v1.0 (7 August 2026)
Version v1.0 (7 August 2026). The version identifier displayed at the point of acceptance and recorded in the acceptance log must match this document exactly.
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Loud Link Terms of Service or other written agreement between the parties governing Customer's use of the Services (the "Main Agreement").
Between:
(1) LOUD LIMITED, a company incorporated in England and Wales with company number 11324023, whose registered office is at 85 Great Portland Street, London, W1W 7LT, United Kingdom, trading as "Loud Link" and "Loud Beings" ("Loud Link", "we", "us"); and
(2) The entity identified as the customer in the Main Agreement ("Customer", "you"),
each a "party" and together the "parties".
Effective Date: the earlier of (a) the date Customer accepts this DPA electronically, (b) the date of last signature below, and (c) the date Customer first uses the Services.
(A) Loud Link operates a platform that connects physical music releases to digital experiences, including release pages, cover and code scanning, previews, fan collections, mailing-list signup capture and engagement analytics (the "Services").
(B) In providing certain elements of the Services, Loud Link processes personal data on Customer's behalf. In providing other elements, Loud Link acts as an independent controller in respect of its own relationship with fans.
(C) The parties enter into this DPA to comply with Article 28 of the UK GDPR and the EU GDPR and equivalent provisions of other Data Protection Laws, and to define their respective roles and responsibilities.
1.1 In this DPA:
"Aggregated Data" means data derived from processing under this DPA which has been aggregated and de-identified such that it does not, and cannot by any means reasonably likely to be used, (a) identify or permit the identification of any Data Subject, or (b) identify Customer or any of Customer's artists, releases or campaigns as the source of that data.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the UK GDPR, and cognate terms are construed accordingly.
"Customer Personal Data" means Personal Data that Loud Link Processes on Customer's behalf under this DPA, as described in Annex 1. For the avoidance of doubt it does not include Platform Personal Data or Aggregated Data.
"Data Protection Laws" means all laws relating to data protection, privacy and electronic communications applicable to a party's Processing under this DPA, including: (a) the UK GDPR and the Data Protection Act 2018 (as amended, including by the Data (Use and Access) Act 2025); (b) the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"); (c) Regulation (EU) 2016/679 ("EU GDPR") and national implementing laws; (d) the ePrivacy Directive 2002/58/EC as implemented in each Member State; (e) the Swiss Federal Act on Data Protection; and (f) US State Privacy Laws.
"EEA" means the European Economic Area.
"Fan" means an individual who interacts with the Services, whether via a Customer's release page, a scan, or the Loud Link application.
"Platform Personal Data" means Personal Data for which Loud Link acts as an independent Controller, as described in clause 11.1.
"Restricted Transfer" means a transfer of Personal Data to a country or territory in respect of which no adequacy decision or equivalent finding is in force under the applicable Data Protection Laws.
"Security Measures" means the technical and organisational measures set out in Annex 2.
"Standard Contractual Clauses" or "SCCs" means (a) for transfers subject to the EU GDPR, the clauses annexed to Commission Implementing Decision (EU) 2021/914; and (b) for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner (the "UK Addendum") or the International Data Transfer Agreement ("IDTA"), as applicable.
"Sub-processor" means any third party engaged by Loud Link to Process Customer Personal Data.
"US State Privacy Laws" means the California Consumer Privacy Act as amended ("CCPA") and comparable comprehensive state privacy statutes.
1.2 Capitalised terms not defined here have the meaning given in the Main Agreement.
2.1 This DPA forms part of the Main Agreement. In the event of conflict, the following order applies, highest first: (a) the SCCs, where they apply; (b) Annex 5 (US State Privacy Laws), in respect of Personal Data subject to those laws; (c) the body of this DPA; (d) the remaining Annexes; (e) the Main Agreement.
2.2 Nothing in this DPA is intended to vary or contradict the SCCs, and no provision of this DPA shall be construed as doing so.
3.1 Customer as Controller. In respect of Customer Personal Data, Customer is the Controller and Loud Link is the Processor.
3.2 Loud Link as Controller. In respect of Platform Personal Data, Loud Link is an independent Controller and clause 11 applies.
3.3 Customer as Processor (dual role). Where Customer acts as a Processor on behalf of a third-party controller (for example, where Customer is a distributor, management company or service company acting for an artist), then in respect of that Personal Data:
(a) Loud Link is a Sub-processor and this DPA operates as a sub-processing agreement;
(b) Customer warrants that it has the third-party controller's authority to appoint Loud Link on these terms and to give the instructions it gives;
(c) references in this DPA to Customer's instructions mean instructions Customer has received from and is permitted to pass on by that controller; and
(d) Loud Link owes no obligation directly to that controller, and Customer remains solely responsible to it.
This clause is intended to allow this DPA to be executed without amendment by both controllers and processors.
3.4 Not joint controllers. The parties do not intend to be joint controllers within the meaning of Article 26 of the UK GDPR or EU GDPR in respect of any Processing under this DPA, and each shall act so as to avoid that outcome.
4.1 Lawfulness. Customer warrants that it has, and will maintain throughout the term, a valid lawful basis under Article 6 (and where applicable Article 9) of the UK GDPR and EU GDPR for all Processing it instructs, and that its instructions do not require Loud Link to act in breach of Data Protection Laws.
4.2 Transparency. Customer is responsible for providing Data Subjects with all information required by Articles 13 and 14, including identifying itself as Controller and disclosing Loud Link's role as Processor.
4.3 Direct marketing consent. Where Customer uses the Services to send, or to enable the sending of, electronic direct marketing, Customer warrants that:
(a) it holds valid, freely given, specific, informed and unambiguous consent from each recipient, or is otherwise lawfully entitled to send that marketing under PECR, the ePrivacy Directive and equivalent laws;
(b) it retains evidence of that consent and will produce it to Loud Link within five (5) business days of request;
(c) it will not upload, import or transmit to the Services any contact list acquired from a third party, purchased, rented, scraped or otherwise obtained other than by direct collection from the Data Subject; and
(d) it will honour all opt-outs and maintain suppression lists, and will not send to any address that has unsubscribed via the Services.
4.4 Content. Customer is solely responsible for the content of any communication it sends via or using data exported from the Services.
4.5 Accuracy of instructions. Customer is responsible for the accuracy and quality of Customer Personal Data and for the legality of the means by which it was obtained.
4.6 Children. Customer warrants that it will not knowingly use the mailing-list or marketing features of the Services to target Data Subjects below the age at which they may consent to information society services in their jurisdiction (being 13 in the UK, and between 13 and 16 in EU Member States) without having obtained and being able to evidence verifiable parental consent.
4.7 Onward destinations. Where Customer connects the Services to a third-party service (including any email service provider, CRM or marketing platform), or exports Customer Personal Data from the Services:
(a) that third-party service is engaged by Customer as its own processor or independent controller and is not a Sub-processor of Loud Link;
(b) Customer is solely responsible for that service's compliance and for the transfer to it, including any transfer safeguards required; and
(c) Loud Link has no responsibility for Customer Personal Data once it has been delivered to that service or exported at Customer's direction, save that Loud Link remains responsible for its own act of transmission.
4.8 Sensitive data. Customer shall not submit to the Services, and shall not instruct Loud Link to Process, any special category data within the meaning of Article 9, criminal offence data, payment card data, government identifiers, or health, financial or precise geolocation data, except where the Services are expressly designed to receive it. The Services are not designed or certified for such data.
5.1 Documented instructions. Loud Link shall Process Customer Personal Data only on Customer's documented instructions, which comprise: (a) this DPA; (b) the Main Agreement; (c) Customer's configuration and use of the Services; and (d) any further written instruction agreed by the parties. Loud Link shall not Process Customer Personal Data for its own purposes save as expressly permitted by clause 11.
5.2 Legal requirement to Process. Loud Link may Process Customer Personal Data where required by law to which it is subject, in which case it will inform Customer of that requirement before Processing unless the law prohibits it on important grounds of public interest.
5.3 Unlawful instruction. If Loud Link forms the opinion that an instruction infringes Data Protection Laws it shall inform Customer without undue delay and may suspend performance of that instruction until it is withdrawn, amended or confirmed. Loud Link is not obliged to conduct a legal review of Customer's instructions.
5.4 Confidentiality. Loud Link shall ensure that all personnel authorised to Process Customer Personal Data are subject to binding obligations of confidentiality that survive termination of their engagement, are trained in data protection, and have access only on a need-to-know basis.
5.5 No sale. Loud Link shall not sell, rent, license or share Customer Personal Data, and shall not use Customer Personal Data to market its own or any third party's products or services to Fans.
5.6 Government and third-party requests. If Loud Link receives a legally binding request for disclosure of Customer Personal Data from a law enforcement, government or other public authority, or any third party, it shall (unless legally prohibited) notify Customer promptly, disclose only the minimum required, and, to the extent lawfully able, delay disclosure to allow Customer to exercise any right to challenge the request.
5.7 Notification of non-compliance. Loud Link shall promptly notify Customer if it determines that it is unable to comply with its obligations under this DPA or Data Protection Laws in respect of Customer Personal Data. If the non-compliance is material and not remedied within thirty (30) days of that notice, Customer may terminate the affected Services on written notice, with a pro-rata refund of prepaid fees for the terminated portion.
6.1 Loud Link shall implement and maintain the Security Measures set out in Annex 2, being appropriate technical and organisational measures under Article 32 having regard to the state of the art, cost of implementation, and the nature, scope, context and purposes of Processing and the risks to Data Subjects.
6.2 Loud Link may update the Security Measures from time to time provided the overall level of security is not materially reduced.
6.3 Customer's responsibilities. Customer is responsible for its own use of the Services, including securing its account credentials, applying appropriate access controls to its users, configuring available security features, and assessing whether the Security Measures are appropriate for its Processing.
6.4 Consent records. Loud Link shall capture and retain, for each mailing-list signup effected through the Services, a record comprising the timestamp, the signup source, and the consent wording presented, and shall make that record available to Customer through the Services. Customer acknowledges this record is provided as a compliance aid and does not relieve Customer of its obligations under clause 4.3.
7.1 General authorisation. Customer grants Loud Link general authorisation to engage Sub-processors. The current list is available at https://loud.link/legal/sub-processors and is incorporated into this DPA. Customer approves the Sub-processors listed there as at the Effective Date.
7.2 Notice of changes. Loud Link shall give at least thirty (30) days' notice before a new Sub-processor begins Processing Customer Personal Data, by updating that page and notifying Customers who have subscribed to notifications at that page. Customer is responsible for subscribing.
7.3 Objection. Customer may object to a new Sub-processor within the notice period by written notice setting out reasonable data protection grounds. The parties shall discuss the objection in good faith for fifteen (15) days. If Loud Link cannot offer a reasonable alternative, Customer's sole and exclusive remedy is to terminate the affected part of the Services on written notice, with a pro-rata refund of prepaid fees for the terminated portion. Failure to object within the notice period constitutes approval.
7.4 Emergency replacement. Where a change of Sub-processor is required urgently to preserve the security or continuity of the Services, Loud Link may make the change and give notice as soon as reasonably practicable, and clause 7.3 applies from the date of that notice.
7.5 Flow-down and liability. Loud Link shall impose on each Sub-processor written data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each Sub-processor's obligations. On Customer's reasonable written request, Loud Link shall make available a copy of the data protection terms of its agreement with a Sub-processor; Loud Link may redact any part of that agreement to the extent necessary to protect confidential or commercially sensitive information, including personal data.
8.1 Self-service. Loud Link shall provide functionality within the Services enabling Customer to access, correct, export, restrict, delete and suppress Customer Personal Data, and to process unsubscribes. Customer shall use that functionality in the first instance to respond to Data Subject requests.
8.2 Additional assistance. To the extent Customer cannot fulfil a request using that functionality, Loud Link shall provide reasonable assistance taking into account the nature of the Processing and the information available to it.
8.3 Requests received by Loud Link. If Loud Link receives a request from a Data Subject relating to Customer Personal Data, it shall not respond substantively (other than to direct the Data Subject to Customer or acknowledge receipt) and shall notify Customer without undue delay.
8.4 Personal Data Breach. Loud Link shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe, to the extent then known: the nature of the breach and categories and approximate numbers of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where information is not available at the time, it shall be provided in phases without undue further delay.
8.5 No admission. Loud Link's notification of a Personal Data Breach is not an acknowledgement of fault or liability.
8.6 Regulatory notification. Customer is solely responsible for notifying Supervisory Authorities and Data Subjects where required, and shall not name Loud Link publicly in connection with a breach without Loud Link's prior written consent, such consent not to be unreasonably withheld and not required where disclosure is legally compelled.
8.7 DPIAs and consultation. Loud Link shall provide Customer with reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36, which may be satisfied by providing the information in Annex 2, Loud Link's then-current security documentation, and its standard DPIA support pack.
8.8 Cost. Assistance under this clause is provided at no charge where reasonable in scope and frequency. Loud Link may charge its then-current professional services rates for assistance that is unreasonable, repetitive, or which arises from Customer's own act or omission, on prior written notice.
9.1 Location. Loud Link Processes Customer Personal Data in the United Kingdom and the EEA, save as identified in the Sub-processor list.
9.2 EEA and Swiss transfers to the UK. The parties acknowledge that transfers of Personal Data from the EEA to the United Kingdom are covered by the European Commission's adequacy decisions in respect of the United Kingdom, and transfers from Switzerland by the corresponding Swiss recognition. Accordingly no additional transfer mechanism is required for those transfers.
9.3 Onward transfers by Loud Link. Where Loud Link makes a Restricted Transfer to a Sub-processor, Loud Link shall ensure a valid transfer mechanism is in place under Article 46 of the applicable GDPR (or the UK "data protection test" where applicable), including where necessary the SCCs together with a transfer risk assessment and any supplementary measures. Loud Link shall provide a summary of the applicable mechanism on request.
9.4 Fallback mechanism. If at any time the adequacy decision referred to in clause 9.2 is suspended, repealed, invalidated or allowed to lapse, or otherwise ceases to cover a transfer under this DPA, then with effect from that date and without further action by either party, the SCCs are incorporated into and form part of this DPA on the terms set out in Annex 4, and the parties are deemed to have executed them.
9.5 Customer as exporter. Where Customer transfers Personal Data to Loud Link from a jurisdiction requiring a transfer mechanism not addressed above, Customer shall notify Loud Link, and the parties shall implement the mechanism required by that jurisdiction, with Annex 4 applying by analogy so far as possible.
10.1 Information. Loud Link shall make available to Customer all information reasonably necessary to demonstrate compliance with Article 28 and this DPA.
10.2 Primary method. Customer's rights under clause 10.1 and Article 28(3)(h) are satisfied by Loud Link providing, on request no more than once in any twelve (12) month period: (a) its then-current security documentation and, where available, third-party audit reports or certifications; and (b) a written response to a reasonable security questionnaire in a standard industry format.
10.3 On-site audit. Customer may conduct an on-site audit only where: (a) a Supervisory Authority with jurisdiction over Customer requires it; (b) it follows a Personal Data Breach affecting Customer Personal Data; or (c) the materials provided under clause 10.2 disclose a material non-compliance that Loud Link has not remedied within thirty (30) days of notice.
10.4 Conditions. Any on-site audit shall be: on at least thirty (30) days' written notice; during business hours; no more than once in any twelve (12) month period; conducted so as to minimise disruption; limited to systems and records relevant to Customer Personal Data and excluding other customers' data, Loud Link's confidential commercial information and any third-party confidential information; subject to written confidentiality undertakings by Customer and its auditors; conducted by an independent auditor who is not a competitor of Loud Link and is reasonably acceptable to Loud Link; and at Customer's sole cost.
10.5 Findings. Audit findings are Loud Link's confidential information. Customer shall provide a copy of any report to Loud Link and shall not disclose it save to its professional advisers, to a Supervisory Authority on request, or as required by law.
11.1 Platform Personal Data. Customer acknowledges that Loud Link acts as an independent Controller in respect of Personal Data relating to Loud Link's own direct relationship with Fans, including: Fan accounts registered with Loud Link; records of releases scanned and collected to a Fan's personal library; use of the Loud Link application; redemption of digital-ownership codes; marketing preferences and consents given directly to Loud Link or to a named partner under clause 11.7; and technical and security telemetry relating to Loud Link's own infrastructure. Loud Link Processes Platform Personal Data under its own privacy notice and its own lawful basis, and Customer has no obligations in respect of it under this DPA.
11.2 Separation. Loud Link shall not combine Platform Personal Data with Customer Personal Data so as to enrich, supplement or expand Customer Personal Data, and shall not disclose Platform Personal Data to Customer in identifiable form, except where the Fan has separately and specifically consented.
11.3 Aggregated Data. Loud Link may generate and use Aggregated Data for the purposes of: operating, securing, monitoring and maintaining the Services; detecting and preventing fraud, abuse and security incidents; developing and improving the Services, including improving cover and artwork recognition; capacity planning; producing internal and published industry statistics and benchmarks; and complying with legal obligations. Loud Link may retain and use Aggregated Data during and after the term.
11.4 Limits on Aggregated Data. Loud Link shall not: (a) publish, disclose or make available Aggregated Data in any form that identifies Customer, any of Customer's artists, or any individual release or campaign, without Customer's prior written consent; (b) attempt to re-identify any individual from Aggregated Data; or (c) present Aggregated Data to a third party in a manner that would reveal Customer's commercial performance.
11.5 No fan marketing. Loud Link shall not use Customer Personal Data to market to Fans on its own behalf or on behalf of any other Loud Link customer. Communications sent by Loud Link to Fans in its capacity as Controller under clause 11.1 relate to the Fan's own Loud Link account and are sent under Loud Link's own lawful basis.
11.6 Analytics in Customer's dashboard. Where Loud Link presents Fan engagement analytics within Customer's account, that analytics data is Customer Personal Data to the extent it relates to identified or identifiable Data Subjects, and is Processed as Processor under this DPA.
11.7 Separate marketing consents. Where a Fan gives a separate, specific, individually actioned opt-in consent through the Services to receive marketing from Loud Link, or from a named third-party partner listed in Loud Link's partner register at https://loud.link/legal/partners, the Personal Data collected under that consent is Platform Personal Data, collected by Loud Link as an independent Controller under its own privacy notice, and is not Customer Personal Data. Any such consent request: (a) is presented separately from, and is never pre-ticked, bundled with, or a condition of, signup to Customer's mailing list or access to any content; (b) names the recipient; and (c) does not constitute, and shall not be represented by either party as, consent to Customer's marketing. Nothing in this clause 11.7 permits Loud Link to use Customer Personal Data for the purposes described in it, and clauses 5.5 and 11.5 continue to apply to Customer Personal Data in full.
12.1 During the term. Customer may export Customer Personal Data at any time using the export functionality in the Services.
12.2 On termination. Following termination or expiry of the Main Agreement, Loud Link shall make Customer Personal Data available for export for thirty (30) days. After that period, Loud Link shall delete Customer Personal Data within a further sixty (60) days, save as set out in clause 12.3.
12.3 Exceptions. Loud Link may retain Customer Personal Data: (a) where required by law, in which case it shall continue to protect it and Process it only for the purpose and duration of that requirement; (b) in encrypted backups made in the ordinary course, which are deleted on Loud Link's ordinary backup cycle, being not more than 90 days; and (c) as Aggregated Data.
12.4 Suppression. Loud Link may retain a hashed record of unsubscribed or suppressed contacts for the purpose of honouring those suppressions.
12.5 Certification. Loud Link shall provide written certification of deletion on request.
13.1 Single cap. Each party's total aggregate liability arising out of or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is subject to the limitations and exclusions of liability set out in the Main Agreement. Liability under this DPA and the Main Agreement together does not exceed the cap in the Main Agreement - the cap is not cumulative and is not duplicated by this DPA.
13.2 Article 82. Where a party has paid compensation under Article 82(4) of the UK GDPR or EU GDPR, it may claim from the other party that part of the compensation corresponding to the other party's part of the responsibility for the damage, subject to clause 13.1.
13.3 Not liable for. Loud Link is not liable for any claim, fine or loss to the extent arising from: Customer's instructions; Customer's lack of a valid lawful basis or consent; the content of Customer's communications; Customer's configuration of the Services; or Customer's use of any third-party service under clause 4.7.
13.4 Customer indemnity. Customer shall indemnify Loud Link on demand against all losses, damages, fines, penalties, costs and expenses (including reasonable legal fees) arising out of or in connection with any claim, investigation or enforcement action brought by a Data Subject, a Supervisory Authority or a third party to the extent arising from Customer's breach of clause 4.3 (direct marketing consent), clause 4.6 (children) or clause 4.8 (sensitive data). The limitations and exclusions in clause 13.1 do not apply to this indemnity.
13.5 Nothing in this DPA limits liability which cannot lawfully be limited.
14.1 This DPA takes effect on the Effective Date and continues for as long as Loud Link Processes Customer Personal Data. Clauses 1, 2, 5.4, 5.5, 11, 12, 13 and 15 survive termination.
14.2 Amendment by Loud Link. Loud Link may amend this DPA on thirty (30) days' written notice where the amendment is: (a) required to comply with Data Protection Laws, a Supervisory Authority decision, or a court judgment; (b) required to reflect a change in a transfer mechanism; or (c) otherwise commercially reasonable and does not materially reduce the protections afforded to Customer Personal Data. If an amendment under (c) materially and adversely affects Customer, Customer may terminate the affected Services on notice before the amendment takes effect, with a pro-rata refund of prepaid fees.
14.3 Other changes. Any other variation requires the written agreement of both parties.
15.1 Governing law and jurisdiction. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, save that where the SCCs apply under clause 9.4 the governing law and forum specified in the SCCs apply to those clauses.
15.2 Notices and contacts. Notices to Loud Link under this DPA shall be sent to [email protected]. Security incident communications shall be sent to [email protected] with a copy to [email protected]. Notices to Customer shall be sent to the email address on Customer's account or the address in Annex 1 Part A. Either party may update its contact addresses by written notice.
15.3 Severance. If any provision is held invalid or unenforceable, it shall be modified to the minimum extent necessary, or severed, and the remainder continues in force.
15.4 Third parties. Save as expressly stated, no third party has any right to enforce this DPA under the Contracts (Rights of Third Parties) Act 1999.
15.5 Electronic acceptance. The parties agree that this DPA may be accepted electronically and that such acceptance constitutes execution for all purposes. Where Customer accepts this DPA by clicking to accept in the course of onboarding, or by using the Services after being presented with it, the person doing so warrants that they are authorised to bind Customer.
15.6 Entire agreement. This DPA and the Main Agreement constitute the entire agreement between the parties in respect of the Processing of Customer Personal Data and supersede any prior data processing terms.
15.7 Counterparts. This DPA may be executed in counterparts, each of which is an original and which together constitute one agreement.
Signature is not required where Customer has accepted this DPA electronically. This block is provided for Customers whose internal policies require a signed counterpart.
For and on behalf of LOUD LIMITED
Signature: ______________________ Name: ______________________ Title: ______________________ Date: ______________________
For and on behalf of CUSTOMER
Signature: ______________________ Name: ______________________ Title: ______________________ Entity legal name: ______________________ Company / registration number: ______________________ Registered address: ______________________ Privacy contact email: ______________________ Date: ______________________
Data Exporter / Controller: Customer, as identified in the Main Agreement and in Customer's account. Contact details are those held in Customer's account or given in the signature block. Role: Controller (or Processor, where clause 3.3 applies).
Data Importer / Processor: Loud Limited (trading as Loud Link), 85 Great Portland Street, London, W1W 7LT, United Kingdom. Contact: [email protected]. Role: Processor (or Sub-processor, where clause 3.3 applies).
Customer's details are populated automatically from Customer's account record. No completion by Customer is required.
Subject matter: Provision of the Loud Link platform, comprising release pages and digital twins, cover and code scanning, audio previews, fan collection features, mailing-list signup capture and management, and engagement analytics.
Duration: The term of the Main Agreement, plus the retention periods in clause 12.
Nature and purpose of Processing: Collection, recording, organisation, structuring, storage, retrieval, consultation, use, display, transmission to Customer's designated third-party services at Customer's instruction, restriction, erasure and destruction - for the purpose of providing the Services.
Categories of Data Subject:
Fans' separate opt-ins to marketing from Loud Link or a named partner under clause 11.7 are Platform Personal Data and are outside the scope of this Annex.
Categories of Personal Data:
| Category | Examples |
|---|---|
| Contact data | Email address; where volunteered, name, country, postcode |
| Consent records | Consent timestamp, signup source URL, wording presented, IP address, opt-in status, unsubscribe status and date |
| Engagement data | Scans, page views, releases opened, previews played, tracks and durations played, collection events, link clicks, referral source |
| Device and technical data | Device type, operating system, browser, app version, IP address, approximate location derived from IP (country/region level) |
| Customer user account data | Name, business email, role, account credentials, access logs |
Special category data: None. Customer shall not submit special category data (clause 4.8).
Children's data: The Services are not directed at children below the applicable digital-consent age. Customer's obligations are set out in clause 4.6.
Frequency: Continuous, for the duration of the Main Agreement.
Retention: For the term plus the periods in clause 12; engagement data is retained for 25 months from collection in identifiable form and thereafter retained only as Aggregated Data.
Sub-processor processing: As set out in the Sub-processor list, for the duration of Loud Link's engagement of each Sub-processor.
Where the EU GDPR applies, the competent authority is that of the Member State in which Customer is established, or where Customer is not established in the EU, that of the Member State in which Customer's Article 27 representative is established. Where the UK GDPR applies, the competent authority is the Information Commissioner's Office.
1. Access control Role-based access control across all systems. Access to production granted on the principle of least privilege and reviewed at least every six months. Multi-factor authentication mandatory for all personnel with production access. Access revoked within 24 hours of a leaver's departure. Unique named accounts; no shared credentials. Administrative actions logged.
2. Encryption Personal Data encrypted in transit using TLS 1.2 or above. Personal Data encrypted at rest using AES-256 or equivalent. Backups encrypted. Secrets and keys held in a managed secrets store with restricted access and rotation.
3. Network and infrastructure security Segregated production and non-production environments. Firewalling and network segmentation. DDoS protection and rate limiting at the edge. Hardened, patched infrastructure with security patches applied according to severity: critical within 7 days, high within 30 days.
4. Application security Secure development lifecycle with peer code review. Dependency vulnerability scanning in CI. Protection against OWASP Top 10 classes of vulnerability. Annual third-party penetration test, with material findings remediated according to risk. No production Personal Data used in development or test environments.
5. Pseudonymisation and data minimisation Fan engagement events stored against pseudonymous identifiers, separated from contact data where technically feasible. Only the data necessary for the relevant feature is collected. Cover recognition is performed on-device; sleeve imagery captured for recognition is not transmitted to or stored by Loud Link.
6. Logging and monitoring Centralised, tamper-resistant logging of access to Personal Data and of administrative actions. Automated alerting on anomalous access patterns. Logs retained for at least 12 months.
7. Availability and resilience Automated encrypted backups taken at least daily. Backup restoration tested at least annually. Documented business continuity and disaster recovery plan reviewed annually. Redundancy across availability zones.
8. Personnel Background screening for personnel with production access, to the extent permitted by law. Written confidentiality undertakings for all personnel. Data protection and security awareness training on induction and at least annually. Documented disciplinary process for breach.
9. Incident management Documented incident response plan with defined roles, severity classification and escalation. 48-hour customer notification commitment under clause 8.4. Post-incident review with documented remediation actions.
10. Sub-processor management Security due diligence before engagement. Written contracts imposing equivalent obligations. Periodic review of Sub-processor security posture.
11. Governance Named individual accountable for data protection. Records of Processing maintained under Article 30. Data protection by design and by default applied to new features. DPIAs conducted where required. Documented data retention schedule.
12. Physical security Personal Data hosted in facilities operated by Loud Link's infrastructure Sub-processors, which maintain physical access controls, environmental controls and 24/7 monitoring, and hold recognised certifications (including ISO/IEC 27001 and/or SOC 2). Loud Link does not operate its own data centres.
The current list of Sub-processors, including each Sub-processor's name, the Processing it performs, and the country in which it Processes Customer Personal Data, is maintained at:
https://loud.link/legal/sub-processors
That page is incorporated into this DPA by reference. Customer may subscribe there to receive notification of changes under clause 7.2.
This Annex operates only where clause 9.4 is engaged, or where clause 9.5 applies. It requires no completion by either party.
Where the EU GDPR applies to a Restricted Transfer under this DPA, the SCCs in Commission Implementing Decision (EU) 2021/914 are incorporated and completed as follows:
Where the UK GDPR applies to a Restricted Transfer under this DPA, the UK Addendum (version B1.0) is incorporated and completed as follows:
Table 1 - Parties: as set out in Annex 1 Part A. Start date: the Effective Date.
Table 2 - Selected SCCs, Modules and Selected Clauses: the EU SCCs as incorporated and completed in Part 1 of this Annex.
Table 3 - Appendix Information: Annex 1A, 1B, II and III as set out in Annex 1 Part A, Annex 1 Part B, Annex 2 and Annex 3 respectively.
Table 4 - Ending the Addendum when the Approved Addendum changes: neither party.
Where the IDTA is used in place of the UK Addendum, the corresponding information in this DPA populates the equivalent tables of the IDTA.
Where Swiss law applies, the EU SCCs as incorporated above apply with the following amendments: references to the GDPR are to the Swiss Federal Act on Data Protection; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the clauses protect the data of legal entities until such protection ceases under Swiss law.
By accepting this DPA, each party is deemed to have executed the SCCs, the UK Addendum and any applicable amendment set out in this Annex, in each case in its relevant capacity, with effect from the date clause 9.4 or 9.5 is engaged.
This Annex applies only to Personal Data subject to US State Privacy Laws. Terms used in this Annex have the meanings given in the CCPA.
Customer is the "Business" and Loud Link is a "Service Provider" (and, under other US State Privacy Laws, Customer is the "Controller" and Loud Link the "Processor").
Loud Link shall Process Personal Information only for the "Business Purposes" of providing the Services under the Main Agreement, and shall not:
(a) "Sell" or "Share" Personal Information;
(b) retain, use or disclose Personal Information for any purpose other than the Business Purposes specified, or outside the direct business relationship between the parties;
(c) combine Personal Information received from Customer with Personal Information received from or on behalf of any other person, or collected from its own interaction with a consumer, except as permitted by the CCPA and applicable regulations; or
(d) use Personal Information for "Cross-Context Behavioral Advertising."
Loud Link certifies that it understands and will comply with the restrictions in paragraph 2.
Loud Link shall notify Customer promptly if it determines it can no longer meet its obligations under US State Privacy Laws, and Customer may on notice take reasonable and appropriate steps to stop and remediate unauthorised use.
Customer may take reasonable and appropriate steps to help ensure Loud Link's Processing is consistent with Customer's obligations, which are satisfied by the mechanisms in clause 10.
Loud Link shall assist Customer in responding to consumer requests to know, delete, correct, opt out and limit, using the functionality described in clause 8.1.
Loud Link shall impose the obligations in this Annex on its Sub-processors.
End of Data Processing Agreement.