- Updated
Data processing agreement
Updated: 24 July 2026
The German version is the editorial source. If the versions differ, the German version prevails.
between
the music school identified by legal name and address in the main contract
— the “Controller” —
and
Tamino Consulting UG (haftungsbeschränkt), Sansibarstraße 4a, 81827 Munich, Germany
— the “Processor” —
1. Subject matter and main contract
The Processor supplies the Concertainly web application for organising student concerts and processes personal data on the Controller's behalf. This agreement specifies the parties' data-protection obligations. It prevails for commissioned processing; applicable Standard Contractual Clauses prevail for the transfers they govern.
2. Duration
Processing begins when the school instance is activated or at the date stated in the main contract and continues for the main contract term. Confidentiality, return, deletion and evidence obligations continue until fulfilled.
3. Nature and purpose
Processing may include collection, recording, organisation, storage, retrieval, display, alteration, transmission, export, restriction, anonymisation and erasure for:
- school, team and role administration;
- planning and running student concerts;
- school registration, waiting list and self-service;
- communication with authorised users and registrants;
- programmes, lists, certificates and exports;
- school-level statistics;
- access, deletion and retention instructions;
- support, backup, troubleshooting and secure operation;
- optional AI assistance only within the agreed data-minimised scope.
4. Data subjects and data
Data subjects may include minor and adult students, parents and guardians, registrants, school owners, staff, administrators and teachers, companions or performers, and customer support contacts.
Data may include identifiers and contact details, accounts, roles and permissions, student birth dates, school, teacher, concert, work, instrumentation and registration relationships, companion and waiting-list information, organisational notes, consent and withdrawal evidence, communication and delivery metadata, technical security and audit data, and export, access, deletion, retention and offboarding information.
Special-category data under Article 9 GDPR is not intended. If identified, the parties will coordinate the next steps. Free-text fields are not intended for health or other sensitive data.
5. Instructions
The Processor acts only on documented instructions, including for international transfers, unless law requires otherwise. The main contract, this DPA, Controller settings and authorised product actions are documented instructions.
Additional instructions must be sent in text form to tamino.rat@gmail.com. The Processor will first explain consequences and possible fees for work outside the agreed scope. Potentially unlawful instructions are flagged and may be suspended to protect the data.
6. Controller obligations
The Controller ensures lawfulness, transparency and minimisation; informs data subjects and handles their rights; manages roles; determines retention; gives clear instructions; reports privacy and security issues promptly; avoids special-category data unless expressly agreed; and assesses whether the measures are appropriate to its risk.
7. Processor obligations
The Processor follows purposes and instructions, binds authorised people to confidentiality, implements Annex 2, limits access, assists under sections 8 and 9, maintains required records, provides compliance information, and documents material changes.
8. Data-subject rights
School-data requests received directly by the Processor are forwarded promptly to the Controller unless the Processor has a separate responsibility. The Processor assists with access, rectification, erasure, restriction, portability, objection and consent evidence through school-scoped search, export, correction, deletion and audit features.
Requests are accepted at tamino.rat@gmail.com, assigned promptly to the relevant school instance and handled under the data-subject-request procedure. The Controller remains responsible for the response and statutory deadline.
9. Security, incidents and impact assessments
Taking into account the nature of processing and available information, the Processor assists with processing security, regulatory and data-subject notifications, impact assessments and prior consultation.
The Processor notifies the Controller without undue delay after becoming aware of a school-data breach. The Controller reports security incidents to tamino.rat@gmail.com. An initial notice will, where available, state the event type and time, affected systems, categories and approximate scale, likely consequences, mitigation and a contact.
The working target is notification without undue delay and, where possible, within 24 hours after internal confirmation. This target does not reduce the obligation to notify without undue delay.
10. Subprocessors
The Controller generally authorises the direct subprocessors listed in Annex 3. The Processor imposes substantially equivalent protections and remains responsible for its obligations.
Notice period: at least five calendar days.
Notice channel: email to the Controller's contract contact.
The Controller may object on reasonable data-protection grounds within three calendar days after receipt. The parties first seek a reasonable solution. If none is available, the Processor may suspend the affected feature or use an equivalent provider. If neither is reasonable, the Controller may terminate the affected part of the service for cause when the change takes effect.
The current public list is at /en/legal/subprocessors; the contractually
incorporated version remains authoritative.
11. International transfers
Processing outside the EEA occurs only on documented instructions and under applicable law. Where there is no adequacy decision, the Processor uses appropriate safeguards, in particular applicable Standard Contractual Clauses, and assesses supplementary measures. Annex 3 identifies the account-specific locations and mechanisms after verification.
12. Technical and organisational measures
Annex 2 describes the measures in force when the contract is entered into. They must provide security appropriate to the risk and be tested regularly. Measures may evolve if the overall protection is not reduced. Material changes are documented.
13. Evidence and audits
The Processor supplies appropriate evidence such as security descriptions, reports, certifications, subprocessor information and reasonable questionnaire responses.
With reasonable notice, the Controller may audit no more than once per calendar year, or appoint an independent auditor bound to confidentiality. Additional audits may be appropriate after an incident or on a substantiated compliance concern.
Audits require at least 14 calendar days' notice and first use available evidence and remote review. Standard evidence is supplied without charge. Additional customer-specific or on-site audits are paid by the Controller after prior coordination unless the audit identifies a material Processor breach.
14. Return and deletion
The Controller may use the available exports during the contract. At the end of the service, the Processor returns or deletes school personal data at the Controller's choice unless law requires retention.
Procedure:
- export window: 30 days from contract end;
- productive-access suspension: at contract end;
- active-data deletion: within 30 days after the export window or earlier on documented instruction;
- encrypted-backup expiry: within a further 30 days, restricted and usable only for recovery in the interim;
- deletion confirmation: in text form within 14 days after completion.
Legally retained data is restricted, purpose-limited and deleted when the period expires.
15. Processor's own responsibility
Own contract administration, billing and strictly necessary platform security processing is not performed on the Controller's instructions and must be covered by the platform privacy notice. School data is not repurposed for advertising, profiling or general AI training merely through a contract term.
16. Liability and final terms
Article 82 GDPR remains unaffected. As between the parties, each party is responsible for damage caused by its culpable breach of this DPA. Otherwise, the main-contract liability terms apply insofar as they do not restrict mandatory data-protection claims.
Changes, including annexes, are documented in text form. Electronic acceptance is permitted if identity, version and time are evidenced.
Annex 1 — Processing description
| Item | Agreement |
|---|---|
| Product | Concertainly |
| Tenant | music school identified in the main contract or account |
| Subject | Student-concert organisation |
| Duration | Main contract term plus return and deletion phase |
| Data subjects | Students, families, adult students, teachers, school team |
| Data | Section 4 |
| Special categories | Not intended |
| Frequency | Continuous during use |
| Controller instruction contact | contact stored in the main contract or customer account |
| Processor privacy contact | Tamino Rat, tamino.rat@gmail.com |
Annex 2 — Technical and organisational measures
The technical and organisational measures supplied by the operator form part of this agreement.
Annex 3 — Subprocessors
The subprocessor list incorporated into the contract applies.