This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Artsume (“we,” “us,” or “our”) and each organization that uses organization features of the Services (the “Organization”). It applies whenever we process personal data on the Organization’s behalf and is incorporated into the Terms by reference. No signature is required. If your organization requires a countersigned copy, contact support@artsume.com.
Roles of the parties
For Organization Records (submitted applications including applicant contact snapshots, review notes and scores, artist and contact entries the Organization creates or imports, and the Organization’s communication history), the Organization is the controller and Artsume is its processor under this DPA.
Artsume is an independent controller for its own purposes: artist accounts (artists’ direct relationship with Artsume), operating and securing the platform, product analytics, and billing. That processing is governed by our Privacy Policy, not this DPA.
Scope of processing
- Data subjects: applicants to the Organization’s programs, artists in its records and network, and its own team members.
- Categories of data: contact details, application content and answers, portfolio and career information, review notes and scores, tags and custom fields, and email engagement events.
- Nature and purpose: hosting, storage, display, search, review workflows, communication delivery, and the AI-assisted features the Organization chooses to use.
- Duration: while the Organization uses the organization features, plus the deletion handling described below.
Processing instructions
We process Organization Records only on the Organization’s documented instructions: its use and configuration of the Services (publishing programs, review settings including blind review, actions on its artists, communications), the Terms, and this DPA. We will process outside those instructions only where law requires, and will inform the Organization first unless the law prohibits it.
Confidentiality
Personnel authorized to process Organization Records are bound by confidentiality obligations. Administrative access is limited to what their role requires and is logged.
Security measures
We implement appropriate technical and organizational measures, including encryption in transit, row-level access controls in the database, role-based workspace permissions, logged administrative access, and regular backups. We may update these measures over time provided overall protection is not reduced.
Sub-processors
The Organization authorizes the sub-processors named in the “How we share information” section of our Privacy Policy (hosting, database, payments, email, analytics, AI, and supporting services). We update that list before adding or replacing a sub-processor, and we remain responsible for our sub-processors’ performance. If the Organization objects to a new sub-processor on reasonable data-protection grounds, its remedy is to stop using the affected features or terminate the affected Services.
International transfers
Organization Records may be processed in Canada, the United States, and other countries where we or our sub-processors operate. Where a restricted transfer occurs, we rely on appropriate safeguards such as Standard Contractual Clauses or an applicable adequacy decision (including Canada’s, for data transferred from the EEA).
Assistance
The Services give the Organization tools to access, correct, export, and delete Organization Records directly, which is the primary way to answer data subject requests. Taking into account the nature of the processing, we provide reasonable further assistance with data subject requests, data protection impact assessments, and regulator consultations where the Organization cannot self-serve.
Personal data breach
If we become aware of a personal data breach affecting Organization Records, we will notify the affected Organization without undue delay and provide the information reasonably available to us to support the Organization’s own notification obligations.
Deletion & return
When the Organization stops using the organization features (or on its written request), we delete Organization Records unless retention is required by law (e.g., payment and tax records). Export options are available in-product where the feature supports it, or via support before deletion.
Artist accounts and artist-owned content are independent of the Organization: artists hold their own relationship with Artsume, and their profiles and portfolios are not deleted when an Organization leaves.
Audits & information
On written request, we make available the information reasonably necessary to demonstrate compliance with this DPA (documentation and completed questionnaires). Audits beyond that require reasonable notice, occur at most once per year, are at the Organization’s cost, and must not access other customers’ data.
Liability & order of precedence
This DPA is part of the Terms; the Terms’ limitations of liability apply to it. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails.
Governing law
This DPA is governed by the same law and venue as the Terms of Service, except where the data protection law giving rise to a claim requires otherwise.
Changes to this DPA
We may update this DPA to reflect changes in the Services or in law. Material changes will be notified (e.g., email or in-app).
Contact
Email support@artsume.com (attention: “Privacy Officer”).