The customer identified in the Agreement ("Customer") and CRDNTR ("Provider") (each a "Party" and together the "Parties") enter into this Data Processing Addendum, including its annexes (this "DPA"). This DPA forms part of, and is governed by, the agreement between the Parties covering Customer’s use of the Services (as amended, the "Agreement"), including our Terms of Use.
To request a countersigned copy of this DPA, email legal@crdntr.io, including your organization’s legal name, address, and data-protection contact. We will return an executed copy with Annex 1 completed.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement.
- Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract, or otherwise.
- Applicable Data Protection Laws means the privacy, data protection, and data security laws and regulations of any jurisdiction within the United States applicable to Provider’s Processing of Personal Data under the Agreement, including, as and to the extent applicable, the State Privacy Laws.
- Customer Data means information provided or otherwise made available by or on behalf of Customer to Provider for Processing on Customer’s behalf to perform the Services.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates.
- Information Security Incident means a breach of Provider’s security resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data in Provider’s possession, custody, or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
- Personal Data means Customer Data that constitutes "personal data," "personal information," or "personally identifiable information" as defined in Applicable Data Protection Laws, or information of a similar character regulated by them. Personal Data does not include such information pertaining to Customer’s business contacts who are Customer personnel, or such information that Provider receives, collects, or generates independently of the Services and not from or on behalf of Customer.
- Process or Processing means any operation or set of operations performed by Provider, or on Provider’s behalf, for Customer under the Agreement on Personal Data, whether or not by automated means — including collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Security Measures has the meaning given in Section 4(a).
- Services has the meaning given in the Agreement.
- State Privacy Laws means, collectively, the comprehensive state-specific data privacy laws, and any implementing regulations, currently in effect and applicable to Provider’s Processing of Personal Data under the Agreement.
- Subprocessors means Provider’s Affiliates and third parties that Provider engages to Process Personal Data in relation to the Services.
2. Duration and scope
This DPA remains in effect so long as Provider Processes Personal Data, notwithstanding the expiration or termination of the Agreement.
Processing of Personal Data subject to the State Privacy Laws, with respect to which Customer is a Business, Controller, Processor, or Service Provider as those terms are defined in the State Privacy Laws, is subject to Annex 2 (State Privacy Laws Annex).
3. Customer instructions
Provider will Process Personal Data only in accordance with Customer’s documented instructions, including as set out in this DPA, the Agreement, any applicable order form, and any other written instructions Customer provides from time to time that are consistent with the Agreement and this DPA. To the extent Customer requests instructions outside the scope of the Services, or that would require Provider to materially change the Services or undertake additional work not contemplated by the Agreement, the Parties will agree to those instructions in a mutually executed amendment to this DPA or other written agreement.
By entering into this DPA, Customer instructs Provider to Process Personal Data to provide the Services and to perform its other obligations and exercise its rights under the Agreement. The Parties agree that the details of Provider’s Processing of Personal Data, including the respective roles of the Parties, are as described in Annex 1 (Data Processing Details).
4. Security
(a) Provider security measures.Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data, as described in Annex 3 (the "Security Measures"), taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing and the risks to Data Subjects. Provider may update the Security Measures from time to time, including to maintain or improve security or address changes in Applicable Data Protection Laws, so long as the updated measures do not materially decrease the overall protection of Personal Data.
(b) Security compliance by Provider staff. Provider will require that its personnel authorized to access Personal Data are subject to appropriate confidentiality obligations.
(c) Information Security Incidents.Provider will notify Customer without undue delay of any Information Security Incident of which Provider becomes aware. The notification will describe, to the extent then known, available details of the incident, including steps taken to mitigate the potential risks and steps Provider recommends Customer take. Provider’s notification of or response to an Information Security Incident is not an acknowledgement of fault or liability. Provider will reasonably cooperate with Customer and take commercially reasonable steps, to the extent within Provider’s control, as may be reasonably requested by Customer and mutually agreed in good faith, to assist in the investigation. Customer is solely responsible for complying with notification laws applicable to Customer and for fulfilling any third-party notification obligations. If Customer determines that an Information Security Incident must be notified to a regulatory authority, Data Subjects, the public, or others, and that notice directly or indirectly refers to or identifies Provider, then where permitted by applicable law Customer agrees to (i) notify Provider in advance, and (ii) consult in good faith with Provider and consider any clarifications or corrections Provider may reasonably request that relate to Provider’s involvement in the incident and are consistent with applicable law.
(d) Customer’s security responsibilities.Without limiting Provider’s obligations under this Section 4, Customer is solely responsible for its use of the Services, including (i) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (ii) securing the account authentication credentials, systems, and devices Customer uses to access the Services; (iii) securing Customer’s systems and devices that Customer provides or makes available for Provider to access in order to provide the Services; and (iv) backing up Personal Data, as applicable.
(e) Customer’s security assessment.Customer acknowledges that it has evaluated the Services, the Security Measures, and Provider’s commitments under this DPA and, based on information made available by Provider, determines that they are adequate to meet Customer’s needs, including with respect to any security obligations of Customer under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.
5. Data subject rights
(a) Provider assistance.Taking into account the nature of the Processing, Provider will provide Customer with assistance reasonably necessary and technically feasible for Customer to perform its obligations under Applicable Data Protection Laws to fulfill requests by Data Subjects to exercise their rights ("Data Subject Requests") with respect to Personal Data in Provider’s possession or control. To the extent such assistance requires work beyond the Services, Customer will compensate Provider at Provider’s then-current professional services rates, made available on request, and Provider will on request provide a good-faith estimate of applicable fees.
(b) Customer responsibility for requests. If Provider receives a Data Subject Request, Provider will (i) promptly notify Customer, unless prohibited by applicable law, and (ii) advise the Data Subject to submit the request to Customer. Customer is solely responsible for responding to any such request, unless otherwise required by applicable law.
6. Customer responsibilities
(a) Customer will ensure, and is solely responsible for ensuring, that it has provided all notices to and obtained all consents and permissions from third parties, including Data Subjects, and has reserved all necessary rights, in each case as may be required under Applicable Data Protection Laws for Provider to Process Personal Data as contemplated by the Agreement.
(b) Customer represents and warrants that Customer Data does not and will not contain: social security numbers or other government-issued identification numbers; protected health information subject to HIPAA or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; health insurance information; biometric information; passwords or other credentials for third-party online accounts, other than credentials created for and used solely to access the Services; credentials to any financial accounts; tax return data; any payment card information subject to the Payment Card Industry Data Security Standard; personal data of children under 16 years of age; or any other information falling within any special categories of data as defined in Applicable Data Protection Laws ("Restricted Data").
7. Subprocessors
(a) Consent to engagement.Customer specifically authorizes the engagement of Provider’s Affiliates as Subprocessors and generally authorizes Provider to engage third parties as Subprocessors in accordance with this Section 7.
(b) Information about Subprocessors. Information about Subprocessors, including their functions and locations, is available in Annex 4 (List of Subprocessors). Provider may continue to use Subprocessors already engaged as of the effective date of this DPA.
(c) Requirements for engagement. When engaging any Subprocessor, Provider will enter into a written contract with that Subprocessor containing data protection obligations not less protective than those in this DPA with respect to Personal Data, to the extent applicable to the nature of the services provided. Provider remains responsible for the performance of all obligations subcontracted to the Subprocessor and is liable for all acts and omissions of the Subprocessor to the same extent as if Provider had performed the Processing itself.
(d) Opportunity to object.When Provider engages a new Subprocessor after the effective date of this DPA, Provider will notify Customer of the engagement, including the name and location of the Subprocessor and the activities it will perform, by updating Annex 4 and providing written notice, including by email, to Customer’s designated contact for Services-related communications. If Customer objects within 15 days after receipt of that notice on reasonable grounds relating to the protection of Personal Data, the Parties will work together in good faith to find a mutually acceptable resolution. If the Parties cannot reach a resolution within a reasonable timeframe, Customer may, as its sole and exclusive remedy, terminate the Agreement and cancel the Services by written notice to Provider and pay Provider all amounts due and owing as of the date of termination.
8. Audits
Customer may audit Provider’s compliance with its obligations under this DPA up to once per year, and on such other occasions as required by Applicable Data Protection Laws solely to the extent Customer is legally required to conduct an additional audit or a competent regulatory authority with jurisdiction over Customer requires it, in each case upon Customer’s written request providing reasonable detail and, where available, supporting documentation of the applicable requirement. Provider will contribute to such audits by providing the information and assistance reasonably necessary to conduct the audit.
If a third party is to conduct the audit, Provider may object to the auditor if, in Provider’s reasonable opinion, the auditor is not independent, is a competitor of Provider, or is otherwise manifestly unsuitable, in which case Customer will appoint another auditor or conduct the audit itself. To request an audit, Customer must submit a proposed audit plan at least two weeks before the proposed audit date describing the proposed scope, duration, and start date, and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the Parties, such acceptance not to be unreasonably withheld. Provider will review the proposed plan and raise any concerns or questions, for example any request for information that could compromise Provider security, privacy, employment, or other relevant policies, and will work cooperatively with Customer to agree on a final audit plan. Nothing in this Section 8 requires Provider to breach any duties of confidentiality.
If the controls or measures to be assessed are addressed in a SOC 2 Type 2, ISO, NIST, or similar audit report performed by a qualified third-party auditor within 12 months of Customer’s audit request, and Provider has confirmed there have been no known material changes in the controls audited since the date of that report, Customer agrees to accept that report in lieu of requesting an audit of those controls or measures.
Audits must be conducted during regular business hours, subject to the agreed final audit plan and Provider’s safety, security, and other relevant policies, and may not unreasonably interfere with Provider’s business activities. Customer will promptly notify Provider of any non-compliance discovered during an audit and provide Provider any audit reports generated, unless prohibited by Applicable Data Protection Laws. Customer may use audit reports only to meet its regulatory audit requirements or to confirm compliance with this DPA. Audits are at Customer’s sole expense, and Customer will reimburse Provider for reasonable, documented costs, including reasonable internal time expended by Provider and any third parties, at Provider’s then-current professional services rates.
9. Return and deletion
(a) Subject to Sections 9(b) and 9(c), upon the date of cessation of any Services involving the Processing of Personal Data (the "Cessation Date"), Provider will promptly cease all Processing of Personal Data for any purpose other than storage and Processing necessary to effect the return, deletion, or anonymization of that Personal Data, or as otherwise permitted or required under this DPA or applicable law.
(b) Subject to Section 9(d), and to the extent technically possible in the circumstances, on written request made no later than 30 days after the Cessation Date (the "Post-cessation Storage Period"), Provider will within a commercially reasonable period either (i) return a complete copy of all Personal Data within Provider’s possession to Customer by secure file transfer or other commercially reasonable secure method, promptly following which Provider will delete or anonymize all other copies, or (ii) at its option, delete or anonymize all Personal Data within Provider’s possession.
(c) If during the Post-cessation Storage Period Customer does not instruct Provider in writing to either delete or return Personal Data under Section 9(b), Provider will, within a commercially reasonable time after the expiry of that period, at its option delete or render anonymous all Personal Data then within its possession, custody, or control to the fullest extent technically feasible.
(d) Provider may retain Personal Data to the extent permitted or required by applicable law, for no longer than that law requires, provided that Provider will (i) maintain the confidentiality of the Personal Data and protect it in accordance with the Security Measures, (ii) Process it only as necessary for the purposes specified in the law permitting or requiring the retention, and (iii) delete or anonymize it once retention is no longer permitted or required.
10. Artificial intelligence and automated processing
(a) Provider will not use Personal Data to train, fine-tune, develop, or improve any artificial intelligence or machine learning model, whether Provider’s own or a third party’s, unless the use is reasonably necessary to provide the Services in accordance with Customer’s documented instructions, or is expressly authorized by Customer in writing.
(b) Provider will prohibit its Subprocessors, including any AI model providers, from using Personal Data for their own model training, fine-tuning, development, or improvement purposes, except as expressly authorized by Customer in writing.
(c) If the Services involve automated decision-making that produces legal or similarly significant effects on Data Subjects, Provider will (i) disclose the existence of that processing to Customer; (ii) to the extent reasonably available, provide meaningful information about the logic involved without requiring disclosure of Provider’s trade secrets or confidential information; and (iii) reasonably cooperate with Customer, as required by Applicable Data Protection Laws, to enable Data Subjects to exercise applicable rights relating to automated decision-making.
11. Miscellaneous
Except as expressly modified by this DPA, the terms of the Agreement remain in full force and effect. To the extent of any conflict or inconsistency between this DPA and the other terms of the Agreement, this DPA governs. Notwithstanding anything in the Agreement or any order form to the contrary, the Parties acknowledge and agree that Provider’s access to Personal Data does not constitute part of the consideration exchanged by the Parties in respect of the Agreement.
Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Provider to Customer under this DPA may be given (a) in accordance with any notice clause of the Agreement; (b) to Customer’s contact details for data protection set out in Annex 1; (c) to Provider’s primary points of contact with Customer; or (d) to any email address designated by Customer in writing for the purpose of receiving Services-related communications or alerts. Customer is solely responsible for ensuring those email addresses are valid.
Provider agrees to cooperate in good faith with Customer to consider any amendments reasonably necessary to address compliance with Applicable Data Protection Laws. Provider may, on written notice, vary this DPA solely to the extent necessary to maintain compliance with Applicable Data Protection Laws from time to time, provided that any such variation will not materially reduce the protections afforded to Personal Data or materially increase Customer’s obligations without Customer’s written agreement.
The total aggregate liability of either Party to the other, however arising, under or in connection with this DPA will under no circumstances exceed any limitations or caps on, and will be subject to any exclusions of, liability and loss agreed by the Parties in the Agreement.
Annex 1 — Data processing details
Provider details
- Name: CRDNTR
- Address: 1533 N Vista St, 301, Los Angeles, CA 90046, United States
- Contact for data protection: legal@crdntr.io
- Provider activities: CRDNTR operates a talent booking and event operations platform for promoters, venues, agencies, artist managers, and tour managers, including offer and contract workflow, production advancing, marketing and settlement tools, and ticket sales.
Customer details
Completed on execution. Customer is the entity that is a counterparty to the Agreement. Customer’s address and data-protection contact are as provided by Customer when requesting a countersigned copy of this DPA.
Customer activities:Customer’s activities relevant to this DPA are the use and receipt of the Services under and in accordance with, and for the purposes anticipated and permitted in, the Agreement, as part of its ongoing business operations.
Processing details
- Categories of Data Subjects:any Data Subjects whose Personal Data Customer causes Provider to Process in connection with the Services, including Customer’s personnel and contractors; artists, agents, managers, and other industry contacts recorded by Customer; venue and production personnel; and ticket buyers and attendees of Customer’s events.
- Categories of Personal Data: personal details such as name and contact information; authentication details such as usernames and access credentials created for the Services; technological details such as IP addresses, unique identifiers including identifiers in cookies or similar technology, pseudonymous identifiers, approximate location data, application activity data, and device identifiers; and, for ticket buyers, order and attendance records.
- Sensitive categories of data:none. As stated in Section 6(b), Customer agrees that Restricted Data must not be submitted to the Services without the Parties’ prior written agreement.
- Additional safeguards for sensitive data: not applicable.
- Frequency of transfer: ongoing, as initiated by Customer in and through its use of the Services.
- Nature of the Processing:Processing operations required to provide the Services and perform Provider’s obligations under the Agreement and this DPA.
- Purpose of the Processing:as necessary to provide the Services as initiated by Customer, and to comply with Customer’s documented instructions as permitted under this DPA and the Agreement.
- Duration of Processing and retention: for the period determined in accordance with the Agreement and this DPA, including Section 9.
- Transfers to Subprocessors: as described from time to time in Annex 4 (List of Subprocessors).
Annex 2 — State Privacy Laws annex
1.For purposes of this Annex 2, the terms "business," " controller," "processor," "commercial purpose," "sell, " "share," "service provider," and "contractor" have the meanings given in the applicable State Privacy Laws, and "personal information" means Personal Data to the extent it constitutes "personal information" or "personal data," or a similar term, governed by the State Privacy Laws.
2.It is the Parties’ intent that, with respect to any personal information, Provider is a service provider, contractor, and/or processor, as applicable under the State Privacy Laws. Provider (a) acknowledges that personal information is disclosed by Customer only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and will provide the same level of privacy protection to personal information as is required by the State Privacy Laws; (c) agrees that Customer has the right to take reasonable and appropriate steps to help ensure that Provider’s Processing of personal information is consistent with Customer’s obligations under the State Privacy Laws; (d) will notify Customer in writing of any determination made by Provider that it can no longer meet its obligations under the State Privacy Laws; and (e) agrees that Customer has the right, upon reasonable notice, including under the preceding clause, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information.
3.Provider will not (a) sell or share any personal information; (b) retain, use, or disclose any personal information for any purpose other than the specific purpose of providing the Services, including retaining, using, or disclosing personal information for a commercial purpose other than the provision of the Services, or as otherwise permitted by the State Privacy Laws; (c) retain, use, or disclose personal information outside of the direct business relationship between Provider and Customer; or (d) combine personal information received under the Agreement with personal information received from or on behalf of another person, or collected from Provider’s own interaction with the Data Subject, except as and to the extent permitted by the State Privacy Laws and necessary as part of Provider’s provision of the Services. Provider certifies that it understands the obligations in this Section 3 and will comply with them.
4.Giving Customer notice of Subprocessor engagements in accordance with Section 7 of the DPA satisfies Provider’s obligation under the State Privacy Laws to give notice of, and an opportunity to object to, those engagements.
5.Customer may conduct audits in accordance with Section 8 of the DPA to help ensure that Provider’s use of personal information is consistent with Provider’s obligations under the State Privacy Laws.
6.The Parties acknowledge that Provider’s retention, use, and disclosure of personal information authorized by Customer’s instructions documented in the Agreement and this DPA are integral to Provider’s provision of the Services and to the business relationship between the Parties.
Annex 3 — Security measures
Provider maintains, at a minimum, the following measures:
- Organizational management and personnel with assigned responsibility for the development, implementation, and maintenance of Provider’s information security program.
- Audit and risk assessment procedures for periodic review and assessment of risks to Provider’s organization, monitoring and maintaining compliance with Provider’s policies and procedures, and reporting the condition of its information security and compliance to internal senior management.
- Data security controls including, at a minimum, logical segregation of data, restricted role-based access and monitoring, and use of commercially available industry-standard encryption technologies, or materially equivalent safeguards, for Personal Data transmitted over public networks or wirelessly, and at rest.
- Logical access controls designed to manage electronic access to data and system functionality based on authority levels and job functions, including granting access on a need-to-know and least-privilege basis, unique user IDs and appropriate authentication credentials for all users, and periodic review and prompt revocation or change of access when employment terminates or job functions change.
- Password controls designed to manage and control password strength, expiration, and usage, including prohibiting password sharing and maintaining controls consistent with generally accepted industry standards and appropriate to the risk: minimum password length and/or multi-factor authentication as appropriate; no storage in readable format; appropriate complexity or compensating controls; a history threshold to prevent reuse of recent passwords; and newly issued or reset passwords being changed after first use.
- System audit and event logging and related monitoring procedures to proactively record user access and system activity.
- Physical and environmental security of data centers, server room facilities, and other areas containing Personal Data, designed to protect information assets from unauthorized physical access, to manage, monitor, and log movement of persons into and out of facilities as appropriate, and to guard against environmental hazards such as heat, fire, and water damage.
- Operational procedures and controls providing for the secure configuration, monitoring, and maintenance of technology and information systems, including secure disposal of systems and media in accordance with commercially reasonable industry standards.
- Change management procedures and tracking mechanisms designed to test, approve, and monitor all material changes to Provider’s technology and information assets that may affect the security of Personal Data.
- Incident management procedures designed to allow Provider to investigate, respond to, mitigate, and provide notifications in accordance with this DPA.
- Network security controls designed to protect systems from intrusion and limit the scope of any successful attack, including firewalls and network segmentation, intrusion detection and/or prevention, monitoring, and traffic and event correlation procedures.
- Vulnerability assessment, patch management, and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate, and protect against identified security threats, viruses, and other malicious code.
- Business resiliency, continuity, and disaster recovery procedures designed to maintain service and recover from foreseeable emergencies or disasters.
Annex 4 — List of Subprocessors
Customer approves Provider’s engagement of the following Subprocessors to provide services under the Agreement. Unless otherwise noted, Processing takes place in the United States.
- Neon — managed PostgreSQL hosting for the primary application database.
- Vercel — application hosting and delivery, file and document storage, and product analytics.
- Clerk — user authentication, session management, and identity records.
- Stripe — payment processing for subscriptions and ticket sales, including payout and fraud-prevention services.
- Twilio — SMS delivery and phone-number verification.
- Resend — transactional and outbound email delivery.
- Sentry — application error and performance monitoring.
- Upstash — ephemeral caching and rate limiting.
- Anthropic — AI-assisted features including document extraction and drafting. Personal Data submitted to these features is not used to train models.
- Mapbox — map rendering and geocoding.
- Google — venue and address search, and, where Customer connects a Google account, Gmail and Google Calendar integration.
- Microsoft — where Customer connects a Microsoft account, Outlook mail and calendar integration.
- Cloudflare — bot and abuse protection on public forms.
- Termly — cookie consent management and consent recordkeeping.
- Apple — delivery of Apple Wallet passes to attendees who choose to add a ticket to Wallet.
To be notified when this list changes, email legal@crdntr.io and ask to be added to the Subprocessor notification list.