Legal — Data Processing Addendum

Data Processing Addendum

GDPR Art. 28 processor terms. Automatically incorporated into every engineer account — this is what governs our handling of your clients' personal data.

Version history →
Last updated2026-07-03
Effective2026-07-03
Versionv1.0
JurisdictionUK GDPR · EU GDPR
ControllerTeam Judas Limited · 10199335
01.—

Definitions and roles

Terms not defined here take their meaning from the UK/EU GDPR. In this Addendum: Controller is you, the engineer (or your studio entity, if you signed up as one); Processor is Team Judas Limited; Data subjects are your clients and their invited collaborators.

02.—

Scope, nature and purpose of processing

We process personal data on your instructions to (a) provide the review and rounds workflow, (b) generate invoices and contracts, (c) deliver files to your clients, (d) offer optional AI text-processing features you enable per-project.

  • Categories: identification data, contact data, project content (audio, comments), and free-text brief content.
  • Duration: as long as you keep the project open, plus 90 days grace (see Privacy Policy §6).
03.—

Documented instructions

Our default instructions are the actions you take in the product. You can issue additional instructions in writing via legal@mixrounds.com; we'll confirm whether we can implement them within the service.

04.—

Confidentiality

Everyone at Team Judas Limited with access to personal data is under a documented confidentiality obligation and has completed data-protection training. Access is role-based and logged.

05.—

Security measures (Annex II)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Least-privilege access, MFA-required for admin roles.
  • Quarterly access reviews, annual penetration testing.
  • Documented incident response, tested twice a year.
  • Isolated environments; production data never on developer laptops.
06.—

Sub-processors

Current list at /legal/subprocessors. 30-day notice by email before any addition or replacement (see Privacy Policy §5). You may object; we'll work with you to resolve, or allow termination without penalty of the affected project.

07.—

Data subject rights

We'll assist you in responding to access, rectification, erasure, restriction and portability requests through in-product controls and, where the tooling can't reach, ad-hoc assistance from our DPO team.

08.—

Personal data breaches

We notify you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your project. Notice includes the nature, categories and approximate volume, likely consequences, and mitigation measures.

09.—

International transfers

For transfers outside the UK/EEA, we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses (2021/914 Module 3, processor-to-sub-processor), with a Transfer Impact Assessment on file. Copies available on request.

10.—

Return or deletion of data

On termination and after any grace period elapses, we delete personal data within 30 days unless you've exported it or law requires retention. Backup rotations complete deletion within 60 days.

See also
99.—

Version history

2026-07-03v1.0Initial publication.