Skip to content
Claviforge

Data processing agreement

Last updated : 1 October 2026

This English text is for information only. The Dutch version is legally authoritative. Verwerkersovereenkomst

In short

  • This text applies when a company has third parties recorded or post-produced with us.
  • You stay the controller; Claviforge is the processor for those third parties.
  • Working sessions are kept 24 months, then deleted or returned.
  • The hosting sub-processor is TransIP B.V. in Leiden; FormSubmit only sees our own form.
  • Dutch law, seat in Amsterdam; questions via [email protected].

1. Parties and roles

This processing agreement (Article 28 GDPR) sits with the terms and conditions of Claviforge B.V., Danzigerkade 78, 1013 AP Amsterdam, Chamber of Commerce 85363453, VAT NL879466819B01, represented by Maarten de Vries (the processor, or Claviforge).

The other party is the business client that accepts a written order or confirmed quote in which personal data of people other than the client itself will be processed (the controller). The payment term between businesses is 14 days, as in the terms. This page is the default set; a signed annex may tighten a point, not weaken one where the GDPR is mandatory.

The Dutch version is authoritative. English is an informative translation.

2. When this agreement applies

It applies when the client engages us to process personal data of third parties, for example:

  • guests or presenters during Podcast recording;
  • singers, session players or voice-over talent during Vocal and instrument recording;
  • recognisable voices in files we receive for Mixing or Mastering;
  • people in a try-out in the Rehearsal room, if the client has that session recorded.

If an artist or podcaster books for themselves, we are the controller toward that person. Then the privacy policy applies, not this processor role. The studio has 3 rooms and admits at most 6 guests per session; the client makes sure those people know a recording is taking place.

3. Subject, nature, purpose and duration

Subject. Technical recording, editing, mix, master or rehearsal support, plus temporary storage of working sessions until delivery.

Nature and purpose. Capturing sound, processing it and exporting the formats the order confirms. No publication by Claviforge, no marketing list, no model training.

Duration. From the confirmed booking until deletion or return after the 24-month archive window after the last session day, or earlier on written request, plus the period the law requires for our own accounts (invoices: seven years).

Prices for the underlying service, for example €78 per podcast hour or €185 per mix track (including 21 % VAT), appear on the quote. They do not change the processor duties.

4. Categories of data subjects and data

Data we see as processor
Data subjectsData
Guests, voices and musicians the client brings or sendsVoice, possibly a name or artist name, monitoring notes, file names
The client’s contact peopleName, email, phone, schedule — we process those as controller for the client relationship; see the privacy policy
MinorsOnly if the client confirms that a legal guardian consents; our house rule floor is 16 years

Special categories (health, political views, religion) do not belong in the briefing. If such content is unavoidable in the conversation, the client remains responsible for the legal basis toward those guests. We do not ask for it and we do not index it.

5. Instructions

We process only on the controller’s documented instructions, plus what the GDPR and Dutch law require. If we doubt that an instruction is lawful, we say so before we carry it out. Publication, sending stems to a third label, or an extra revision round beyond the 2 rounds already set, happens only after a clear order. A spoken wish in the control room is confirmed by email if it changes the processing.

6. Confidentiality

Access to session files is limited to Maarten de Vries, Fleur Bakker and Jonas Meijer, each for their own craft. They are bound to keep the material confidential. We do not play a take for outsiders, put a fragment on a showreel or name a guest on the site without written permission from the controller (and, where needed, from the guest). Working sessions do not sit in a public folder.

7. Security

In line with Article 32 GDPR we apply appropriate technical and organisational measures: HTTPS for the site, individual accounts, strong passwords, encrypted work disks, a locked building outside Tue–Fri 10–20, Sat 11–18, and deletion after the archive window. The live room (42 m²) and the 2 booths are reserved for that booking; we do not let a second production listen in. A residual risk remains on any path across the internet; the client chooses how stems are delivered.

8. Sub-processors

The client gives general written authorisation for the following sub-processors, to the extent they take part in this processing:

  • TransIP B.V., Vondellaan 47, 2332 AA Leiden, the Netherlands, transip.nl — hosting and storage in the Netherlands;
  • our bookkeeper — only the client’s invoice lines, not guest audio.

FormSubmit processes messages from our own contact form, in which the client types contact details. That is not sub-processing of guest recordings. If we add a new sub-processor that will see guest data, we say so in advance. An objection within fourteen days is taken seriously; without a reasonable alternative the order can stop without extra studio hire for hours not yet run.

9. Transfers outside the EEA

Guest recordings and working sessions stay with TransIP B.V. in the Union. We do not send those files to FormSubmit or to a US platform unless the client chooses that channel and instructs us in writing. If the client picks a transfer service outside the EEA, that choice is an instruction of the controller, who must itself have a valid transfer ground.

10. Assistance

We help the controller with data-subject requests (access, erasure, restriction), with a data-protection impact assessment if the production requires one, and with contact with the Dutch Data Protection Authority. We reply to the client within 2 working days so that the statutory one-month period can be met. Requests from a guest are forwarded to the client, unless the law obliges us to act ourselves.

11. Breaches

If we discover a personal-data breach that falls under this agreement, we notify the controller without undue delay and in any event within 48 hours after we established the breach. We describe the nature of the incident, the categories involved, the likely consequences and the steps already taken. The client decides whether notification to the Autoriteit Persoonsgegevens or to the guests is required. Our own duties as a studio remain, see article 8 of the privacy policy.

12. Return, deletion and audits

When the order ends we deliver the agreed files and delete the working sessions after 24 months, or earlier on request, except what we must keep by law (invoice records). On written request we confirm the deletion. With reasonable notice, and at most once every twelve months, the client may ask for a written account of our measures or — if that account is not enough — an on-site audit during Tue–Fri 10–20, Sat 11–18, without disturbing other sessions. The client bears the cost of an external auditor, unless the audit shows a serious shortcoming we should have prevented.

13. Liability, law and closing

Each party remains liable for its own GDPR role. We are not liable for instructions from the client that turn out to be unlawful, nor for publication the client carries out. Dutch law applies. Disputes about this processor role go to the competent court in Amsterdam, without affecting mandatory rights.

Effective date: 1 October 2026. Last review: 1 October 2026. Questions: [email protected] or contact. See also the legal notice and mastering and rights if you want a reminder of which exploitation rights stay with the client.