Definitions and roles
Terms not defined here take their meaning from the UK/EU GDPR. In this Addendum: Controller is you, the engineer (or your studio entity, if you signed up as one); Processor is Team Judas Limited; Data subjects are your clients and their invited collaborators.
Scope, nature and purpose of processing
We process personal data on your instructions to (a) provide the review and rounds workflow, (b) generate invoices and contracts, (c) deliver files to your clients, (d) offer optional AI text-processing features you enable per-project.
- Categories: identification data, contact data, project content (audio, comments), and free-text brief content.
- Duration: as long as you keep the project open, plus 90 days grace (see Privacy Policy §6).
Documented instructions
Our default instructions are the actions you take in the product. You can issue additional instructions in writing via legal@mixrounds.com; we'll confirm whether we can implement them within the service.
Confidentiality
Everyone at Team Judas Limited with access to personal data is under a documented confidentiality obligation and has completed data-protection training. Access is role-based and logged.
Security measures (Annex II)
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Least-privilege access, MFA-required for admin roles.
- Quarterly access reviews, annual penetration testing.
- Documented incident response, tested twice a year.
- Isolated environments; production data never on developer laptops.
Sub-processors
Current list at /legal/subprocessors. 30-day notice by email before any addition or replacement (see Privacy Policy §5). You may object; we'll work with you to resolve, or allow termination without penalty of the affected project.
Data subject rights
We'll assist you in responding to access, rectification, erasure, restriction and portability requests through in-product controls and, where the tooling can't reach, ad-hoc assistance from our DPO team.
Personal data breaches
We notify you without undue delay and within 48 hours of becoming aware of a personal data breach affecting your project. Notice includes the nature, categories and approximate volume, likely consequences, and mitigation measures.
International transfers
For transfers outside the UK/EEA, we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses (2021/914 Module 3, processor-to-sub-processor), with a Transfer Impact Assessment on file. Copies available on request.
Return or deletion of data
On termination and after any grace period elapses, we delete personal data within 30 days unless you've exported it or law requires retention. Backup rotations complete deletion within 60 days.