This Data Processing Agreement ("DPA") forms part of the agreement between the Business Customer identified in the applicable Order or account acceptance (the Controller) and MC Studio (the Processor) where MC Studio processes Customer Personal Data on behalf of that Business Customer. It applies to that processing, including on a Free plan, when incorporated into and accepted with the relevant agreement. A separate signature is not required unless the parties agree otherwise.
MC Studio is a trade name of REVE Media, KVK 88874990, VAT identification number NL004665647B65, with business address Diamantdreef 16, 7828 AW Emmen, the Netherlands.
1. Scope and roles
The Controller determines the purposes and means of processing Customer Personal Data.
MC Studio processes Customer Personal Data on documented instructions from the Controller, including instructions contained in:
-
the main agreement;
-
this DPA;
-
the applicable Order; and
-
the Controller's ordinary authorised configuration and use of the Services.
For personal data that MC Studio processes for its own purposes - such as billing, account administration, security of its own service, fraud prevention and MC Studio's own legal obligations - MC Studio may act as an independent controller and the Privacy Policy applies. The role depends on the actual processing. Security or support processing carried out on behalf of the Controller remains governed by this DPA.
2. Definitions
Customer Personal Data means personal data processed by MC Studio on behalf of the Controller through the Services.
Data Protection Law means the GDPR and other data-protection law applicable to the processing.
Subprocessor means a processor engaged by MC Studio to process Customer Personal Data on behalf of the Controller.
Terms such as personal data, processing, controller, processor, data subject and personal-data breach have the meanings given by the GDPR. Other capitalised terms not defined here have the meanings given in the MC Studio Terms of Service.
3. Processing details
The subject matter, duration, nature, purpose, categories of data and categories of data subjects are described in Annex 1.
Processing continues for the duration of the Controller's use of the relevant Services and the applicable return/deletion period, unless law requires otherwise.
4. Documented instructions
MC Studio will process Customer Personal Data only on documented instructions from the Controller unless EU or Member State law requires processing for another purpose.
If law requires processing beyond the Controller's instructions, MC Studio will inform the Controller before processing unless the law prohibits such notice.
MC Studio will inform the Controller if, in MC Studio's opinion, an instruction infringes Data Protection Law.
5. Confidentiality
MC Studio will ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality.
Access to Customer Personal Data will be limited to persons who reasonably need it for their role.
6. Security
MC Studio will implement appropriate technical and organisational measures under Article 32 GDPR, taking into account:
-
the state of the art;
-
implementation cost;
-
nature, scope, context and purposes of processing; and
-
the risk to individuals.
The baseline controls are described in Annex 2 and are minimum contractual safeguards when this DPA is in force.
MC Studio may update those controls as technology and risk evolve, provided the overall level of protection is not materially reduced.
7. Subprocessors
The Controller gives MC Studio general written authorisation to engage Subprocessors necessary to provide the Services, subject to this section and the current list made available under Annex 3 before acceptance of the agreement.
MC Studio will:
-
select Subprocessors providing sufficient data-protection guarantees for the delegated processing;
-
bind them in writing to the same relevant data-protection obligations imposed on MC Studio by this DPA;
-
remain responsible to the Controller for their performance of those obligations to the extent required by applicable law; and
-
maintain current information about Subprocessors and their relevant processing activities.
Notice of additions and replacements. MC Studio will normally give at least 14 calendar days' advance notice before a new or replacement Subprocessor begins processing the affected Controller's Customer Personal Data. A longer period will be provided where reasonably necessary in light of the processing, complexity or risk. Notice is sent by service email to the Controller's designated privacy contact or, if none has been designated, the workspace owner/account contact. It identifies the provider, intended activity, relevant processing locations, applicable transfer safeguards, proposed start date and how to object.
Updating a webpage or publishing a blog post without actively notifying the Controller does not replace this notice. The notice concerns intended additions and replacements, not only those MC Studio considers material.
Objections. The Controller may object on reasonable data-protection grounds by contacting privacy@mcstudio.io within the stated notice period. Under this general authorisation, MC Studio may proceed after that period where no such objection has been made and applicable legal requirements are satisfied.
If a timely objection is made, the parties will work in good faith to resolve it, for example through an alternative provider or another reasonable arrangement. MC Studio will not send the affected Customer Personal Data to the objected-to Subprocessor while a reasonable objection remains unresolved. If no reasonable solution is available, the Controller may terminate the affected Service before that Subprocessor begins the affected processing. The consequences of termination, including data return/deletion and any prepaid amounts, are governed by the main agreement and mandatory law.
Earlier use and urgent situations. An earlier start may be agreed through the Controller's specific written approval. Urgency alone does not remove the requirements for prior authorisation and a meaningful opportunity to object. MC Studio may use an already authorised provider or take proportionate protective action where needed to safeguard the Service. Any legally compelled processing remains subject to section 4 and applicable law.
MC Studio will obtain and maintain the information needed to identify the relevant processing chain and make it readily available to the Controller through the Annex 3 information, including maintained provider subprocessor disclosures where appropriate. Relevant additions and replacements remain subject to the applicable authorisation and notification requirements.
8. International transfers
MC Studio will not transfer Customer Personal Data outside the European Economic Area without a lawful transfer mechanism where one is required.
Mechanisms may include:
-
an adequacy decision;
-
the European Commission Standard Contractual Clauses; or
-
another lawful safeguard under Chapter V GDPR.
Where appropriate, MC Studio will assess transfer risks and apply supplementary measures.
9. Data-subject rights
Taking into account the nature of processing, MC Studio will assist the Controller by appropriate technical and organisational measures, insofar as reasonably possible, with requests to exercise data-subject rights. The Controller may send requests to privacy@mcstudio.io, identifying the relevant workspace, the request and applicable deadline. MC Studio will provide the reasonably available information or administrative assistance without undue delay so that the Controller can meet its legal obligations. Identity and authority checks will be proportionate to the request.
If MC Studio receives a request concerning Customer Personal Data and can identify the Controller, MC Studio will normally refer the requester to the Controller and notify the Controller, unless applicable law requires MC Studio to respond directly.
10. Personal-data breaches
MC Studio will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
The notification will include available information reasonably required under Article 33 GDPR, including where known:
-
the nature of the breach;
-
categories and approximate number of affected data subjects;
-
categories and approximate number of affected records;
-
likely consequences; and
-
measures taken or proposed to contain/remediate the breach.
Information may be provided in phases where it is not all immediately available.
MC Studio will take reasonable steps to contain, investigate and remediate the incident.
11. DPIAs and prior consultation
Taking into account the nature of processing and information available to MC Studio, MC Studio will provide reasonable assistance with data-protection impact assessments and prior consultation where the processing carried out by MC Studio is relevant.
12. Compliance information and audits
MC Studio will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR.
The Controller should first use available reports, documentation, questionnaires and remote review.
Where those materials are insufficient and an audit is legally justified, the Controller may request a proportionate audit:
-
on reasonable prior notice;
-
during normal business hours;
-
without unnecessary disruption;
-
no more than once per year unless a material incident, regulator or demonstrated compliance concern reasonably requires more; and
-
subject to measures protecting other customers and MC Studio's confidential/security-sensitive information.
The Controller will bear reasonable external audit costs where the audit is not triggered by a material MC Studio breach, unless applicable law requires otherwise.
13. Return and deletion
At the end of the processing Services, MC Studio will, at the Controller's choice, return/export or delete Customer Personal Data and delete existing copies unless EU or Member State law requires storage. The lawful retrieval, recovery and deletion arrangements below remain subject to that choice.
The current product lifecycle distinguishes:
-
cancellation/downgrade recovery: if the Controller leaves the workspace/account open after paid use ends and does not instruct deletion, the Controller instructs MC Studio to retain the relevant archived/locked Customer Personal Data for up to 12 months solely to support recovery/reactivation; the Controller may override that recovery instruction at any time by requesting return/export or deletion;
-
normal account deletion: where the Controller requests ordinary account deletion rather than immediate Processor deletion, a 30-day accidental-deletion recovery period applies, after which primary customer/workspace data is permanently deleted and ordinary backup copies are deleted or expire within the same 30-day deletion lifecycle; and
-
valid earlier return/deletion instruction: where the Controller's lawful instruction or Data Protection Law requires earlier return or permanent deletion, MC Studio will carry out that action within the applicable legal period, without relying on the recovery period to postpone it.
At the end of the Processor Services, the Controller retains the Article 28 GDPR choice to require return/export or deletion, unless applicable law requires storage. MC Studio will not rely on the general 12-month product recovery window or 30-day accidental-deletion recovery period as a blanket right to retain Processor-held Customer Personal Data contrary to that choice or mandatory Data Protection Law.
Return/export is currently provided through a manual, administrator-assisted process. Returned data will be provided in structured, commonly used and machine-readable formats where legally required, and uploaded files in their original/stored form where applicable. Current data categories, structures, formats and known limitations are described on our Data Export & Portability page. That information does not restrict the Controller's mandatory return, deletion or switching rights.
14. EU Data Act switching
Where the EU Data Act applies to the affected data-processing Service, MC Studio will cooperate with applicable switching/export obligations in addition to this DPA.
This DPA does not reduce rights available under the Data Act.
15. Controller obligations
The Controller is responsible for:
-
having a lawful basis for Customer Personal Data;
-
providing legally required privacy notices;
-
ensuring its instructions are lawful;
-
configuring user access appropriately;
-
complying with data-minimisation requirements;
-
responding to data-subject requests as controller; and
-
not using MC Studio for data categories or purposes outside the intended Service scope without establishing the necessary safeguards.
16. Special-category and criminal-offence data
MC Studio is not designed as a specialist platform for routine processing of health data, criminal-record data or other highly regulated special-category data.
The Controller must not intentionally use MC Studio to process special-category personal data under Article 9 GDPR or criminal-conviction/offence data under Article 10 as a routine purpose unless the parties have expressly agreed the required lawful basis, controls and processing scope.
Incidental information appearing in ordinary project correspondence does not by itself create an agreed specialist-processing service. The Controller should minimise such data.
17. Liability
Liability under this DPA follows the liability allocation in the main agreement to the extent legally permitted.
Nothing limits liability that cannot lawfully be limited.
18. Priority
If this DPA conflicts with the main agreement regarding the processing of Customer Personal Data on behalf of the Controller, this DPA controls for that processing.
Mandatory Data Protection Law prevails over contractual terms.
Annex 1 - Processing Details
A. Subject matter
Hosting and processing Customer Personal Data submitted to MC Studio's CRM, workspace, project-management, file and collaboration functions.
B. Duration
For the term of the relevant Service plus the lawful return/deletion and secured-backup period.
C. Nature and purpose
Storage, organisation, retrieval, display, collaboration, support, security, backup, export and other processing necessary to provide the Business Customer's configured MC Studio Services.
D. Categories of data subjects
May include:
-
the Controller's customers and prospects;
-
employees, contractors and team members;
-
suppliers and business contacts;
-
installers, designers, partners and other project contacts; and
-
individuals appearing in uploaded project files or correspondence.
E. Categories of personal data
May include:
-
name and contact details;
-
address and site/location details;
-
project/customer identifiers;
-
notes, communications and task information;
-
photographs and uploaded files;
-
measurements and site-visit information linked to an individual;
-
quote/project/payment-status information entered by the Controller;
-
account and role information; and
-
other ordinary business/project information entered by the Controller.
F. Special categories
Special-category or criminal-offence data is not intentionally required as part of the standard Service and is not authorised as a routine processing category.
Annex 2 - Baseline Technical and Organisational Measures
-
Access control - unique user accounts, workspace access controls and restricted administrative access appropriate to the deployed architecture.
-
Authentication - Supabase Auth for user authentication, with access and session controls appropriate to the deployed Service.
-
Encryption in transit - TLS/HTTPS for data transmitted over public networks.
-
Data isolation - logical separation of customer workspaces appropriate to the architecture.
-
Operational/security logging - logs reasonably necessary for authentication, security, abuse investigation and service operation. MC Studio does not currently use a separate third-party error-monitoring provider in its core application stack. Relevant provider changes are reflected in the current Subprocessor information and notified under section 7.
-
Backups and recovery - controlled Supabase/hosting backup and recovery procedures appropriate to the Service and data risk, with deletion and expiry handled consistently with section 13, including the 30-day ordinary account-deletion lifecycle and applicable earlier deletion requirements.
-
Change and vulnerability management - reasonable testing, dependency management and remediation of security vulnerabilities.
-
Incident response - escalation, containment, investigation and legally required notification procedures.
-
Personnel confidentiality - access limited to authorised personnel subject to confidentiality obligations.
-
Vendor management - assessment and contractual protection for relevant Subprocessors.
-
Data minimisation and retention - purpose-limited processing with deletion/retention controls.
-
Business continuity - reasonable recovery planning proportionate to MC Studio's stage and the risk of the Service.
Annex 3 - Current Subprocessor Information
The current Subprocessor list is maintained at mcstudio.io/legal/subprocessors and forms part of this Annex. A dated copy is made available before acceptance of the agreement and can also be requested through privacy@mcstudio.io. Later additions and replacements are governed by section 7, not merely by changing the webpage.
The list identifies the provider's legal identity and contact details, purpose, relevant Customer Personal Data categories, processing locations and applicable international-transfer safeguard. It also makes the relevant onward-processing chain identifiable through maintained information and linked provider disclosures, with supplementary information supplied where needed.
The core application functions currently use the following services. Their exact legal entities and processing particulars are stated in the current Subprocessor information referenced above.
| Service | Core function |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Hosting and application delivery |
| Resend | Transactional email, including messages from notifications@mcstudio.io |
The Supabase production project is configured in an EU region. This does not represent that all processing, support or delivery operations by every provider take place only in the EU.
Stripe is also used for MC Studio payments and billing. A provider is a Subprocessor under this DPA only to the extent it processes Customer Personal Data on behalf of the Controller through MC Studio. Providers processing MC Studio's own account, billing or business-administration data, or acting independently as controllers, are described separately in the Privacy Policy and provider information. Listing a payment service does not automatically classify all its activities as subprocessing under this DPA.
MC Studio does not currently use a separate third-party analytics provider, separate error-monitoring provider or customer-facing AI provider in its core application stack. This statement does not exclude necessary logs or the business email/support providers described in the Privacy Policy. Any provider handling Customer Personal Data on behalf of the Controller remains subject to this DPA and must be covered by the current Subprocessor information.