Data processing agreement
This English text is a courtesy translation. Only the Dutch version is legally binding.
VerwerkersovereenkomstSummary
- This agreement applies when we record people for a business, and those people are not our clients themselves.
- The client decides what happens to the recordings; we act only on documented instructions.
- Project files are kept for 12 months, then deleted or returned.
- We report data breaches without undue delay, so the client can act within the statutory deadline.
01 Parties and scope
This data processing agreement is made between the business client (the controller) and Variatesystems B.V., Wibautstraat 164, 1091 GR Amsterdam, KvK 88433815, represented by Sanne de Vries (the processor).
It forms part of every assignment in which we process personal data on behalf of a company or organisation, and supplements our terms and conditions. Where they conflict on data protection, this agreement prevails. It meets Article 28 of the General Data Protection Regulation (GDPR). This English text is a translation for information; the Dutch version is binding.
02 Subject and duration
The processor carries out recording sessions, editing, mixing and mastering for the client, for example for advertising, voice-overs, podcasts or music productions. The agreement runs for as long as the processor processes personal data for the client, and ends only once all data has been deleted or returned.
03 Types of data and data subjects
- Data subjects
- Voice actors, singers, musicians, speakers, podcast guests and the client's contact persons.
- Data
- Name, contact details, audio recordings of voice and performance, session files, scripts and recording notes.
- Special categories
- Not intended. If scripts or content do involve sensitive information, the client says so in advance.
04 The client's instructions
The processor processes the data only on the client's documented instructions, email included, and only for the agreed production. The processor does not use recordings for its own purposes, as examples in its own promotion, or to train software or AI models, unless the client agrees in writing. If the processor considers an instruction to breach the GDPR, it says so immediately.
05 Confidentiality
Only staff working on the production get access to the data. They are bound to confidentiality, also after the assignment ends. Visitors who are not part of the production are not in the control room during confidential sessions.
06 Security
The processor takes appropriate technical and organisational measures, including:
- project files on studio systems that are not publicly reachable, with a separate backup;
- personal accounts with strong passwords and two-step verification where available;
- delivery through download links that expire after a limited period;
- a studio that is locked outside sessions;
- encrypted connections for the website and email.
The client assesses whether these measures suit the risk of its production and may set additional requirements, for instance for a release under embargo.
07 Sub-processors
The client gives general authorisation for the following sub-processors:
- TransIP B.V., Leiden: website and email hosting within the EU;
- a file transfer service for delivering large audio files.
The processor announces any new sub-processor in advance, and the client may object within fourteen days. The processor imposes the same obligations on sub-processors as in this agreement and remains responsible to the client. Transfers outside the EEA only take place with appropriate safeguards, such as the European Commission's standard contractual clauses.
08 Data subject rights
If the processor receives a request from a data subject, for example to access or delete a recording, it forwards the request to the client without answering it on the merits. The processor reasonably helps the client handle such requests within the statutory deadline.
09 Data breaches
If the processor discovers a security breach affecting the client's personal data, it notifies the client without undue delay, with what is known about the nature of the breach, the data involved, the likely consequences and the measures taken. This lets the client notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours where required. The client decides on notifying the authority and the data subjects.
10 Retention, return and deletion
After the last session the processor keeps project files for 12 months so revisions remain possible; mixing includes 2 revision rounds. After that, or earlier on request, the processor deletes or returns the data, as the client prefers. Data the processor must keep by law, such as invoices, is excluded.
11 Audits and information
The processor makes available all information needed to demonstrate compliance. The client may have an audit carried out at most once a year, with at least two weeks' notice, by an independent expert bound by confidentiality. The client bears the cost, unless the audit shows that the processor materially fails to comply with this agreement.
12 Liability and governing law
Liability is governed by the terms and conditions, unless mandatory GDPR rules provide otherwise. Dutch law applies to this agreement, and disputes go to the competent court of the Amsterdam District Court. Questions about this agreement can be sent to [email protected]; how we handle data of our own clients is set out in the privacy policy. This version applies from 5 October 2026.