Legal
Data Processing Addendum
Last updated: 7 July 2026
This Data Processing Addendum forms part of the agreement between WALDHORN AI INC, which operates WALDHORN.AI, and the customer identified in the applicable order or terms, and governs the processing of personal data on the customer’s behalf.
Contents
1. Roles and scope
For personal data contained in the documents, accounts, and configurations a customer submits, the customer is the controller and WALDHORN AI INCis the processor. We process that data only on the customer’s documented instructions, which include this Addendum, the agreement, and the in-product settings, to provide and secure the service and to meet our legal obligations.
Under the CCPA and CPRA, WALDHORN AI INC acts as a service provider. We do not sell or share personal data, and we do not retain, use, or disclose it for any purpose other than performing the service.
2. Processing details
- Subject matter. Operation of WALDHORN.AI, which generates, reviews, negotiates, e-signs, and audits music-industry contracts and organizes related rights information.
- Nature and purpose. Hosting, storage, parsing, AI inference, display, analytics, support, security (including abuse detection), and backups.
- Duration. The term of the agreement, plus limited post-termination retention as described in section 7.
- Data subjects and categories.The customer’s authorized users, and any individuals named in the content the customer submits. Categories include names, business contact details, account credentials, usage logs, and contract content that may reference individuals.
- AI training is opt-in. We do not use customer personal data to train models unless the customer explicitly enables training consent, and that consent is revocable on a going-forward basis.
3. Controller responsibilities
The customer is responsible for the lawfulness of the data it submits, for any notices or consents required from data subjects, and for its own retention, deletion, and training settings. The customer will not submit unlawful content, malware, or data it lacks the rights to process.
4. Security and confidentiality
Personnel authorized to process personal data are bound by confidentiality. We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based least-privilege access, and multi-factor authentication for administrative access. A summary is set out in Annex II and on the Trust center.
5. Subprocessors
The customer grants a general authorization for WALDHORN AI INC to engage the subprocessors listed at the Subprocessors page. We impose data-protection obligations on each subprocessor and remain responsible for their acts and omissions. We will update that page before a new subprocessor that handles personal data begins processing, except for emergency security changes.
6. International transfers
WALDHORN AI INC is based in the United States. Where processing involves a transfer of personal data from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties rely on the following, together with supplementary safeguards such as encryption:
- EU Standard Contractual Clauses, Module Two (controller to processor), incorporated by reference with the annexes populated by the details in this Addendum.
- UK International Data Transfer Addendum to the EU SCCs for transfers subject to UK law.
7. Return and deletion
On termination or on the customer’s instruction, we will return or delete customer personal data, subject to any retention the law requires. Data held in routine encrypted backups is isolated from active use and purged on our standard backup rotation. For how this fits into our overall data handling, see the Privacy Policy.
8. Annexes
Annex I. Processing details
Data exporter: the customer identified in the order or agreement. Data importer: WALDHORN AI INC, operator of WALDHORN.AI. Subject matter, categories, and duration are as set out in section 2. Transfers run from the EEA, the United Kingdom, and Switzerland to the United States under the safeguards in section 6.
Annex II. Security measures
- Access control. Role-based, least-privilege access; multi-factor authentication for administrative access; periodic access review.
- Encryption. TLS 1.3 in transit; AES-256 at rest.
- Resilience. Routine encrypted backups and multi-zone redundancy.
- Assurance. Vulnerability scanning and incident response, with notice to affected customers where the law requires it.
Annex III. Subprocessors
The current list is maintained at the Subprocessors page and is incorporated here by reference.
For privacy or DPA inquiries, contact privacy@waldhorn.net. Corporate registration details for WALDHORN AI INC are available on request.