In short
- This agreement only concerns business clients who ask us to record people they have recruited.
- In that case, the client is the controller and the Studio acts on its instructions, as processor.
- For requests received via the website and the commercial relationship, the Studio remains the controller (see the privacy policy).
- Data stays in the European Union and is deleted or returned at the end of the service.
1. Scope and roles
This agreement supplements the terms of service and the accepted quote. It applies when a business client (label, agency, production company, training organisation…) — the "Controller" — entrusts Bertrum Nivonu SARL — the "Processor" — with a service involving the processing of personal data of people the Controller has recruited or whose participation it determines: performers, voiceover actors, podcast guests.
The Studio is not a processor for data it collects on its own behalf (quote requests, client management, invoicing): it is the controller of that data, as described in the privacy policy.
The agreement is deemed accepted together with the quote that refers to it. A signed version can be issued on request.
2. Subject matter, nature, purpose and duration
- Subject matter: recording, editing, mixing and delivering audio files containing the voices and performances of the data subjects.
- Nature of operations: capture, storage, editing, backup copies, transmission to the Controller, deletion.
- Purpose: producing the recordings ordered by the Controller, for the use it determines.
- Duration: duration of the service, then the retention period in Section 9.
3. Data and data subjects
- Data subjects: performers, actors, guests and, where relevant, the Controller's representatives attending sessions.
- Data: recorded voice and performance; name, stage name and credits; business contact details needed to organise sessions; attendance sheets.
- No special category data within the meaning of Article 9 GDPR is processed; voice is not used for biometric identification. The Controller refrains from sending data not needed for the service.
4. Documented instructions
The Processor processes data only on the Controller's documented instructions (quote, e-mails, brief), including with regard to transfers outside the European Union. It immediately informs the Controller if it considers that an instruction infringes the GDPR or applicable law.
The Controller warrants that it has a legal basis for the processing entrusted and has informed the data subjects; it obtains the authorisations required by the French Intellectual Property Code for fixing and exploiting their performances.
5. Confidentiality
The Processor ensures that people authorised to process the data (engineers, independent contributors) are bound by confidentiality and only access the data needed for their task.
6. Security (Article 32 GDPR)
- Access to the premises limited to people attending sessions; studio locked outside appointments.
- Workstations and accounts password-protected, access restricted to authorised people.
- Backup copies on separate media, kept at the Studio's premises.
- Delivery via protected, time-limited download links, through the service agreed with the Controller.
- Secure deletion at the end of the retention period.
7. Sub-processors
The Controller gives general authorisation for the following sub-processors:
- OVH SAS, 2 rue Kellermann, 59100 Roubaix, France: e-mail (exchanges and delivery links), hosted in France;
- the file transfer service agreed with the Controller for each project.
The Processor informs the Controller of any intended addition or replacement at least 30 days in advance; the Controller may object on legitimate grounds. The Processor imposes on its sub-processors obligations equivalent to those in this agreement. The website form (FormSubmit) is never used for data covered by this agreement.
8. Location and transfers
Data covered by this agreement is processed and stored within the European Union. No transfer to a third country is made without the Controller's prior written instruction and appropriate safeguards within the meaning of Chapter V GDPR.
9. Data at the end of the service
On delivery of final files, the Processor keeps a backup copy for 6 months unless the Controller instructs otherwise; the Controller may at any time request early deletion or full return. After that period the data is deleted, unless a legal obligation requires retention. On request, the Processor confirms deletion in writing.
10. Assistance to the Controller
- Data subject rights: the Processor forwards without delay any rights request it receives to the Controller and helps, as far as possible, to answer it.
- Data breaches: the Processor notifies the Controller of any personal data breach within 48 hours of becoming aware of it, with the information available (nature, categories and approximate number of people and records, likely consequences, measures taken).
- Impact assessment and consultation: the Processor provides useful information if the Controller must carry out an impact assessment or consult the CNIL.
11. Documentation and audits
The Processor keeps a record of processing carried out on behalf of its clients (Article 30(2) GDPR) and makes available to the Controller the information needed to demonstrate compliance. The Controller may carry out or commission an audit, at most once a year, with 30 days' notice, at its own cost, without disrupting other clients' sessions and subject to the auditor's confidentiality undertaking.
12. Liability and term of the agreement
Each party is liable for breaches attributable to it under Article 82 GDPR. This agreement applies for the duration of the service and until data is deleted or returned. It is governed by French law; disputes fall under the jurisdiction of the Tribunal des activités économiques de Lyon (Lyon Economic Activities Court, which replaces the Commercial Court from 2025 under Law No. 2023-1059).