Version 1.6 — Effective September 17, 2026
Version 1.6 replaces the description of emailed invitations with what the service does since Privacy Policy 1.11: people join with a join code and a request the Customer's owner or administrators answer in the app (introduction, 1.4, 2.1, 2.3, 2.4, 2.5, 3.5, 3.8, 4.1, Annexes 1 and 2), and we send no email about a team. Version 1.5 had added one item to the categories of personal data (2.4): a label that the Customer's owner or administrators can give a member, described in Section 3.8 of the Privacy Policy. Version 1.4 had answered a fifth review: Section 3.8 describes placeholder replacement as exactly that and says what the audit trail retains and that it remains linkable. Version 1.3 had answered a fourth review: it scoped the transfer commitment to restricted transfers (5), referenced the legal-hold exception from the no-own-purpose promise (3.1), aligned the hold trigger with the Privacy Policy and described the placeholder operation (3.8). Version 1.2 had answered a third review: it applies to every team owner, not only organizations (introduction, 1.1); discloses that used invitations are retained (1.4); removes the audit-record retention exception so all team data is deleted with the team (3.8); stops describing transfer clauses as in force and gives any later instrument priority (5, 7.3); and states whose liability Section 7.1 limits. Version 1.1 had replaced version 1.0 of the same day: it adds pending-invitation handling (1.4), US state service-provider terms (Section 6), return at the Customer's direction and defined retained records (3.8), compliance information outside the audit cycle (3.9), and corrects the transfer and consent wording.
This Data Processing Addendum ("DPA") forms part of the Setliner End User License Agreement (the "Agreement") between Setliner, LLC ("Setliner," "we," "us") and the owner of a team (the "Customer," "you"), whether that owner is an organization that accepted the Agreement under its Section 1.2 or an individual account holder running a team for a band or group of their own. It applies automatically, without signature, from the moment the Customer first causes us to process personal data on its behalf, which today means creating a team in the Teams feature and letting people ask to join it. Capitalized terms not defined here have the meaning given in the Agreement.
1. Roles and scope
1.1 For the personal data that the Customer, its administrators and its members enter into a team, the Customer is the controller and Setliner is the processor, whatever the Customer's size or legal form. We process that data only to run the team for the Customer, as described in Section 3.8 of our Privacy Policy.
1.2 This DPA does not cover the personal data we hold as controller for our own purposes: account email addresses, device identifiers, entitlements, purchase records, update requests and support correspondence. Those are governed by the Privacy Policy directly, and we are the controller for them even where the account holder is a member of the Customer's team.
1.3 "Data Protection Laws" means the laws that apply to the processing under this DPA, which may include the California Consumer Privacy Act as amended, the Oregon Consumer Privacy Act and other United States state privacy laws, and, where they apply to a particular person's data, the EU and UK General Data Protection Regulations. We do not currently offer Teams, accounts or purchases in the European Economic Area or the United Kingdom; see Section 8 of the Privacy Policy.
1.4 People join the Customer's team by entering its join code in the app, which creates a join request. A request holds the requester's account email address, the team's identifier and when it was made; the Customer's owner and administrators see it until one of them approves or declines it or the requester withdraws it. A declined, withdrawn or unanswered request is deleted 30 days after it was made. The join code itself is stored only as a one-way hash until the owner or an administrator replaces it. Approving a request is the Customer's decision to add that person to its team, with or without a seat, and that is processing on the Customer's behalf from the moment the request is made.
2. Details of the processing
2.1 Subject matter and purpose: operating the Customer's team, namely keeping its roster, roles, events, role assignments, setlist grants and join requests, so that the Customer's members can see and respond to them in the app. We send no email about a team.
2.2 Duration: for as long as the Customer's team exists, plus the deletion periods in Section 9 of the Privacy Policy.
2.3 Categories of data subjects: the Customer's owner and administrators; members of the team; people who have asked to join the Customer's team and have not yet been approved or declined.
2.4 Categories of personal data: email address; display name, and any label the Customer's owner or administrators give a member; permission level (owner, administrator, planner or member) and roles within the team; events and who is assigned to them, with responses; which setlists a member has been granted; join requests (email address and when the request was made); when each answer to an assignment was given.
2.5 Special categories: the service asks for none. The Customer decides what it names its team and roles and what events it schedules. If those choices reveal a person's religious or other beliefs, for example because the team is a church's worship team, the Customer is the controller of that fact and is responsible for having a lawful basis and, where the law requires it, the person's explicit consent. The Customer, as controller, obtains that consent from the person before entering the information, and can show us evidence of it on request; the Privacy Policy tells members that the team's owner entered the information and is responsible for it. Asking to join a team, or being approved, is not by itself that consent.
2.6 Content is not processed: the Customer's songs, charts and setlist contents are neither stored nor transmitted by the team service. Teams stores only a setlist's identifier and who may receive it; the setlist itself reaches the member through channels outside this DPA, such as a shared folder, an export or a linked session.
3. Our obligations as processor
3.1 Instructions. We process the Customer's personal data only on the Customer's documented instructions. The Agreement, this DPA, the Privacy Policy and the Customer's use of the product's controls (creating, editing, granting, revoking, removing, deleting) are those instructions. We will tell the Customer if an instruction appears to us to infringe Data Protection Laws. We will not process the data for any purpose of our own, other than the narrow legal-hold exception in Section 3.8, and we will not sell or share it.
3.2 Confidentiality. Only people who need access to run and support the service have it, and each of them is bound by a confidentiality obligation.
3.3 Security. We apply the measures in Annex 1, and we keep them under review. We will not reduce the overall level of protection they provide during the term.
3.4 Sub-processors. The Customer gives general authorization for the sub-processors listed in Annex 2, each of which is bound by written terms that impose data protection obligations no less protective than this DPA. We will give the Customer at least 30 days' notice, by email to the team owner's address and by updating Section 7 of the Privacy Policy, before adding or replacing a sub-processor. If the Customer objects on reasonable data-protection grounds and we cannot resolve the objection, the Customer may delete its team and terminate the affected service, and the discontinuation remedy in Section 5.7(4) of the Agreement applies to any seat bundle bought outright. We remain responsible for the acts and omissions of our sub-processors.
3.5 Data subject requests. If a member, or a person who has asked to join, sends us a request to exercise a right under Data Protection Laws about data in the Customer's team, we will tell the Customer promptly and will not respond except to say that the request has been passed on, unless the law requires us to respond directly. We will help the Customer answer such requests with the tools in the product (a member can leave; an administrator can remove a member, cancel an assignment or revoke a grant) and, where those are not enough, by reasonable manual assistance.
3.6 Assistance. Taking into account the nature of the processing and the information available to us, we will give the Customer reasonable assistance with its obligations to keep the data secure, to notify breaches, and to carry out data protection impact assessments and consultations with a supervisory authority where required.
3.7 Personal data breach. If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to the Customer's personal data, we will notify the team owner's email address without undue delay, aiming for 24 hours and in any event within 72 hours of becoming aware, with what we know at the time: what happened, which data and roughly how many people are affected, what we have done, and what we recommend the Customer do. We will update that notice as we learn more. To reach us about a suspected incident at any time, email support@setliner.com with "Security" in the subject line.
3.8 Deletion and return. At the Customer's direction at any time, including during a suspension, and in any case when the Customer deletes its team or the Agreement ends, we delete the team's personal data from our active systems within 30 days; copies in routine backups age out within 60 days after that. The Customer can export its team's data with the product's own export functions at any time before deletion, or ask us for a copy in a machine-readable format, which we provide within 30 days. Cancelled assignments, join requests that have not yet aged out, and the team's audit trail (which account changed what and when, by identifier, with no content) are all part of the team's data, under the Customer's control, until the team is deleted, and are deleted with it on the schedule above; on the Customer's or the member's request we replace a departed member's display name and email address in the history and in any join request with a placeholder. That is placeholder replacement, not anonymisation: the audit trail is unchanged and retains, for each change to the team, the acting account's internal identifier, the action, a reference to the item changed (for a join request, a one-way hash of the requester's email address), the team revision and the time. Those records may remain linkable to a person by anyone who already holds the identifier or the address, so they remain personal data under this DPA, subject to its access, retention and rights provisions, and are deleted with the team. We keep nothing from a deleted team beyond that schedule except where the law requires it, or where a specific claim, investigation or abuse case involving that team is already open when the deletion falls due, in which case we keep only what that case needs, in our own capacity as controller, and delete it when the case ends. Purchase transaction records are not team data; they are ours as controller and follow the tax and accounting retention period in Section 9 of the Privacy Policy.
3.9 Audits. On written request we will provide the information reasonably necessary to demonstrate our compliance with this DPA, to answer a specific compliance question, or to support a legitimate investigation by the Customer or a regulator, at any time, in the form of written answers, our current security description, and any independent assessment we hold. If that information is not reasonably sufficient, the Customer may, at its own cost and on at least 30 days' notice, carry out or commission a remote audit during business hours, limited to the systems that process its data, under a confidentiality obligation, and not more than once a year unless a supervisory authority requires otherwise or a breach has occurred.
3.10 Records and cooperation. We keep the records of processing that Data Protection Laws require of a processor and will cooperate with a supervisory authority that has jurisdiction over the Customer's processing, on request.
4. Customer obligations
4.1 The Customer is responsible for the lawfulness of the personal data it enters and of its instructions, for telling its members, and people it gives its join code to, how their data is used (the Privacy Policy may be used for that purpose), and for obtaining any consent Data Protection Laws require, including under Section 2.5.
4.2 The Customer will not enter personal data of anyone under 13, and will comply with Section 1.1 of the Agreement for members between 13 and the age of majority.
4.3 The Customer will keep its owner and administrator accounts secure, remove members promptly when they leave the organization, and use the product's controls rather than emailing us to make routine changes, so that our records match its instructions.
5. International transfers
Our services are hosted in the United States. Because Teams is not offered in the European Economic Area or the United Kingdom today, we do not expect a restricted transfer under the EU or UK GDPR to occur, and no transfer instrument is currently in place. Whether a disclosure to us is a restricted transfer depends on the processing, the law that applies to the Customer and the parties, not only on where a member lives. Where the Customer's disclosure of personal data to us under this DPA would be a restricted transfer, the Customer must tell us before making it; we will then either put the appropriate instrument in place with the Customer (the European Commission's Standard Contractual Clauses, module two, which applies to this controller-to-processor relationship, or, for the UK, those clauses with the International Data Transfer Addendum, each completed with the parties, transfer details and annexes, together with a transfer assessment and any supplementary measures) before the disclosure occurs, or decline that processing. An instrument executed afterwards does not cure a disclosure already made. Any such instrument, once executed, prevails over this DPA and over the Agreement's liability, dispute-resolution, venue and amendment terms to the extent they conflict with it. If we open Teams there, we will appoint a representative as Section 8 of the Privacy Policy promises.
6. United States state service-provider terms
Where a United States state privacy law such as the California Consumer Privacy Act or the Oregon Consumer Privacy Act applies to the Customer's processing, we act as the Customer's service provider or processor, and the following apply in addition to Section 3:
- We process the Customer's personal data only for the business purpose of running the Customer's team as this DPA describes, and only within our direct business relationship with the Customer.
- We do not sell or share it, do not retain, use or disclose it for any other purpose, and do not combine it with personal data we receive from anyone else or collect ourselves, except as those laws permit a service provider to do.
- We comply with those laws' obligations on service providers and provide the same level of privacy protection they require.
- We will notify the Customer without undue delay if we determine that we can no longer meet our obligations under those laws.
- The Customer may take reasonable and appropriate steps to ensure we use its personal data in a manner consistent with its obligations, and, on notice, to stop and remediate any unauthorized use.
- Our sub-processors are bound by written terms that impose the same obligations, and we remain responsible for them.
7. Liability, term and general
7.1 Sections 14 and 15 of the Agreement limit our liability under this DPA in the same way and to the same extent as they limit it under the Agreement; nothing in this DPA limits the Customer's liability, and nothing in it limits any liability that Data Protection Laws do not allow to be limited.
7.2 This DPA lasts for as long as we process personal data on the Customer's behalf and Section 3.8 survives until that deletion is complete.
7.3 Where this DPA conflicts with the Agreement about the processing of the Customer's personal data, this DPA prevails, and a transfer instrument executed under Section 5 prevails over both. Section 19 of the Agreement governs changes to this DPA, and a change that reduces the Customer's protection takes effect only on 30 days' notice. Section 20 of the Agreement governs its law and any dispute.
7.4 If the Customer needs a signed copy of this DPA, or a version incorporating the Standard Contractual Clauses, write to support@setliner.com and we will provide one at no charge.
Annex 1 — Technical and organizational security measures
- Transport encryption (TLS) for every connection to the team service; encryption at rest for its database and backups.
- A team's join code is stored only as a one-way hash, is replaced whenever the owner or an administrator makes a new one, and does not by itself admit anyone: every request it produces waits for the owner's or an administrator's answer.
- Every change to a team is authorized against the acting member's current permission at the moment it is applied; a removed member's pending deliveries are cancelled in the same transaction.
- Ordinary members can see the roster and roles but only their own assignments, grants and the events those belong to; owners, administrators and planners see the whole team.
- An audit record of who changed what, and when, is kept for each team without storing any secret in it.
- Access to production systems is limited to the people who operate the service, by named account, and reviewed when roles change.
- Routine encrypted backups that age out within 60 days; deletion from active systems within 30 days of a team being deleted.
- No song, chart or setlist content is stored or transmitted by the team service.
Annex 2 — Sub-processors
- Hostinger — hosting of the team service and its database, and the transactional email that delivers account messages such as sign-in codes. No email is sent about a team. United States hosting.
Payments are handled by Polar Software, Inc. as an independent controller under the Privacy Policy, Section 3.7; Polar does not process the Customer's team data and is not a sub-processor under this DPA.
Setliner is a product of Setliner, LLC. Questions about this DPA: support@setliner.com.