Data Processing Agreement
Effective date: September 21, 2026
This Data Processing Agreement ("DPA") supplements the Mosaic Biz Terms of Service (the "Agreement") between Bajache, LLC ("Processor") and the customer organization ("Controller") whenever Processor processes personal data on Controller's behalf in the course of providing the Service. Capitalized terms not defined here have the meaning given in the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.
1. Roles of the Parties
Controller determines the purposes and means of processing personal data it submits to the Service (for example, data about its artists, staff, or business contacts). Processor processes such personal data only on behalf of, and under the documented instructions of, Controller, as set out in the Agreement and this DPA.
2. Scope and Nature of Processing
| Subject matter | Provision of the Mosaic Biz platform |
| Duration | For as long as Processor provides the Service under the Agreement |
| Nature & purpose | Hosting, storage, transmission, and AI-assisted analysis of Controller's data to deliver the Service's features |
| Categories of data | Account and contact information of Controller's team and business contacts (e.g., artists, supervisors, venue contacts) entered into the Service |
| Data subjects | Controller's team members and the business contacts Controller records in the Service |
3. Processor Obligations
- Process personal data only on documented instructions from Controller, including regarding international transfers, unless required to do otherwise by law;
- Ensure personnel authorized to process personal data are bound by confidentiality obligations;
- Implement appropriate technical and organizational measures to protect personal data, as described in Section 6;
- Assist Controller, insofar as reasonably possible, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments;
- Make available information reasonably necessary to demonstrate compliance with this DPA; and
- At Controller's election, delete or return all personal data after the end of the Service, except as required by law.
4. Subprocessors
Controller authorizes Processor to engage the subprocessors listed in the Privacy Policy's Subprocessors section to provide the Service. Processor will impose data protection obligations on each subprocessor no less protective than those in this DPA, and remains liable for each subprocessor's performance. Processor will provide notice through the Service or by email of any new subprocessor with material access to personal data, and Controller may object on reasonable data protection grounds by contacting legal@mosaicbiz.app within 14 days of notice.
5. International Transfers
Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, Processor will apply appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to the extent required by applicable data protection law.
6. Security Measures
Processor maintains technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit;
- Database-level row security that isolates each organization's data from every other organization;
- Role-based access controls within each organization's workspace;
- Access logging and authentication controls for administrative access to production systems; and
- Regular review of subprocessor security practices.
7. Personal Data Breach Notification
Processor will notify Controller without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal data breach affecting Controller's data, and will provide information reasonably available to assist Controller in meeting any of its own notification obligations.
8. Audit Rights
No more than once per 12-month period, and on reasonable prior written notice, Processor will make available information reasonably necessary to demonstrate compliance with this DPA, which may include a summary of relevant security certifications or third-party audit reports in lieu of an on-site audit.
9. Liability
Liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
10. Contact
Questions about this DPA, or requests to countersign an organization-specific copy, can be sent to legal@mosaicbiz.app.
This document is a general-purpose template based on common SaaS industry practice and does not constitute legal advice. If you have customers subject to GDPR or similar laws requiring a negotiated or countersigned DPA, have this reviewed by a privacy attorney and consider adding the EU Standard Contractual Clauses as an attachment.