36
We assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to us. That includes providing the information a data protection impact assessment needs about how Studio processes data, and supporting a prior consultation with a supervisory authority where one is required.
Annex 1 and Annex 2 of this document, plus the Sub-processors and Data Retention Schedule pages, are intended to be sufficient for an ordinary impact assessment without a separate request.
10Personal Data Breach Notification
We notify the Customer without undue delayafter becoming aware of a personal data breach affecting personal data we process on the Customer's behalf. Notice goes to the email address on the account and, where the Customer has given one, to a nominated security contact.
The notification describes, to the extent known at the time:
- The nature of the breach, including the categories and approximate number of data subjects and records concerned
- The likely consequences
- The measures taken or proposed to address it and to mitigate its effects
- A contact point for further information
Where the full picture is not available at once, we provide the information in phases rather than delaying the first notification until everything is known. We do not notify a supervisory authority or data subjects on the Customer's behalf unless the Customer asks us to and we agree: those are the controller's obligations, and a duplicate notification from a processor is not a help to anyone.
11Deletion or Return at the End
At the Customer's choice, we delete or return the personal data we process on its behalf after the end of the provision of the service, and delete existing copies, unless Union or Member State law requires us to keep them.
- Return is self-service and available throughout the term: any project member can export a project as a machine-readable show file, and uploaded source files can be downloaded from the project. We recommend doing this before the entitlement lapses.
- Deletion happens on the schedule published in the Data Retention Schedule, or earlier on written request to privacy@cuesync.live.
Two honest exceptions. First, encrypted operational backups are taken on a rolling cycle and are not selectively editable; data deleted from the live system persists in backups until those backups age out on the cycle stated in the retention schedule, and remains subject to this DPA while it does. Second, records we must keep by law — principally transaction records kept for the statutory accounting period — survive an erasure request, and the retention schedule says which they are.
12Audit & Information Rights
We make available to the Customer all information necessary to demonstrate compliance with the obligations in Article 28, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
In the first instance we satisfy this by providing the published documentation — this DPA and its annexes, the sub-processor list, the retention schedule — and by answering a written questionnaire. Where that is genuinely insufficient for the Customer's own compliance obligation, the Customer may request an audit on 30 days' written notice, no more than once in any 12-month period except where a supervisory authority requires otherwise or following a personal data breach.
An audit must be conducted during business hours, must not unreasonably interfere with our operations, and must not access another customer's data or any part of our systems that would compromise their security. The auditor must be bound by confidentiality and must not be a competitor of ours. The Customer bears its own costs and our reasonable costs of supporting an on-site audit.
We do not currently hold a SOC 2 or ISO 27001 report. Whether to obtain one is a business decision that has not been made; we would rather say so than imply a certification we do not have.
13International Transfers
Studio is operated from infrastructure in more than one country, and several of our sub-processors are global providers. Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or the UK to a country without an adequacy decision, that transfer is made under an approved transfer mechanism — the European Commission's Standard Contractual Clauses (Decision 2021/914) with the UK International Data Transfer Addendum where UK data is involved — together with the supplementary measures set out in Annex 2, principally encryption in transit and at rest.
The per-sub-processor location and transfer mechanism is published in the Sub-processorstable. Cells in that table that read "to be confirmed" are exactly that: not yet verified, and marked rather than guessed.
The controller-side transfer analysis also depends on where CueSync's own establishment sits, which is recorded on this page as: to be confirmed — write to contact@cuesync.live. Until that is settled, treat the transfer position as provisional and ask us before relying on it in your own assessment.
14Liability, Term & Precedence
This DPA takes effect when the Customer first uses Studio and continues for as long as we process personal data on the Customer's behalf. The obligations in the deletion, confidentiality and audit clauses survive its termination for as long as we hold any of that data.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where those limitations cannot lawfully be applied to a claim under data protection law.
In the event of a conflict, this DPA prevails over the Terms of Service and the Studio Terms on matters of data protection, and the Standard Contractual Clauses prevail over this DPA where they apply.
15Annex 1 — Details of Processing
Categories of data subject
- The Customer's collaborators and crew invited to a Studio project — designers, operators, stage management, production staff, freelancers and contractors
- People the Customer invites who never accept the invitation (an email address held against a pending invitation)
- People named or described inside content the Customer uploads — for example a name in a cue note, a rehearsal schedule, or a contact sheet attached as a spec document
Categories of personal data
| Category | What it is |
|---|---|
| Identity & contact | Email address, display name, account identifier |
| Membership | Which projects a person belongs to, their role (owner, admin, member, viewer), their discipline tags, who invited them and when they joined |
| Invitation | The invited email address, the intended role and disciplines, who sent it, its expiry, and whether it was accepted |
| Contributed content | Comments, cue names and notes, section notes, project metadata, and the files uploaded to the project — audio, PDFs, images, Markdown and plain-text specs |
| Activity | An activity feed of who changed what in a project, and ephemeral presence showing who is currently in it |
| Technical | IP address and request metadata in server logs, session records, and security telemetry generated by access to the service |
Special-category data.Studio is not designed for special categories of personal data under Article 9, and we ask the Customer not to put any into it. A production's medical, accessibility or union records do not belong in a cue note. If the Customer does upload such data, it does so on its own instruction and must satisfy itself of the lawful basis.
Frequency and duration
Processing is continuous for the duration of the Customer's use of Studio. Retention of each category is set out in the Data Retention Schedule.
16Annex 2 — Technical & Organisational Measures
The measures below are the ones in place, described specifically enough to be checked. Where a measure has a stated threshold, the threshold is the one the service enforces.
| Area | Measure |
|---|---|
| Encryption at rest | Licence keys are held under envelope encryption: AES-256-GCM with a fresh per-row data encryption key, itself wrapped under a master key held in the server environment and never in the database. A licence key is never stored in a recoverable plaintext form. Two-factor secrets are encrypted at rest and recovery codes are stored as bcrypt hashes. The same envelope mechanism is implemented for account email addresses but is not yet enabled; until it is, email addresses rely on encryption in transit, database access control, and encrypted backups. |
| Encryption in transit | TLS on every connection to the website, the API and the object store. Uploaded objects are written and read only through short-lived signed URLs, and the content type served is forced to the value the server validated rather than one the uploader asserted. |
| Access control (customer data) | Role-based access enforced server-side on every Studio request against the four project roles, with discipline scoping inside a project. A request from a non-member is answered as if the project did not exist, so membership is not discoverable. Web sessions are held in server-side storage with a 7-day lifetime, carried in HTTP-only secure cookies, and every state-changing request is CSRF-validated. |
| Access control (administrative) | Administrative surfaces require all of: an authenticated session, membership of an explicit operator allowlist, an enrolled TOTP authenticator, and a recent step-up re-authentication. Destructive account actions additionally require a fresh password or TOTP challenge within a 5-minute window, and a session whose network and device fingerprint have both changed is forced to re-authenticate regardless of recency. |
| Auditability | Security-relevant events are written to an append-only audit log protected by an HMAC chain: each row's MAC covers the previous row's MAC, so removing or altering a row breaks verification. A database trigger blocks modification. A scheduled job re-verifies the chain and alerts on a break. Retention pruning would otherwise trip that alarm — the surviving rows chain back to predecessors that no longer exist — so the prune also advances the checkpoint the verifier starts from. The prune commits in batches first and the checkpoint is advanced afterwards, in a separate statement, so that a failure to record it cannot roll back deletions already committed; the anchor only ever moves forward, and a failed advance is raised as an alert rather than passed over. |
| Availability & resilience | Encrypted database backups: a nightly local dump encrypted before it touches disk, retained 30 days, plus an hourly off-site copy to separate storage. The backup job refuses to run at all if the encryption key is absent, rather than writing a plaintext dump. Restores are exercised by a verification script. |
| Abuse & brute-force resistance | Per-identifier rate limiting on authentication, licensing and Studio endpoints, with the most sensitive limiters failing closed when the rate-limit store is unavailable rather than admitting the request. Licence-key brute force is met with a prefix lockout after 20 failures in 24 hours. Public forms are protected by Cloudflare Turnstile. |
| Data minimisation in tooling | Error-monitoring events pass through an explicit redaction filter before they leave the application, which strips credentials, tokens, licence keys and other product-specific identifiers that a generic scrubber would not recognise. |
| Retention & deletion | Scheduled jobs enforce the published retention windows per category rather than leaving tables to grow, including deletion of orphaned uploaded objects from the object store. The windows are published in the Data Retention Schedule. |
| Organisational | Need-to-know access, confidentiality obligations on all personnel, written data-protection terms with every sub-processor, and a published security contact for vulnerability reports. |
17Contact
Data protection enquiries, DPA acceptance and data-subject assistance: privacy@cuesync.live.
Security reports: security@cuesync.live.
Related documents: Studio Terms, Sub-processors, Data Retention Schedule, and the Privacy Policy.