Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (the “Customer” and “Controller”) and Dreamer Studios [GmbH], trading as Elev8labs (“Elev8labs”, the “Processor”). It governs our processing of personal data contained in Customer Data on your behalf when we provide the mastroHQ Service. It is designed to meet the requirements of the Swiss revFADP and Article 28 GDPR.
The short version
- This covers the data your customers entrust to you — their names, addresses, project details.
- You are in charge of that data (the controller); we just process it on your instructions to run mastroHQ.
- We keep it secure (encryption, tenant isolation) and only use vetted sub-processors.
- If a data breach affects you, we tell you promptly.
- When you leave, you can export your data, then we delete it.
The short version is a friendly summary — the full text below is what applies. This is a working draft and will be reviewed by counsel before launch; items in square brackets are still to be filled in.
1. Roles
You are the controller of the personal data you and your Authorised Users upload to the Service about your own clients, projects, staff and correspondents. We process that personal data only as a processor, on your documented instructions, to provide the Service. Where this DPA conflicts with the Terms regarding processing of personal data, this DPA prevails.
2. Subject-matter and details of processing
- Subject-matter: provision of the mastroHQ platform.
- Duration: for the term of your subscription plus the deletion/return period in Section 9.
- Nature and purpose: hosting, storage, organisation, transmission, display, backup and other operations needed to run the Service.
- Types of personal data: identification and contact details, addresses, project and quote details, photos, signatures, message content and metadata, and any other data you choose to submit.
- Categories of data subjects: your End Clients (e.g. homeowners), your staff and crew, your suppliers, and other contacts you record.
3. Our obligations as processor
- Instructions: we process personal data only on your documented instructions (including via your use and configuration of the Service), unless required by law, in which case we will inform you where permitted.
- Confidentiality: personnel authorised to process the data are bound by confidentiality obligations.
- Security: we implement appropriate technical and organisational measures as set out in Section 6.
- Assistance: taking into account the nature of the processing, we assist you with data-subject requests and with your obligations on security, breach notification and data-protection impact assessments.
- No onward use: we do not sell Customer Data or use it for our own purposes (such as advertising). We may use aggregated and de-identified data that cannot identify you or any individual to operate and improve the Service.
4. Your obligations as controller
- You warrant that you have a lawful basis to collect and provide the personal data and to instruct us to process it, and that you have given any required notices and obtained any required consents from data subjects.
- You are responsible for the accuracy of Customer Data and for the configuration choices that determine how it is processed (for example who you grant access via portal and crew links).
5. Sub-processors
You authorise us to engage sub-processors to provide the Service. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. Our current sub-processors include:
| Sub-processor | Service provided | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU [region to confirm] |
| Vercel | Application hosting | EU / global edge |
| Stripe | Payment processing | EU / US |
| Resend | Email delivery | EU / US |
| Twilio | WhatsApp / messaging | EU / US |
| Sign-in and mailbox sync (if connected) | EU / US | |
| OpenAI / Replicate | AI room renders (if used) | US |
| Cal.com | Booking | EU / US |
| PostHog | Product analytics | EU [region to confirm] |
We will give you reasonable prior notice of any new or replacement sub-processor. You may object on reasonable data-protection grounds; if we cannot accommodate the objection, you may terminate the affected part of the Service as your sole remedy.
6. Security measures
- Encryption of data in transit (TLS) and encryption of stored integration credentials.
- Tenant isolation enforced at the database layer via row-level security.
- Role-based access controls and least-privilege service credentials.
- Backups and recovery procedures.
- Logging and monitoring of access and significant events.
- Vetting of personnel and confidentiality undertakings.
7. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data, and provide information reasonably available to help you meet your notification obligations to authorities and data subjects.
8. International transfers
Where processing involves transferring personal data outside Switzerland or the EU/EEA to a country without an adequacy decision, we put in place appropriate safeguards, including the EU Standard Contractual Clauses together with the Swiss addendum recognised by the FDPIC, and supplementary measures where needed.
9. Return and deletion
On termination, and at your choice, we will return or delete Customer Data containing personal data. You may export your data for 30 days after termination, after which we will delete or anonymise it within a reasonable period, except where retention is required by law (for example billing records). Backups are purged on our standard rotation cycle.
10. Audits
On reasonable request and no more than once per year (unless required by a supervisory authority), we will make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to confidentiality and reasonable scheduling. We may satisfy audit requests by providing third-party reports or summaries where available.
11. Liability and order of precedence
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of conflict, this DPA governs for matters of personal-data processing; the EU Standard Contractual Clauses (where they apply) prevail over both for the transfers they cover.
12. Contact
Data-protection contact: privacy@mastrohq.com — Dreamer Studios [GmbH], [Registered address, Basel-Stadt, Switzerland].