Legal
Data Processing Agreement.
Last Updated: 4 October 2026
This Data Processing Agreement (“DPA”) is between Planning Beats Limited (“we”, “us”, “our”) and the business that holds a Planning Beats account (“you”). It forms part of our Terms & Conditions and applies automatically when you use Planning Beats. You do not need to sign it.
It covers the personal data you put into Planning Beats about other people, such as your clients. It sets out what we do with that data, on your behalf, and how we protect it.
1) Definitions
- “Data Protection Law” means the UK GDPR and the Data Protection Act 2018 and, where they apply to you, the EU GDPR and any other privacy law that applies to the personal data.
- “Customer Personal Data” means personal data within your Customer Data that we process on your behalf to provide the Service.
- “Sub-processor” means another company we use to process Customer Personal Data on our behalf.
- “Controller”, “processor”, “personal data”, “processing” and “personal data breach” have the meanings given in Data Protection Law. “Service” and “Customer Data” have the meanings given in the Terms & Conditions.
2) Roles
- You are the controller of Customer Personal Data. We are your processor.
- This DPA does not cover the information we hold about you as our customer, such as your account, billing and usage. We are the controller of that information, and our Privacy Policy explains how we use it.
- If this DPA and the Terms & Conditions say different things about Customer Personal Data, this DPA applies.
3) What We Process and Why
Subject matter and purpose: Providing the Planning Beats service to you: managing your enquiries, bookings, clients, staff, documents, payments, music planning and messages, and the features you choose to use. This includes keeping the Service secure and working, finding and fixing faults, and supporting you.
Nature of the processing: Collecting, storing, organising, displaying, sending, importing, extracting and structuring, backing up and deleting data, as needed to run the Service.
Duration: For as long as you have an account, and afterwards only as set out in clause 12.
People the data is about: Your clients and prospective clients, their guests where you collect guest requests, your staff and contractors, your suppliers, and contacts at venues and agencies.
Types of personal data: Names, email addresses, phone numbers, postal addresses, event and booking details, dates and venues, notes, planning and questionnaire answers, messages, contracts and signatures, invoices and payment records, song requests and music preferences, staff rotas and pay records, and anything else you choose to store.
Sensitive data: The Service is not designed for special category data. Some may appear where you or your clients choose to enter it, for example in notes or planning answers. Card payments are handled by your payment provider.
4) Your Instructions
- We process Customer Personal Data only on your documented instructions. Your instructions are the Terms & Conditions, this DPA, the settings you choose and the features you use.
- We do not sell Customer Personal Data and we do not use it for advertising. We look at it only where that is needed to run, secure, support or fix the Service.
- If the law requires us to process Customer Personal Data in another way, we will tell you first, unless the law forbids it.
- We will tell you if we believe an instruction breaks Data Protection Law.
5) Your Responsibilities
- You are responsible for having a lawful basis to collect and use the personal data you put into Planning Beats, and for telling the people it is about how you use it.
- You are responsible for the accuracy of your Customer Data and for the instructions you give us.
- You are responsible for keeping your logins secure and for choosing who on your team can see what.
6) Confidentiality
Only people who need Customer Personal Data to provide, support or secure the Service can access it. Everyone who can access it is bound by a duty of confidentiality.
7) Security
We keep appropriate technical and organisational measures in place to protect Customer Personal Data, taking account of the risks involved. They include:
- Encryption in transit and at rest for appropriate data classes.
- Secure authentication and session management.
- Role-based access controls with least-privilege principles.
- Audit logging and monitoring for security events.
- Backups and disaster recovery procedures.
- Vendor due diligence and data protection agreements with our Sub-processors.
We may update these measures over time, but we will not reduce the overall level of protection.
8) Sub-processors
- You give us general authorisation to use Sub-processors. The current list is on our Sub-processors page.
- We have a written contract with each Sub-processor that requires it to protect Customer Personal Data to the standard this DPA requires.
- We remain responsible to you for what our Sub-processors do with Customer Personal Data.
- Changes: Before a new Sub-processor starts processing Customer Personal Data, we will update the Sub-processors page and tell you by email or in the app at least 14 days in advance.
- Objections: If you object on reasonable data protection grounds, email us within those 14 days. We will try to resolve it with you. If we cannot, you may cancel your subscription before the change takes effect.
- Services you connect with your own account, such as your email, calendar, payment or accounting provider, or your own AI app, are not our Sub-processors. They handle data under your own agreement with them.
9) AI Processing
- Smart import and the setup assistant are optional. When you use them, you instruct us to send the files and text you provide to Anthropic’s commercial Claude API, so they can be read and returned in a structured form.
- Anthropic acts as our Sub-processor for this. Anthropic’s commercial terms say that content sent through its commercial API is not used to train its models by default.
- The results are shown to you for review. Nothing is saved to your account until you confirm it. These features do not make decisions about people.
- Our AI features use Customer Personal Data only to carry out what you ask them to do in your own account. We do not use it to train AI models.
10) International Transfers
We and our Sub-processors may process Customer Personal Data outside the United Kingdom. Where we do, we make sure a lawful transfer mechanism is in place, such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. The Sub-processors page shows where each Sub-processor processes data.
11) Helping You Meet Your Obligations
- Requests from individuals: Planning Beats lets you find, correct and export the personal data you hold, and we will delete a person’s data on your request where you cannot do it yourself. If someone contacts us about data you control, we will pass the request to you and will not answer it ourselves unless you ask us to or the law requires it. We will give you reasonable help to respond.
- Personal data breaches: If we become aware of a personal data breach affecting Customer Personal Data, we will tell you without undue delay. We will give you the information we have about what happened, what data is affected and what we are doing about it, so that you can meet your own reporting duties.
- Assessments: We will give you reasonable help with data protection impact assessments and with consulting a regulator, where these relate to our processing for you.
12) When Your Account Closes
- While your account is open, you can export your Customer Data at any time.
- When your account closes, we delete or irreversibly anonymise Customer Personal Data at your request. If you do not ask, we delete or anonymise it once the retention period in our Privacy Policy ends.
- We may keep a copy only where the law requires us to. Copies in routine encrypted backups are not used for active processing and are overwritten on rotation.
13) Information and Audits
- On request, we will give you the information you reasonably need to check that we are meeting this DPA.
- If that information is not enough, you or an independent auditor you appoint may audit our compliance with this DPA. An audit can take place once in any 12 months, on at least 30 days’ written notice, during business hours, at your cost and under a duty of confidentiality. It must not put other customers’ data or the security of the Service at risk.
- These limits do not apply where a regulator requires an audit or after a personal data breach affecting your data.
14) General
- The liability terms in the Terms & Conditions apply to this DPA. Nothing in this DPA limits either of our responsibilities to individuals or regulators under Data Protection Law.
- This DPA is governed by the same law and courts as the Terms & Conditions.
- We may update this DPA when the law, our Service or our Sub-processors change. If a change is material, we will tell you by email or in the app before it takes effect.
15) Contact
Planning Beats Limited
17 Youngs Orchard, Abbeymead, Gloucester, GL4 4RR, United Kingdom
Company Number: 15813860
Email: info@planningbeats.com
Built with working DJs since 2024. Because nothing existed that fit how a DJ business actually runs.
