← Back to BandHQ
Legal

Data Processing Agreement

For: BandHQ customers, as an annex to the Terms of Service · Version: 1.0 · 1 September 2026

1. Parties and scope

This DPA is between Vivid Vision Designs Ltd (“Processor”, “we”) and the band or organisation identified in the main agreement (“Controller”, “you”). It forms part of, and is governed by, our Terms of Service (“Agreement”). Where this DPA conflicts with the Agreement on data-protection matters, this DPA prevails.

It applies whenever we process personal data on your behalf in providing BandHQ. Where we act as controller (our own account, billing and marketing data), our Privacy Policy applies instead.

2. Definitions

“UK GDPR”, “controller”, “processor”, “personal data”, “processing”, “personal data breach”, “special category data” and “data subject” have the meanings in the UK GDPR and the Data Protection Act 2018. “Sub-processor” means any third party we engage to process personal data under this DPA.

3. Roles and instructions

  • You are the controller and we are the processor of the personal data described in Annex 1.
  • We will process that personal data only on your documented instructions, including those in the Agreement, this DPA, and your configuration and use of the service. We will tell you if, in our opinion, an instruction infringes data-protection law.
  • You confirm you have a lawful basis (and, for special category data, an Article 9 condition) for the processing you instruct, and that your own privacy information covers it.

4. Duration

This DPA applies for as long as we process personal data on your behalf under the Agreement. Provisions that by their nature should survive termination (for example confidentiality and deletion) do so.

5. Confidentiality and staff access

We ensure that people authorised to process the personal data are bound by an appropriate duty of confidentiality and only access it as needed to provide the service.

Access to your band’s data outside the app is limited to our operator console, restricted to named people at Vivid Vision Designs Ltd and protected by a separate login. It shows membership, provisioning and safeguarding information, and the moderation queue. It cannot browse your band’s chat or announcements — there is no screen that lists or reads conversations. It does show the text of an individual message once that message has been reported, because a report cannot be judged without seeing what was reported.

Safeguarding and provisioning actions are recorded with the operator’s identity and the time. Not every action in the console is recorded, and we do not claim a comprehensive audit trail. Records of access are retained indefinitely. We do not currently notify a band when an operator views its data.

6. Security

We implement appropriate technical and organisational measures to protect the personal data, as required by Article 32. The measures in place are described in Annex 2 and may be updated as the service evolves, provided the level of protection is not reduced.

7. Sub-processors

  • You give general authorisation for us to engage the sub-processors listed in Annex 3 to help provide the service.
  • Each sub-processor is bound by data-protection terms no less protective than this DPA, and we remain responsible to you for their performance.
  • We keep the current list of sub-processors on our Trust & security page, with the date it last changed. We will notify you when we add or replace one, at the time of the change. You may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the service without penalty and receive a pro-rata refund of any fee paid for the remainder of the term.

8. Assisting you

Taking into account the nature of the processing, we will assist you, by appropriate measures and so far as possible:

  • Data-subject requests. The service lets a member view and export their own data and correct their own details. If you receive a request only we can fulfil, we will support you. We do not charge for this. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or decline it, as UK GDPR permits. Erasure and rectification are applied to our support records as well as to the service itself.
  • Security, breaches and DPIAs. We assist you with your obligations under Articles 32–36, taking into account the information available to us.
  • Supervisory authority. We cooperate, on request, with the ICO or another competent supervisory authority in relation to the processing under this DPA.

9. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and provide the information you reasonably need to meet your own notification obligations (a controller generally has 72 hours to notify the ICO). We aim to reach you well inside that window so it is yours to use rather than ours.

10. Deletion or return

On the end of the provision of the service, at your choice we will delete or return the personal data and delete existing copies, unless the law requires us to keep it.

11. Audits

We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits.

12. International transfers

Where providing the service involves transferring personal data outside the UK/EEA (see Annex 3), we will ensure an appropriate safeguard is in place — the UK International Data Transfer Agreement / Addendum or Standard Contractual Clauses — before doing so.

13. Liability

Liability under this DPA is subject to the limitations and exclusions in the Agreement.


Annex 1 — Details of the processing

  • Subject matter: Provision of the BandHQ management and community app to the Controller (its band).
  • Duration: For the term of the Agreement (see section 4).
  • Nature and purpose: Hosting, storing, organising and making available the Controller's personal data so it can run and communicate within its band; sending service and notification emails and push notifications; and any features the Controller enables.
  • Types of personal data (as configured/used by the Controller): identity and contact details (name, email, phone); date of birth, and the derived indicator of whether a member is under 18; band details (instrument, section, role, availability); messages, announcements and reactions; practice logs; event attendance; profile photos; guardian relationships linking a young member to a parent or guardian; records of consent; reports and moderation records, including the content reported; sign-in identifiers and authentication data; and, for a guest player booked to cover a chair, their name and optionally the band they normally play for, a phone number, an email address and a free-text note — held for the event only and deleted with it.
  • Special category data: may be present where the Controller records it (e.g. accessibility or health-related needs) — see the Privacy Policy.
  • Categories of data subjects: the Controller's band members and administrators, and any individuals it records (e.g. deputies/“deps”, guests, emergency contacts). This may include members under 18 — see section 3.

Annex 2 — Technical and organisational measures

Current measures include:

  • Tenant isolation: Row-Level Security enforced on every database table, so each band's data is separated at the database layer.
  • Access control: Role-based capabilities and least-privilege service credentials. Two-step sign-in is required on our own internal operator console — every account that can reach customer data carries a second factor. It is not currently offered to band administrators.
  • Encryption: Encryption in transit; encryption at rest at the infrastructure layer.
  • Secret handling: Passwords are never stored by us — authentication is handled by our authentication provider, which stores them hashed. Invitation links use unguessable random tokens that expire; these are stored unhashed so an invitation can be reissued.
  • File protection: Private files reachable only via short-lived signed links, with access re-checked per request.
  • Data-subject tooling: Self-service data export and profile correction.

Organisational measures. Access to the operator console is limited to named people at Vivid Vision Designs Ltd, who are bound by confidentiality. Backups are taken by our database provider under its own retention schedule. We do not currently run a formal access review or vulnerability-management programme, and we do not claim one. Our breach-response commitment is in section 7.

Annex 3 — Approved sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storageEU (AWS eu-west-1, Ireland)
VercelApplication hostingEU (Dublin, AWS eu-west-1) — functions are pinned to dub1; global edge network
ResendTransactional / notification emailUSA. Sending region may be set to EU (Ireland), but account data, logs and email metadata are stored in the USA
Google Cloud (Vision API)Automated safety scanning of images at uploadEU — Google’s European Union endpoint, which commits to storing and processing only in the EU
ExpoPush notification delivery to phonesGlobal. Push messages are relayed through Expo’s service, which handles the device token and the notification content
Apple & GoogleMobile app distribution, and the push networks themselves — Apple Push Notification service on iPhone, Google Firebase Cloud Messaging on AndroidGlobal. Apple does not publish a processing location for push notifications

Vivid Vision Designs Ltd — privacy@usebandhq.com · 5 High Street, Husbands Bosworth, Lutterworth, England, LE17 6LJ. Company no. 16091475.

© 2026 BandHQ · A Vivid Vision Designs productHome · Terms · Privacy