Data Processing Agreement (DPA)
Last Updated: July 28, 2026
This Data Processing Agreement forms part of the Terms of Service between you (the Data Subject / User) and Moore World Wide Enterprises, LLC (the Data Controller / Processor).
1. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1)
- Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
- Controller: Moore World Wide Enterprises, LLC, which determines the purposes and means of processing Personal Data
- GDPR: General Data Protection Regulation (EU) 2016/679
2. Scope of Processing
2.1 Purpose
We process Personal Data to provide the Festival Planner service, including:
- Authenticating users via Spotify OAuth
- Analyzing music preferences and listening history
- Matching users to festivals and concerts
- Generating personalized recommendations
- Building conflict-aware schedules
2.2 Categories of Data
- Identity data (Spotify user ID, display name)
- Music preference data (top artists, tracks, genres)
- Usage data (festival searches, saved festivals)
- Technical data (IP address, browser type, session data)
3. Sub-processors
We engage the following sub-processors:
| Sub-processor | Service | Location | Safeguards |
|---|---|---|---|
| Vercel Inc. | Application Hosting | USA | SCCs, DPA |
| Neon | Database Hosting | USA | SCCs, Encryption |
| Spotify AB | Music Data Provider | Sweden (EEA) | GDPR Compliant |
| JamBase Inc. | Festival Data | USA | SCCs, DPA |
| Google LLC | Analytics | USA | SCCs, DPA |
4. International Data Transfers
When transferring Personal Data from the EEA to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and implement supplementary measures including encryption and access controls.
5. Data Subject Rights
We assist Data Subjects in exercising these rights under GDPR:
- Right of Access (Art. 15): Request a copy of your data
- Right to Rectification (Art. 16): Correct inaccurate data
- Right to Erasure (Art. 17): Request deletion
- Right to Data Portability (Art. 20): Receive data in structured format
- Right to Object (Art. 21): Object to certain processing
To exercise these rights, contact us at hello@moorewwe.com. We will respond within 30 days as required by GDPR Article 12.
6. Security Measures
We implement appropriate technical and organizational measures, including:
Technical Measures
- Encryption in transit (TLS 1.3)
- Encrypted database connections
- Secure session management
- Regular security patches and updates
Organizational Measures
- Confidentiality agreements with personnel
- Principle of least privilege for data access
- Incident response procedures
- Data minimization practices
7. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33). If the breach poses a high risk, we will also notify affected Data Subjects without undue delay (GDPR Article 34).
8. Data Retention and Deletion
Upon termination of your account or at your request, we will delete all Personal Data, unless legally required to retain it. We will provide confirmation of deletion upon request.
9. Contact Information
For questions about this DPA or to exercise your rights:
Data Controller:Moore World Wide Enterprises, LLC
2102 Quail Hollow Dr
Bryan, Texas 77802
United States
Email: hello@moorewwe.com