Data Processing Addendum
Article 28 terms for personal data we process on your instructions.
- Effective:
- Last updated:
This addendum applies where a customer routes personal data through the service and the GDPR, UK GDPR, or a comparable law applies. The customer is the controller; we are the processor.
It sets out what we do with that data, the security we apply, how sub-processors are authorised, how we help with data-subject requests and breach notification, and what happens to the data when the contract ends.
The summary above is provided for convenience only. Where it differs from the full text of this document, the full text governs.
1. Scope, roles, and order of precedence
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Customer and TODO_LEGAL: registered company name (e.g. "RadioHeart Ltd") and applies to the processing of personal data carried out by us on the Customer’s behalf in providing the service.
In the event of conflict, this DPA prevails over the Terms of Service and the Privacy Policy on matters of personal-data processing, and the Standard Contractual Clauses prevail over this DPA on matters they govern.
2. Subject matter, duration, nature, and purpose
- Subject matter
- Provision of the RadioHeart broadcasting platform to the Customer.
- Duration
- For as long as the Customer’s subscription is in force, plus the deletion period in section 9.
- Nature of processing
- Collection, recording, organisation, storage, transcoding, transmission, retrieval, consultation, restriction, erasure, and destruction — carried out by automated means in operating the service.
- Purpose
- Operating the Customer’s stations, delivering streams to listeners, providing analytics and moderation tooling to the Customer, and providing support at the Customer’s request.
- Types of personal data
- Identifiers and account details of the Customer’s users; listener connection data including IP address, approximate location derived from it, device and player type, and session times; chat messages and moderation records; and any personal data contained in material the Customer uploads or broadcasts.
- Categories of data subject
- The Customer’s staff, volunteers, hosts, and administrators; the Customer’s listeners and website visitors; and individuals featured in material the Customer broadcasts.
3. Processing only on documented instructions
We process personal data only on the Customer’s documented instructions, including as to international transfers, unless required to do otherwise by law to which we are subject. Where that exception applies, we inform the Customer of the requirement before processing, unless the law prohibits it on important grounds of public interest.
The Terms of Service, this DPA, and the Customer’s use of the service’s features constitute the Customer’s complete documented instructions. Additional instructions outside that scope require a separate written agreement and may be chargeable.
We will inform the Customer if, in our opinion, an instruction infringes the GDPR, UK GDPR, or another applicable data-protection provision.
4. Personnel and confidentiality
We ensure that personnel authorised to process personal data are bound by an appropriate obligation of confidentiality, receive data-protection training proportionate to their role, and have access only to the data their role requires, on a least-privilege basis that is reviewed periodically.
5. Security of processing
We implement and maintain the technical and organisational measures described in Annex II, which are appropriate to the risk having regard to the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing, as required by Art. 32 GDPR.
We may update those measures over time provided the level of protection is not reduced.
6. Sub-processors
The Customer gives a general written authorisation for us to engage sub-processors for the purposes described in Annex III. Each sub-processor is engaged under a written contract imposing data-protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for their performance.
We will give the Customer at least 30 days’ notice before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds within that period; if we cannot offer a reasonable alternative, the Customer may terminate the affected part of the service without penalty, with a pro-rata refund of prepaid fees for the unused period.
7. Assistance with data-subject requests
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data-subject rights.
Where we receive a request directly from a data subject relating to data we process for the Customer, we will not respond to it substantively ourselves, except to direct the individual to the Customer, and we will notify the Customer without undue delay.
8. Assistance with security, breaches, and impact assessments
We assist the Customer in ensuring compliance with the obligations in Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to us. In particular:
- We notify the Customer without undue delay after becoming aware of a personal-data breach affecting personal data processed on their behalf.
- The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information — supplemented as more becomes known.
- It remains the Customer’s responsibility, as controller, to notify its supervisory authority and affected data subjects where the law requires it.
- We provide reasonable information to support the Customer’s data-protection impact assessments and any prior consultation with a supervisory authority.
9. Deletion or return at the end of the contract
At the Customer’s choice, we delete or return all personal data processed on their behalf at the end of the provision of services, and delete existing copies, unless applicable law requires storage.
The Customer can export its data through the service while the account is open. After closure, data remains available for export for 30 days, is deleted from live systems thereafter, and expires from backups on their ordinary rotation, normally within a further 35 days.
10. Audits and information rights
We make available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
In the first instance we satisfy this by providing our then-current security documentation and any third-party audit reports or certifications we hold. Where that is insufficient to demonstrate compliance, the Customer may request an audit not more than once in any 12-month period, on at least 30 days’ written notice, during business hours, subject to confidentiality, without unreasonably disrupting the service, and at the Customer’s cost — except where the audit reveals a material breach of this DPA.
11. International transfers
Where the processing involves a transfer of personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate by reference the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914:
- Module Two (controller to processor) where the Customer is a controller;
- Module Three (processor to processor) where the Customer is itself a processor;
- with the docking clause applicable, the optional clause on independent dispute resolution deleted, the supervisory authority being that of the Customer’s establishment, and the audit and sub-processor provisions of this DPA applying;
- Annexes I, II, and III of this DPA serving as Annexes I, II, and III to the Clauses;
- the UK International Data Transfer Addendum applying to UK transfers, and the Swiss amendments applying to Swiss transfers.
12. The Customer’s responsibilities as controller
We are not responsible for determining whether the Customer has a lawful basis, and we do not review the content the Customer transmits. Nothing in this DPA makes us the controller of data the Customer collects through its station.
Annex I — Parties and details of processing
- Data exporter
- The Customer, as identified in its account and Order. Role: controller (or processor, where Module Three applies).
- Data importer
- TODO_LEGAL: registered company name (e.g. "RadioHeart Ltd"), TODO_LEGAL: registered office street address, TODO_LEGAL: city, postal code, TODO_LEGAL: country of incorporation. Role: processor. Contact: support@radioheart.io (TODO_LEGAL: DPO or Art. 27 representative name and contact).
- Categories of data subject
- As set out in section 2.
- Categories of personal data
- As set out in section 2.
- Special-category data
- None is requested or required. The Customer must not route special-category data through the service without a separate written agreement.
- Frequency of transfer
- Continuous, for the duration of the subscription.
- Nature and purpose
- As set out in section 2.
- Retention
- As set out in section 9 and in the Privacy Policy.
- Competent supervisory authority
- That of the data exporter’s establishment, in accordance with Clause 13 of the Standard Contractual Clauses.
Annex II — Technical and organisational measures
- Encryption of personal data in transit using current TLS, and encryption at rest for stored media, databases, and backups.
- Role-based access control on a least-privilege basis, with multi-factor authentication for administrative access and periodic access reviews.
- Credential hashing with a modern algorithm; no storage of payment card numbers.
- Network segmentation, firewalling, and isolation between customer stations.
- Centralised logging and monitoring of administrative actions, with alerting on anomalous behaviour.
- Vulnerability management: dependency scanning and timely patching, with severity-based remediation targets.
- Change management: peer-reviewed code changes and automated testing before deployment.
- Backup and restore procedures with periodic restore testing.
- A documented incident-response process covering detection, containment, notification, and post-incident review.
- Confidentiality obligations and data-protection training for personnel with access to personal data.
- Written data-protection terms with every sub-processor.
- Secure deletion procedures for data at the end of its retention period.
Annex III — Sub-processors
Sub-processors are engaged in the categories listed in the Privacy Policy: cloud hosting and storage, content delivery and streaming, payment processing, transactional and marketing email, support tooling, product and website analytics, and error monitoring.
- Current named list
- TODO_LEGAL: DPO or Art. 27 representative name and contact — the up-to-date list of named sub-processors, their processing activities, and their locations is maintained separately and provided on request to support@radioheart.io.
- Change notification
- At least 30 days before a sub-processor is added or replaced, with the objection right described in section 6.
Contact
To request a countersigned copy of this DPA, the named sub-processor list, or our security documentation:
- support@radioheart.io
- Data protection contact
- TODO_LEGAL: DPO or Art. 27 representative name and contact
- Entity
- TODO_LEGAL: registered company name (e.g. "RadioHeart Ltd")
- Registered office
- TODO_LEGAL: registered office street address, TODO_LEGAL: city, postal code, TODO_LEGAL: country of incorporation