KLEVRManagement

Data Processing Agreement

Effective: 21 September 2026

This agreement is part of the Terms of Service and applies to every team using KLEVR Management. It sets out how KLEVR AUDIO LLC processes personal data on behalf of the customer, as Article 28 of the General Data Protection Regulation (GDPR) requires, and it incorporates the EU Standard Contractual Clauses for the transfer to a processor outside the EU. A countersigned copy, and the registered details of KLEVR AUDIO LLC, are available on request from hello@klevrmanagement.com.

1. Parties and roles

The customer is the legal entity that created the team in KLEVR Management (the "Controller"). KLEVR AUDIO LLC, a company established in the United States, provides the service (the "Processor"). The Controller decides why and how personal data is processed in its team; the Processor processes it only to provide the service. The data itself is stored in the EU (section 11).

2. Subject matter, nature and purpose

The Processor hosts and operates KLEVR Management: planning of events and tours, crew booking and replies, schedules, travel, chat, riders, settlements and related documents. Processing consists of storing, displaying, transmitting between team members, sending notifications, and producing documents from the data the Controller enters. It lasts for as long as the Controller has a team in the service, plus the deletion period in section 8.

3. Data subjects and categories of data

Data subjects: the Controller's team members, freelance crew and musicians, guests invited to a gig, and contact persons at venues, promoters and clients.

Categories of data: names, email addresses, phone numbers, roles and instruments, profile photos, availability, gig assignments and replies, travel details such as flights and hotel stays, dietary and rider preferences the Controller records, fees and settlement figures, messages in team and event chats, and files the Controller uploads.

The service is not designed for special categories of data. If the Controller records health information (for example allergies in a rider), the Controller is responsible for having a lawful basis for it.

4. Instructions

The Processor processes personal data only on documented instructions from the Controller. Using the service as intended, including its notification, sharing and export features, is such an instruction. The Processor informs the Controller if it believes an instruction infringes data protection law.

5. Confidentiality and security

Persons authorised by the Processor to process personal data are bound by confidentiality. The Processor maintains the technical and organisational measures in Annex 2, appropriate to the risk, and reviews them as the service changes.

6. Sub-processors

The Controller gives general authorisation for the sub-processors listed on the security page (Annex 1). The Processor informs customers with an active team at least 30 days before adding or replacing a sub-processor; the Controller may object on reasonable data protection grounds, and if no solution is found may end the service without penalty. The Processor imposes data protection obligations on each sub-processor equivalent to this agreement and remains responsible for their performance.

7. Assistance

Taking into account the nature of the processing, the Processor assists the Controller with requests from data subjects (access, rectification, erasure, portability), with security, breach notification and data protection impact assessments, and with consultations with supervisory authorities. Where a request creates significant work, the Processor may charge a reasonable fee agreed in advance.

8. Deletion and return

When the Controller ends its team or the service, the Processor deletes the personal data within 30 days, except where law requires it to be kept. Before that, the Controller can export its data from the service or ask for a copy. Backups holding the data are overwritten within a further 7 days.

9. Personal data breaches

The Processor notifies the Controller without undue delay, and at the latest within 72 hours of confirming a personal data breach affecting the Controller's data, with what happened, the likely consequences and the measures taken. The Processor keeps a record of every breach.

10. Audits and information

The Processor makes available the information necessary to demonstrate compliance with this agreement and allows audits, including inspections, by the Controller or an auditor mandated by the Controller, at most once a year unless a supervisory authority or a breach requires more, with at least 30 days' notice and during working hours. Reports from independent audits of the Processor's sub-processors are provided in place of on-site inspection of their facilities.

11. International transfers

Personal data is stored and processed on servers in the EU/EEA (Ireland). Because the Processor is established in the United States, the parties conclude the EU Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this agreement by reference. For the Clauses: the Controller is the data exporter and KLEVR AUDIO LLC the data importer; Clause 7 (docking) is not used; under Clause 9 Option 2 (general authorisation) applies with the 30 days' notice in section 6; the optional language in Clause 11 is not adopted; under Clause 13 the competent supervisory authority is that of the Controller's member state; under Clauses 17 and 18 the law and the courts of Ireland apply. Annex I of the Clauses is completed by sections 1 to 3 of this agreement, Annex II by Annex 2, and the list of sub-processors by Annex 1.

For a Controller in the United Kingdom the UK International Data Transfer Addendum applies to the Clauses; for a Controller in Switzerland the adaptations required by the Swiss Federal Data Protection and Information Commissioner apply. Sub-processors established outside the EU/EEA are engaged under the Clauses or a valid adequacy decision such as the EU-US Data Privacy Framework, as recorded in Annex 1.

12. Liability and term

This agreement lasts as long as the Terms of Service between the parties. Liability follows the Terms of Service. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails. This agreement and the Standard Contractual Clauses are governed by the law of Ireland.

Annex 1: Sub-processors and locations

The current list, with purpose and location for each provider, is maintained on the security page and forms part of this agreement.

Annex 2: Technical and organisational measures

  • Hosting in the EU (Ireland) with providers holding SOC 2 Type II and ISO 27001 attestations.
  • Encryption in transit (TLS with HSTS) and at rest; passwords stored only as salted hashes.
  • Tenant isolation enforced in the database with row level security on every table; the active team as a hard boundary; guests limited to their own gig.
  • Role-based access with per-person permissions; two-factor authentication with an authenticator app; password rules; current-password check on password change.
  • Daily physical database backups kept for seven days with continuous log archiving; the application is stateless and redeployable from source.
  • External availability checks every five minutes and capacity alerts to the operator; automatic build and type checks before every release; continuous dependency vulnerability scanning.
  • Audit trail of actions taken through integrations under the acting person's identity.
  • Least privilege for service credentials; secrets kept in the hosting provider's encrypted configuration, never in source code.
  • Account and data deletion available to users in the app and to anyone through a public deletion page.
  • Breach handling as in section 9, with a written record of every incident.