Dancetu legal
Data Processing Addendum
This DPA is incorporated into the Dancetu Terms and governs QikBuild’s processing of personal data on behalf of a studio customer.
- Effective:
- 15 September 2026
- Version:
- 2026-09-15-v1.0
1. Parties, scope, and precedence
The “Customer” is the business identified in the Dancetu subscription. The “Processor” is QikBuild, s. r. o., Bottova 2A, 811 09 Bratislava – Staré Mesto, Slovak Republic. This DPA applies when QikBuild processes Customer Personal Data to provide Dancetu.
Terms such as controller, processor, data subject, personal data, processing, personal-data breach, and supervisory authority have their GDPR meanings. The Customer is controller and QikBuild is processor. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls.
2. Processing details
Subject matter and purpose: hosting and operating dance-studio scheduling, booking, student records, attendance, courses, passes, communications, security, support, backup, and customer-requested exports.
Duration: the subscription term plus the export, deletion, backup, and legal-retention periods described in the Terms and this DPA.
Data subjects: students, prospective students, guests, parents or guardians, emergency contacts, instructors, employees, contractors, staff invitees, and other people whose information the Customer enters.
Data types: names, contact details, account identifiers, dates of birth, gender and partner-role fields, emergency contacts, bookings, attendance, cancellations, course/pass records, instructor profiles and availability, studio notes, consent evidence, communications, and technical metadata. Special-category data is not an intended standard data type.
Operations: collection, recording, organization, storage, retrieval, consultation, transmission to authorized recipients/subprocessors, restriction, backup, export, deletion, and anonymization.
3. Customer instructions and responsibilities
The agreement, configuration chosen by authorized users, documented support requests, and lawful use of Dancetu are the Customer’s documented instructions. QikBuild will process Customer Personal Data only on those instructions unless EU or Member State law requires otherwise; where legally permitted, QikBuild will inform the Customer before that processing.
- The Customer determines lawful bases, purposes, data accuracy, notices, retention, and which people may access its data.
- The Customer will not instruct processing that violates GDPR or other applicable law and will not place unnecessary or unsupported sensitive data in Dancetu.
- The Customer will handle data-subject requests and regulator communications, with QikBuild’s reasonable assistance.
If QikBuild believes an instruction infringes data-protection law, it will inform the Customer unless prohibited and may pause the affected processing.
4. Confidentiality and personnel
QikBuild ensures that people authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their duties. Access is reviewed and removed when no longer required.
5. Security measures
Taking account of the state of the art, costs, scope, context, purposes, and risks, QikBuild maintains measures appropriate to the risk, including:
- managed encryption at rest and TLS in transit;
- tenant-aware authorization, database row-level security, role checks, and service-role isolation;
- multi-factor authentication for privileged provider access where available, least-privilege secrets, and environment separation;
- signature verification and idempotency for billing webhooks, secure session handling, input validation, and rate controls;
- backups, recovery procedures, dependency review, security logging, and incident investigation;
- tests for tenant isolation and permission boundaries and controls preventing secrets or full payment-card data from entering application logs.
QikBuild may update measures without materially reducing overall protection.
6. Subprocessors
The Customer gives general written authorization for subprocessors listed at dancetu.com/subprocessors. QikBuild imposes data-protection obligations appropriate to each subprocessor’s services and remains responsible for their performance to the extent required by GDPR.
QikBuild will provide at least 30 days’ advance notice of a new or replacement material subprocessor where practicable. The Customer may object during that period on reasonable, documented data-protection grounds. The parties will seek a reasonable solution; if none is available, the Customer may terminate the materially affected service before the change without a termination penalty.
7. International transfers
QikBuild will not transfer Customer Personal Data outside the EEA except in compliance with GDPR Chapter V. Where no adequacy decision applies, QikBuild will use the European Commission’s Standard Contractual Clauses, the relevant module, supplementary measures where appropriate, or another lawful mechanism. The Customer authorizes QikBuild to execute those safeguards with subprocessors on its behalf where required.
8. Data-subject and compliance assistance
Considering the nature of processing, QikBuild will reasonably assist the Customer with technical and organizational measures for access, correction, deletion, restriction, portability, objection, and consent-withdrawal requests. QikBuild will not independently respond to a request about Customer-controlled data except on documented instruction or where law requires it.
QikBuild will also reasonably assist with security obligations, breach notifications, data-protection impact assessments, and prior consultation, considering the information available to it. Unusually extensive assistance outside normal product functionality may be charged at agreed reasonable rates unless caused by QikBuild’s breach.
9. Personal-data breaches
QikBuild will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. Notice will include available information about the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as the investigation develops.
The Customer is responsible for deciding whether and how to notify authorities or data subjects. A notice is not an admission of fault or liability.
10. Return and deletion
During the subscription and for 30 days after termination, the Customer may use supported exports or request a reasonable export. QikBuild then deletes or anonymizes Customer Personal Data in active systems within 90 days, unless the Customer requests earlier deletion that can safely be fulfilled or law requires retention.
Residual backup copies expire through the rolling backup lifecycle and remain protected and unavailable for ordinary processing. QikBuild may retain controller records such as invoices, contract acceptance, security evidence, and communications as described in the Privacy Policy.
11. Information and audits
QikBuild will make information reasonably necessary to demonstrate Article 28 compliance available through this DPA, current subprocessor information, security documentation, and relevant independent reports or certifications when available.
Where that is insufficient, the Customer may request one audit per year on at least 30 days’ notice, during business hours, subject to confidentiality, security, and protection of other customers. The audit must use an independent qualified auditor, avoid vulnerability exploitation and production disruption, and be at the Customer’s cost unless it identifies a material QikBuild breach. Regulators’ mandatory powers are unaffected.
12. Liability, duration, and contact
The Terms’ liability provisions apply to this DPA to the extent permitted by mandatory data-protection law. This DPA remains in effect while QikBuild processes Customer Personal Data.
Data-protection communications should be sent to privacy@dancetu.com. Operational requests should use support@dancetu.com.