Trust Center
Legal · Article 28 GDPR

Data Processing Addendum

Version 1.0·Effective 1 September 2026

This Data Processing Addendum (the “DPA”) forms part of the agreement between Lanced B.V. (“Lanced”) and the Customer (the “Business Terms” or “Terms”) and applies where and to the extent Lanced processes Customer Personal Data as a processor on behalf of the Customer.

It does not apply to processing for which Lanced acts as an independent controller. That layer includes artist accounts, artist profiles, artist media libraries and Artist Studio; the account records of the Customer's own users; the published company profile and its media; platform identity and authentication; Lanced's own billing, support, security, analytics, product improvement and marketing; and making artist and company profiles discoverable through search. That processing is governed by the Lanced Privacy Policy.

No separate signature is required. This DPA is incorporated into the Business Terms by reference and takes effect when the Customer accepts those Terms. A countersigned copy is available on request at privacy@lancedhq.com.
Data Processing Addendum

Terms of processing

1

Definitions and interpretation

Capitalised terms not defined here have the meaning given in the Business Terms. The following definitions apply:

TermMeaning
Data Protection LawRegulation (EU) 2016/679 ("GDPR"), the Dutch Uitvoeringswet AVG ("UAVG"), Directive 2002/58/EC as implemented in the Netherlands, and any other data protection or privacy law applicable to the processing under this DPA.
Customer Personal DataPersonal Data that Lanced processes as a processor on behalf of the Customer under the Business Terms, as described in Annex 1.
Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, Special Category DataHave the meanings given in the GDPR.
ArtistAn individual holding a Lanced artist account.
Sub-processorAny third party engaged by Lanced to process Customer Personal Data on behalf of the Customer.
SCCsThe Standard Contractual Clauses approved by the European Commission under Implementing Decision (EU) 2021/914, as amended or replaced.
Supervisory AuthorityThe competent data protection authority, including the Dutch Autoriteit Persoonsgegevens ("AP").

In the event of any conflict between this DPA and the Business Terms regarding the processing of Customer Personal Data, this DPA prevails. In the event of any conflict between this DPA and the SCCs, the SCCs prevail.

2

Roles of the parties and scope

2.1 The Customer acts as Controller, and Lanced acts as Processor, in respect of the Customer Personal Data described in Annex 1 — namely the Customer's recruitment, audition, casting, open call, competition, residency, review, contracting and talent-management workflows conducted through the Lanced platform.

2.2 Lanced acts as an independent Controller for the artist layer (artist accounts, artist profiles, uploaded media libraries and Artist Studio), for the company account and profile layer described in clause 2.7, and for general platform operations including platform identity and authentication, Lanced's own billing, support, security, analytics, product improvement and marketing. That processing is not subject to this DPA and is governed by the Lanced Privacy Policy.

2.3 The submission of an application to a Customer opportunity does not transfer control of the artist account, profile or media library to the Customer. The Customer is Controller for the application and review workflow it creates and for the data generated within it, including application answers, submitted materials, reviewer notes, votes, scores, labels, review statuses and shortlist decisions.

2.4 Each party shall comply with its obligations under Data Protection Law. The Customer is responsible for the lawfulness of the Customer Personal Data it processes and of the instructions it gives to Lanced, including for identifying an appropriate lawful basis and, where relevant, a condition under Article 9 GDPR.

2.5

Network discovery and saved artist records

Making artist profiles discoverable and searchable, and disclosing them to the Customer through network search, is processing carried out by Lanced as independent Controller of the artist layer. It is not processing on the Customer's behalf and is not subject to this DPA.

An artist is not added to a Customer's saved records or talent pools without that artist's consent. Where an artist has consented and the Customer creates its own records about that artist — including pools, notes, tags and assessments — the Customer is Controller of those records and Lanced processes them on the Customer's behalf under this DPA. An artist may withdraw consent at any time, and Lanced will act on that withdrawal in accordance with clause 7.

2.6

Exported material — independent controllers

Where the Customer exports, downloads or prints material from applications it has received, that material passes into the Customer's own systems and premises. From that point Lanced and the Customer are independent Controllers of their respective copies. Lanced has no access to, and no control over, the Customer's copy, and this DPA does not apply to it.

Export is limited to material submitted by artists through their applications to the Customer. Artist profiles, artist media libraries and network search results cannot be exported from the platform.

The Customer is solely responsible for the security, retention, lawful use and secure disposal of its copy, including printed materials, and for responding to any data subject request in relation to it.

2.7

Company accounts, company users and the company profile

(a) Account and identity layer — Lanced as Controller. Lanced acts as independent Controller in respect of the account records of the Customer's users, including name, email address, credentials and authentication data, session and device records, account settings and preferences, security and access logs, support correspondence, billing contact details, and platform communications sent to those users. Lanced determines the purposes and means of that processing in order to operate and secure the platform and to administer its own contractual relationship with the Customer. That processing is governed by the Lanced Privacy Policy, and the Customer's users may exercise their rights in respect of it directly with Lanced.

(b) Workspace layer — Customer as Controller. The Customer acts as Controller, and Lanced as Processor under this DPA, in respect of the assignment of its users to its workspace, their roles and permissions, guest and external reviewer access, and the record of their activity within the workspace, including reviewer notes, votes, decisions and the workspace activity log.

(c) Company profile — Lanced as Controller. The company profile, including the company name, logo, cover and profile media, uploaded media, published updates and any personnel the Customer chooses to display, is published, displayed, indexed and made discoverable by Lanced as independent Controller, on the same basis as the artist layer under clause 2.5. Where the Customer chooses to display personal data of its own personnel on the profile, the Customer is Controller of that decision and is responsible for informing those individuals and for having a lawful basis for the disclosure. In respect of that data the parties act as separate Controllers in succession, and not as joint controllers within the meaning of Article 26 GDPR.

(d) Profiles without an active plan. Where the Customer holds only a company profile, with or without use of the Billboard, applications are received through the Customer's own channels and not within the platform. Lanced does not process personal data on the Customer's behalf, and this DPA does not apply. It applies from the point the Customer takes a plan, and continues to apply to Customer Personal Data retained following a downgrade until that data is deleted in accordance with clause 11.3.

3

Processing on documented instructions

3.1 Lanced shall process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law to which Lanced is subject; in such a case Lanced shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.2 The Business Terms, this DPA (including Annex 1), and the configuration choices the Customer makes through the platform constitute the Customer's complete and documented instructions. Additional or different instructions must be agreed in writing and may be subject to adjustment of fees where they require material additional effort.

3.3 Lanced shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law. Lanced is not obliged to carry out a general legal review of the Customer's instructions.

3.4

Operating and maintaining the platform

Lanced may process Customer Personal Data as necessary to host, operate, monitor, secure, troubleshoot and maintain the platform, to detect and prevent security incidents, fraud and abuse, and to identify and correct faults and make functional improvements to the service. This processing forms part of providing the platform under the Business Terms and does not extend to any purpose unrelated to it.

3.5

Artificial intelligence and machine learning

(a) Lanced does not use Customer Personal Data to train, fine-tune or develop artificial intelligence or machine learning models. AI-assisted functionality offered through the platform is developed by Lanced using personal data for which Lanced is Controller, together with aggregate statistical information from which individuals cannot be identified and which cannot be attributed to any Customer.

(b) Where Lanced makes AI-assisted search, discovery, matching, organisation or application-review functionality available within the Customer's workspace, the Customer decides whether to enable it. Where the Customer enables it, Lanced processes Customer Personal Data to deliver that functionality to the Customer and for no other purpose. Any third party engaged to deliver such functionality is a Sub-processor, subject to clause 6 and Annex 3.

(c) Lanced does not provide functionality intended to produce decisions with legal or similarly significant effects for a data subject based solely on automated processing within the meaning of Article 22 GDPR. AI-assisted outputs are informational and support human review; the Customer remains responsible for its selection, shortlisting, contracting and hiring decisions.

4

Confidentiality and personnel access

4.1 Lanced shall ensure that persons authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory, and process the data only as necessary to provide the platform.

4.2

Lanced personnel access and support sessions

Authorised Lanced personnel may access a Customer workspace, or access the platform in the context of a user account, where necessary to provide support, investigate a reported fault, or investigate a suspected breach of the Business Terms or of security. Such access is:

  • restricted by role and by individual permission;
  • limited to what is necessary for the purpose;
  • recorded in an internal audit trail, including the start and end of any support session conducted in the context of a user account; and
  • available to the Customer on written request in respect of its own workspace.
5

Security of processing

5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk to data subjects, Lanced shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in place as at the effective date are described in Annex 2.

5.2 The Customer acknowledges that the measures in Annex 2 are appropriate for the platform as offered and agrees that Lanced may update them provided the level of protection is not materially reduced.

5.3

Contract documents and identity data

Where the Customer uses the Contracts & Onboarding functionality, Lanced processes contract documents and related engagement records on the Customer's instruction. Signed contract documents are held in a dedicated private storage location, separate from other media, with no public route, and are accessible only through short-lived authenticated links.

The Customer shall not upload, and shall not require any individual to upload, copies of identity documents, passports, residence permits, or national identification numbers including the Dutch burgerservicenummer, through the platform. Lanced does not provide functionality intended for the collection of such documents and does not inspect the contents of documents uploaded by the Customer. The Customer remains responsible for collecting any such data through its own systems.

6

Sub-processors

6.1 The Customer gives Lanced general written authorisation to engage Sub-processors to process Customer Personal Data. The Sub-processors authorised as at the effective date are listed in Annex 3.

6.2 Lanced shall impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular appropriate technical and organisational measures. Lanced remains liable to the Customer for the performance of each Sub-processor's obligations.

6.3 Changes. Lanced shall give the Customer prior notice of the addition or replacement of any Sub-processor and, where that change involves a transfer of Customer Personal Data to a third country, shall ensure that an appropriate transfer mechanism under Chapter V GDPR, including where required the SCCs, is put in place before any such transfer occurs.

6.4 Objection. The Customer may object to a new Sub-processor on reasonable data-protection grounds within 30 days of notice. The parties shall work together in good faith to resolve the objection. If it cannot be resolved, the Customer may terminate the affected service as its sole remedy, with a pro-rata refund of prepaid fees for the unused remainder of the term.

6.5 Notice mechanism. Lanced maintains a current list of Sub-processors in the Trust Center. The Customer may subscribe to change notifications by writing to privacy@lancedhq.com. Lanced publishes Sub-processors it has committed to but not yet engaged, so that the Customer has notice before any Customer Personal Data is transferred to them.

7

Assistance with data subject rights

7.1 Taking into account the nature of the processing, Lanced shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III GDPR. Lanced provides self-service tooling within the Customer workspace for this purpose and supplements it with manual assistance where the tooling does not cover the request.

7.2 If Lanced receives a request directly from a data subject relating to Customer Personal Data, Lanced shall not respond to the substance of the request, except to confirm receipt and direct the data subject appropriately, and shall forward it to the Customer without undue delay.

7.3 Two layers, two requests. The parties acknowledge that an artist's personal data may exist both in the artist layer, for which Lanced is Controller, and in the Customer's workflow layer, for which the Customer is Controller. Deletion in one layer does not effect deletion in the other. Lanced informs artists of this distinction. Requests relating to material the Customer has exported or printed under clause 2.6 are a matter for the Customer alone.

7.4 Timescales. Lanced shall respond to a request for assistance under this clause without undue delay and in any event within 10 working days, so as to allow the Customer to meet its own deadline under Article 12(3) GDPR.

8

Assistance with compliance obligations

8.1 Lanced shall assist the Customer, taking into account the nature of processing and the information available to Lanced, in ensuring compliance with the Customer's obligations under Articles 32 to 36 GDPR, covering security of processing, breach notification, data protection impact assessments and prior consultation.

8.2 Lanced may charge a reasonable fee for assistance that goes materially beyond the standard functionality of the platform, having given the Customer prior notice where practicable.

9

Personal data breach notification

9.1 Lanced shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

9.2 The notification shall, to the extent available, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and mitigate its effects. Where the information is not all available at once, it may be provided in phases without undue further delay.

9.3 Notification by Lanced is not an acknowledgement of fault or liability. The Customer, as Controller, remains responsible for any notification to a Supervisory Authority under Article 33 GDPR or to data subjects under Article 34 GDPR that Data Protection Law requires of it.

9.4 Lanced maintains a documented incident response procedure with defined severity levels, an assigned owner, an initial triage target and a security disclosure channel at security@lancedhq.com.

10

International transfers

10.1 Primary location. Lanced hosts the platform database, application infrastructure and database backups within the European Economic Area, in Amsterdam, the Netherlands, and stores uploaded media and contract documents within the European Union. Customer Personal Data is not transferred outside the EEA except as set out in clause 10.2 and Annex 3.

10.2 Transfers under appropriate safeguards. Certain Sub-processors listed in Annex 3 involve processing of limited categories of Customer Personal Data outside the EEA, principally in the United States. Each such transfer is covered by an appropriate safeguard under Chapter V GDPR, being the SCCs and, where applicable, the recipient's certification under the EU–U.S. Data Privacy Framework. The categories concerned and the transfer mechanism applicable to each are identified in Annex 3.

10.3 SCC incorporation. Where the SCCs apply to a transfer between the Customer and Lanced, they are incorporated into this DPA by reference and completed as follows: the Customer is the data exporter and Lanced is the data importer; Module Two applies where the Customer acts as controller, and Module Three applies where the Customer acts as processor for a third-party controller; Annex 1 of this DPA populates SCC Annex I and Annex 2 of this DPA populates SCC Annex II; the governing law is the law of the Netherlands and the competent courts are the courts of Amsterdam. The Customer's acceptance of the Business Terms constitutes its signature to the SCCs to the extent they apply.

10.4 Transfer impact assessment. Lanced maintains an assessment of the transfers identified in Annex 3 and makes a summary available to the Customer on request.

11

Return, deletion and retention

11.1 Election on termination. On termination or expiry of the Business Terms, the Customer may elect, within 30 days, whether Lanced shall return or delete the Customer Personal Data. If the Customer makes no election within that period, Lanced shall delete the Customer Personal Data.

11.2 Effect. Lanced shall delete or return the Customer Personal Data accordingly and delete existing copies, unless Union or Member State law requires continued storage. Customer Personal Data retained in routine backups is deleted in the ordinary course of the backup cycle and remains subject to this DPA until deleted.

11.3 Retention during the term. The Customer, as Controller, determines how long Customer Personal Data is retained within its workspace and is responsible for ensuring that retention is limited to what is necessary for the purposes for which it is processed. Lanced deletes Customer Personal Data on the Customer's instruction and in accordance with clauses 11.1 and 11.2.

The following retention periods are applied by the platform:

CategoryRetention
Candidate conversations after closure30 days
Message attachments30 days after the last referencing conversation closes
Deleted media objectsRemoved from object storage within 7 days of deletion
Workspace data after downgrade to a free profile12 months, then permanent deletion, with export reminders at 9 and 11 months
Workspace after a deletion request30-day grace period, then finalised automatically

Lanced expects to introduce platform-wide maximum retention periods for applications, review records and saved artist records, and will give the Customer notice before any such maximum takes effect.

11.4 Where an artist withdraws consent to being saved to the Customer's records, Lanced shall notify the Customer and the corresponding saved record shall be deleted or anonymised.

12

Audits and information

12.1 Lanced shall make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. Lanced satisfies this obligation primarily by responding to reasonable written information requests and completed security questionnaires, and by maintaining the Lanced Security Statement and Sub-Processor Register.

12.2 Lanced does not currently hold third-party audit certification such as ISO 27001 or SOC 2. Where such a report becomes available, Lanced may satisfy audit requests by providing the relevant report.

12.3 Any audit beyond written information requests shall be limited to once per twelve-month period, save where required by a Supervisory Authority, conducted on at least 30 days' prior notice, during business hours, subject to confidentiality, at the Customer's cost, and in a manner that does not disrupt Lanced's operations or affect the data of other customers.

12.4 Lanced makes an in-product activity log available to the Customer covering actions taken within its own workspace, including candidate transitions, votes, labels, invitations, reviewer access, contracts, membership and settings changes.

13

Liability, term and general

13.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Business Terms, to the extent permitted by Data Protection Law. Liability arising from a breach of this DPA is subject to the enhanced liability cap in Section 20.3 of the Business Terms. Nothing in this DPA or the Business Terms limits or excludes either party's liability to a data subject for compensation under Article 82 GDPR, or either party's liability for wilful misconduct or gross negligence.

13.2 This DPA takes effect on the effective date and remains in force for as long as Lanced processes Customer Personal Data on behalf of the Customer. Clauses that by their nature should survive termination, including clauses 4, 9, 11, 12 and 13, survive.

13.3 This DPA is governed by the laws of the Netherlands. The courts of Amsterdam have exclusive jurisdiction, consistent with the Business Terms.

13.4 If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect and the parties shall replace the affected provision with a valid provision achieving as nearly as possible the same commercial and legal effect.

Annexes

Annexes to this DPA

Annex 1

Details of processing

Provides the information required by Article 28(3) GDPR and, where the SCCs apply, populates SCC Annex I.

ItemDetail
Subject-matterProvision of the Lanced Business platform for the Customer's recruitment, audition, casting, open call, competition, residency and talent-management workflows.
DurationFor the term of the Business Terms and until return or deletion under clause 11, subject to the maxima in clause 11.3.
Nature and purposeCollection, recording, storage, organisation, structuring, retrieval, consultation, display, hosting, transmission, export, restriction and erasure of Customer Personal Data, in order to enable the Customer to publish opportunities, receive and review applications, evaluate candidates, schedule and run audition days, build and maintain shortlists and saved artist records, communicate with candidates, issue and receive signed contracts, and run onboarding workflows.
Categories of data subjectsArtists and other individuals who apply to, or are considered for, the Customer's opportunities; artists who have consented to being saved to the Customer's records or pools; individuals engaged by the Customer through the platform; and the Customer's own users — owners, administrators, members, reviewers and guest or external reviewers — in respect of their membership, roles and activity within the Customer's workspace only. The account records of the Customer's users, and the published company profile, are not Customer Personal Data and are processed by Lanced as Controller under clause 2.7.
Categories of personal dataIdentity and contact data; professional profile data including discipline, roles, skills, styles, languages and career record; physical characteristics where the Customer requests them, such as height and measurements; media including photographs, video, self-tapes, audio, documents and CVs; application answers, motivation letters and submitted materials; availability data; evaluation data including reviewer notes, votes, scores, labels, review status and shortlist and round decisions; consent records showing what an artist disclosed per application; saved artist records, pools and tags; workspace membership, role and permission assignments and records of user activity within the workspace; scheduling and slot-booking data; messages, broadcasts and communication metadata; signed contracts and engagement documents; technical and usage data including IP address, user agent and session records.
Special category dataNot required by Lanced. Date of birth, nationality, ethnicity and gender are held in a dedicated, access-restricted store in the artist layer and are disclosed to the Customer only per application, on the basis of the artist's disclosure choice, by means of a point-in-time consent record. Special category data may additionally arise unsolicited in free-text answers, motivation letters, CVs and media, including data concerning health, disability and racial or ethnic origin. The Customer is responsible for identifying a condition under Article 9 GDPR for any special category data it collects or receives and for applying additional safeguards.
Frequency of processingContinuous, for the duration of the Business Terms.
Sub-processorsAs set out in Annex 3.
RetentionAs set out in clause 11.3.
Annex 2

Technical and organisational measures

As at the effective date, and described in fuller detail in the Lanced Security Statement. Lanced may update these measures in accordance with clause 5.2 provided the level of protection is not materially reduced.

AreaMeasures
Hosting and residencyApplication infrastructure, the managed PostgreSQL database and database backups are hosted in Amsterdam, the Netherlands. Uploaded media and contract documents are stored in EU-jurisdiction object storage, with the EU jurisdiction setting enforced at application start-up. Certain limited-scope sub-processors involve processing outside the EEA under the safeguards identified in Annex 3.
Encryption in transitTLS 1.2 and 1.3 at the edge; HTTP Strict Transport Security with a one-year max-age including subdomains; database connections require SSL.
Encryption at restData at rest is encrypted by the underlying infrastructure providers for both the managed database and object storage, using provider-managed keys.
Tenant and record isolationLogical separation between customer workspaces. Database-enforced row-level security on artist-owned tables, including sensitive and physical-characteristic data, with forced row-level security and self-scoped policies. The application runs as a restricted database role and refuses to start in staging or production if that role is a superuser or holds bypass privileges.
Special category isolationDate of birth, nationality, ethnicity and gender are held in a dedicated table excluded from ordinary profile reads and protected by row-level security. Disclosure to a customer occurs only per application, through a point-in-time consent record that the review interface reads instead of the live profile, so that later profile edits cannot retroactively change what was disclosed.
Access control — customer usersRole-based access within the workspace, covering Owner, Admin, Member and, on higher plans, External roles. Guest reviewer access uses tokens stored only as hashes, scoped to specific opportunities and rooms, with mandatory expiry, individual revocation and a distinct audit actor type. Two-factor authentication is available on all plans; Single Sign-On is available on Custom plans.
Access control — Lanced personnelInternal administrative access requires an internal account type, an assigned administrative role, a per-action permission and a non-disabled administrative flag. Support sessions conducted in the context of a user account are permission-gated, with start and end recorded in an internal audit trail, and are blocked from administrative tooling.
AuthenticationManaged authentication and credential hosting through a specialist provider identified in Annex 3. Passwords are stored as hashes. Session cookies are set httpOnly, secure and SameSite-restricted; OAuth state is protected by a short-lived nonce.
Media and document accessUploaded media is served from an EU content delivery layer over long, randomised, non-indexed object keys, with cross-origin access restricted to Lanced production origins. Signed contract documents are held in a separate private store with no public route, no development URL and no cross-origin policy, and are readable only through short-lived pre-signed links issued by authenticated endpoints.
Application securitySecurity headers; cross-origin resource sharing restricted to an explicit origin list; rate limiting in production; inbound webhook signature verification using constant-time comparison, with rejection monitoring and alerting; redaction of credentials, tokens and signing URLs from request logs; fail-closed production start-up that rejects missing or placeholder secrets and misconfigured storage.
Logging and monitoringThree separate audit trails covering customer-workspace actions, artist-side actions and internal staff actions, each recording actor, target, payload, IP address and user agent. Application error monitoring with personally identifying data collection disabled at the SDK level. The customer-workspace trail is surfaced to the Customer in-product under clause 12.4.
Deletion and media lifecycleDeleted media objects are physically removed from object storage within 7 days by a scheduled process. Message attachments are purged 30 days after the last referencing conversation closes. Abandoned uploads expire rather than persisting as orphaned objects. Erasure of an account clears profile fields, nulls special-category fields, revokes all sessions and replaces conversation identity with a non-identifying placeholder, and is permission-gated and audited.
Backup and recoveryManaged database backups, together with a database snapshot taken before every production deployment and a retained rotation of recent snapshots.
Change managementVersion-controlled source; continuous integration; manual approval before production deployment; deployment images held in a private registry.
Incident responseA documented incident response procedure with defined severity levels, an assigned owner, an initial triage target and a dedicated security disclosure channel.
PersonnelConfidentiality obligations for all personnel with access to personal data.
Sub-processor managementWritten data processing agreements with each sub-processor, with the data region selected deliberately at account creation for providers whose region is fixed at that point.
Annex 3

Authorised sub-processors

Authorised as at the effective date. Changes are notified under clause 6.3.

The current list is maintained in the Sub-Processor Register in the Lanced Trust Center.

Sub-processorPurposeLocationTransfer mechanism
Cloudflare, Inc.Object storage for uploaded files including headshots, portfolio media, self-tapes, documents, CVs and signed contracts; media delivery and processingEuropean UnionProcessing within the EEA under the Cloudflare DPA; storage pinned to EU jurisdiction
DigitalOcean, LLCApplication hosting, managed PostgreSQL database, database backupsNetherlands (Amsterdam)Processing within the EEA
Functional Software, Inc. (Sentry)Application error monitoring; may incidentally receive personal data appearing within an error messageEuropean Union (EU data region)Sentry DPA incorporating SCCs; EU–U.S. Data Privacy Framework certification
ResendTransactional email triggered by platform actions, including applicant and reviewer notifications, invitations and contract confirmationsIreland for sending; United States for account data, delivery logs and metadataStandard Contractual Clauses
WorkOS, Inc.Authentication, identity management and credential hosting for platform usersUnited StatesStandard Contractual Clauses
Zoho Corporation (Zoho Sign)Electronic signature for contracts agreed through the platform; processes signer name, signer email and the contract documentEuropean UnionProcessing within the EEA

Committed, not yet engaged

Sub-processorPurposeLocationTransfer mechanism
Google Ireland Ltd. (Google Calendar), with Google LLC (US) as onward sub-processorOptional calendar integration for audition and interview schedulingIreland as contracting entity; global Google infrastructure including the United StatesGoogle Cloud Data Processing Addendum incorporating SCCs

Not sub-processors of Customer Personal Data

The following providers appear on the Lanced Sub-Processor Register but do not process personal data on the Customer's behalf. They process personal data for which Lanced is the independent controller and are covered by the Lanced Privacy Policy rather than by this DPA: Stripe for subscription billing between Lanced and the Customer, Brevo for Lanced marketing email and customer service, GitHub for source code and deployment infrastructure, Google Maps Platform for location autocomplete, and PostHog for product analytics, committed but not yet engaged.

Annex 4

Standard Contractual Clauses

Where a transfer requires the SCCs as between the Customer and Lanced, the Standard Contractual Clauses approved by the European Commission under Implementing Decision (EU) 2021/914 apply in full, with the modules and elections set out in clause 10.3, and with Annex 1 and Annex 2 of this DPA populating SCC Annex I and SCC Annex II respectively.

The full text of the SCCs is reproduced here in the published version, so that no separate execution is required.