All legal documents

Version 1.0 · Effective October 5, 2026

Data Processing Addendum

1. Definitions

2. Roles and scope

The Customer is the business (or controller) and StudioCue is the service provider (or processor) with respect to Client Data. The Customer determines the purposes and means of processing Client Data. The details of processing are set out in Annex 1. Each party will comply with the obligations that apply to it under Data Protection Laws.

The Customer is responsible for the lawfulness of the Client Data it provides and of its instructions, including providing any required notices to, and obtaining any required consents from, individuals, and for ensuring that its instructions comply with Data Protection Laws.

3. Processing on instructions

StudioCue will process Client Data only on the Customer’s documented instructions, which consist of: the Agreement; the Customer’s use and configuration of the Service; and any further written instructions agreed by the parties. StudioCue will inform the Customer if, in its opinion, an instruction violates Data Protection Laws, and is not required to follow such an instruction. StudioCue may process Client Data where required by law, in which case it will inform the Customer before processing unless the law prohibits it.

4. U.S. state-law service-provider terms

With respect to Client Data, StudioCue certifies that it understands and will comply with the following restrictions. StudioCue will not:

StudioCue will provide the same level of privacy protection as required of the Customer by Data Protection Laws, will notify the Customer if it determines that it can no longer meet its obligations under those laws, and grants the Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Client Data.

5. Confidentiality and personnel

StudioCue will ensure that personnel authorized to process Client Data are bound by appropriate obligations of confidentiality, receive appropriate training, and have access only to the Client Data necessary to perform their duties.

6. Security

StudioCue will implement and maintain appropriate technical and organizational measures to protect Client Data against Security Incidents, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing. These measures include, at a minimum, those described in Annex 2. StudioCue may update its measures from time to time provided that the update does not materially decrease the overall protection of Client Data.

7. Subprocessors

The Customer gives StudioCue general authorization to engage Subprocessors. StudioCue’s current Subprocessors are listed on the Subprocessors page, which identifies each Subprocessor, its purpose and location. StudioCue will:

The Customer may object to a new Subprocessor on reasonable data-protection grounds by emailing support@studio-cue.com within 15 days after the update. The parties will discuss the objection in good faith. If StudioCue cannot reasonably accommodate it, the Customer may terminate the affected subscription and receive a refund of prepaid fees for the unused remainder of the then-current billing period.

Third-Party Services that the Customer chooses to connect (such as Google Calendar, Zoom, QuickBooks Online or Dropbox) are engaged by the Customer, not by StudioCue, and are not StudioCue’s Subprocessors; data flows to them at the Customer’s direction.

8. Assistance with individuals’ requests

Taking into account the nature of the processing, StudioCue will assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from individuals to exercise their rights under Data Protection Laws. The Service provides tools for the Customer to access, correct, export and delete Client Data. If StudioCue receives a request from an individual relating to Client Data, it will promptly refer the individual to the Customer and will not respond directly except to confirm the referral or as required by law. StudioCue will also provide reasonable assistance with any data-protection assessments and consultations with regulators that the Customer is required to carry out in relation to the Service.

9. Security Incidents

StudioCue will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting the Customer’s Client Data. The notice will be sent to the Account Owner’s email address and will describe, to the extent known: the nature of the incident; the categories and approximate number of individuals and records concerned; the likely consequences; and the measures taken or proposed to address it. StudioCue will take reasonable steps to contain, investigate and mitigate the incident, will provide updates as information becomes available, and will reasonably cooperate with the Customer’s legal obligations to notify individuals or authorities. Notification is not an acknowledgement of fault or liability.

10. Return and deletion

During the Subscription Term, the Customer may export and delete Client Data using the Service. After termination, StudioCue will make Client Data available for export for 30 days, and will then delete it from the active Service, with residual backup copies overwritten within 90 days, except where retention is required by law. Signature evidence records retained with signed agreements, and audit records needed to demonstrate compliance, are deleted with the workspace they belong to.

11. Information and audits

StudioCue will make available to the Customer, on reasonable written request no more than once in any 12-month period (or following a Security Incident or a regulator’s request), information reasonably necessary to demonstrate compliance with this DPA, which may include responses to a reasonable security questionnaire, summaries of StudioCue’s security measures, and certifications or reports of its infrastructure providers. Any further audit will be at the Customer’s expense, on at least 30 days’ notice, during business hours, subject to confidentiality obligations and in a manner that does not compromise the security of the Service or other customers’ data.

12. Location of processing

StudioCue stores and processes Client Data in the United States. If the Customer is subject to laws that restrict transfers of personal data to the United States, the Customer must not use the Service for such data unless the parties have first agreed appropriate transfer terms in writing.

13. Liability and precedence

Each party’s liability arising out of or relating to this DPA is subject to the limitations of liability in the Terms. In the event of a conflict between this DPA and the Terms regarding the processing of Client Data, this DPA prevails. This DPA remains in effect for as long as StudioCue processes Client Data on the Customer’s behalf.

Annex 1 — Details of processing

Annex 2 — Technical and organizational security measures