Data Processing Agreement
Last updated: October 8, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Hagen NK, trading as Artistu, and the customer for the use of the Artistu service (the "Agreement"), including our Terms and Conditions. It applies automatically to every customer who uses Artistu. A signed copy is available on request from [email protected].
1. Parties
Processor: Hagen NK, trading as Artistu, Utrechtseweg 310 B46, 6812 AR Arnhem, the Netherlands. Chamber of Commerce (KVK) 82235082, VAT NL862387929B01 ("Artistu", "we", "us").
Controller: the organization that has an Artistu account and agreed to the Agreement (the "Customer", "you").
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"). "Customer Personal Data" means the personal data that we process on behalf of the Customer when providing the service. "Sub-processor" means a third party we engage to process Customer Personal Data.
3. Roles and scope
The Customer is the controller of Customer Personal Data and Artistu is the processor. The subject matter, nature, purpose and duration of the processing and the categories of data and data subjects are described in Annex 1. Artistu acts as an independent controller only for the data it needs to run its own business, such as account administration, billing of the Customer and marketing, which is covered by our Privacy Policy.
4. Instructions
We process Customer Personal Data only on the documented instructions of the Customer. The Agreement, this DPA and the Customer's use and configuration of the service are the Customer's complete instructions. We will tell the Customer if we believe an instruction infringes the GDPR or other data protection law, unless the law forbids us to do so. If the law requires us to process data otherwise, we will inform the Customer first, unless that law prohibits it.
5. Confidentiality
Everyone at Artistu who has access to Customer Personal Data is bound by a duty of confidentiality and only accesses it where this is needed to provide, support or secure the service.
6. Security
We take appropriate technical and organizational measures to protect Customer Personal Data, as required by Article 32 GDPR. These measures are described in Annex 2. We may update them, provided the overall level of protection does not go down.
7. Sub-processors
The Customer gives general authorization for us to engage sub-processors. The current sub-processors are listed in Annex 3. We will announce any new or replacement sub-processor by updating Annex 3 and emailing the account owner at least 30 days before the change takes effect. The Customer may object on reasonable data protection grounds within that period. If we cannot address the objection, the Customer may terminate the affected part of the service and receive a refund of prepaid fees for the remaining term. We impose data protection obligations on every sub-processor that are no less protective than this DPA and remain responsible for their performance.
8. International transfers
Our primary database is hosted in the Netherlands and our file storage in Germany. Where a sub-processor processes Customer Personal Data outside the European Economic Area, the transfer is protected by an adequacy decision, including the EU-US Data Privacy Framework where the sub-processor is certified, or by the Standard Contractual Clauses adopted by the European Commission.
9. Data subject requests
Most requests, such as access, correction, export and deletion, can be handled by the Customer directly in Artistu. Where that is not possible, we will help the Customer respond to requests from data subjects. If a data subject contacts us directly about Customer Personal Data, we will forward the request to the Customer without answering it ourselves.
10. Personal data breaches
We will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, as far as known, the nature of the breach, the data and data subjects concerned, the likely consequences and the measures taken. We will help the Customer meet its own notification duties under Articles 33 and 34 GDPR.
11. Assistance
Taking into account the nature of the processing and the information available to us, we will help the Customer with data protection impact assessments and prior consultations with a supervisory authority, where these relate to the service.
12. Return and deletion
The Customer can export its data from Artistu at any time. When the Agreement ends, we delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in backups are overwritten in the normal backup cycle and no later than 90 days after deletion.
13. Audits
We will make available the information needed to demonstrate compliance with Article 28 GDPR. The Customer, or an independent auditor bound by confidentiality, may audit our compliance with this DPA once a year on 30 days' written notice, during business hours and at the Customer's own cost, or at any time after a personal data breach. Audits of sub-processors take place through the certifications and reports those sub-processors make available.
14. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, unless the GDPR does not allow such a limitation.
15. Term, precedence and law
This DPA stays in force as long as we process Customer Personal Data. If this DPA conflicts with the Agreement, this DPA prevails on matters of data protection. This DPA is governed by Dutch law. Disputes are submitted to the competent court in Arnhem, the Netherlands.
Annex 1: Description of the processing
Subject matter and purpose: providing the Artistu service, a platform for artist agencies and managers to manage artists, bookings, agreements, electronic signatures, invoices, advancing, itineraries, guestlists, press kits and related communication.
Nature of the processing: storing, organizing, displaying, sending, generating documents from and deleting data entered by the Customer or by people the Customer invites.
Duration: the term of the Agreement plus the deletion period in section 12.
Categories of data subjects:
- the Customer's team members who use Artistu
- artists and artist team members
- promoters, venues, clients and other business contacts of the Customer
- people who sign agreements, fill in forms, submit offers or are added to guestlists
- crew and travel party members named in itineraries
Categories of personal data:
- names, job titles, email addresses and phone numbers
- postal and billing addresses, company details, VAT and tax numbers and bank account numbers (IBAN)
- booking, fee, invoice and payment details linked to a person
- travel and itinerary details, which can include a date of birth when the Customer enters it
- electronic signatures and the signing audit trail: name, job title, IP address, device information and timestamps
- content of emails, notes and documents the Customer creates or uploads
- technical data such as IP addresses, browser information and usage logs
Special categories of data: none are required for the service. The Customer should not enter special categories of personal data, unless it has a legal basis to do so.
Annex 2: Security measures
- Customer data is hosted in the European Union, with the database in the Netherlands and file storage in Germany.
- All traffic to and from Artistu is encrypted with TLS. Uploaded files are stored encrypted at rest.
- Every organization's data is logically separated, and every request is checked against the organization and the user's permissions.
- Customers control who can see what through roles and permissions. Sign-in is handled by Clerk and supports multi-factor authentication.
- Customer links, such as signing and advancing links, use long random keys and can be revoked.
- Electronic signatures keep an audit trail with a SHA-256 fingerprint of the signed document.
- Access to production systems is limited to the people who need it, protected with multi-factor authentication and not shared.
- The database is backed up daily. Errors are monitored so problems are found and fixed quickly.
- Sub-processors are chosen for their security practices and bound by data processing terms.
Annex 3: Sub-processors
| Sub-processor | Purpose | Data location | Transfer safeguard |
|---|---|---|---|
| Railway Corporation | Application hosting and primary database | Amsterdam, the Netherlands | Data stored in the EU, SCCs for remote access |
| Amazon Web Services EMEA SARL | File storage, transactional email and scheduled jobs | Frankfurt, Germany | Data stored in the EU, SCCs and EU-US DPF |
| Clerk, Inc. | User sign-in and account management | United States | SCCs and EU-US DPF |
| Stripe Payments Europe, Ltd. | Subscription billing and online invoice payments | Ireland and United States | SCCs and EU-US DPF |
| Functional Software, Inc. (Sentry) | Error monitoring | Frankfurt, Germany | Data stored in the EU, SCCs for remote access |
| PostHog, Inc. | Product usage analytics | Frankfurt, Germany | Data stored in the EU, SCCs for remote access |
| Crisp IM SAS | In-app customer support chat | France | Not applicable (EU) |
| Google Ireland Limited | Address lookup and geocoding (Google Maps Platform), push notifications on Android (Firebase Cloud Messaging) | Ireland and United States | SCCs and EU-US DPF |
| Recommand BV | Peppol e-invoice delivery, only when the customer enables Peppol | Belgium | Not applicable (EU) |
| Cloudflare, Inc. | DNS, network security and traffic routing | Global network | SCCs and EU-US DPF |
Signatures
Signing is optional. This DPA applies to every customer without a signature.