Legal
Data Processing Addendum
This addendum forms part of the Choir Central Terms of service where a customer uses Choir Central to process personal data for which that customer is the controller.
Effective and last updated: 14 August 2026
1. Parties and scope
The customer is the controller and Richard Keenan and Natasha May, trading in partnership as Choir Central, are the processor. UK GDPR, the Data Protection Act 2018 and applicable replacement legislation apply. Terms such as controller, processor and personal data have their statutory meanings. This addendum prevails over conflicting service terms.
2. Processing details
- Subject and duration: hosting and operating choir-management data while the customer uses the service, plus limited backup, wind-down and legal-retention periods.
- Nature and purpose: storing, organising, retrieving, transmitting, securing, backing up and deleting data for membership, events, attendance, files, music, programmes, email and support.
- People: customers, organisers, members, invitees, attendees, ticket holders, performers and other people identified in customer content.
- Data: identity and contact details, memberships, roles, voice parts, attendance, event and location data, communications, files, recordings, programme data and technical identifiers.
- Sensitive data: only necessary information the customer lawfully chooses to submit, which may include health, accessibility, religion or information relating to children.
3. Customer instructions and duties
The service configuration, authorised user actions and these terms are the customer’s documented instructions. The customer must ensure that its instructions and processing are lawful, provide required notices, have a valid lawful basis and Article 9 condition where needed, minimise data, manage user access and respond to data-subject requests. We will tell the customer if an instruction appears unlawful unless prohibited.
4. Our obligations
We will:
- process customer personal data only on documented instructions, including for international transfers;
- ensure people authorised to process it are subject to confidentiality duties;
- maintain appropriate technical and organisational security measures;
- reasonably assist with rights requests, security incidents, impact assessments and regulator consultations, taking account of the processing and information available;
- notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data; and
- make information reasonably necessary to demonstrate compliance available and support proportionate audits, subject to confidentiality, security and reasonable notice.
5. Security measures
Measures include managed authentication, role-based access, encrypted transport, encrypted cloud services, short-lived signed file links, request validation, backups, monitoring, secret management and incident logging. We review measures as risk and technology change. The customer remains responsible for permissions, endpoint security and content backups.
6. Subprocessors
The customer gives general authorisation to use subprocessors. Current providers include Amazon Web Services, Cloudflare, Clerk, Resend, Stripe, Google Maps Platform, Sentry and GitHub, according to the feature used. YouTube and Spotify may act independently when embeds are requested. We require equivalent data-protection obligations where applicable and remain responsible for our subprocessors’ processing.
We will provide reasonable notice of a material new subprocessor. A customer may object on reasonable data-protection grounds by contacting us promptly; we will work in good faith on a practical solution.
7. International transfers
Where customer data is transferred outside the UK, we will use a lawful mechanism such as UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to approved standard contractual clauses, together with supplementary measures where required.
8. Return and deletion
During the subscription, customers can retrieve data through service views and available exports. On written request following termination, we will delete or return customer personal data unless law requires retention. Deletion from backups occurs through normal backup expiry. The customer should request an export before access ends.
9. Contact
Data-protection questions, rights requests and audit enquiries should be sent to support@choircentral.com.