Data Processing Agreement

This data processing agreement (“DPA”) is made in the Effective Date (as established in the MSA)

by and between:

(1) Qlero AB, a company limited by shares incorporated in Sweden under company registration number 559496-7654 (“Qlero”), with address c/o CC Young & Co Sverige AB, Box 271, 581 02 Linköping, Sweden;

and

(2) Customer, as defined in MSA (hereinafter referred to as the “Customer”),

each a "Party" and together the "Parties"

BACKGROUND AND SCOPE

(1) This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer and Qlero (“Provider”) as referenced in the applicable Order Form entered into between the parties. This DPA governs the processing of Personal Data by Qlero on behalf of the Customer in connection with the Services provided under the Master Services Agreement (“MSA”).

(2) This DPA applies where and to the extent that Qlero processes Personal Data on behalf of the Customer in the course of providing the Services under the MSA. For the purposes of this DPA, the Customer acts as a Data Controller or as a Processor acting on behalf of a Data Controller, and Qlero acts as a Data Processor.

(3) The Customer determines the purposes and means of the processing of Personal Data carried out by Qlero under the Services and provides the relevant instructions for such processing. Qlero shall process Personal Data only on documented instructions from the Customer and in accordance with this DPA and the MSA.

(4) This DPA governs all processing of Personal Data carried out by Qlero on behalf of the Customer and, where applicable, its Affiliates in connection with the Services. The parties intend this DPA to ensure that such processing complies with applicable Data Protection Legislation, including Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”).

(5) If the documents conflict: (a) the DPA prevails for processing or protection of Personal Data; (b) the Order Form prevails for commercial terms, including pricing, billing, Subscription Term, Usage Limits and service scope; and (c) the MSA prevails otherwise.

(6) This DPA applies to Personal Data processed by Qlero as a Data Processor on behalf of the Customer in connection with Customer Data submitted to or otherwise processed through the Customer’s use of the Platform, including Personal Data entered by the Customer or its Users.

(7) Qlero also processes certain Personal Data as an independent Data Controller, including Personal Data relating to user account administration, authentication, security monitoring, service analytics, support communications, and billing. Such processing is governed by Qlero’s Privacy Policy and does not form part of the processing activities regulated by this DPA.

1. Definitions

1.1. In addition to the concepts defined in the terms for the MSA, these definitions shall, regardless of whether they are used in the plural or singular, in definite or indefinite form, have the following meaning when entered with capital letters as the initial letter.

Affiliate(s): Has the meaning given in the MSA. This DPA may cover Personal Data submitted by the Customer on behalf of its Affiliates, but does not grant any Affiliate a right to access or use the Services.

Customer: Means the Customer identified in the applicable Order Form, acting as Controller or, where applicable, as Processor on behalf of another Controller.

Data Breach: Has the meaning as per Article 4 (12) GDPR.

Data Protection Legislation: Refers to all applicable privacy and personal data protection legislation, along with any other legislation (including regulations and directives) applicable to the Processing carried out in accordance with the MSA and the Service Orders, including EU legislation, such as the General Data Protection Regulation (“GDPR”).

Data Subject: The identified or identifiable natural person to whom Personal Data relates, as per Articles 4 and 4 (1) GDPR.

DPA: Means this Data Processing Agreement as per the GDPR and the meaning in Article 28 GDPR.

DPIA: Data Protection Impact Assessment (DPIA), defined under Article 35 of the GDPR, consists of a process that assesses the impact of specific data processing activities on the privacy of individuals required for processing that poses a high risk to individual rights and freedoms.

GDPR: Means the General Data Protection Regulation, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data and repealing Directive 95/46/EC.

Instruction(s): It consists of the documented instructions provided by the Customer to Qlero, as defined by the GDPR (Art. 28.3), that, among other aspects, defines the object, duration, type, and purpose of the Personal Data processing, as well as the categories of Data Subjects and special requirements that apply to the Processing.

MSA: Stands for the Master Services Agreement, the overarching contract under which Qlero provides Services to the Customer, processes data on behalf the Customer (as governed by this DPA) outlining the terms and conditions that govern their business relationship.

Personal Data: Has the meaning as per Article 4 (1) GDPR.

Processing: Has the meaning as per Article 4 (2) GDPR.

Processor: This term has the meaning as per Article 4 (8) GDPR. Under this DPA, it refers to Qlero AB and its subsidiaries; but it can also refer to the Customer in case it is acting as a Processor on behalf of a Controller.

Pseudonymization / Pseudonymized: The processing of Personal Data in a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, as long as such additional information is kept separately, as defined in Article 4(5) of the GDPR.

Services: Refer to the operations, functions, or tasks provided by Qlero to the Customer under the MSA, either paid or free of charge

Sub-processor: A processor, upon being engaged by the primary Processor and authorized by the Controller, undertakes specific processing tasks on their behalf. This role is typically filled by a third-party service provider. In the context of this DPA, the term is exclusively applicable to Qlero’s Sub-processors. Nonetheless, it should be highlighted that Qlero may also serve as a Sub-processor, particularly when the Customer acts as a Processor for a Controller.

Third Country: Any country outside the EU/EEA that does not have an adequacy decision by the European Commission under the GDPR.

Third Party: Any natural or legal person, public authority, agency, or body other than the Data Subject, Controller, Processor, and persons who, under the direct authority of the Customer or Qlero, are authorized to process Personal Data.

1.2. Terms and expressions not defined in this DPA shall have the same meaning as in the GDPR unless otherwise clearly stated in the DPA or the context obviously requires otherwise.

2. Processing of personal data and purpose

2.1. This DPA and its Instructions govern Qlero’s processing of Personal Data on behalf of the Customer or its Affiliates. These documents form part of the broader framework established by the MSA and aim to protect the freedoms and rights of the Data Subjects in accordance with Article 28(3) of the GDPR.

2.2. The Customer authorizes Qlero to conduct Personal Data processing activities strictly in accordance with the written Instructions outlined in this DPA. Qlero is permitted to process Personal Data only for purposes explicitly defined under the MSA and the signed Service Orders within the scope of the current DPA Instructions. Any processing outside of these parameters requires prior express approval from the Customer.

2.3. Each Party is responsible for complying with the applicable Data Protection Legislation in connection with its role and responsibilities towards its processing of Personal Data.

2.4. This DPA, along with its Instructions and the list of potential Sub-processors, regulates Qlero's processing of Personal Data on behalf of the Customer. These documents are integral components of the broader MSA framework and are designed to safeguard the freedoms and rights of Data Subjects as stipulated by Article 28(3) of the GDPR.

2.5. The Customer hereby authorizes Qlero to process Personal Data strictly according to the written Instructions provided in this DPA, which is part of the MSA. Qlero is allowed to process Personal Data solely for the purposes explicitly defined in this DPA, the MSA and only within the limits of the current DPA Instructions. Processing beyond these boundaries and instructions is not allowed as it requires the Customer's prior approval.

2.6. Each Party is responsible for adhering to applicable Data Protection Legislation relative to its respective roles and responsibilities in processing Personal Data.

3. Obligations of the Customer

3.1. The Customer undertakes to ensure that there is a legal basis for the Processing at all times and for establishing adequate Instructions with regard to the nature of the Processing so that Qlero and any Sub-processor can fulfill their tasks according to this DPA and the MSA, as well as any signed Service Orders.

3.2. The Customer shall, without unnecessary delay, inform Qlero of changes in the Processing that affect Qlero's obligations pursuant to this DPA and/or the applicable Data Protection Legislation.

3.3. The Customer is responsible for informing Data Subjects, as necessary or required, about the Processing and protecting the rights of Data Subjects, pursuant to the applicable Data Protection Legislation, as well as taking any other action incumbent on the Customer according to Data Protection Legislation.

4. Obligations of Qlero

4.1. Qlero undertakes to Process the Personal Data under the MSA strictly in accordance with this DPA, the MSA along with its Service Orders, the specified Instructions, and the applicable Data Protection Legislation, remaining continuously informed throughout the duration of this DPA.

4.2. Qlero shall implement measures to protect Personal Data from any processing activities incompatible with this DPA, the MSA, the Instructions, and the applicable Data Protection Legislation. This includes limiting access to Personal Data to those individuals or organizations who require it to perform the Services and ensuring all Qlero’s employees and collaborators are bound by confidentiality and privacy obligations, either contractual or statutory.

4.3. If the Processing Instructions are unclear, contravene the applicable Data Protection Legislation, or are inadequate, Qlero must immediately inform the Customer. When necessary, and with the Customer's approval, Qlero will suspend processing until revised Instructions are received unless the Customer directs otherwise. Should the Customer amend the Instructions, Qlero will promptly communicate any related cost implications, if applicable. Additionally, Qlero may propose changes if the Instructions conflict with GDPR or any other applicable Data Protection Legislation; in this case, the Customer will be responsible for reviewing and collaboratively confirming the necessary amendments with Qlero.

4.4. Qlero will assist the Customer in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Qlero.

4.5. Qlero will promptly inform the Customer of any complaints, notices, or communications related to processing Personal Data and provide necessary cooperation and assistance as outlined in this DPA. This includes assisting the Customer with the relevant Data Breach notifications, in the relevant DPIA, assessments or other types of relevant assessments required to the Customer, and, when necessary, consulting supervisory authorities in case of high-risk processing activities.

4.6. In the event of a Data Breach affecting the Personal Data processed on behalf of the Customer under this DPA, Qlero must promptly notify the Customer and assist with any resulting obligations as specified under applicable Data Protection Legislation and this DPA.

5. Security measures

5.1. Qlero shall implement and maintain all measures required pursuant to Article 32 of the GDPR, as detailed in the Instructions of this DPA, to ensure a level of security appropriate to the risk. These measures include, but are not limited to:

(i) Pseudonymization and encryption of Personal Data;

(ii) Ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

(iii) Restoring the availability and access to Personal Data in a timely manner after a physical or technical incident;

(iv) Regularly testing, assessing, and evaluating the effectiveness of all technical and organizational security measures.

5.2. Qlero shall continuously ensure that there are technical and organizational measures in place in order to maintain the required confidentiality, integrity, availability, and resilience. This includes regular verification and updates as necessary to meet the requirements of this DPA and any new security requirements or Instructions specified by the Customer after the signing of this DPA.

5.3. Any added or revised security requirements from the Customer post-signature of this DPA will be treated as new Instructions, requiring prompt evaluation and implementation by Qlero to ensure continued compliance with the GDPR and Data Protection Legislation.

5.4. Access or processing to Personal Data under this DPA and MSA shall be strictly limited to relevant individuals and/or organizations, governed by robust authorization control systems. Qlero commits to continuously logging access to Personal Data as required by this DPA and the MSA, in accordance with the Instructions provided.

6. Secrecy/duty of confidentiality

6.1. Qlero and all individuals or organizations working under its management must maintain confidentiality and professional secrecy throughout the Processing. This includes binding confidentiality obligations, either through specific agreements or existing legally sanctioned duties of confidentiality.

6.2. Qlero shall promptly inform the Customer of any interactions with supervisory authorities concerning the Processing of Personal Data under this DPA.

6.3. If a Data Subject, supervisory authority, or third-party requests information about the Processing, Qlero must notify the Customer and refrain from disclosing any information without the Customer’s written consent, unless otherwise required by law.

7. Information, Audits and inspections

7.1. Upon the Customer's written request, Qlero shall provide all necessary information to demonstrate compliance with the data protection obligations outlined in this DPA. This includes facilitating audits and inspections by the Customer or an independent third party, as specified under Article 28(1) of the GDPR. Qlero will assist by providing documentation, access to facilities, and technical systems necessary for reviewing compliance with this DPA, the Instructions, and the GDPR. All involved individuals must adhere to confidentiality obligations as required by law or contractual duty.

7.2. The Customer's audit requests must include reasonable notice and be preceded by a clearly defined audit plan detailing the scope and objectives, agreed upon by both Parties. Alternative verification methods, such as evaluations or audits by independent third parties, would also be considered.

7.3. Qlero will facilitate supervision by supervisory authorities or other legal authorities when required, notifying the Customer as appropriate and providing the necessary means for these authorities to carry out their supervisory roles according to applicable laws, even if such actions conflict with other provisions of this Agreement.

7.4. Qlero must ensure that any Sub-processors give the Customer similar audit and inspection rights as those agreed between the Customer and Qlero, to the extent feasible in light of the circumstances and the function performed by the Sub-processor.

8. Handling of Data Subjects’ rights

8.1. Upon the Customer's instructions, Qlero shall promptly (without undue delay) take necessary actions to correct or delete Personal Data if the processing is found to be inaccurate or to comply with Data Subjects' rights requests under the GDPR. For deletion requests, Qlero is permitted to continue processing the Personal Data solely as part of the deletion process and as required by applicable laws.

8.2. If Qlero receives a request from a Data Subject relating to their rights under the GDPR, and the request pertains to Personal Data processed under the Services, Qlero will promptly notify the Customer. Qlero will inform the Data Subject that their request has been forwarded to the Customer and will not undertake any direct actions to address the request, ensuring that all responses are managed by the Customer.

8.3. Qlero will assist the Customer in fulfilling Data Subjects' rights requests by providing appropriate technical and organizational support, as far as this is feasible, considering the nature of the Processing.

9. Personal Data Breaches

9.1. Qlero shall notify the Customer without undue delay upon becoming aware of a Data Breach affecting Personal Data under this DPA. Qlero will provide the Customer with all necessary information to meet any obligations to report the Authorities or inform Data Subjects of the Data Breach under the GDPR. This information shall include:

(i) The nature of the Personal Data and if possible, the categories and the number of Data Subjects affected, as well as the categories and number of Personal Data categories affected.

(ii) The probable consequences of the Data Breach.

(iii) Measures that have been taken or planned, as well as measures to mitigate the potential negative effect of the Data Breach.

9.2. If Qlero is unable to supply the entire description at once, it may supply it in stages without additional unnecessary delay.

9.3. If any physical or technical incident compromises the accessibility or integrity of Personal Data, Qlero shall restore access and functionality to the affected data within a reasonable timeframe, as stipulated under Article 32.1.c of the GDPR.

10. Sub-processors

10.1. Qlero may engage Sub-processors to carry out specific processing activities on behalf of the Customer. Prior to engaging a Sub-processor, Qlero will ensure that the Sub-processor is capable of fulfilling its obligations under Data Protection Legislation, particularly the GDPR. Qlero is committed to maintaining an up-to-date list of Sub-processors available to the Customer at all times.

10.2. Qlero will inform the Customer in advance of any intended changes regarding the addition or replacement of Sub-processors, providing details such as the Sub-processor’s identity, the type of data processed, and the categories of affected data subjects. The Customer has fourteen (14) days from receipt of the notification to object to the engagement of the new Sub-processor based on reasonable data protection concerns.

10.3. Qlero is required to have a written agreement with every Sub-processor to impose the same data protection obligations on the Sub-processor as those imposed on Qlero under this DPA. Such agreement must also require appropriate technical and organizational measures to be taken to ensure the protection of the Personal Data that is processed.

10.4. Qlero remains fully responsible for any acts or omissions of its Sub-processors and will ensure that all Sub-processors agree to obligations consistent with the provisions of this DPA. Upon terminating the use of a Sub-processor, Qlero will ensure that the Sub-processor either returns or destroys all Personal Data in accordance with this DPA requirements and/or any instructions provided by the Customer.

10.5. Qlero will promptly inform the Customer of any significant issues arising from the Sub-processor’s failure to comply with their obligations related to Personal Data Processing.

10.6. The Customer grants general prior authorization for the Provider to engage sub-processors within the following functional categories. The Provider shall notify the Customer of any proposed change to its sub-processor arrangements, and the Customer may object on reasonable data protection grounds within fourteen (14) days of receiving such notice.

(i) Cloud infrastructure: Hosting of the Platform application, databases, and network traffic (e.g., AWS, Google Cloud, or equivalent hyperscale provider);
(ii) Database services: Storage and management of royalty accounting and application data;

(iii) Content delivery and security: CDN services, DNS management, and network security; and

(iv) Customer support tooling: Ticketing and communication systems for technical support delivery

10.7. Qlero shall ensure that the Customer can exercise its right to audit Sub-processors to the extent possible or instruct the Sub-processor to erase or return the Personal Data in specific circumstances, such as insolvency or if Qlero ceases operations.

11. Localization and transfer of Personal Data to a Third Country

11.1. Transfers of Personal Data must only occur under conditions that comply with the GDPR and other applicable Data Protection Legislation. This includes ensuring appropriate safeguards are in place and that all contractual obligations or legal mechanisms used to protect Personal Data during transfer meet or exceed the standards set forth in the GDPR.

11.2. Qlero agrees not to transfer any Personal Data outside the EU/EEA or jurisdictions recognized as adequate by the GDPR or the applicable Data Protection Legislation without confirming the presence of adequate protections and safeguards as required by Data Protection Legislation. Furthermore, no Personal Data shall be transferred outside the EU/EEA without implementation of Standard Contractual Clauses (SCC) or equivalent safeguards in accordance with GDPR requirements.

12. Indemnity and limitation of liability

12.1. Each Party shall bear any fines imposed on them pursuant to Article 83 of the GDPR or under any other applicable Data Protection Legislation. The responsibility for the fines will fall on the Party named explicitly as the recipient of such sanctions.

12.2. In the event of a compensation claim related to data processing that may affect both Parties, the Party receiving the claim must promptly notify the other Party, providing full details and relevant documentation. Both Parties shall cooperate to prevent or minimize potential damage or loss resulting from such a claim.

12.3. Liability for damages caused by processing that infringes the GDPR or any applicable Data Protection Legislation shall be assigned to the Party responsible for the damage or infringement.

12.4. A Party shall be exempt from liability if they can demonstrate that they were not responsible in any way for the event giving rise to the damage.

12.5. Compensation for damages to a Data Subject resulting from a breach of this DPA or the applicable Data Protection Legislation shall be governed by Article 82 of the GDPR.

12.6. If either Party becomes aware of circumstances potentially detrimental to the other Party, it shall promptly notify the other Party and cooperate to mitigate the damage or loss. Liability between the Parties arising under or in connection with this DPA is subject to Clause 14 of the MSA, except to the extent such limitation is prohibited by applicable law.

13. Renegotiation, Term, and Termination

13.1. This DPA becomes effective when the applicable Order Form is signed and remains in force for as long as Qlero processes Personal Data under the MSA.

13.2. Each Party may request renegotiation of the DPA if the other Party's ownership changes significantly or if significant changes in applicable Data Protection Legislation or interpretation thereof affect the Processing materially. Renegotiation does not affect the DPA's efficacy unless agreed upon in writing by both Parties.

13.3. Provisions of this DPA that should survive termination, including, but not limited to, obligations regarding the handling of Personal Data, confidentiality, and Data Protection, shall continue in full force and effect post-termination.

14. Completion of Services

14.1. Upon termination of the Services, Qlero shall cease processing Personal Data on behalf of the Customer. If the Customer requests return of the Personal Data within thirty (30) days, Qlero shall provide it in a complete, commonly used and machine-readable format within thirty (30) days after the request. Qlero shall then securely delete the Personal Data, unless retention is required by law.

14.2. The obligations related to secrecy and the duty of confidentiality shall continue to apply even after the cessation of the MSA and the DPA.

15. Notifications within this DPA

15.1. All notifications related to this DPA, including termination or Data Breaches, must be communicated to the designated contact person of the other Party via email or another expressly agreed-upon method.

16. Contact

16.1. Each Party shall appoint a contact person for the administration of this DPA and for cooperation on data protection matters. Contact details shall be mutually exchanged and updated as necessary to facilitate communication.

16.2. If a change occurs in the contact person, the Party shall inform the counterparty immediately.

17. Governing law and disputes

17.1. This DPA is governed by Swedish law, without regard to choice-of-law rules.

17.2. Any dispute arising out of or relating to this DPA shall be resolved in accordance with Clause 20 (Dispute Resolution) of the MSA.

DPA Instructions (Appendix)

This Appendix forms part of the Customer’s written Instructions to Qlero as regards the Processing of Personal Data required for Qlero to provide the Services under the MSA.

Categories of Data Subjects

The processing of Personal Data concerns the following categories of Data Subjects:

  • Users authorized under the Customer’s account (e.g., employees, consultants, administrators)
  • Payees designated by the Customer (e.g., artists, songwriters, rights holders)
  • Representatives of the Customer’s business partners or counterparties, where relevant to royalty administration

Categories of Personal Data

The processing may include the following categories of Personal Data, as determined and submitted by the Customer:

  • Identification data (e.g., name, personal identity number, email address, contact details)
  • Professional or business information (e.g., company name, role)
  • Financial information (e.g., bank account details such as IBAN, VAT number where applicable)
  • Royalty Data, including contractual parameters, revenue allocations, royalty statements, and payment references
  • Technical usage data associated with user accounts (e.g., login activity, IP addresses, access logs)

Qlero does not intentionally process special categories of personal data (as defined in Article 9 GDPR) through the Platform.

Nature and purpose of the Processing

Personal Data is processed solely for the purpose of:

  • Providing the royalty management functionality of the Platform
  • Performing automated royalty calculations based on parameters defined by the Customer
  • Generating royalty statements and self-billing documentation
  • Enabling reporting, reconciliation and payment preparation workflows
  • Providing customer support and technical maintenance
  • Ensuring the security, integrity and availability of the Platform
  • Complying with applicable legal obligations

Qlero does not independently determine the purposes of the processing of Customer Data and processes such data strictly in accordance with the Customer’s documented instructions.

Duration of Processing

Qlero processes Personal Data for the duration of the Customer’s use of the Services and in accordance with the retention settings and instructions defined by the Customer, subject to applicable legal obligations.

The Customer retains control over the retention and deletion of Customer Data stored within the Platform.

Security measures

Qlero shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the nature, scope and purposes of the processing of Personal Data under this Agreement. Such measures include, inter alia:

Access control

Access to Personal Data is restricted to authorized personnel and Users based on role-based access controls (RBAC) and the principle of least privilege. Personnel with access to Personal Data are subject to confidentiality obligations.

Authentication and encryption

Secure authentication mechanisms are implemented for access to the Platform. Personal Data is protected by encryption in transit (e.g., TLS/HTTPS) and encryption at rest within databases and storage environments.

Infrastructure and environment segregation

The Platform is hosted on professionally managed cloud infrastructure environments. Production environments are segregated from staging and development environments to reduce risk exposure.

Logging and monitoring

System activity and access to Personal Data are logged to enable traceability and investigation of unauthorized access or abnormal activity. Access to logs is restricted to authorized personnel.

Network and system protection

Appropriate safeguards are implemented to protect against unauthorized access, malware and other security threats, including the use of firewall protections and security controls within the hosting environment.

Backup and resilience

Regular backup procedures are in place to support restoration of Personal Data in the event of an incident affecting availability. Backup data is appropriately protected.

Secure development and change management

Qlero applies structured development and change management practices designed to promote system stability and security, including testing prior to deployment.

Incident management and breach notification

Qlero maintains procedures to detect, investigate and respond to security incidents. In the event of a confirmed Data Breach affecting Personal Data processed on behalf of the Customer, Qlero shall notify the Customer without undue delay and provide reasonable cooperation to support the Customer’s compliance obligations.

Sub-processors

Qlero may engage sub-processors to provide hosting, infrastructure, authentication, analytics, and support services. Qlero shall ensure that any sub-processor is bound by data protection obligations equivalent to those set out in the Data Processing Agreement.

Data Breaches

Qlero has implemented procedures to detect, investigate and respond to Data Breaches. In the event of a Data Breach affecting Personal Data processed under this Agreement, Qlero shall notify the Customer without undue delay and provide information reasonably necessary for the Customer to comply with its legal obligations.

Deletion and return of Personal Data

Upon termination of the Services, Qlero shall cease processing Personal Data on behalf of the Customer. If the Customer requests return of the Personal Data within thirty (30) days, Qlero shall provide it in a complete, commonly used and machine-readable format within thirty (30) days after the request. Qlero shall then securely delete the Personal Data, unless retention is required by law.

Qlero
Qlero does not provide legal, tax, or accounting advice. Royalty statements and calculations are based on data you and third parties supply.
© Qlero 2026. All rights reserved.