Production Tools - Data processing agreement
Last modified: 26 August 2026
1. Natural or legal person concluding this data processing agreement (“Data Controller”), and
2. Production Tools, UAB (company code 306215201, VAT number LT100015651310, registered office at Jono Basanavičiaus g. 26, Vilnius 03224, Lithuania) (“Data Processor”),
Data Controller and Data Processor are hereinafter collectively referred to as the “Parties” and the “Party” if referred to separately,
Taking into account that:
1. The Parties have entered into an agreement under which Data Processor has agreed to provide Services (as described at https://production.tools/termsofservice) and related technical support to the Data Controller (“Agreement”);
2. In the course of providing Services to the Data Controller, the Data Processor has to process personal data on behalf of and for the interest of the Data Controller;
3. Article 28(3) of the European Union Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”) requires that processing by a processor shall be governed by a contract or other legal act under the EU or the EU Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller;
Have concluded this data processing agreement (“Data Processing Agreement”) and agreed as follows:
1. DEFINITIONS
1.1. Unless the context requires otherwise, the capitalised terms used in this Data Processing Agreement, including its Preamble and annexes, shall have the meanings indicated below:
Applicable Data Protection Laws means any national or internationally binding data protection laws or regulations applicable at any time during the term of this Data Processing Agreement to, as the case may be, the Data Controller or the Data Processor, including GDPR;
Data Controller means an entity or a person that has accepted the Terms of Service (as described at https://production.tools/termsofservice) and that determines the purposes and means of the processing of Personal Data;
Data Processor means Production Tools, UAB that processes Personal Data on behalf of the Data Controller under this Data Processing Agreement;
Personal Data means any information relating to an identified or identifiable natural person;
Sub-processor means a third-party subcontractor engaged by the Data Processor which, as part of the subcontractor’s role of delivering the services, will process Personal Data on behalf of the Data Controller.
2. DATA CONTROLLER’S OBLIGATIONS
2.1. Data Controller shall comply with its obligations as a data controller under the Applicable Data Protection Laws in respect of its processing of Personal Data and any processing instructions it issues to Data Processor.
2.2. Data Controller has provided privacy notice and/or obtained all consents and rights necessary under the Applicable Data Protection Laws for Data Processor to process Personal Data and provide Service pursuant to the Agreement and this Data Processing Agreement.
3. DATA PROCESSING INSTRUCTIONS
3.1. Data Processor undertakes to process the Personal Data on documented Data Controller’s instructions, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by EU or EU Member State law to which the Data Processor is subject. In such a case, the Data Processor shall inform the Data Controller of that legal requirement before processing, unless the law prohibits this. The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions.
3.2. The Data Controller’s instructions to the Data Processor regarding the subject-matter and duration of the processing, the nature and purpose of the processing, the type of Personal Data and categories of data subjects are as follows:
Subject Matter: Provision of Production Tools production management platform to the Data Controller.
Nature and Purpose of the Processing: Data Processor will process Personal Data for the purposes of providing Production Tools production management platform and related Services in accordance with the Agreement, including hosting, storage, organisation, structuring, display, transmission, export and deletion of Personal Data.
Categories of Data Subjects: Natural persons whose information the Data Controller enters into its databases or collects through its registration forms, including actors, performers and other talent (including minors, where managed by the Data Controller), crew members and other production professionals, guardians and representatives of talent, and employees and other representatives of the Data Controller.
Types of Personal Data: Data relating to natural persons provided to Data Processor via the Services by (or at the direction of) Data Controller or by such natural persons themselves, which may include names and contact details, dates of birth, physical characteristics and measurements, photographs, video and audio materials, work history and skills, documents and attachments, communications, and any other information entered into the Data Controller’s databases, including custom fields defined by the Data Controller.
Duration of Processing: As long as the Data Controller has an account with the Data Processor, plus the limited period during which residual copies remain in automatic backups after termination, in accordance with Section 6.2.
3.3. Data Processor shall, when processing Personal Data under this Data Processing Agreement, comply with any Applicable Data Protection Laws and applicable recommendations by the data protection authorities or other competent authorities.
3.4. Data Controller entitles Data Processor to enter into agreements with Sub-processors on the Data Controller’s behalf for the performance of its obligations under this Data Processing Agreement. Data Processor shall maintain a list of Sub-processors used to fulfil its obligations as set forth in this Data Processing Agreement. The Sub-processors currently engaged by the Data Processor are: Microsoft Corporation (cloud infrastructure and hosting) and Twilio (SendGrid) (delivery of emails sent through the platform). The Data Processor shall impose on each Sub-processor, by way of a contract, data protection obligations equivalent to those set out in this Data Processing Agreement, and shall remain fully liable to the Data Controller for the performance of the Sub-processors’ obligations.
3.5. The Data Controller acknowledges and agrees that Personal Data is processed and hosted on Microsoft Azure infrastructure located in the United States. Such transfers are safeguarded by the European Commission adequacy decision for the EU-U.S. Data Privacy Framework, under which Microsoft is certified, and, where applicable, by the European Commission Standard Contractual Clauses.
4. COOPERATION
4.1. To the extent reasonable, taking into account the nature of processing, Data Processor shall assist the Data Controller in fulfilling its legal obligations under Applicable Data Protection Laws, including but not limited to the Data Controller’s obligation to respond to requests for exercising the data subject's rights to request information and for Personal Data to be corrected, blocked or erased at their request.
4.2. In case of any requests made by data subjects, competent authorities or any other third parties to Data Processor regarding the processing of Personal Data covered by this Data Processing Agreement, the Data Processor shall refer such requests to the Data Controller.
4.3. The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this Data Processing Agreement, and shall allow for and contribute to audits, including inspections, conducted by the Data Controller or an auditor mandated by the Data Controller, on reasonable prior notice, during normal business hours, no more than once per year unless required by a competent supervisory authority, and at the Data Controller’s expense.
4.4. In the terms agreed between the Parties and to the reasonable extent, the Data Processor shall assist the Data Controller in data protection impact assessments, prior consultations and other communications with data protection authorities.
5. DATA SECURITY MEASURES
5.1. Data Processor shall protect the Personal Data against destruction, modification, unlawful dissemination, or unlawful access. The Personal Data shall also be protected against all other forms of unlawful processing. Having regard to the state of the art and the costs of implementation and taking into account the nature, scope, context and purposes of the processing as well as the risk of varying likelihood and severity for the rights and freedoms of individuals, the Data Processor shall implement adequate technical and organizational measures.
5.2. Data Processor shall ensure that access to Personal Data is granted only to necessary employees by virtue of performing direct work functions under this Data Processing Agreement. Data Processor shall ensure that such employees respect confidentiality obligations to the same extent as the Data Processor under this Data Processing Agreement. The Data Processor ensures that all persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3. Data Processor undertakes not to, without the Data Controller’s prior written consent disclose or otherwise make Personal Data processed under this Data Processing Agreement available to any third party, except for Sub-processors engaged in accordance with this Data Processing Agreement.
5.4. The Data Processor shall take all necessary actions to assist and shall promptly notify the Data Controller in relation to any accidental or unauthorized access to Personal Data or any other security incidents (Personal Data breach) immediately if possible.
5.5. The technical and organisational measures implemented by the Data Processor include: encryption of data in transmission (TLS); encryption of data at rest provided by the Microsoft Azure platform; access controls limiting access to Personal Data to authorised persons; multi-factor authentication available for user accounts; automatic backups performed on an ongoing basis; logging of system activity; and an internal process for managing and notifying security incidents.
6. FINAL PROVISIONS
6.1. The provisions in this Data Processing Agreement shall apply during such time that Data Processor processes Personal Data in respect of which the Data Controller is the data controller.
6.2. Upon expiry of this Data Processing Agreement, the Data Processor shall, at the choice of the Data Controller as communicated to the Data Processor, delete or return all Personal Data to the Data Controller and shall ensure that any Sub-processor does the same. Copies of Personal Data may remain in automatic backups for a limited period after deletion (uploaded images for up to 30 days, other data for up to 6 months), after which they expire and cannot be recovered.
6.3. This Data Processing Agreement shall be an integral part of the Agreement. Any matter not expressly governed by this Data Processing Agreement shall be governed by the Agreement.