GDPR Article 28 Agreement
Data Processing Agreement (DPA)
Last updated: September 29, 2026 · Applicable to studio projects of Lymnaean Space B.V. via lymnaeanspaceio.click
This Data Processing Agreement applies between the Client (the Data Controller) and Lymnaean Space B.V. in Amsterdam-Noord (the Data Processor, KvK 84920173, Aambeeldstraat 18, 1021 KB Amsterdam, The Netherlands). This agreement governs the processing of personal data and audio materials in the context of studio recording, mixing, mastering, or facility rental upon documented instructions from the Client in accordance with Article 28 of the General Data Protection Regulation (GDPR).
1. Subject Matter and Scope of Processing
The Processor processes personal data exclusively on behalf of and under documented instructions of the Data Controller for the execution of agreed studio services. The processing includes:
- Categories of Data Subjects: artists, session musicians, vocalists, producers, and crew designated by the client.
- Types of Personal Data: audio tracks with vocal performances, vocal characteristics, performer names, session credits, and track documentation.
- Purpose of Processing: recording, editing, mixing, mastering, and delivering digital audio files as agreed in the booking confirmation.
2. Obligations of the Processor
Lymnaean Space B.V. guarantees the following technical and operational safeguards:
- Personal data and session files are processed solely based on written instructions from the Client, unless statutory EU or Dutch laws require otherwise.
- All studio staff (including resident recording and mixing engineers) are bound by statutory confidentiality agreements.
- Appropriate technical and organizational security measures are maintained in accordance with Article 32 GDPR (see Appendix 1).
- The Studio makes no commercial use of client materials and never uses audio files to train machine learning or AI models without explicit prior written authorization.
3. Sub-processors
The Processor does not engage third-party sub-processors or public cloud storage providers for active multi-track sessions. All recording and signal processing occur locally on physical hardware inside our Amsterdam-Noord studio facility. Should any sub-processor become necessary in the future, the Client will be notified at least 30 days in advance with the right to object.
4. Data Storage and Transfers outside the EEA
All personal data, multitrack audio, and master files remain stored exclusively within the European Economic Area (EEA) on local studio media in The Netherlands. No cross-border transfers outside the EEA take place.
5. Personal Data Breach Notifications
In the unlikely event of a security incident or personal data breach, the Processor shall inform the Data Controller without undue delay and at the latest within 48 hours after becoming aware of the incident. The Processor provides all relevant details to enable the Controller to satisfy mandatory notification obligations to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
6. Data Subject Rights and Audits
If a data subject exercises their GDPR rights (such as access, rectification, or erasure), the Processor forwards the request immediately to the Client. The Client is entitled to request a written summary of the implemented technical and organizational safeguards once per calendar year upon reasonable notice.
7. Data Return and Deletion
Upon completion of studio services and final delivery of master files, the Studio will, at the Client's choice, securely return and/or permanently erase all session files and multitracks from local disks within 30 days of receiving a written request.
8. Applicable Law and Jurisdiction
This agreement is governed exclusively by the laws of The Netherlands. Any disputes arising in connection with this agreement shall be submitted to the competent court in Amsterdam.
Appendix 1 — Technical & Organizational Security Measures
- Physical access control to the control room and live recording floors in Amsterdam-Noord; no unauthorized public entry.
- Active multi-track sessions stored on isolated local NVMe arrays without public cloud syncing.
- Project access restricted strictly to authorized resident engineers and designated client representatives.
- Final master files delivered via secure direct encrypted channels to the client's verified address.
- Absolute non-disclosure regarding unreleased tracks, song titles, and artist schedules.