This English translation is provided for convenience only. The German version is the legally binding version. Read the German version.
Data Processing Agreement (DPA)
pursuant to Art. 28 GDPR · Version 1.2 · Last updated: 14 July 2026 · Part of the user agreement (Terms of Service § 9). Tip: you can save this page as a PDF using your browser’s print function.
1. Parties and subject matter
(1) The Controller is the taktjam user (teacher or music school as per the account registration, “Controller”). The Processor is clubjam FlexCo, Göstling 170, 3345 Göstling an der Ybbs, Österreich (Austria), FN 629031x (Regional Court of St. Pölten), datenschutz@clubjam.co (“Processor”). (2) The subject matter is the processing of personal data of students and parents/legal guardians in the course of providing the SaaS application taktjam. (3) This DPA becomes part of the user agreement upon registration; it applies for the agreement’s entire term.
2. Nature, purpose and scope of the processing (Annex 1)
The processing takes place exclusively to provide the functions of taktjam (hosting, storage, display, transmission, deletion) on the documented instructions of the Controller. Details — categories of data, data subjects, purposes — are described in Annex 1. The Processor does not process the data for its own purposes.
3. Right to issue instructions
(1) The Processor processes the data only on documented instructions from the Controller; use of the application’s functions constitutes such instructions. Supplementary instructions shall be given in text form to datenschutz@clubjam.co. (2) If the Processor considers an instruction to be unlawful, it shall inform the Controller without undue delay and may suspend execution until the instruction is confirmed.
4. Confidentiality
The Processor engages only persons who have committed themselves to confidentiality or who are subject to an appropriate statutory obligation of secrecy.
5. Security of processing (Art. 32 GDPR)
The Processor implements the technical and organizational measures (TOMs) described in Annex 2 and develops them further in line with the state of the art; in doing so, the level of protection must not be reduced.
6. Subprocessors (Art. 28 paras. 2 and 4 GDPR)
(1) The Controller grants general authorization for the use of the subprocessors listed in Annex 3. (2) Intended changes (additions/replacements) will be announced at least four weeks in advance by e-mail or in the application; the Controller may object on important grounds relating to data protection. In the event of an objection, both parties have the right to terminate the main agreement effective at the end of the current period. (3) Contracts meeting the requirements of Art. 28 GDPR are in place with each subprocessor. For transfers to third countries, appropriate safeguards pursuant to Chapter V GDPR are used (EU-US Data Privacy Framework or EU Standard Contractual Clauses); data is stored in the EU regions named in Annex 3.
7. Support obligations
(1) Data subject rights: The Processor supports the Controller in fulfilling the rights under Chapter III GDPR through the built-in self-service functions (complete data export, rectification within the application, deletion of individual records and of the entire account) and, in addition, upon request. Requests from data subjects received directly by the Processor will be forwarded to the Controller without undue delay. (2) Art. 32–36 GDPR: The Processor provides support with security measures, with the notification of personal data breaches and, where necessary, with data protection impact assessments. (3) Data breach: Breaches of the protection of the data processed on behalf of the Controller will be reported to the Controller without undue delay, at the latest within 48 hours of becoming aware of them, including the information pursuant to Art. 33 para. 3 GDPR.
8. Evidence and audits
(1) The Processor makes available all information necessary to demonstrate compliance with Art. 28 GDPR (in particular this DPA, the TOMs and the subprocessors’ certification/audit reports, e.g. Supabase’s SOC 2). (2) Further audits, including inspections, are possible upon prior notice of at least 14 days during business hours; they must not disrupt operations disproportionately or endanger the confidentiality of other customers.
9. Deletion and return
(1) During the term, the Controller can rectify, export and delete data itself at any time. (2) After termination of the main agreement, all data processed on behalf of the Controller will be deleted 30 days after the end of the contract (including stored content such as audio, image and PDF files), unless a statutory retention obligation prevents this. Exporting the data beforehand is the Controller’s responsibility; the export functions remain available until deletion. (3) Subprocessor backups rotate out automatically within at most 35 days.
10. Final provisions
(1) Duration and termination follow the main agreement. (2) Liability is governed by the main agreement (Terms of Service § 10) and Art. 82 GDPR. (3) Austrian law applies; the place of jurisdiction is the Processor’s registered office. (4) In the event of conflicts between this DPA and the Terms of Service, this DPA prevails in data protection matters.
Annex 1 — Subject matter of the processing
Categories of data subjects
Students of the Controller (including minors) and their parents/legal guardians.
Categories of data
Master data (name, optional date of birth, instrument), contact data (e-mail, phone, including that of parents/legal guardians), lesson data (appointments, attendance/cancellation status, make-up lesson credits, lesson notes, homework), messages between teacher and student/parents, teaching materials and recordings including profile photos (audio, image, video, PDF — only with documented consent), student billing data (rates, invoice amounts, payment status), technical portal access data (login attempt counters), device identifiers for push notifications (web push endpoint or FCM token — only where notifications are enabled). Special categories of personal data (Art. 9 GDPR) are not part of the engagement; the Controller shall ensure that no such data is entered.
Purposes
Lesson administration, scheduling, billing, communication, provision of the practice area and — only where the feature is enabled — AI-assisted drafts (Annex 3, Mistral AI; only the first name, instrument and excerpts from notes/homework are transmitted).
Annex 2 — Technical and organizational measures (TOMs)
Encryption: transport encryption (TLS 1.2+) for all connections; encryption of data at rest (AES-256) for the database and file storage. Tenant separation: end-to-end row-level security — every data row is bound to the Controller’s account and technically inaccessible to other accounts. Access control: access only after authentication; privileged system access (service role) exclusively server-side, never in the client; the practice space is protected by teacher-managed passwords (scrypt-hashed, verified in a timing-safe manner), signed HMAC session cookies (httpOnly, 30 days) and rate limiting (max. 20 login attempts/day). Transfer control: files are delivered only via short-lived signed URLs (60 minutes); recordings are displayed in the practice space only where consent is on record and are never sent as e-mail attachments. Input control: status changes with timestamps and system notes (e.g. make-up lesson audit trail); messages are immutable. Availability: daily automated database backups by the hosting subprocessor; self-service exports (JSON/CSV/PDF) at any time. Deletion concept: self-service deletion of individual records and of the entire account including storage cleanup; deletion 30 days after the end of the contract. Privacy-friendly defaults: no tracking and no analytics tools in the practice space; AI chat histories are not stored server-side; per-student media consent management. Location: data stored in the EU (Frankfurt am Main).
Annex 3 — Approved subprocessors
| Subprocessor | Service | Data location | Transfer safeguard |
|---|---|---|---|
| Supabase, Inc. (USA) | Database, authentication, file storage | EU (Frankfurt, AWS eu-central-1) | EU-US DPF / SCC |
| Vercel Inc. (USA) | Application hosting | EU (Frankfurt, region fra1) | EU-US DPF / SCC |
| Plus Five Five, Inc. (“Resend”, USA) — optional | E-mail delivery of lesson notes | EU region configured | EU-US DPF / SCC |
| Mistral AI SAS (France) — optional | AI features (no storage, no training) | EU (France) | — (EU provider) |
| Crisp IM SAS (France) — optional | Live chat support | EU (Netherlands/Germany) | — (EU provider) |
| Google Ireland Ltd. / Google LLC (USA) — optional | Firebase Cloud Messaging — push delivery to the mobile app (device token, notification text) | USA / global | EU-US DPF / SCC |
“Optional” = used only if the Controller actively uses the respective feature (e-mail delivery, AI features, live chat or mobile-app push notifications). Web push is triggered by the Processor’s own server; its content is end-to-end encrypted (RFC 8291), so the browser/ operating-system vendors’ push services cannot read it.
clubjam FlexCo · datenschutz@clubjam.co · Terms of Service (AGB) · Privacy Policy · Legal Notice (Impressum)
Last updated: 14 July 2026.