Last updated: 28 July 2026
Document version: 1.0
ShowTiming
ShowTiming DPA — B2B. Version 1.0 — Effective date: 28 July 2026. Complements the Terms of Use and Terms of Sale when ShowTiming processes personal data on a Customer’s behalf.
Last updated: 28 July 2026
Document version: 1.0
This agreement is between: the Customer, a professional natural or legal person who has subscribed to or uses the ShowTiming Service in their professional activity (the “Controller” or “Customer”); and Lucas Ait Madi — sole trader, trade name ShowTiming, 91 rue d’Étion, 08000 Charleville-Mézières, France, SIREN 915 300 289, email hello@show-timing.com (the “Processor” or “ShowTiming”).
This DPA sets the conditions under which ShowTiming processes, on the Customer’s behalf, personal data that the Customer or its users enter into the Service.
Processing by a processor on behalf of a controller must be governed by a contract meeting Article 28 GDPR.
This DPA complements the ShowTiming Terms of Use and Terms of Sale.
If there is a conflict about protection of personal data the Customer entrusts to ShowTiming, this DPA prevails over the Terms of Use and Terms of Sale.
This DPA does not govern processing where ShowTiming acts as controller, including: Account creation and management; authentication; licenses, subscriptions and payments; billing; customer relations and support; Service security; ShowTiming’s own legal obligations; and audience measurement subject to consent where applicable.
Those processing activities are described in the ShowTiming Privacy Policy: https://show-timing.com/en/privacy.
ShowTiming processes personal data only: to provide, maintain, secure and support the Service; on the Customer’s documented instructions; within the Terms of Use, Terms of Sale, this DPA and features actually used; or to comply with a legal obligation applicable to ShowTiming, in which case ShowTiming informs the Customer before processing unless legally prohibited.
The Terms of Use, Terms of Sale, this DPA, actions the Customer takes in the interface, and the Customer’s written support requests constitute the Customer’s documented instructions.
The Customer must not give instructions contrary to the GDPR, other applicable law or data-subject rights.
If ShowTiming considers an instruction to violate applicable data-protection law, it informs the Customer without undue delay, unless legally prohibited.
The processing entrusted to ShowTiming is described in Annex 1.
Primarily, the Service may let the Customer create and store Events, segments, rundowns, cue messages, Stage or Broadcast displays and related information. Those elements may contain personal data when they identify a person directly or indirectly.
As controller, the Customer undertakes to: determine the essential purposes and means of processing; ensure a valid legal basis for each processing; inform data subjects as required; respect minimisation, accuracy, storage limitation and security; entrust ShowTiming only with data strictly needed to use the Service; not enter special-category data (health, biometrics, political opinions, religious beliefs, sex life, sexual orientation or criminal data) without ShowTiming’s prior written agreement and adapted safeguards; respond to data-subject rights requests; ensure lawfulness of content, text, names, messages and information shown via Stage or Broadcast; ensure Stage and Broadcast links are shared only with authorised persons; and clearly inform its own users, performers, employees, contractors or participants when their data is processed in the Service.
The Customer alone remains responsible for the lawfulness, accuracy, updating, disclosure and deletion of data it enters.
ShowTiming ensures authorised persons who process personal data: are under a statutory or contractual confidentiality duty; access data only as needed for their tasks; and receive instructions suited to personal-data protection.
Administrative access is limited to persons authorised by ShowTiming, notably for maintenance, security, support or incident handling.
ShowTiming reviews Customer Event content only when needed for support, incident resolution, Service security, a legal obligation or at the Customer’s request.
ShowTiming implements appropriate technical and organisational measures given the nature of the Service, the state of the art, implementation costs, the nature, scope, context and purposes of processing, and risks to data subjects.
Measures include, depending on features and systems: Account-holder authentication; access rights management; administrative access control; identified hosting infrastructure; logging of certain security events; backups with a maximum rolling retention of thirty-five (35) days; Stage and Broadcast link revocation or regeneration when available; logical separation of environments and access as needed; and security measures of technical sub-processors used.
The Customer acknowledges security also depends on its own measures, including protection of credentials, devices, browsers, networks, Access Links and operational procedures.
The Customer authorises ShowTiming to use the sub-processors listed in Annex 2, within their respective roles.
As of the effective date, potential sub-processors include: OVH SAS (VPS hosting, France); Supabase (auth, database, realtime — Paris region); Brevo (transactional email — France / European Union (per Brevo DPA in force)); Stripe (payment, billing, licenses and customer portal — Ireland (Stripe Payments Europe) and sub-processors per Stripe DPA; transfers outside the EEA subject to SCCs or other admitted mechanisms); PostHog (product analytics, only after consent when required — declared EU environment).
ShowTiming may replace or add a sub-processor when needed to provide, maintain, secure or improve the Service.
Except for a security emergency, legal obligation or no impact on Customer-entrusted data, ShowTiming informs the Customer of any material addition or replacement by a reasonable means, including email, in-Account notice or updating Annex 2.
The Customer may raise a reasoned objection related to data protection within fifteen (15) days after notice. The parties will then seek a reasonable solution. Failing that, the Customer may terminate the affected feature or the contract, without penalty for the unused period directly affected, subject to amounts already due.
ShowTiming ensures its sub-processors are bound by data-protection obligations substantially equivalent to this DPA.
The current sub-processor list is published in Annex 2 of this DPA: https://show-timing.com/en/dpa.
ShowTiming prefers providers and infrastructure in the EU or EEA.
If a transfer of personal data to a country outside the EEA is necessary, ShowTiming ensures it relies on a valid transfer mechanism, including: an adequacy decision; European Commission standard contractual clauses; or any other mechanism recognised under applicable law.
The Customer authorises transfers needed to perform the Service when appropriate safeguards apply.
Information on potential sub-processor transfers should be checked in their DPAs, privacy policies and up-to-date sub-processor lists. Periodic provider document review remains recommended.
Given the nature of processing, ShowTiming assists the Customer, as reasonably possible, so the Customer can respond to data-subject rights requests.
If a data subject contacts ShowTiming directly about data for which the Customer is controller, ShowTiming: forwards the request to the Customer without undue delay unless legally prohibited; does not respond on the merits without the Customer’s instruction unless legally required; and may provide reasonable technical assistance based on available features.
The Customer remains responsible for responding to the data subject within applicable legal timelines.
As reasonably and proportionately possible, ShowTiming provides the Customer with information needed to help meet GDPR obligations, including: processing security; personal-data breach handling; data protection impact assessments (DPIA) when required; and prior consultation of a supervisory authority.
Assistance takes into account the nature of the Service and information available to ShowTiming.
Assistance requests beyond standard support or requiring specific work may be billed separately, subject to the Customer’s prior written agreement.
ShowTiming informs the Customer without undue delay after becoming aware of a personal-data breach affecting data processed on the Customer’s behalf.
The notice includes, where information is available: the nature of the breach; categories and, if possible, approximate number of data subjects; categories and, if possible, approximate number of records concerned; likely consequences; measures taken or proposed to address the breach or mitigate effects; and useful contact details for further information.
As controller, the Customer remains responsible for deciding whether to notify the CNIL and, where applicable, data subjects.
ShowTiming makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA.
The Customer may request security or compliance information in writing at hello@show-timing.com.
An on-site audit may be requested only for a serious, documented and risk-proportionate reason, notably a significant security incident affecting the Customer’s data or a mandatory legal requirement.
Any audit: is at the Customer’s expense unless ShowTiming’s breach is demonstrated; requires at least thirty (30) business days’ prior written notice; is limited to once per twelve (12) months except for a significant incident; takes place during business hours; must not disrupt the Service, compromise its security or disclose other customers’ confidential information; and may be replaced by reasonably sufficient documents, questionnaires, attestations or compliance materials.
Audit modalities must remain proportionate to risk and to the actual means of the sole trader publishing ShowTiming.
On cessation of the Service or Account closure, ShowTiming deletes or anonymises personal data processed on the Customer’s behalf within thirty (30) days.
Data may remain temporarily in backups for at most thirty-five (35) days, without reuse in normal Service operation.
ShowTiming may retain data required for a legal obligation, contractual proof, a dispute or defense of its rights. In that case data are isolated as reasonably possible and not processed for other purposes.
Before closing the Account, the Customer must retrieve data it wishes to keep when an export feature is available. As of this version, no complete self-service export is guaranteed.
Each party’s liability under this DPA is governed by the Terms of Use and Terms of Sale, subject to mandatory personal-data protection rules.
Nothing in this DPA limits data-subject rights or the powers of competent authorities.
This DPA takes effect upon acceptance of the Terms of Use and Terms of Sale or upon the Customer’s use of the Service.
It remains applicable for as long as ShowTiming processes personal data on the Customer’s behalf, including the limited technical retention periods in Article 14.
For questions about this DPA or personal-data protection: ShowTiming — Lucas Ait Madi, sole trader. Email: hello@show-timing.com. Address: 91 rue d’Étion, 08000 Charleville-Mézières, France.
Subject matter: providing the ShowTiming Service, including creating, storing, syncing and displaying live-event rundowns.
Duration: contract term, then thirty (30) days after Account closure; backups up to thirty-five (35) days maximum.
Nature of operations: hosting, storage, consultation, display, synchronisation, transmission, backup, deletion or anonymisation.
Purpose: enable the Customer to manage timing, segments, messages and displays for its Events.
Data subjects: performers, artists, technicians, employees, contractors, Customer contacts, participants or any person whose data the Customer enters.
Data categories: names, roles, titles, cue messages, schedules, organisation information, text or other data entered by the Customer.
Special-category data: not intended and prohibited without prior written agreement and adapted safeguards.
Authorised persons: ShowTiming authorised staff and admins on a need-to-know basis; necessary sub-processors.
OVH SAS — application VPS hosting; technical and application data per effective architecture; location: France.
Supabase — database, authentication and realtime; Account and Event data; location: Paris region.
Brevo — transactional email; email address, transactional content and data needed to send; location: France / European Union (per Brevo DPA in force). Event content (rundowns, cue messages) is not sent to Brevo unless the Customer voluntarily includes it in an email.
Stripe — payments, subscriptions and billing; billing data, email and payment status; no full card data at ShowTiming; location: Ireland (Stripe Payments Europe) and sub-processors per Stripe DPA; transfers outside the EEA subject to SCCs or other admitted mechanisms. Stripe does not receive Stage/Broadcast Event content.
PostHog — usage analytics after consent; pseudonymised usage data (pages, product events, funnels). PostHog must not receive Event content, cue messages or personal data unnecessary for analytics; location: declared EU environment.
Current list: https://show-timing.com/en/dpa. Periodic review of provider DPAs is recommended.