Home · Legal · DPA
Legal · last updated 2026-10-01

Data processing.

This Data Processing Agreement ("DPA") under Art. 28 of the EU General Data Protection Regulation (GDPR) is concluded between the customer named in the Labelflow account (the "Controller") and Digital Music Systems, Inhaber Till Antonio Mahler, Am Berlin Museum 12, 10969 Berlin, Germany (the "Processor", "Labelflow"). It forms part of the Terms and applies automatically to every Labelflow subscription, including the free trial. No separate signature is needed. If you need a countersigned copy for your records, email hello@labelflow.ai.

1 · Subject matter and duration

Labelflow processes personal data on behalf of the Controller in order to provide the Labelflow service described in the Terms: release operations software for record labels. This DPA runs for as long as the Processor processes personal data for the Controller, which is the term of the subscription plus the period needed for return and deletion under section 10.

2 · Nature and purpose of the processing

Hosting, storage, organisation, retrieval, display, transmission and deletion of the Controller's workspace data; sending emails on the Controller's instruction; analysing catalogue and streaming data; running AI features the Controller uses (text drafting, artwork generation, data extraction from demo emails, catalogue reconciliation); file conversion and audio checks; support. The purpose is solely to provide the service to the Controller.

3 · Types of personal data

  • Contact and identity data: names, artist names, email addresses, phone numbers, postal addresses, social and streaming profile links.
  • Contract and release data: roles, splits, release credits, deliverable and payment status.
  • Communication data: emails and messages drafted, sent and received through Labelflow, demo submissions.
  • Files: audio masters, artwork, photos and documents uploaded to the workspace.
  • Usage data of the Controller's team members: account details, activity logs.

The Controller does not put special categories of personal data (Art. 9 GDPR) into Labelflow unless it is necessary and a legal basis exists.

4 · Categories of data subjects

The Controller's team members; artists and their representatives; contacts such as curators, press, promoters and distributors; people who submit demos to the Controller; recipients of communications sent through Labelflow.

5 · Instructions of the Controller

The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required to do so by EU or member state law; in that case the Processor informs the Controller before processing unless that law prohibits it. The Terms, this DPA and the Controller's use and configuration of the service are the Controller's instructions. Further instructions are given in text form to hello@labelflow.ai. The Processor informs the Controller without delay if it considers that an instruction infringes data protection law.

6 · Confidentiality

The Processor ensures that everyone authorised to process the personal data has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality.

7 · Technical and organisational measures

The Processor implements appropriate technical and organisational measures under Art. 32 GDPR. A summary is in Annex 1. The Processor may adapt the measures to technical progress as long as the level of protection is not reduced.

8 · Sub-processors

The Controller gives its general authorisation for the Processor to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex 2. The Processor informs the Controller by email at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Controller may cancel the affected service with effect from the change. The Processor imposes data protection obligations on each sub-processor that are equivalent to those in this DPA and remains responsible to the Controller for its sub-processors. Transfers to countries outside the EU or EEA take place only with an adequacy decision, including the EU-U.S. Data Privacy Framework, or the EU Standard Contractual Clauses.

9 · Assistance

Taking into account the nature of the processing, the Processor assists the Controller with appropriate measures in responding to requests from data subjects exercising their rights under Chapter III GDPR, and in meeting the Controller's obligations under Art. 32 to 36 GDPR (security, notification of personal data breaches, data protection impact assessments and prior consultation). Requests that reach the Processor directly are forwarded to the Controller without delay. The Processor notifies the Controller without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, with the information the Controller needs for its own notification.

10 · Deletion and return

When the subscription ends, the Processor provides an export of the workspace data in a common machine-readable format on request made within 30 days. After those 30 days the Processor deletes the personal data, including copies, unless EU or member state law requires its storage. Backups are overwritten in their normal rotation.

11 · Information and audits

The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates. Audits take place after reasonable notice, during business hours, without disrupting operations, and with a commitment to confidentiality. The Processor may first answer a request with documentation, such as a description of its measures and its sub-processors' certifications. Each party bears its own costs of an audit.

12 · Controller responsibilities

The Controller is responsible for the lawfulness of the processing, including having a legal basis for the personal data it puts into Labelflow and for the communications it sends through it, and for informing data subjects.

13 · Liability and precedence

Liability under this DPA follows the liability provisions of the Terms, without prejudice to Art. 82 GDPR. If this DPA and the Terms conflict on data protection, this DPA prevails.

Annex 1 · Technical and organisational measures (summary)

  • Hosting: application and database in the EU (Frankfurt) with providers that maintain recognised security certifications.
  • Access control: every workspace is isolated in the database with row-level security on the tables that hold label data; team members get role-based access within a workspace.
  • Encryption: all traffic over TLS; data encrypted at rest by the hosting and storage providers.
  • Authentication: email link, password stored only as a hash, or Google sign-in; administrative access to production systems is limited to the operator and protected with multi-factor authentication.
  • Secrets: credentials held in the providers' secret stores, never in code.
  • Logging and monitoring: error monitoring with masked replays; activity log for actions taken through the Labelflow MCP server.
  • Availability: managed database backups by the hosting provider.
  • Data minimisation: catalogue lookups send only public release identifiers; AI providers may not train on the data.

Annex 2 · Sub-processors

  • Supabase Inc. (USA): Database, sign-in and file storage for the app and your workspace. Location and transfer basis: Hosted in the EU (Frankfurt). Transfers to the US provider under the EU Standard Contractual Clauses (SCCs).
  • Vercel Inc. (USA): Hosting of labelflow.ai and app.labelflow.ai; Vercel Web Analytics on labelflow.ai and Speed Insights in the app. Location and transfer basis: App server functions run in Frankfurt; edge network worldwide. EU-U.S. Data Privacy Framework (DPF) and SCCs.
  • Cloudflare Inc. (USA): DNS and network protection; the Labelflow API (Workers); file storage for masters, artwork and exports (R2); audio checks in containers; AI models run on Workers AI (Llama 3.3) for demo-email extraction, onboarding emails, quality-check summaries and catalogue reconciliation; Turnstile bot protection on our forms. Location and transfer basis: Global network. DPF and SCCs.
  • Stripe Payments Europe, Ltd. (Ireland): Subscription billing, card payments, invoices and tax calculation. Location and transfer basis: EU entity. Onward transfers to Stripe, Inc. (USA) under DPF and SCCs.
  • Twilio Inc. (USA), trading as SendGrid: Sending email (sign-in links, billing and trial notices, the emails you send to artists and contacts from Labelflow, our newsletter) and receiving demo submissions by email (Inbound Parse). Location and transfer basis: USA. DPF and SCCs.
  • Functional Software, Inc., trading as Sentry (USA): Error monitoring for the app and the API, including a session replay of the moments around an error in the app (text and media masked by default). Location and transfer basis: Stored in Sentry's EU data region (Germany). DPF and SCCs for access from the USA.
  • PostHog Inc. (USA): Product analytics in the app: page views, feature use and, only for accounts in our early-customer programme, session recording with all form inputs masked. Location and transfer basis: PostHog EU Cloud (Frankfurt). SCCs for access from the USA.
  • Anthropic PBC (USA): AI drafting in your label's voice and other text features you use, such as communication drafts and copy edits. Location and transfer basis: USA. SCCs. API data is not used to train models.
  • Replicate, Inc. (USA): Image generation for the Design add-on (cover and social artwork). Location and transfer basis: USA. SCCs.
  • Lunaweb GmbH (Germany), operating CloudConvert: Audio file conversion (for example a listening copy of a master). Location and transfer basis: Processing in the EU (Germany).
  • Chartmetric, Inc. (USA): Catalogue enrichment and streaming analytics. Location and transfer basis: USA. SCCs.
  • Songstats, accessed through the RapidAPI marketplace: Label and track analytics; finding a label's public website. Location and transfer basis: Location of processing to be confirmed. SCCs where outside the EU.
  • Spotify AB (Sweden), Deezer S.A. (France), Apple Inc. (iTunes Search, USA), MetaBrainz Foundation (MusicBrainz, USA), Google (YouTube Data API): Looking up public metadata and statistics for your releases. Location and transfer basis: Various. Only publicly available catalogue data is sent.

Version 2026-10-01. Last updated: 2026-10-01.