Data Processing Agreement
Effective: 21 September 2026
This agreement is part of the Terms of Service and applies to every team using KLEVR Management. It sets out how KLEVR AUDIO LLC processes personal data on behalf of the customer, as Article 28 of the General Data Protection Regulation (GDPR) requires, and it incorporates the EU Standard Contractual Clauses for the transfer to a processor outside the EU. A countersigned copy, and the registered details of KLEVR AUDIO LLC, are available on request from hello@klevrmanagement.com.
1. Parties and roles
2. Subject matter, nature and purpose
3. Data subjects and categories of data
Data subjects: the Controller's team members, freelance crew and musicians, guests invited to a gig, and contact persons at venues, promoters and clients.
Categories of data: names, email addresses, phone numbers, roles and instruments, profile photos, availability, gig assignments and replies, travel details such as flights and hotel stays, dietary and rider preferences the Controller records, fees and settlement figures, messages in team and event chats, and files the Controller uploads.
The service is not designed for special categories of data. If the Controller records health information (for example allergies in a rider), the Controller is responsible for having a lawful basis for it.
4. Instructions
5. Confidentiality and security
Persons authorised by the Processor to process personal data are bound by confidentiality. The Processor maintains the technical and organisational measures in Annex 2, appropriate to the risk, and reviews them as the service changes.
6. Sub-processors
7. Assistance
8. Deletion and return
9. Personal data breaches
10. Audits and information
11. International transfers
Personal data is stored and processed on servers in the EU/EEA (Ireland). Because the Processor is established in the United States, the parties conclude the EU Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this agreement by reference. For the Clauses: the Controller is the data exporter and KLEVR AUDIO LLC the data importer; Clause 7 (docking) is not used; under Clause 9 Option 2 (general authorisation) applies with the 30 days' notice in section 6; the optional language in Clause 11 is not adopted; under Clause 13 the competent supervisory authority is that of the Controller's member state; under Clauses 17 and 18 the law and the courts of Ireland apply. Annex I of the Clauses is completed by sections 1 to 3 of this agreement, Annex II by Annex 2, and the list of sub-processors by Annex 1.
For a Controller in the United Kingdom the UK International Data Transfer Addendum applies to the Clauses; for a Controller in Switzerland the adaptations required by the Swiss Federal Data Protection and Information Commissioner apply. Sub-processors established outside the EU/EEA are engaged under the Clauses or a valid adequacy decision such as the EU-US Data Privacy Framework, as recorded in Annex 1.
12. Liability and term
Annex 1: Sub-processors and locations
Annex 2: Technical and organisational measures
- Hosting in the EU (Ireland) with providers holding SOC 2 Type II and ISO 27001 attestations.
- Encryption in transit (TLS with HSTS) and at rest; passwords stored only as salted hashes.
- Tenant isolation enforced in the database with row level security on every table; the active team as a hard boundary; guests limited to their own gig.
- Role-based access with per-person permissions; two-factor authentication with an authenticator app; password rules; current-password check on password change.
- Daily physical database backups kept for seven days with continuous log archiving; the application is stateless and redeployable from source.
- External availability checks every five minutes and capacity alerts to the operator; automatic build and type checks before every release; continuous dependency vulnerability scanning.
- Audit trail of actions taken through integrations under the acting person's identity.
- Least privilege for service credentials; secrets kept in the hosting provider's encrypted configuration, never in source code.
- Account and data deletion available to users in the app and to anyone through a public deletion page.
- Breach handling as in section 9, with a written record of every incident.