Data processing
Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the Business Terms of Service whenever Riera Studio processes personal data on behalf of a business customer.
The Customer is controller and the Riera Studio operator is processor for Customer Personal Data. Each party remains independently responsible for personal data it processes as controller.
1. Scope and duration
This DPA applies to Customer Personal Data submitted to or generated within a private Riera Studio workspace. Processing begins when the Customer uses the Service and continues until deletion or return following termination, subject to lawful retention and backup expiry.
The Business Terms, documented product functions, workspace settings, support instructions and lawful written requests are the Customer’s documented instructions. Riera Studio will notify the Customer if an instruction appears to infringe applicable data protection law, unless prohibited from doing so.
2. Processing details
Subject matter: hosting and operation of event-supplier business records, account access, collaboration, document generation, imports, exports, support, security, backup and recovery.
Nature and purpose: collection from Customer users, storage, organisation, retrieval, display, calculation, document generation, transmission to authorised recipients, support access, security monitoring, export and deletion.
Data subjects may include Customer staff, contractors, clients, prospects, venue contacts, suppliers, crew, invoice contacts and other business contacts entered by the Customer.
Data may include names, business contact details, addresses, event details, notes, correspondence, service history, invoice and payment records, documents, account roles, authentication references and technical audit data. Full payment card data is not intended to be stored in Customer workspace fields.
The standard Service is not designed for large-scale special-category data, medical records, criminal-offence data or children’s data. The Customer must not enter such data without prior written agreement and appropriate safeguards.
3. Processor obligations
Riera Studio will process Customer Personal Data only on documented instructions or where required by applicable law. Where law requires processing beyond instructions, the Customer will be informed before processing unless law prohibits notice.
People authorised to process Customer Personal Data are subject to confidentiality obligations and receive access only where required for service operation, support, security or legal compliance.
Riera Studio will maintain technical and organisational measures appropriate to the risk, assist the Customer with data subject rights and regulatory obligations, and make information reasonably necessary to demonstrate compliance available to the Customer.
4. Security measures
Measures include authenticated access, company-scoped membership and role checks, row-level database security, restricted service credentials, private document access, encrypted transport, provider access controls, audit logging, backups, incident handling and secure development practices.
Riera Studio reviews access and architecture as the Service changes. The Customer is responsible for secure devices, individual accounts, suitable passwords, membership review, lawful exports and prompt reporting of suspected compromise.
5. Subprocessors
The Customer gives general authorisation for the subprocessors listed on the Subprocessors page. Riera Studio remains responsible for engaging subprocessors under written terms that provide materially equivalent data protection obligations.
Material additions or replacements are published before they take effect where practical. A Customer with a reasonable data protection objection may contact Riera Studio promptly. The parties will attempt a practical solution; where none is available, the Customer may terminate the affected Service before the change takes effect.
6. International transfers
Where Customer Personal Data is transferred outside the United Kingdom or EEA in a restricted transfer, Riera Studio or the relevant subprocessor will use an applicable adequacy decision, EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful mechanism.
The Customer authorises Riera Studio to enter relevant transfer clauses on its behalf where required for subprocessing. Supplementary technical, contractual or organisational measures are applied where the transfer assessment requires them.
7. Data subject requests
If Riera Studio receives a request relating to Customer Personal Data, it will normally direct the individual to the Customer unless law requires direct action. Riera Studio will provide reasonable technical assistance through search, correction, export, restriction or deletion functions available in the Service.
The Customer remains responsible for deciding whether a right applies and for communicating the substantive response. Assistance beyond standard product functions may be charged at reasonable cost where the request is unusually complex, after notice.
8. Personal data breaches
Riera Studio will notify the Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. Notice will include available information about the nature, likely consequences, affected data, containment and recommended steps.
Information may be supplied in phases as investigation continues. Notification is not an admission of fault. The Customer is responsible for regulator and data-subject notification decisions as controller, with reasonable assistance from Riera Studio.
9. DPIAs and regulator cooperation
Taking account of the nature of processing and information available, Riera Studio will provide reasonable assistance with data protection impact assessments and prior consultation that relate specifically to use of the Service.
Each party will cooperate with a competent supervisory authority as required by applicable law.
10. Audit and evidence
Riera Studio will provide current policies, security information, subprocessor details and other reasonable evidence needed to demonstrate compliance. The Customer should first use that information before requesting an audit.
Where an on-site or specialist audit is legally necessary, it must be limited to relevant systems, scheduled with reasonable notice, protect other customers and confidential information, avoid operational disruption and be performed by an independent qualified auditor. The requesting Customer bears reasonable costs unless the audit identifies a material breach by Riera Studio.
11. Return, export and deletion
During the contract and available recovery period, the Customer can request or use available exports in commonly used machine-readable formats. Riera Studio will not intentionally obstruct a lawful switch to another provider.
After verified closure, Riera Studio will delete or anonymise Customer Personal Data from active systems unless the Customer requests return or law requires retention. Data in backups is placed beyond normal use and expires through the backup cycle. Minimal billing, security and compliance evidence may be retained under the Privacy Notice.
12. Order of precedence and liability
For processor obligations, this DPA prevails over conflicting general terms. The Business Terms continue to govern fees, liability and the remainder of the Service relationship, except where data protection law requires otherwise.
Legal operator and contact
Riera Studio is operated by Sergi Riera Félix, trading as SRF Systems, a sole trader in the United Kingdom.
Service address: United Kingdom. The full geographic address for formal service is stated on contractual order documents and is available from the contact email.
Email: RieraStudio@srfsystems.uk
