Data Processing Agreement
For the data you record in TheJay about other people: bookers, labels, promoters, venues and peers.
The Dutch text is the binding version. This translation is here so it can be read; where the two differ, the Dutch text prevails.
There is nothing you need to do. This agreement is part of the terms and conditions and applies automatically. If you would like a signed copy for your records, email —.
1. Parties and roles
You are the controller for everything you record about other people. We are the processor (—, KvK —): we store and display it on your behalf and do nothing further with it.
For your own account data we are the controller ourselves — see the privacy statement, section 2.
2. Subject matter, nature and duration
| Question | Answer |
|---|---|
| Subject matter | Delivering TheJay |
| Nature of processing | Storing, organising, displaying, amending, transmitting on your instruction, and deleting |
| Purpose | Your network management, outreach, bookings and promotion |
| Categories of data subject | Bookers, agents, A&Rs, label staff, promoters, programmers, venue contacts, fellow artists, and the recipients of your demos |
| Categories of data | Name, email address, phone number, organisation and role, roles in your career with start and end dates, contact moments and their content, your notes, and behavioural data around a demo link (opened, played, how far, downloaded) |
| Duration | As long as you use the service, and thereafter as in section 9 |
Special categories. TheJay is not built for data on health, religion, political opinions, sexual orientation, criminal matters or a Dutch citizen service number (BSN). Do not record those here. The note fields make it technically possible; this agreement does not cover it.
3. What measuring demos asks of you
This section exists because TheJay does one thing most software does not: it measures whether someone else listened to your music.
That is processing the data subject notices only if you tell them. As the controller you must inform that person. It need not be formal — one sentence when you send the link is enough, for example: "This link tells me whether you've had a listen."
We help where we can: no IP address, device or location is recorded, an unassigned link cannot be traced to a person, and every link can be revoked. The telling itself we cannot do for you.
4. Our instructions
We process only on your instruction; your use of the service is that instruction. Additional instructions can be emailed to —.
We do not use this data for our own purposes, for statistics across customers, or to train AI models. If we believe an instruction breaches the GDPR, we will say so.
5. Confidentiality and security
Everyone on our side with access is bound to confidentiality, and access goes to those who need it to deliver the service or resolve a fault.
Our measures are in section 11 of the privacy statement. In short: separation per workspace, no passwords in this product, encrypted tokens, files reachable only through a token, demo links with a password and expiry, and everything over HTTPS. Measures may change as long as the level of protection stays equivalent or improves.
6. Sub-processors
You give us general authorisation to engage sub-processors; who they are is on the sub-processors page, which forms part of this agreement. We impose the same obligations on each and remain fully liable to you.
For a new or replacement sub-processor we give at least 30 days' notice by email. If you have a reasoned objection and we cannot resolve it, you may terminate free of charge with a refund of the prepaid portion.
7. Transfers outside the EEA
The service runs inside the EU. Transfers beyond it happen only as described under sub-processors — today that amounts to having text written with the AI feature. We rely on the European Commission's Standard Contractual Clauses.
8. Assistance with your obligations
Data subject rights
If a booker or promoter asks what you hold about them, that is your request to answer. In TheJay you can view, amend and delete every record, including the events on a demo link. If something will not work, we help within two business days. If such a request reaches us, we forward it to you.
Data breaches
If we discover a breach involving your data, we report it without undue delay and at the latest within 48 hours of discovery, with what we know about its nature, scope, consequences and the measures taken. Notifying the supervisory authority and the data subjects is yours to do.
DPIA
If you have to carry out a data protection impact assessment, we supply the information about our processing that you need.
9. Return and deletion
When the agreement ends we delete the personal data within 30 days, unless the law requires longer retention. Within that period you may ask for a copy, in a common, machine-readable format.
Backups are not searched to remove individual records; they expire on their own cycle and stay secured and unused until then.
10. Audit
On request we provide the information you need to establish that we meet these obligations. You may have an audit carried out at most once a year by an independent expert bound to confidentiality, at your own cost, announced at least 30 days in advance. If a failure on our part is found, we bear the cost of putting it right.
11. Liability and closing
The liability regime in section 12 of the terms and conditions applies here too. This agreement ends with the main agreement; sections 5 and 9 survive.