Data Processing Agreement
Effective 29 September 2026 · Version 1.0 · Incorporated into the Terms of Service
This Data Processing Agreement ("DPA") is entered into between the Tenant (the "Data Fiduciary" under the DPDP Act, 2023 / the "Controller" under GDPR) and Cosmoura Marketing Private Limited (the "Data Processor" / "Processor"), governing personal data processed by the MyShowPage platform. It is accepted at signup; a countersigned PDF version is available on request from [email protected].
1. Roles
The Tenant determines the purposes and means of processing personal data of its own enquirers, clients, artists and team members. Cosmoura processes that data only on the Tenant's documented instructions, as recorded in these Terms and the DPA. Tenant remains accountable to Data Principals / Data Subjects.
2. Subject matter, duration, nature and purpose (GDPR Art. 28(3))
- Subject matter: personal data submitted to the MyShowPage platform.
- Duration: for the term of the subscription, plus the retention periods in §8.
- Nature and purpose: to provide the MyShowPage SaaS features (CRM, invoicing, calendar, media, messaging, AI assistance).
- Categories of Data Principal / Data Subject: booking enquirers, clients, managed artists, team members.
- Categories of personal data: name, contact details, event brief, financial data, KYC (where uploaded), messages, uploaded media.
- Special categories: none intentionally processed. Do not upload sensitive data.
3. Processor obligations
Cosmoura will:
- Process personal data only on documented Tenant instructions, unless required by law (in which case Cosmoura will notify Tenant unless legally prohibited).
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures in §5 (Security).
- Assist the Tenant in fulfilling Data Principal / Data Subject rights requests.
- Assist the Tenant with Data Protection Impact Assessments and prior consultations with the DPB / supervisory authority, where applicable.
- At the Tenant's choice, delete or return personal data at end of processing, subject to statutory retention.
- Make available all information necessary to demonstrate compliance and allow for audits (see §9).
4. Sub-processors
Tenant grants general written authorisation for Cosmoura to engage sub-processors. Current list (also in the Privacy Policy):
- Cloudflare — CDN, R2 storage.
- Contabo — primary hosting (India).
- OVHcloud — DR (Singapore).
- Razorpay — payments (India).
- Dodo Payments — payments (international).
- Meta Platforms (WhatsApp Cloud API) via BookMySMS — messaging.
- Anthropic PBC (Claude) — AI features (redacted prompts only).
- SignupDesk — ticketing.
- Google LLC — one-way calendar push.
- Postmark / Amazon SES — transactional email.
Cosmoura will impose on each sub-processor materially the same data-protection obligations as in this DPA. We give Tenant 30 days' notice of intended additions/replacements via email or in-app banner; Tenant may object with reasonable grounds within that period, in which case Cosmoura will either propose a workaround or Tenant may terminate the affected feature.
5. Security (DPDP Act §8(5); GDPR Art. 32)
- Encryption in transit (TLS 1.2+) and at rest for KYC/financial fields (AES-256).
- Password hashing with bcrypt (cost 12).
- Role-based access control; MFA for privileged roles; least-privilege access reviewed quarterly.
- Tamper-evident audit logging of access to personal data.
- Vulnerability scanning; annual third-party penetration test; documented incident response.
- Regular back-ups; documented restore drills; 35-day retention.
- Segregation of customer data by
tenant_id; row-level authorisation checks.
6. Personal-data breach
Cosmoura will notify Tenant of a confirmed personal-data breach without undue delay and in any event within 48 hours of confirmation, providing:
- Nature of the breach and affected data categories.
- Approximate number of Data Principals / Data Subjects and records.
- Likely consequences.
- Measures taken or proposed to mitigate.
- Contact point for further information.
This allows Tenant to meet its own notification obligations to the Data Protection Board of India (DPDP §8(6)) and, for EU/UK residents, GDPR Art. 33 (72 hours) and Art. 34.
7. Cross-border transfers
India (DPDP §16): primary storage in India; DR replication to Singapore. Named sub-processors may process outside India. Where the Central Government issues restrictions, Cosmoura will reconfigure or provide alternative Tenant configuration.
EU/UK (GDPR Chapter V): transfers to India and third countries without adequacy are subject to the EU Standard Contractual Clauses (2021/914 — modules as applicable) and, where applicable, the UK IDTA, plus supplementary measures identified in a transfer-impact assessment. Copies on request.
8. Return and deletion
On expiry or termination of the subscription:
- Tenant has 30 days to export personal data using in-product tools.
- Cosmoura deletes or anonymises personal data within a further 30 days.
- Financial records with PII tokens are retained for the statutory period (see Privacy Policy §7).
- Backups roll off within 35 days.
9. Audits
Cosmoura will make available a summary of controls (SOC-2-style report once available) annually. Where a Tenant reasonably requires additional information, Cosmoura will cooperate to answer written questions. On-site audit rights are limited to regulator-mandated inspections at Tenant's cost and with 30 days' notice, coordinated to avoid disruption.
10. Children's data
Where the Tenant manages a Data Principal known to be a child (below 18 in India; below 16 or the age set by an EU Member State), the Tenant is responsible for obtaining verifiable parental consent and for restricting behavioural tracking / targeted advertising (DPDP §9; GDPR Art. 8). The Service provides tooling to record and honour this.
11. Governing law
This DPA is governed by the laws of India. For EU/UK data subjects the EU SCCs / UK IDTA prevail on the matters they govern.
12. Order of precedence
In case of conflict: EU SCCs / UK IDTA (where they apply) prevail over this DPA, which prevails over the Terms of Service.