studiotasker.
GDPR / CONTROLLER–PROCESSOR TERMS

Data Processing Agreement

Version 2026-10-06.3

1. Scope and parties

This Data Processing Agreement (“DPA”) forms part of the StudioTasker Terms of Service between Customer and the independent individual operator of StudioTasker. It applies only where StudioTasker processes personal data on Customer’s behalf in connection with the StudioTasker service.

For that processing, Customer is the controller (or a processor acting for another controller, where applicable) and StudioTasker is the processor, unless applicable law requires a different classification for a specific activity.

Excluded from this processor DPA: buyer/payment data independently processed by Paddle as StudioTasker’s authorised reseller and Merchant of Record. Paddle and StudioTasker act as independent controllers for their respective checkout/payment purposes under the applicable Paddle–supplier data-sharing terms.

2. Customer instructions

StudioTasker will process Customer Personal Data only on documented instructions from Customer, including the instructions embodied in the Terms, Customer’s configuration and ordinary use of the service, unless law requires otherwise. If legally permitted, StudioTasker will inform Customer before processing required solely by law.

3. Processing details

Subject matterHosting and operating studio-management software and related support/security functions.
DurationFor the subscription term and the limited post-termination period necessary for export, deletion, backup rotation and legal obligations.
Nature and purposeStorage, organisation, retrieval, display, scheduling, booking administration, attendance, internal credit/package tracking, follow-up tasks, exports, backups and security monitoring.
Data subjectsCustomer staff, leads, members/clients/students and other contacts entered by Customer.
Data categoriesNames, contact details, relationship/status information, booking/class history, attendance, internal credit/package status, notes and workspace identifiers.
Special-category dataNot intended or authorised by default. Customer must not submit health, biometric, criminal-offence or comparable sensitive data unless separately agreed in writing and supported by appropriate safeguards.

4. Confidentiality

StudioTasker will ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as needed for their role.

5. Security

StudioTasker will implement appropriate technical and organisational measures taking into account the nature of processing and risk. Current measures are described in Security and include tenant isolation, restricted database access, secure sessions, production HTTPS requirements, access controls, tested backups and security-oriented logging.

6. Subprocessors

Customer grants general written authorisation for StudioTasker to use subprocessors necessary to provide the service, subject to data-protection obligations no less protective than required by applicable law. The current list is maintained at Subprocessors. Where required by law, StudioTasker will provide notice of material new subprocessors and a reasonable opportunity to object on legitimate data-protection grounds.

7. Data-subject requests

Taking into account the nature of processing, StudioTasker will provide reasonable assistance to Customer with requests to exercise rights under applicable data-protection law. StudioTasker will not independently respond to a studio member’s request concerning Customer-controlled data except as legally required or authorised by Customer.

8. Security incidents

StudioTasker will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to assist Customer with its notification and risk-assessment obligations. Notification does not constitute an admission of fault or liability.

9. DPIAs and regulatory assistance

Taking into account the nature of processing and information available to it, StudioTasker will provide reasonable assistance with data-protection impact assessments and prior consultations where the processing through StudioTasker gives rise to such obligations.

10. Return and deletion

At the end of the services, StudioTasker will delete or return Customer Personal Data as required by Customer and applicable law, subject to secure backup rotation and data that must be retained for legal, accounting, security or dispute-resolution purposes. Customer should export required business records before account closure.

11. Audit information

StudioTasker will make available information reasonably necessary to demonstrate compliance with processor obligations. Audits must be proportionate, protect other customers’ confidentiality and security, and should ordinarily use available documentation or independent evidence before intrusive inspection.

12. International transfers

If Customer Personal Data is subject to a restricted international transfer, the parties will use a legally valid transfer mechanism. Where applicable, this may require the unmodified European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914, typically the controller-to-processor module when Customer is an EEA controller and StudioTasker is a processor outside the EEA.

StudioTasker is being prepared for an EU-region production hosting setup. EU hosting can reduce cross-border infrastructure exposure, but it does not by itself eliminate transfer analysis where the individual operator or authorised support access occurs from Türkiye.

SCC execution: acceptance of this DPA records the controller–processor contract. Where SCCs are legally required for a specific Customer, the applicable SCC transfer addendum must also be put in place without modifying the mandatory clauses. A dedicated legal contact is provided before paid service activation.

13. Processing Annex

ControllerCustomer/studio for member, lead and staff data entered for the studio’s purposes.
ProcessorStudioTasker for Customer Personal Data processed to provide the studio-management service.
Data subjectsCustomer staff, leads, members/clients/students and other contacts entered by Customer.
Data categoriesNames, business/contact details, studio relationship/status information, class/booking/attendance history, internal package/credit status, tasks, notes and workspace identifiers.
PurposeCRM, scheduling, booking administration, attendance, studio-confirmed entitlements, follow-up workflows, exports, support, backup and service security.
DurationSubscription term plus limited export/deletion/backup-rotation and legally required retention periods.
Special-category dataNot intended or authorised by default; Customer must not upload it unless separately agreed in writing and technically supported.
SubprocessorsMaintained on the public Subprocessors page; Paddle checkout processing is separately classified as independent-controller processing, not a Customer Personal Data subprocessor.

14. Order of precedence

If this DPA conflicts with the Terms on protection of Customer Personal Data, this DPA controls to the extent of the conflict. Mandatory SCC provisions, when applicable and executed, take precedence as required by those clauses.