Business instructions should control Business data.
This Data Processing Addendum forms part of the Business SaaS Agreement when a Business uses Galaxy Cue to process Client or Event personal information.
1. Roles and scope
For Client and Event personal information the Business submits or controls, the Business acts as controller/business and Galaxy Cue LLC, operating Galaxy Cue, acts as processor/service provider, to the extent those concepts apply. Each party separately controls information it determines for its own account, legal, security, billing, or employment purposes.
2. Documented instructions
Galaxy Cue processes Business data only to provide, secure, support, and improve the contracted service; follow documented settings and authorized actions; comply with law; or as otherwise agreed in writing. Galaxy Cue will inform the Business when it believes an instruction violates applicable data-protection law unless prohibited from doing so.
3. Confidentiality and personnel
Galaxy Cue limits access to personnel and contractors with a service need and confidentiality duties. Production access should be logged and reviewed. The Business controls its members and is responsible for promptly removing unauthorized access.
4. Security
Galaxy Cue will maintain risk-appropriate administrative, technical, and organizational safeguards, including authentication, role/tenant isolation, public-table row-level policies, protected provider secrets, encryption in transit, provider encryption at rest, logging, backup/recovery practices, secure development, incident response, and deletion controls. The Business must securely configure accounts, integrations, exports, and staff access.
5. Individual rights and compliance assistance
Taking into account the nature of processing, Galaxy Cue will provide reasonable product and support assistance for verified access, correction, deletion, portability, restriction, opt-out, consent, and appeal requests. Galaxy Cue will direct a request concerning Business-controlled Event data to the Business unless legally permitted to respond directly.
6. Security incidents
Galaxy Cue will notify the affected Business without undue delay after confirming unauthorized access, acquisition, disclosure, alteration, or destruction of Business data that qualifies as a reportable incident under the DPA. Notice will include available facts, affected data, likely consequences, containment, and contact details. Notification is not an admission of fault. Notice timing also follows applicable law and any controlling written agreement.
7. Subprocessors
The Business authorizes the subprocessors listed on the Subprocessor page, subject to equivalent data-protection obligations appropriate to their work. Galaxy Cue remains responsible for its subprocessor obligations to the extent required by law and this DPA. Material additions receive notice and a reasonable objection path where required.
8. Government requests and audits
Galaxy Cue will evaluate legal demands, seek appropriate limits, and notify the Business when legally permitted. Reasonable compliance information should satisfy ordinary audit requests; intrusive audits require advance notice, confidentiality, scope limits, and protection of other customers.
9. International transfers
Galaxy Cue does not currently target a dedicated Italy or European Union offering. When protected data is transferred outside the European Economic Area and those rules apply, the parties must use an applicable adequacy decision, EU Standard Contractual Clauses, or another lawful transfer mechanism, together with any required assessment and supplemental measures. Galaxy Cue does not represent that a transfer instrument applies until it is verified for the relevant provider and processing.
This DPA is supplemented by the processing exhibit below, the current Subprocessor List, and the Italy & EU Supplement when applicable.
10. Return and deletion
At the end of service, Galaxy Cue will make supported exports available and delete or return Business data as agreed, except limited records retained for law, security, accounting, consent, dispute, or backup rotation. Retained records remain protected and are not used for ordinary product purposes.
Processing exhibit
| Subject matter | Business booking, Client relationship, Event workflow, documents, messages, payments status, marketing consent, and support |
|---|---|
| Duration | Subscription/authorized use plus documented retention and backup periods |
| People | Business members, Clients, Event Contacts, performers/providers, Marketplace participants, and support users |
| Data | Identifiers, contact/profile, Business/professional, Event/commercial, preferences/content, technical/security, consent and connected-provider status |
| Special restrictions | No raw payment credentials, passwords, government IDs, health records, biometric templates, or other unnecessary highly sensitive data |
| Business purpose | Operate and secure the contracted Galaxy Cue service under documented Business instructions |
