🪙Your Tokens: 0
quindieradio is offline

Data Processing Addendum (DPA)

Effective: August 2026

This Data Processing Addendum (“DPA”) supplements the Master Terms of Service (“Agreement”) between Quindie / Private Spaces (“Provider”) and the registered customer or organization (“Customer”).

1. Scope & Relationship of the Parties

Customer Data (Processor Role):

With respect to personal data, video assets, attendee details, or guestbook information uploaded or hosted by Customer within Quindie or Private Spaces (“Customer Data”), Customer is the Data Controller and Provider is the Data Processor.

Account & Administrative Data (Controller Role):

With respect to direct account registration information, billing contacts, and platform usage data, Provider acts as an Independent Data Controller and may process such information for account administration, platform improvement, and direct marketing communications strictly in accordance with Provider’s Privacy Policy. Provider does not sell, rent, or trade personal data to third-party data brokers or marketing vendors.

2. Processing Instructions & Limitations

  • Provider shall process Customer Data solely on documented instructions from Customer and for the explicit purpose of providing the video hosting, streaming, transcoding, and portal services described in the Agreement.
  • Provider shall not retain, use, disclose, or market to Customer Data outside of the direct business relationship established with Customer.

3. Authorized Sub-Processors

Customer grants general written authorization for Provider to engage the following categories of third-party infrastructure and sub-processors to deliver the service:

Cloud Infrastructure & Storage:

Cloudflare (Edge routing, R2 object storage) and Google Cloud Platform (Cloud Run transcoding).

Payment Processing:

Stripe (PCI-DSS compliant payment processing).

Provider shall ensure that all sub-processors are bound by data protection obligations no less restrictive than those set forth in this DPA.

4. Technical & Organizational Security Measures

Provider implements and maintains appropriate technical safeguards, including:

Encryption:

Enforcing TLS 1.2+ for all data in transit and industry-standard AES-256 encryption for data at rest.

Access Controls:

Restricting internal administrative access to authorized personnel via role-based access control (RBAC) and mandatory multi-factor authentication (MFA).

5. Security Incident Notification

In the event of a confirmed security incident resulting in unauthorized access to or disclosure of Customer Data, Provider shall notify Customer in writing without undue delay (and in any event within 72 hours of verification) and take commercially reasonable steps to mitigate the effects.

6. Data Deletion and Return

Upon termination of the Agreement or expiration of the designated event storage period, Provider shall delete or make unavailable Customer Data and hosted media files in accordance with Provider's standard data lifecycle and retention policies, unless applicable law requires continued retention.