Data Processing Agreement
Effective June 18, 2026 · Last updated June 18, 2026
This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Master Services Agreement and applicable Order Form(s) (together, the "MSA") between The Cur8 Group Corp., a Delaware corporation ("CreateBase," "we," "us," or "our"), and the customer identified in the Order Form ("Customer"). This DPA governs the Processing of Personal Data by CreateBase on behalf of Customer in connection with the CreateBase music-catalog diligence, valuation, and royalty-administration platform and related services (the "Services"). Capitalized terms not defined in this DPA have the meaning given in the MSA. In the event of a conflict between this DPA and the MSA with respect to the subject matter of this DPA, this DPA controls.
1. Definitions
For purposes of this DPA, the following terms have the meanings set out below. Terms used but not defined here (including "Sell," "Share," "Business," "Business Purpose," and "Service Provider") have the meanings given to them under Applicable Data Protection Law.
- Applicable Data Protection Law means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, as applicable: (a) Regulation (EU) 2016/679 (the "GDPR"); (b) the GDPR as incorporated into the law of the United Kingdom by the Data Protection Act 2018 and the European Union (Withdrawal) Act 2018 (the "UK GDPR"); and (c) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act ("CCPA/CPRA"), together with their implementing regulations.
- Controller means the entity that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. Under CCPA/CPRA, "Controller" corresponds to "Business."
- Processor means the entity that Processes Personal Data on behalf of the Controller. Under CCPA/CPRA, "Processor" corresponds to "Service Provider."
- Personal Data means any information relating to an identified or identifiable natural person that is Processed by CreateBase on behalf of Customer under the MSA, and includes "personal information" as defined under CCPA/CPRA.
- Processing (and "Process") means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, use, disclosure, and erasure.
- Data Subject means the identified or identifiable natural person to whom Personal Data relates (a "consumer" under CCPA/CPRA).
- Subprocessor means any third party engaged by CreateBase to Process Personal Data on its behalf in connection with the Services.
2. Roles & Scope
The parties acknowledge and agree that the allocation of roles depends on the category of Personal Data:
- Customer is the Controller, and CreateBase is the Processor, of Personal Data contained in User Content — for example, the names, contact details, payee information, and other personal details of co-writers, counterparties, payees, royalty recipients, and other third parties appearing in the royalty statements, contracts, splits, ownership metadata, and other materials Customer or its Authorized Users upload to or paste into the Platform. CreateBase Processes such Personal Data only on behalf of, and on the documented instructions of, Customer.
- CreateBase is the Controller of account data and usage data — for example, the registration, authentication, billing, support, security-log, and product-telemetry data that CreateBase collects to operate, secure, bill for, and improve the Services. CreateBase Processes such data as a Controller in accordance with its Privacy Policy, and that data is outside the scope of CreateBase's Processor obligations under this DPA.
The subject matter, duration, nature and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are described in Annex I.
3. Processing Instructions
CreateBase shall Process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by applicable law to which CreateBase is subject; in such a case, CreateBase shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest. The MSA, this DPA, the applicable Order Form, and Customer's configuration and use of the Services constitute Customer's complete and final documented instructions to CreateBase for the Processing of Personal Data. CreateBase shall Process Personal Data solely to provide and support the Services and shall promptly inform Customer if, in CreateBase's opinion, an instruction infringes Applicable Data Protection Law.
4. Confidentiality of Personnel
CreateBase shall ensure that persons authorized to Process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access to Personal Data is limited to personnel who require access to perform CreateBase's obligations under the MSA. CreateBase shall ensure such persons receive appropriate training on their data-protection responsibilities.
5. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of natural persons, CreateBase shall implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk. Those measures are described in Annex II and summarized in our Security Overview. CreateBase may update its security measures from time to time provided that such updates do not materially decrease the overall level of protection of Personal Data.
6. Subprocessors
Customer provides a general authorization for CreateBase to engage Subprocessors to Process Personal Data in connection with the Services. CreateBase shall: (a) enter into a written agreement with each Subprocessor imposing data-protection obligations no less protective than those in this DPA, to the extent applicable to the nature of the Subprocessor's services; and (b) remain responsible for each Subprocessor's performance of its data-protection obligations. A current list of Subprocessors is available on our Subprocessor list. CreateBase shall provide notice of any intended addition or replacement of a Subprocessor (for example, through the Subprocessor list or by email) with a reasonable opportunity for Customer to object on reasonable data-protection grounds before the new Subprocessor begins Processing Personal Data.
7. Data Subject Requests
Taking into account the nature of the Processing, CreateBase shall provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). If CreateBase receives a request from a Data Subject relating to Personal Data Processed on Customer's behalf, CreateBase shall promptly notify Customer and shall not respond to the request itself except on Customer's documented instructions or as required by applicable law.
8. Personal Data Breach
CreateBase shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on Customer's behalf. Such notification shall, to the extent then known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. CreateBase shall take reasonable steps to mitigate and remediate the breach and shall cooperate with Customer's reasonable requests in connection with the breach.
9. Return & Deletion on Termination
Upon expiration or termination of the Services, and at Customer's election, CreateBase shall return to Customer or delete the Personal Data Processed on Customer's behalf, and delete existing copies, unless retention is required by applicable law. CreateBase may retain Personal Data to the extent and for the period required by applicable law, provided that CreateBase shall continue to protect such Personal Data in accordance with this DPA and Process it only as necessary for the purpose specified by that law.
10. Audits & Information
CreateBase shall make available to Customer information reasonably necessary to demonstrate compliance with its obligations under this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. To minimize disruption, Customer shall first accept CreateBase's then-current third-party certifications, audit reports (such as SOC 2), and security documentation in satisfaction of an audit request. Any on-site audit shall be conducted no more than once per twelve (12) months (except where required by a supervisory authority or following a Personal Data Breach), during regular business hours, subject to reasonable confidentiality and security controls, and upon reasonable prior written notice.
11. International Transfers
To the extent the Processing of Personal Data under this DPA involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not benefit from an adequacy decision, the parties agree to the following transfer mechanisms, which are incorporated into this DPA by reference:
- EU Standard Contractual Clauses. The standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated by reference and apply to transfers subject to the GDPR. Module Two (controller-to-processor) applies where Customer is a Controller and CreateBase is a Processor, and Module Three (processor-to-processor) applies where Customer is itself a Processor acting on behalf of a third-party controller, in each case as applicable to the relevant transfer.
- UK International Data Transfer Addendum. For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (the "UK Addendum") is incorporated by reference and amends the EU SCCs as set out therein.
- Switzerland. For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the adjustments necessary to address Swiss-law requirements (including references to the Swiss Federal Data Protection and Information Commissioner and to Swiss law).
Where the EU SCCs apply, the parties agree that: the optional docking clause applies; the governing law and forum for disputes are as specified in the SCCs and, where the SCCs permit a choice, the law of the Republic of Ireland; Annex I and Annex II to this DPA supply the information required by the SCCs; and the relevant Annex III is the Subprocessor list referenced in Annex III below. In the event of a conflict between the SCCs and this DPA, the SCCs prevail with respect to transfers they govern.
12. CCPA/CPRA Service-Provider Terms
To the extent CreateBase Processes Personal Data that constitutes "personal information" subject to CCPA/CPRA on Customer's behalf, CreateBase acts as a "Service Provider." CreateBase shall:
- not Sell or Share such Personal Data within the meaning of CCPA/CPRA;
- not retain, use, or disclose such Personal Data for any purpose other than the specific business purpose of providing the Services, or as otherwise permitted by CCPA/CPRA, including not retaining, using, or disclosing it outside the direct business relationship between the parties;
- not combine such Personal Data with personal information received from, or on behalf of, another person, or collected from CreateBase's own interactions, except as permitted by CCPA/CPRA; and
- comply with the applicable obligations of a Service Provider under CCPA/CPRA and provide the same level of privacy protection required of a Business.
Customer may take reasonable and appropriate steps to help ensure CreateBase uses such Personal Data consistent with Customer's obligations under CCPA/CPRA, and to stop and remediate unauthorized use, in accordance with Sections 5 and 10. CreateBase shall notify Customer if it determines it can no longer meet its obligations under CCPA/CPRA.
13. No-Training Commitment for Personal Data in User Content
CreateBase shall not, and shall ensure that its AI Subprocessors do not, use Personal Data contained in User Content to train, fine-tune, or otherwise develop or improve any general-purpose or foundation machine-learning models. Personal Data in User Content is Processed solely to provide the Services and generate Outputs for Customer. This commitment is in addition to, and does not limit, the AI-specific commitments set out in CreateBase's AI Terms.
14. General
This DPA is governed by the law and subject to the jurisdiction specified in the MSA, except where Applicable Data Protection Law or the SCCs require otherwise. Each party's and its affiliates' aggregate liability arising out of or related to this DPA, whether in contract, tort, or any other theory of liability, is subject to the limitations and exclusions of liability set out in the MSA, and any reference in the MSA to a party's liability includes its liability under this DPA. In the event of any conflict, the order of precedence is: (1) the SCCs (for transfers they govern); (2) this DPA; and (3) the remainder of the MSA. Except as amended by this DPA, the MSA remains in full force and effect.
15. Annex I — Parties & Description of Processing
A. Parties
Data exporter / Controller: The Customer identified in the applicable Order Form, acting as Controller (or, where applicable, as a Processor on behalf of a third-party controller) of Personal Data contained in User Content. Contact details are as set out in the Order Form.
Data importer / Processor: The Cur8 Group Corp., 13223 Black Mountain Rd, Ste 1189, San Diego, CA 92129, USA, acting as Processor. Contact: legal@createbase.com.
B. Categories of Data Subjects
- Customer's Authorized Users and personnel who access the Services;
- Co-writers, songwriters, composers, performers, and other contributors named in User Content;
- Counterparties, rights-holders, and other parties to agreements appearing in User Content;
- Payees and royalty recipients identified in royalty statements, splits, and ownership metadata.
C. Categories of Personal Data
- Identification and contact data (such as names, email addresses, postal addresses, telephone numbers);
- Professional and creative-credit data (such as writer/performer credits, roles, and affiliations);
- Financial and payee data contained in royalty statements, splits, and ownership metadata (such as ownership percentages, payee identifiers, and payment-direction details); and
- Any other Personal Data that Customer or its Authorized Users choose to include in User Content. The parties do not intend for special categories of data to be Processed under this DPA.
D. Nature & Purpose of Processing
Processing is carried out to provide the Services, namely: hosting and storing User Content; performing automated rights checks and AI-assisted analysis to generate Diligence Outputs and Valuations; and, where applicable, supporting royalty administration. The nature of the Processing includes collection, storage, organization, analysis, retrieval, transmission to Subprocessors strictly as needed to provide the Services, and deletion.
E. Duration of Processing
CreateBase Processes Personal Data for the duration of the MSA and thereafter only as described in Section 9 (Return & Deletion) and as required by applicable law.
16. Annex II — Technical & Organizational Measures
CreateBase maintains the following technical and organizational measures, as further described in our Security Overview:
- Encryption. Encryption of Personal Data in transit (TLS) and at rest.
- Access control. Role-based access controls, least-privilege access, unique credentials, and multi-factor authentication for administrative access.
- Confidentiality, integrity, availability, and resilience. Measures designed to ensure the ongoing confidentiality, integrity, availability, and resilience of Processing systems and services.
- Backup and recovery. Regular backups and the ability to restore availability and access to Personal Data in a timely manner following an incident.
- Logging and monitoring. Security logging, monitoring, and alerting across production systems.
- Testing and review. Processes for regularly testing, assessing, and evaluating the effectiveness of the measures, including vulnerability management and periodic penetration testing.
- Vendor management. Security review of Subprocessors and contractual data-protection commitments as described in Section 6.
- Personnel. Confidentiality obligations and security and privacy training for personnel with access to Personal Data.
17. Annex III — Authorized Subprocessors
The authorized Subprocessors for the Services, including AI model providers (OpenAI, Anthropic), hosting providers (AWS, Vercel, Netlify), database and authentication (Supabase), payments (Stripe), and identity verification (Persona), are listed and kept current on our Subprocessor list, which is incorporated into this DPA by reference and constitutes Annex III to the SCCs where applicable.
Questions about this DPA may be directed to legal@createbase.com.