DPA · GDPR ART. 28

Data Processing Agreement.

If you use OGRECORDS™ as a label, studio or business customer and process personal data of third parties (e.g. your artists or producers) through us, OGR acts as your data processor under GDPR Art. 28. This template explains what we agree on.

Preview — last updated: May 2026

1. Subject and duration

Subject is the processing of personal data within the distribution, royalty-split, smart-link and sync-marketplace functions of the OGR platform.

Processing takes place for the duration of the distribution agreement between you and OGR plus reasonable retention periods after its termination.

2. Nature and purpose of processing

We process:

  • Master data (name, artist name, IBAN, tax ID) of your artists, producers and royalty recipients.
  • Order and accounting data (streaming earnings, splits, payout status).
  • Audit and login data for evidence requirements and platform security.

Purpose: performance of the distribution agreement and of statutory record-keeping and tax obligations.

3. OGR's obligations as processor

OGR commits to processing personal data only on your documented instructions, ensuring the confidentiality of all persons involved in the processing, and implementing all technical-organizational measures under GDPR Art. 32.

Concretely: encryption at rest and in transit, least-privilege access separation, audit logging, regular backups with documented recovery tests.

4. Sub-processors

OGR uses the following sub-processors. You generally consent to these on contract conclusion; OGR informs you in advance whenever a sub-processor is added or replaced and gives you a 14-day objection window:

  • AWS (EU region Frankfurt) — hosting (Aurora Postgres), S3 backups, Bedrock AI (Claude Haiku/Sonnet).
  • Hetzner Online (Germany) — server hosting via self-hosted Coolify.
  • Firebase (Google) — auth, cloud storage, analytics, remote config, app check.
  • Mailgun (EU region) — transactional email + inbound webhook for support tickets.
  • whapi.cloud — WhatsApp Business channel.
  • OneSignal — push notifications.
  • Polar.sh — inbound payments for premium add-ons and the Priority-Support subscription.
  • PayPal — manual payouts to non-EU artists.
  • eSignatures.com — contract signing (Distribution Agreement).
  • Cloudflare — DNS, edge CDN, DDoS protection.

5. International transfers

Where sub-processors transfer data to third countries (e.g. Polar.sh USA, Mailgun USA, PayPal USA/SG, OneSignal USA), the transfer is based on the EU Commission's Standard Contractual Clauses (SCC, version 04 June 2021) plus supplementary technical measures (encryption, pseudonymization, audit logging).

On request you receive a list with detailed information on every third-country transfer.

6. Cooperation, deletion and return

OGR supports you in fulfilling your obligations under GDPR Art. 32-36 and in handling data-subject requests (Art. 15-22 GDPR).

After contract termination, we delete or return all personal data within 90 days, unless statutory retention obligations preclude this.

7. Audit right

You may audit compliance with this DPA once per calendar year — either by reviewing OGR's current security certifications and penetration-test reports, or via an on-site audit with 30 days' notice.

Extraordinary audits are possible at any time on substantiated suspicion.

Get the DPA countersigned

Email info@og-records.com with subject "DPA request". We'll send the signature-ready final version as PDF and can countersign via DocuSign or eSignatures.com on request.

info@og-records.com