Data Processing Agreement

Data Processing Agreement

Effective August 13, 2026 · Midtown West LLC d/b/a Phantone.fm · Version 1.0

This Data Processing Agreement applies to Processing of Personal Data by Midtown West LLC d/b/a Phantone.fm on behalf of its customers. To execute this DPA, complete the Controller signature block below and return a signed copy to compliance@phantone.fm. Processor's signature is pre-applied below.

01Parties

This Data Processing Agreement ("DPA") is entered into between the customer identified in the underlying agreement ("Controller") and Midtown West LLC, a California limited liability company doing business as Phantone.fm, with offices at 705 Gold Lake Dr Suite 250, Folsom CA 95630 ("Processor"). It forms part of, and is subject to, the Master Services Agreement, Order Form, or terms of service between the parties (the "Agreement").

02Definitions

Capitalized terms not defined here have the meanings given in the Agreement or in Regulation (EU) 2016/679 (the "GDPR") and the UK Data Protection Act 2018 and UK GDPR (together, "Data Protection Laws"). "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR. "Standard Contractual Clauses" or "SCCs" means the EU Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor). "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018. "Restricted Transfer" means a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country not subject to an adequacy decision.

03Scope, nature and purpose of Processing

Processor will Process Personal Data on behalf of Controller solely to provide and support the Phantone audio-watermarking software-as-a-service, including audio fingerprint encoding and decoding, attribution event ingestion, dashboards, APIs, webhooks, billing, and customer support. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex I.

04Duration

This DPA is effective on the effective date of the Agreement and continues until the later of (a) termination of the Agreement and (b) Processor's deletion or return of all Personal Data in accordance with Section 13 below.

05Categories of Data Subjects

Listeners, viewers, and end users of Controller's audio content; Controller's authorized users (employees, contractors, and agents) of the Phantone product.

06Categories of Personal Data

Account identifiers (email address, name); listening and device telemetry (hashed device or installation identifiers, IP address, user agent); location derived from IP address at coarse (city/region) resolution by default, with precise location Processed only where the end user has separately opted in through the participating application; allowlisted context fields defined per campaign, meaning Processor receives only the fields configured for that campaign and not arbitrary device or application content; short-lived ephemeral presence records; attribution and impression event records; audit log entries; and support correspondence. Raw audio is Processed on the end user's device and is not transmitted to or stored by Processor.

07Processor obligations

  • Process Personal Data only on documented instructions from Controller, including with regard to Restricted Transfers, unless required to do so by applicable law (in which case Processor will inform Controller of that legal requirement before Processing, unless that law prohibits such information).
  • Ensure that personnel authorized to Process Personal Data have committed to confidentiality.
  • Implement and maintain appropriate technical and organizational measures as described in Annex II.
  • Assist Controller, taking into account the nature of the Processing, in fulfilling its obligations to respond to Data Subject requests.
  • Make available to Controller all information necessary to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits as described in Section 11.

08Sub-processors

Controller provides a general written authorization for Processor to engage Sub-processors. Processor will (a) maintain a current list of Sub-processors at /trust and provide at least 30 days' prior notice (by email to the workspace owner or via the dashboard) of any intended addition or replacement of a Sub-processor that Processes Personal Data; (b) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA; and (c) remain liable for the acts and omissions of its Sub-processors. Controller may object to a new Sub-processor on reasonable data protection grounds within 30 days; if the parties cannot agree on a resolution, Controller may terminate the affected service for convenience.

09Data Subject rights

Taking into account the nature of the Processing, Processor will assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).

10Personal Data Breach notification

Processor will notify Controller without undue delay, and in any event within 72 hours of becoming aware of a confirmed Personal Data Breach affecting Controller's Personal Data. The notification will include the information reasonably available to Processor, including the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.

11Audits

Processor will make available to Controller, on reasonable request and subject to confidentiality obligations, the most recent SOC 2 Type 2 report covering the Phantone service (when available) and the equivalent reports for its infrastructure providers, which the parties agree satisfy Controller's audit right. To the extent additional information is reasonably required, Controller may, no more than once per twelve-month period and at Controller's expense, conduct an on-site audit on reasonable advance written notice, during normal business hours, and in a manner that does not interfere with Processor's operations or compromise the confidentiality of other customers' data.

12International transfers

Where the Processing of Personal Data under this DPA involves a Restricted Transfer from the EEA, the SCCs (Module Two, Controller to Processor) are hereby incorporated by reference and entered into between the parties, with Controller as data exporter and Processor as data importer. The optional Docking Clause (Clause 7) does not apply. Under Clause 9, Option 2 (general written authorization) applies with a 30-day notice period as set out in Section 8 above. Under Clauses 17 and 18, the parties select the law and forum of the EU Member State where the Controller is established or, if none, of Ireland. For Restricted Transfers originating in the United Kingdom, the UK Addendum is incorporated by reference and entered into between the parties, completing Tables 1, 2, and 3 by reference to the information in this DPA and its Annexes.

13Return and deletion of Personal Data

Upon termination or expiry of the Agreement, Processor will, at Controller's election, return or delete all Personal Data Processed on behalf of Controller within 30 days, unless applicable law requires further storage. Controller may also request earlier deletion of specific Personal Data by written notice to compliance@phantone.fm. Retention exception: audit log entries and impression records are maintained on an append-only basis for integrity and verification purposes. Where deletion would compromise that integrity record, Processor will delete or de-identify the Personal Data associated with the entry and retain only the non-identifying verification data, for no longer than necessary and only where permitted by applicable law. Processor will identify to Controller any Personal Data retained under this exception.

14Liability

Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits liability that cannot be limited under applicable law.

15Governing law

Except where Data Protection Laws or the SCCs require otherwise, this DPA is governed by the law specified in the Agreement, or, absent such specification, by the laws of the State of California, without regard to its conflict-of-laws principles.

16Order of precedence

In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA prevails with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or the UK Addendum, the SCCs and UK Addendum prevail.

Annex I

Details of Processing

Data exporterThe customer identified in the Agreement (Controller).
Data importerMidtown West LLC d/b/a Phantone.fm, 705 Gold Lake Dr Suite 250, Folsom CA 95630, United States. Contact: compliance@phantone.fm.
Categories of Data SubjectsListeners, viewers, and end users of Controller's audio content; Controller's authorized users.
Categories of Personal DataAccount identifiers; listening and device telemetry (hashed device IDs, IP address, user agent, coarse geolocation); attribution event records; audit log entries; support correspondence.
Special categories of dataNone intended. Controller will not submit special categories of data via the Phantone service.
Frequency of transferContinuous, for the duration of the Agreement.
Nature of ProcessingHosting, storage, encoding and decoding of audio fingerprints, attribution analytics, dashboard access, webhook delivery, billing, and support.
Purpose of ProcessingProvision of the Phantone audio-watermarking SaaS as described in the Agreement.
Duration / retentionFor the duration of the Agreement, plus up to 30 days following termination for return or deletion; audit logs retained up to 365 days.
RecipientsSub-processors listed at /trust and in Annex III.
Restricted TransfersFrom the EEA and the United Kingdom to the United States. Safeguarded by the SCCs (Module 2) and, for UK transfers, the UK Addendum.
Competent supervisory authorityWhere Controller is established in the EEA, the supervisory authority of its main establishment. For UK transfers, the UK Information Commissioner.
Annex II

Technical and Organizational Measures

Encryption at restAES-256 across database, object storage, and backups, with managed KMS and documented key rotation.
Encryption in transitTLS 1.2 or higher for all traffic between clients, the Phantone application, the Phantone API, and outbound webhook receivers.
PseudonymizationDevice identifiers are hashed before storage. Aggregated reporting does not expose raw identifiers.
Access controlLeast-privilege RBAC, six application roles, SAML SSO with enforced MFA for production access, quarterly access reviews, automated deprovisioning within 24 hours of separation.
Tenant isolationRow-level security on every workspace-scoped table, enforced via a security-definer has_role() function.
Network securityPrivate VPC, no public database exposure, WAF, DDoS mitigation, optional per-workspace IP allowlisting.
Logging and monitoringCentralized application, infrastructure, and audit logs retained for at least 365 days; 24/7 on-call rotation.
Backups and recoveryDaily backups, 7-day point-in-time recovery, 4-hour RTO, 1-hour RPO, restore tested at least quarterly.
Incident responseDocumented Incident Response Plan; customer notification without undue delay and within 72 hours of confirmation; written postmortem within 10 business days of resolution.
PersonnelConfidentiality and acceptable-use agreements at hire, background checks where permitted by law, security awareness training at hire and annually.
Secure developmentMandatory peer code review, dependency scanning and static analysis in CI, secret scanning, annual third-party penetration test.
Sub-processor governanceDocumented list, equivalent contractual obligations flowed down, 30-day prior notice of additions or replacements.
Annex III

Sub-processors

Sub-processorPurposeRegion
Amazon Web Services, Inc.Cloud infrastructure hostingUnited States (with EU region available on request)
Managed Postgres providerPrimary application databaseUnited States (with EU region available on request)
Transactional email providerAccount, billing, and notification email deliveryUnited States / EEA
Error monitoring providerApplication error and performance monitoringUnited States / EEA
Support helpdesk providerCustomer support ticketing and correspondenceUnited States
Payment processorBilling, invoicing, and tokenized card processingUnited States

The current sub-processor list is also maintained at /trust. Updates are notified per Section 8.

Processor
Matthew Loughran

Matthew Loughran, EMBA

Founder, Midtown West LLC

d/b/a Phantone.fm

Date: August 13, 2026

Controller

Signature

Name and title

Company

Date