Data Processing Agreement

Version 2026-08-16

This agreement governs how MusicFlow processes personal data on behalf of your organisation, as the GDPR requires. It forms part of the terms of service.

The Dutch text is the authentic version. In case of any difference, the Dutch text prevails.

This data processing agreement forms part of the MusicFlow terms of service and is entered into between Cubewave, a sole proprietorship registered with the Dutch Chamber of Commerce under number 42099205, trading as MusicFlow ("MusicFlow", the processor), and the organisation using MusicFlow that has accepted this agreement ("the Organisation", the controller).

The parties enter into this agreement as referred to in Article 28(3) GDPR.

1. Definitions and precedence

  1. Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "special categories of personal data" have the meaning given to them by the GDPR (Regulation (EU) 2016/679).
  2. "the Service" means the application provided by MusicFlow for managing sheet music, practice material, groups, events and member access.
  3. This agreement forms part of the MusicFlow terms of service. In the event of conflict this agreement prevails, but only in so far as the processing of personal data is concerned. For all other matters — including availability, payment and the limitation of liability — the terms of service apply.

2. Subject matter, nature, purpose and duration

  1. MusicFlow processes personal data solely on behalf of the Organisation and solely in order to provide the Service.
  2. Nature of the processing: storage, retrieval, display, organisation, distribution within the Organisation, backup, and sending notifications.
  3. Purpose of the processing: managing and making available the Organisation’s sheet music, practice material, groups, events, setlists and member access.
  4. MusicFlow does not process the personal data for its own purposes, does not sell it, and does not use it to build profiles or train models.
  5. This agreement applies for as long as the Organisation uses the Service and ends once all personal data has been deleted or returned in accordance with clause 10.

3. Categories of data subjects and personal data

Data subjects: members, conductors and leaders, administrators, and guests of the Organisation.

Categories of personal data:

  • name and email address;
  • instrument and voice-part selections, focus preference;
  • group and role assignment within the Organisation;
  • participation in and attendance at events and rehearsals;
  • user-generated content (setlists, favourites, notes and annotations on sheet music);
  • files uploaded by the Organisation, in so far as these contain personal data;
  • optionally, and only where the data subject activates it themselves: a Telegram link ID and/or a browser push subscription;
  • technical log data (IP address, timestamp, action) for security and troubleshooting.

Special categories. MusicFlow does not request special categories of personal data and does not need them for the Service; the data model has no field for religion, health or any other category under Article 9 GDPR. The Organisation decides whom it enrols as a member and what content it uploads. In so far as data within the meaning of Article 9 GDPR can be inferred from the Organisation’s identity, from membership itself, or from content the Organisation places in the Service, the Organisation is the controller for that data and warrants that it has a valid basis under Article 9(2) GDPR. MusicFlow processes such data solely as an unavoidable consequence of storing what the Organisation supplies, and solely on the Organisation’s instructions.

4. Instructions and obligations of MusicFlow

  1. MusicFlow processes the personal data solely on the documented instructions of the Organisation. Use of the Service, the settings the Organisation chooses within the application, and this agreement together constitute those instructions.
  2. Where MusicFlow processes personal data because a legal obligation requires it, MusicFlow informs the Organisation beforehand, unless that law prohibits such notification on important grounds of public interest.
  3. MusicFlow ensures that persons with access to the personal data are bound by confidentiality.
  4. MusicFlow limits access to production systems and personal data to those persons for whom such access is necessary to provide or maintain the Service.
  5. If MusicFlow considers that an instruction from the Organisation infringes the GDPR or other data protection provisions, MusicFlow informs the Organisation immediately. MusicFlow may suspend performance of that instruction until the Organisation confirms or withdraws it.

5. Security

  1. MusicFlow implements appropriate technical and organisational measures as referred to in Article 32 GDPR. What is appropriate is determined — in accordance with that Article — taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of data subjects, varying in likelihood and severity. This is an obligation of effort: MusicFlow does not guarantee absolute security, and no measure can.
  2. The measures MusicFlow currently implements are described in Annex B.
  3. MusicFlow may change and develop the measures, provided the level of protection is not thereby reduced. A change to the measures does not constitute an amendment of this agreement.
  4. On request, MusicFlow provides a current description of the measures implemented.

6. Subprocessors

  1. The Organisation hereby grants MusicFlow general written authorisation to engage subprocessors, as referred to in Article 28(2) GDPR.
  2. The current list of subprocessors is published on the Subprocessors page and forms Annex A to this agreement. That page is the authentic source; any snapshot reproduced in this document is not.
  3. MusicFlow announces the addition or replacement of a subprocessor at least 30 days in advance on that page and by email to the contact address provided by the Organisation.
  4. Within those 30 days the Organisation may object in writing, with reasons, on reasonable data protection grounds. The parties will then consult. If they do not reach agreement, the Organisation may terminate this agreement and the agreement for the Service with effect from the date the change takes effect, without either party incurring liability for damages as a result. If the Organisation does not object within the period, the change is deemed accepted.
  5. Where a subprocessor must be replaced urgently because of an outage, a security incident or that subprocessor ceasing to be available, MusicFlow may do so immediately and will inform the Organisation as soon as possible afterwards. The right to object under paragraph 4 then runs from that notification.
  6. MusicFlow imposes on each subprocessor, by contract, the data protection obligations that rest on MusicFlow under Article 28(3) GDPR, including in particular sufficient guarantees as to appropriate technical and organisational measures.
  7. MusicFlow remains fully responsible to the Organisation for the performance of its subprocessors’ obligations, in accordance with Article 28(4) GDPR. The limitations in clause 13 apply thereto.

7. Transfers outside the EEA

The Organisation’s personal data is stored and processed within the European Economic Area (EEA).

One optional notification channel is an exception, and is used only once the data subject has activated it: browser push notifications. Delivery runs via the push service of the data subject’s browser (including Apple, Google, Mozilla or Microsoft — see the Subprocessors page for the current list). The message content is encrypted; the push service sees only encrypted content, the technical delivery address and traffic data.

Where this transfer to a third country takes place, it is made on the basis of an adequacy decision or of the standard contractual clauses adopted by the European Commission, with supplementary measures where necessary.

Telegram notifications sit outside this clause. They are sent only where the data subject links their own account and directs their own notifications there — MusicFlow relays to a destination the data subject has chosen, comparable to the Organisation sending a member an email at an address of their own choosing. MusicFlow does not instruct Telegram as a subprocessor; once a message is delivered, Telegram processes it as an independent controller under its own privacy terms. The Telegram chat ID and message content are sent unencrypted, outside the EEA.

The Organisation may discourage use of these channels within its organisation; the data subject can unlink either at any time.

8. Assistance to the Organisation

  1. Taking into account the nature of the processing and the information available to it, MusicFlow provides the Organisation with reasonable assistance with data subject requests (access, rectification, erasure, restriction, objection and portability) and with compliance with the obligations under Articles 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation of the supervisory authority.
  2. The Service includes administrative functions with which the Organisation can handle most access and modification requests about its members itself, through the organisation roster: viewing members and their role, and changing or removing that role. The Service does not yet include self-service export or deletion of a member’s data; those requests are handled under paragraph 4.
  3. Where MusicFlow receives a request from a data subject concerning the Organisation, MusicFlow does not answer that request itself but refers the data subject to the Organisation and informs the Organisation accordingly.
  4. Assistance going beyond the administrative functions referred to in paragraph 2 and requiring more than incidental effort is charged by MusicFlow at its usual hourly rate, after prior notification of the expected cost — except for export or deletion requests under paragraph 2 that are only manual because that self-service function does not yet exist, which MusicFlow does not charge for.

9. Personal data breaches

  1. MusicFlow notifies the Organisation without undue delay after becoming aware of a personal data breach affecting the Organisation. No fixed deadline in hours applies: Article 33(2) GDPR obliges the processor to notify without undue delay, and the 72-hour period in Article 33(1) GDPR rests on the Organisation as controller.
  2. Notification is sent to the contact address the Organisation has provided in the Service. The Organisation ensures that this address is current and monitored.
  3. The notification contains, in so far as known at that time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
  4. Where not all information is available at the time of notification, MusicFlow reports what it knows and provides the remainder in phases, without undue delay, as it becomes available.
  5. Notification to the Dutch Data Protection Authority and, where required, to data subjects, is the responsibility of the Organisation. MusicFlow does not make that notification on the Organisation’s behalf.
  6. A notification or investigative step by MusicFlow does not constitute an admission of liability.

10. Deletion and return

  1. On termination of the Service MusicFlow will, at the Organisation’s choice, delete all personal data or return it to the Organisation. The Organisation makes that choice known no later than on termination; absent a choice, MusicFlow deletes the data.
  2. Deletion or return takes place within 30 days of termination. Return is effected by exporting the Organisation’s data in a common, machine-readable format.
  3. Data held in backups is not deleted separately but expires according to the normal retention period of at most 7 months. For as long as it remains in a backup it is not restored or otherwise processed, except for disaster recovery.
  4. By way of exception to paragraph 1, MusicFlow may retain data in so far as a legal obligation requires it — including the statutory retention period for invoices and accounting records. For that data MusicFlow acts as controller.
  5. If MusicFlow discontinues the Service itself, the undertaking in the terms of service applies: at least 60 days’ prior notice and an opportunity to export.

11. Audit

  1. On request, MusicFlow makes available to the Organisation all information necessary to demonstrate compliance with Article 28 GDPR.
  2. A request for verification is handled in the first instance by providing documentation and answering a questionnaire. Where that proves demonstrably insufficient, MusicFlow cooperates with an on-site audit.
  3. An on-site audit is subject to: no more than once per calendar year, announced in writing at least 30 days in advance, during business hours, and without unnecessary disruption to operations — unless a supervisory authority prescribes otherwise or an established breach gives cause.
  4. The auditor is independent, is not a competitor of MusicFlow, and is bound by confidentiality. The audit findings are confidential and are used solely to assess compliance.
  5. Each party bears its own costs for the documentation referred to in paragraph 2. The reasonable costs incurred by MusicFlow for an on-site audit are borne by the Organisation, unless the audit reveals an attributable failure on the part of MusicFlow.

12. Obligations and warranties of the Organisation

The Organisation warrants that:

  • it has a valid legal basis for the processing of the personal data and, where data within the meaning of Article 9 GDPR is concerned, a valid exception under Article 9(2) GDPR;
  • it has informed its members and other data subjects about the processing, including the use of MusicFlow, in accordance with Articles 13 and 14 GDPR;
  • its instructions to MusicFlow are lawful and do not infringe the GDPR;
  • it is entitled to store the files it uploads and to share them within its organisation, and holds the necessary rights or licences to do so;
  • it does not upload or enter personal data that is not necessary for use of the Service;
  • the contact address it has provided is current.

The Organisation indemnifies MusicFlow against third-party claims — including from data subjects, rightsholders and supervisory authorities — and against the reasonable costs of defence arising therefrom, in so far as those claims arise from a breach of the warranties above. This indemnity does not apply in so far as the claim results from intent or conscious recklessness on the part of MusicFlow itself.

13. Liability

  1. The limitation of liability in the terms of service applies to this agreement.
  2. MusicFlow is not liable for indirect or consequential loss. This includes in any event: lost profits, missed performances, reputational harm, the cost of informing data subjects, and administrative fines imposed on the Organisation.
  3. The limitations in paragraphs 1 and 2 do not apply in the case of intent or conscious recklessness on the part of MusicFlow itself.
  4. Any claim lapses if it is not notified to MusicFlow in writing within twelve months after the Organisation became or could have become aware of the loss. This is without prejudice to the duty to complain under Article 6:89 of the Dutch Civil Code.
  5. MusicFlow is not liable for the acts or omissions of the providers of the optional notification channels referred to in clause 7, other than for their careful selection.

This clause does not limit: (a) a data subject’s right to compensation from MusicFlow under Article 82 GDPR; (b) the powers of a supervisory authority, including the imposition of an administrative fine under Article 83 GDPR; (c) liability that cannot be limited under mandatory law.

14. Final provisions

  1. This agreement is governed by Dutch law.
  2. Disputes are submitted to the competent court in the Netherlands.
  3. If any provision is void or voidable, the remaining provisions remain in force and the parties will replace that provision with a valid one approximating its intent as closely as possible.
  4. The Dutch text of this agreement is authoritative. In the event of any difference with a translation, the Dutch text prevails.
  5. MusicFlow may amend this agreement where legislation, case law or a change to the Service gives cause. Substantive amendments are announced at least 30 days in advance to the Organisation’s contact address. Clause 6(4) applies mutatis mutandis.

Annex A — Subprocessors

The current list is on the Subprocessors page and forms part of this agreement. For each party it states what it is engaged for, which data is involved, where that data is processed, and whether this takes place inside or outside the EEA. That list contains only subprocessors within the meaning of art. 28(4) GDPR: parties that process personal data on MusicFlow’s instruction. Components MusicFlow runs itself, parties that act as independent controllers, and channels used at the data subject’s own direction, are not subprocessors and are therefore not on it; the privacy statement names them where relevant.

Annex B — Security measures

Current as at this version; subject to change in accordance with clause 5(3).

  • Access and authorisation: role-based authorisation per organisation, with separation between organisations enforced in the software and covered by automated tests; hashed passwords; support for passkeys and two-factor authentication; access to production systems limited to the administrator(s).
  • Transport and storage: all traffic over TLS with automatically renewed certificates; storage within the EEA (Germany); a strict Content Security Policy with no external scripts, fonts or trackers.
  • Backup and recovery: daily backups retained as 7 daily, 4 weekly and 6 monthly snapshots; an off-site copy in object storage separate from the application server, encrypted client-side so that the storage provider holds only encrypted data; a documented and tested recovery procedure.
  • Logging and detection: application and access logs with a limited retention period (approximately 30 days); structured logging containing no personal data; monitoring of availability and error patterns with alerting.
  • Organisational: confidentiality obligations for everyone with access; periodic security updates of dependencies; changes managed through version control and an automated build and test pipeline.

Annex C — Contact points

Contact for data protection matters and for reporting incidents at MusicFlow: . For the Organisation, the contact address it has provided in the Service applies.

MusicFlow has not appointed a data protection officer; there is no obligation to do so under Article 37 GDPR.

View the subprocessor list