Effective Date: December 5, 2025
Last Updated: December 5, 2025
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer," "Data Controller," or "you") and PANARCHIA LLC ("Processor," "we," "us," or "our") and governs the processing of Personal Data in connection with the Song Vitals service.
This DPA applies when Song Vitals processes Personal Data on behalf of the Customer, particularly when the Customer is subject to data protection laws such as:
Capitalized terms not defined in this DPA have the meanings given in the GDPR or applicable data protection laws:
The Customer acts as the Data Controller and is responsible for:
PANARCHIA LLC acts as the Data Processor and will:
PANARCHIA LLC processes Personal Data to provide the Song Vitals service, which includes:
The Personal Data processed may include:
Data Subjects may include:
Personal Data will be processed for the duration of the service agreement and retained according to our data retention policies as outlined in our Privacy Policy, unless longer retention is required by law.
PANARCHIA LLC will process Personal Data only in accordance with the Customer's documented instructions, which include:
If PANARCHIA LLC believes that any instruction from the Customer would violate applicable Data Protection Laws, we will promptly inform the Customer and may refuse to carry out the instruction.
PANARCHIA LLC implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Upon reasonable request and subject to confidentiality obligations, PANARCHIA LLC will provide information about our security measures to demonstrate compliance with this DPA.
The Customer authorizes PANARCHIA LLC to engage Sub-processors to process Personal Data. Current Sub-processors include:
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and storage | United States |
| Stripe, Inc. | Payment processing | United States |
| Google LLC | Analytics and authentication | United States |
Note: This list is current as of the effective date and may be updated. See Section 6.3 for notification procedures.
PANARCHIA LLC will:
PANARCHIA LLC will provide at least 30 days' notice before adding or replacing Sub-processors by:
If the Customer objects to a new Sub-processor on reasonable data protection grounds, the Customer may terminate the affected services by providing written notice within 30 days.
PANARCHIA LLC will, to the extent legally permitted, promptly notify the Customer if we receive a request from a Data Subject to exercise their rights under Data Protection Laws (access, rectification, erasure, restriction, portability, objection).
The Customer is responsible for responding to Data Subject requests. PANARCHIA LLC will provide reasonable assistance to help the Customer fulfill such requests, including:
If assistance requires significant additional effort beyond our standard platform features, PANARCHIA LLC may charge reasonable fees based on our then-current professional services rates.
PANARCHIA LLC will notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach affecting the Customer's data.
The notification will include, to the extent known:
PANARCHIA LLC will cooperate with the Customer and provide reasonable assistance in investigating and remediating the breach, and in fulfilling any obligations to notify Data Subjects or regulatory authorities.
PANARCHIA LLC will provide reasonable assistance to the Customer in conducting Data Protection Impact Assessments (DPIAs) when required by Data Protection Laws, including providing information about our processing activities and security measures.
PANARCHIA LLC will make available to the Customer information necessary to demonstrate compliance with this DPA and allow for audits, including inspections, by the Customer or an independent auditor mandated by the Customer, subject to:
The Customer is responsible for all costs associated with audits. PANARCHIA LLC may charge reasonable fees for time and resources required to facilitate audits beyond providing standard documentation.
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA) or the Customer's jurisdiction. PANARCHIA LLC ensures such transfers comply with Data Protection Laws through appropriate safeguards, including:
To the extent required by Data Protection Laws, the parties agree to execute the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 (available at https://songvitals.com/legal/scc).
PANARCHIA LLC implements supplementary measures to ensure adequate protection for international transfers, including encryption, access controls, and contractual protections with Sub-processors.
PANARCHIA LLC will retain Personal Data only for as long as necessary to provide the Service and fulfill the purposes described in our Privacy Policy, unless a longer retention period is required or permitted by law.
Upon termination of the service agreement, PANARCHIA LLC will, at the Customer's choice:
Exceptions: We may retain Personal Data to the extent required by applicable law or for legitimate business purposes (e.g., dispute resolution, legal compliance, fraud prevention).
Upon request, PANARCHIA LLC will provide written certification that Personal Data has been deleted in accordance with this DPA.
PANARCHIA LLC ensures that all personnel authorized to process Personal Data:
Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service. Nothing in this DPA limits either party's liability for:
This DPA takes effect on the effective date and continues for as long as PANARCHIA LLC processes Personal Data on behalf of the Customer.
Sections relating to confidentiality, data deletion, limitation of liability, and dispute resolution survive termination of this DPA.
This DPA is governed by the same law and jurisdiction provisions as the Terms of Service. For customers subject to GDPR, this DPA is also governed by the data protection laws of the European Union.
PANARCHIA LLC may update this DPA from time to time to reflect changes in Data Protection Laws or our processing activities. Material changes will be communicated to customers with at least 30 days' notice. Continued use of the Service after changes take effect constitutes acceptance of the updated DPA.
In the event of any conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters. In the event of conflict between this DPA and Standard Contractual Clauses, the Standard Contractual Clauses prevail.
For questions about this DPA or data processing practices, please contact:
PANARCHIA LLC
Data Protection Officer
Email: dpo@songvitals.com
Website: https://songvitals.com
For EU-specific inquiries: eu-dpo@songvitals.com
This Data Processing Addendum governs how PANARCHIA LLC processes Personal Data on behalf of customers using Song Vitals. We act as a Data Processor, implementing appropriate security measures, using authorized Sub-processors, assisting with Data Subject rights, and ensuring compliance with applicable data protection laws including GDPR and CCPA. For detailed information about our data practices, please also review our Privacy Policy.