Data Processing Agreement
Effective August 13, 2026 · Midtown West LLC d/b/a Phantone.fm · Version 1.0
This Data Processing Agreement applies to Processing of Personal Data by Midtown West LLC d/b/a Phantone.fm on behalf of its customers. To execute this DPA, complete the Controller signature block below and return a signed copy to compliance@phantone.fm. Processor's signature is pre-applied below.
01Parties
This Data Processing Agreement ("DPA") is entered into between the customer identified in the underlying agreement ("Controller") and Midtown West LLC, a California limited liability company doing business as Phantone.fm, with offices at 705 Gold Lake Dr Suite 250, Folsom CA 95630 ("Processor"). It forms part of, and is subject to, the Master Services Agreement, Order Form, or terms of service between the parties (the "Agreement").
02Definitions
Capitalized terms not defined here have the meanings given in the Agreement or in Regulation (EU) 2016/679 (the "GDPR") and the UK Data Protection Act 2018 and UK GDPR (together, "Data Protection Laws"). "Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR. "Standard Contractual Clauses" or "SCCs" means the EU Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor). "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018. "Restricted Transfer" means a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country not subject to an adequacy decision.
03Scope, nature and purpose of Processing
Processor will Process Personal Data on behalf of Controller solely to provide and support the Phantone audio-watermarking software-as-a-service, including audio fingerprint encoding and decoding, attribution event ingestion, dashboards, APIs, webhooks, billing, and customer support. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex I.
04Duration
This DPA is effective on the effective date of the Agreement and continues until the later of (a) termination of the Agreement and (b) Processor's deletion or return of all Personal Data in accordance with Section 13 below.
05Categories of Data Subjects
Listeners, viewers, and end users of Controller's audio content; Controller's authorized users (employees, contractors, and agents) of the Phantone product.
06Categories of Personal Data
Account identifiers (email address, name); listening and device telemetry (hashed device or installation identifiers, IP address, user agent); location derived from IP address at coarse (city/region) resolution by default, with precise location Processed only where the end user has separately opted in through the participating application; allowlisted context fields defined per campaign, meaning Processor receives only the fields configured for that campaign and not arbitrary device or application content; short-lived ephemeral presence records; attribution and impression event records; audit log entries; and support correspondence. Raw audio is Processed on the end user's device and is not transmitted to or stored by Processor.
07Processor obligations
- Process Personal Data only on documented instructions from Controller, including with regard to Restricted Transfers, unless required to do so by applicable law (in which case Processor will inform Controller of that legal requirement before Processing, unless that law prohibits such information).
- Ensure that personnel authorized to Process Personal Data have committed to confidentiality.
- Implement and maintain appropriate technical and organizational measures as described in Annex II.
- Assist Controller, taking into account the nature of the Processing, in fulfilling its obligations to respond to Data Subject requests.
- Make available to Controller all information necessary to demonstrate compliance with Article 28 of the GDPR and allow for and contribute to audits as described in Section 11.
08Sub-processors
Controller provides a general written authorization for Processor to engage Sub-processors. Processor will (a) maintain a current list of Sub-processors at /trust and provide at least 30 days' prior notice (by email to the workspace owner or via the dashboard) of any intended addition or replacement of a Sub-processor that Processes Personal Data; (b) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA; and (c) remain liable for the acts and omissions of its Sub-processors. Controller may object to a new Sub-processor on reasonable data protection grounds within 30 days; if the parties cannot agree on a resolution, Controller may terminate the affected service for convenience.
09Data Subject rights
Taking into account the nature of the Processing, Processor will assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller's obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making).
10Personal Data Breach notification
Processor will notify Controller without undue delay, and in any event within 72 hours of becoming aware of a confirmed Personal Data Breach affecting Controller's Personal Data. The notification will include the information reasonably available to Processor, including the nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.
11Audits
Processor will make available to Controller, on reasonable request and subject to confidentiality obligations, the most recent SOC 2 Type 2 report covering the Phantone service (when available) and the equivalent reports for its infrastructure providers, which the parties agree satisfy Controller's audit right. To the extent additional information is reasonably required, Controller may, no more than once per twelve-month period and at Controller's expense, conduct an on-site audit on reasonable advance written notice, during normal business hours, and in a manner that does not interfere with Processor's operations or compromise the confidentiality of other customers' data.
12International transfers
Where the Processing of Personal Data under this DPA involves a Restricted Transfer from the EEA, the SCCs (Module Two, Controller to Processor) are hereby incorporated by reference and entered into between the parties, with Controller as data exporter and Processor as data importer. The optional Docking Clause (Clause 7) does not apply. Under Clause 9, Option 2 (general written authorization) applies with a 30-day notice period as set out in Section 8 above. Under Clauses 17 and 18, the parties select the law and forum of the EU Member State where the Controller is established or, if none, of Ireland. For Restricted Transfers originating in the United Kingdom, the UK Addendum is incorporated by reference and entered into between the parties, completing Tables 1, 2, and 3 by reference to the information in this DPA and its Annexes.
13Return and deletion of Personal Data
Upon termination or expiry of the Agreement, Processor will, at Controller's election, return or delete all Personal Data Processed on behalf of Controller within 30 days, unless applicable law requires further storage. Controller may also request earlier deletion of specific Personal Data by written notice to compliance@phantone.fm. Retention exception: audit log entries and impression records are maintained on an append-only basis for integrity and verification purposes. Where deletion would compromise that integrity record, Processor will delete or de-identify the Personal Data associated with the entry and retain only the non-identifying verification data, for no longer than necessary and only where permitted by applicable law. Processor will identify to Controller any Personal Data retained under this exception.
14Liability
Each party's liability arising out of or in connection with this DPA, whether in contract, tort, or any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits liability that cannot be limited under applicable law.
15Governing law
Except where Data Protection Laws or the SCCs require otherwise, this DPA is governed by the law specified in the Agreement, or, absent such specification, by the laws of the State of California, without regard to its conflict-of-laws principles.
16Order of precedence
In the event of any conflict or inconsistency between this DPA and the Agreement, this DPA prevails with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or the UK Addendum, the SCCs and UK Addendum prevail.
Details of Processing
| Data exporter | The customer identified in the Agreement (Controller). |
| Data importer | Midtown West LLC d/b/a Phantone.fm, 705 Gold Lake Dr Suite 250, Folsom CA 95630, United States. Contact: compliance@phantone.fm. |
| Categories of Data Subjects | Listeners, viewers, and end users of Controller's audio content; Controller's authorized users. |
| Categories of Personal Data | Account identifiers; listening and device telemetry (hashed device IDs, IP address, user agent, coarse geolocation); attribution event records; audit log entries; support correspondence. |
| Special categories of data | None intended. Controller will not submit special categories of data via the Phantone service. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature of Processing | Hosting, storage, encoding and decoding of audio fingerprints, attribution analytics, dashboard access, webhook delivery, billing, and support. |
| Purpose of Processing | Provision of the Phantone audio-watermarking SaaS as described in the Agreement. |
| Duration / retention | For the duration of the Agreement, plus up to 30 days following termination for return or deletion; audit logs retained up to 365 days. |
| Recipients | Sub-processors listed at /trust and in Annex III. |
| Restricted Transfers | From the EEA and the United Kingdom to the United States. Safeguarded by the SCCs (Module 2) and, for UK transfers, the UK Addendum. |
| Competent supervisory authority | Where Controller is established in the EEA, the supervisory authority of its main establishment. For UK transfers, the UK Information Commissioner. |
Technical and Organizational Measures
| Encryption at rest | AES-256 across database, object storage, and backups, with managed KMS and documented key rotation. |
| Encryption in transit | TLS 1.2 or higher for all traffic between clients, the Phantone application, the Phantone API, and outbound webhook receivers. |
| Pseudonymization | Device identifiers are hashed before storage. Aggregated reporting does not expose raw identifiers. |
| Access control | Least-privilege RBAC, six application roles, SAML SSO with enforced MFA for production access, quarterly access reviews, automated deprovisioning within 24 hours of separation. |
| Tenant isolation | Row-level security on every workspace-scoped table, enforced via a security-definer has_role() function. |
| Network security | Private VPC, no public database exposure, WAF, DDoS mitigation, optional per-workspace IP allowlisting. |
| Logging and monitoring | Centralized application, infrastructure, and audit logs retained for at least 365 days; 24/7 on-call rotation. |
| Backups and recovery | Daily backups, 7-day point-in-time recovery, 4-hour RTO, 1-hour RPO, restore tested at least quarterly. |
| Incident response | Documented Incident Response Plan; customer notification without undue delay and within 72 hours of confirmation; written postmortem within 10 business days of resolution. |
| Personnel | Confidentiality and acceptable-use agreements at hire, background checks where permitted by law, security awareness training at hire and annually. |
| Secure development | Mandatory peer code review, dependency scanning and static analysis in CI, secret scanning, annual third-party penetration test. |
| Sub-processor governance | Documented list, equivalent contractual obligations flowed down, 30-day prior notice of additions or replacements. |
Sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure hosting | United States (with EU region available on request) |
| Managed Postgres provider | Primary application database | United States (with EU region available on request) |
| Transactional email provider | Account, billing, and notification email delivery | United States / EEA |
| Error monitoring provider | Application error and performance monitoring | United States / EEA |
| Support helpdesk provider | Customer support ticketing and correspondence | United States |
| Payment processor | Billing, invoicing, and tokenized card processing | United States |
The current sub-processor list is also maintained at /trust. Updates are notified per Section 8.
Matthew Loughran, EMBA
Founder, Midtown West LLC
d/b/a Phantone.fm
Date: August 13, 2026
Signature
Name and title
Company
Date