Data Processing Agreement

Effective date: September 21, 2026

This Data Processing Agreement ("DPA") supplements the Mosaic Biz Terms of Service (the "Agreement") between Bajache, LLC ("Processor") and the customer organization ("Controller") whenever Processor processes personal data on Controller's behalf in the course of providing the Service. Capitalized terms not defined here have the meaning given in the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.

1. Roles of the Parties

Controller determines the purposes and means of processing personal data it submits to the Service (for example, data about its artists, staff, or business contacts). Processor processes such personal data only on behalf of, and under the documented instructions of, Controller, as set out in the Agreement and this DPA.

2. Scope and Nature of Processing

Subject matterProvision of the Mosaic Biz platform
DurationFor as long as Processor provides the Service under the Agreement
Nature & purposeHosting, storage, transmission, and AI-assisted analysis of Controller's data to deliver the Service's features
Categories of dataAccount and contact information of Controller's team and business contacts (e.g., artists, supervisors, venue contacts) entered into the Service
Data subjectsController's team members and the business contacts Controller records in the Service

3. Processor Obligations

  • Process personal data only on documented instructions from Controller, including regarding international transfers, unless required to do otherwise by law;
  • Ensure personnel authorized to process personal data are bound by confidentiality obligations;
  • Implement appropriate technical and organizational measures to protect personal data, as described in Section 6;
  • Assist Controller, insofar as reasonably possible, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments;
  • Make available information reasonably necessary to demonstrate compliance with this DPA; and
  • At Controller's election, delete or return all personal data after the end of the Service, except as required by law.

4. Subprocessors

Controller authorizes Processor to engage the subprocessors listed in the Privacy Policy's Subprocessors section to provide the Service. Processor will impose data protection obligations on each subprocessor no less protective than those in this DPA, and remains liable for each subprocessor's performance. Processor will provide notice through the Service or by email of any new subprocessor with material access to personal data, and Controller may object on reasonable data protection grounds by contacting legal@mosaicbiz.app within 14 days of notice.

5. International Transfers

Where personal data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, Processor will apply appropriate safeguards, such as the European Commission's Standard Contractual Clauses, to the extent required by applicable data protection law.

6. Security Measures

Processor maintains technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit;
  • Database-level row security that isolates each organization's data from every other organization;
  • Role-based access controls within each organization's workspace;
  • Access logging and authentication controls for administrative access to production systems; and
  • Regular review of subprocessor security practices.

7. Personal Data Breach Notification

Processor will notify Controller without undue delay, and in any event within 72 hours of becoming aware, after confirming a personal data breach affecting Controller's data, and will provide information reasonably available to assist Controller in meeting any of its own notification obligations.

8. Audit Rights

No more than once per 12-month period, and on reasonable prior written notice, Processor will make available information reasonably necessary to demonstrate compliance with this DPA, which may include a summary of relevant security certifications or third-party audit reports in lieu of an on-site audit.

9. Liability

Liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

10. Contact

Questions about this DPA, or requests to countersign an organization-specific copy, can be sent to legal@mosaicbiz.app.


This document is a general-purpose template based on common SaaS industry practice and does not constitute legal advice. If you have customers subject to GDPR or similar laws requiring a negotiated or countersigned DPA, have this reviewed by a privacy attorney and consider adding the EU Standard Contractual Clauses as an attachment.