Data Processing Agreement

Last updated: October 8, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Hagen NK, trading as Artistu, and the customer for the use of the Artistu service (the "Agreement"), including our Terms and Conditions. It applies automatically to every customer who uses Artistu. A signed copy is available on request from [email protected].

1. Parties

Processor: Hagen NK, trading as Artistu, Utrechtseweg 310 B46, 6812 AR Arnhem, the Netherlands. Chamber of Commerce (KVK) 82235082, VAT NL862387929B01 ("Artistu", "we", "us").

Controller: the organization that has an Artistu account and agreed to the Agreement (the "Customer", "you").

2. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means the personal data that we process on behalf of the Customer when providing the service. "Sub-processor" means a third party we engage to process Customer Personal Data.

3. Roles and scope

The Customer is the controller of Customer Personal Data and Artistu is the processor. The subject matter, nature, purpose and duration of the processing and the categories of data and data subjects are described in Annex 1. Artistu acts as an independent controller only for the data it needs to run its own business, such as account administration, billing of the Customer and marketing, which is covered by our Privacy Policy.

4. Instructions

We process Customer Personal Data only on the documented instructions of the Customer. The Agreement, this DPA and the Customer's use and configuration of the service are the Customer's complete instructions. We will tell the Customer if we believe an instruction infringes the GDPR or other data protection law, unless the law forbids us to do so. If the law requires us to process data otherwise, we will inform the Customer first, unless that law prohibits it.

5. Confidentiality

Everyone at Artistu who has access to Customer Personal Data is bound by a duty of confidentiality and only accesses it where this is needed to provide, support or secure the service.

6. Security

We take appropriate technical and organizational measures to protect Customer Personal Data, as required by Article 32 GDPR. These measures are described in Annex 2. We may update them, provided the overall level of protection does not go down.

7. Sub-processors

The Customer gives general authorization for us to engage sub-processors. The current sub-processors are listed in Annex 3. We will announce any new or replacement sub-processor by updating Annex 3 and emailing the account owner at least 30 days before the change takes effect. The Customer may object on reasonable data protection grounds within that period. If we cannot address the objection, the Customer may terminate the affected part of the service and receive a refund of prepaid fees for the remaining term. We impose data protection obligations on every sub-processor that are no less protective than this DPA and remain responsible for their performance.

8. International transfers

Our primary database is hosted in the Netherlands and our file storage in Germany. Where a sub-processor processes Customer Personal Data outside the European Economic Area, the transfer is protected by an adequacy decision, including the EU-US Data Privacy Framework where the sub-processor is certified, or by the Standard Contractual Clauses adopted by the European Commission.

9. Data subject requests

Most requests, such as access, correction, export and deletion, can be handled by the Customer directly in Artistu. Where that is not possible, we will help the Customer respond to requests from data subjects. If a data subject contacts us directly about Customer Personal Data, we will forward the request to the Customer without answering it ourselves.

10. Personal data breaches

We will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, as far as known, the nature of the breach, the data and data subjects concerned, the likely consequences and the measures taken. We will help the Customer meet its own notification duties under Articles 33 and 34 GDPR.

11. Assistance

Taking into account the nature of the processing and the information available to us, we will help the Customer with data protection impact assessments and prior consultations with a supervisory authority, where these relate to the service.

12. Return and deletion

The Customer can export its data from Artistu at any time. When the Agreement ends, we delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in backups are overwritten in the normal backup cycle and no later than 90 days after deletion.

13. Audits

We will make available the information needed to demonstrate compliance with Article 28 GDPR. The Customer, or an independent auditor bound by confidentiality, may audit our compliance with this DPA once a year on 30 days' written notice, during business hours and at the Customer's own cost, or at any time after a personal data breach. Audits of sub-processors take place through the certifications and reports those sub-processors make available.

14. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Agreement, unless the GDPR does not allow such a limitation.

15. Term, precedence and law

This DPA stays in force as long as we process Customer Personal Data. If this DPA conflicts with the Agreement, this DPA prevails on matters of data protection. This DPA is governed by Dutch law. Disputes are submitted to the competent court in Arnhem, the Netherlands.

Annex 1: Description of the processing

Subject matter and purpose: providing the Artistu service, a platform for artist agencies and managers to manage artists, bookings, agreements, electronic signatures, invoices, advancing, itineraries, guestlists, press kits and related communication.

Nature of the processing: storing, organizing, displaying, sending, generating documents from and deleting data entered by the Customer or by people the Customer invites.

Duration: the term of the Agreement plus the deletion period in section 12.

Categories of data subjects:

  • the Customer's team members who use Artistu
  • artists and artist team members
  • promoters, venues, clients and other business contacts of the Customer
  • people who sign agreements, fill in forms, submit offers or are added to guestlists
  • crew and travel party members named in itineraries

Categories of personal data:

  • names, job titles, email addresses and phone numbers
  • postal and billing addresses, company details, VAT and tax numbers and bank account numbers (IBAN)
  • booking, fee, invoice and payment details linked to a person
  • travel and itinerary details, which can include a date of birth when the Customer enters it
  • electronic signatures and the signing audit trail: name, job title, IP address, device information and timestamps
  • content of emails, notes and documents the Customer creates or uploads
  • technical data such as IP addresses, browser information and usage logs

Special categories of data: none are required for the service. The Customer should not enter special categories of personal data, unless it has a legal basis to do so.

Annex 2: Security measures

  • Customer data is hosted in the European Union, with the database in the Netherlands and file storage in Germany.
  • All traffic to and from Artistu is encrypted with TLS. Uploaded files are stored encrypted at rest.
  • Every organization's data is logically separated, and every request is checked against the organization and the user's permissions.
  • Customers control who can see what through roles and permissions. Sign-in is handled by Clerk and supports multi-factor authentication.
  • Customer links, such as signing and advancing links, use long random keys and can be revoked.
  • Electronic signatures keep an audit trail with a SHA-256 fingerprint of the signed document.
  • Access to production systems is limited to the people who need it, protected with multi-factor authentication and not shared.
  • The database is backed up daily. Errors are monitored so problems are found and fixed quickly.
  • Sub-processors are chosen for their security practices and bound by data processing terms.

Annex 3: Sub-processors

Sub-processorPurposeData locationTransfer safeguard
Railway CorporationApplication hosting and primary databaseAmsterdam, the NetherlandsData stored in the EU, SCCs for remote access
Amazon Web Services EMEA SARLFile storage, transactional email and scheduled jobsFrankfurt, GermanyData stored in the EU, SCCs and EU-US DPF
Clerk, Inc.User sign-in and account managementUnited StatesSCCs and EU-US DPF
Stripe Payments Europe, Ltd.Subscription billing and online invoice paymentsIreland and United StatesSCCs and EU-US DPF
Functional Software, Inc. (Sentry)Error monitoringFrankfurt, GermanyData stored in the EU, SCCs for remote access
PostHog, Inc.Product usage analyticsFrankfurt, GermanyData stored in the EU, SCCs for remote access
Crisp IM SASIn-app customer support chatFranceNot applicable (EU)
Google Ireland LimitedAddress lookup and geocoding (Google Maps Platform), push notifications on Android (Firebase Cloud Messaging)Ireland and United StatesSCCs and EU-US DPF
Recommand BVPeppol e-invoice delivery, only when the customer enables PeppolBelgiumNot applicable (EU)
Cloudflare, Inc.DNS, network security and traffic routingGlobal networkSCCs and EU-US DPF