Draft. This agreement has not yet been reviewed by a lawyer and must be before launch — read it as a statement of intent, not as final contract wording.

Legal

Data processing agreement

Last updated 12 September 2026.

Article 28 GDPR requires a written agreement between a controller and its processor. When you put a casting folder on Scout Lane, you are the controller and we are the processor. This is that agreement. Broadcasters and agency legal teams normally ask for it by name.

Request a countersigned copy

1. Parties and roles

This agreement is made between the customer identified in Annex I, Part A (the Controller) and the Scout Lane entity identified in Annex I, Part A (the Processor).

It applies to all processing of personal data that the Processor carries out on behalf of the Controller in providing the Scout Lane service under the terms of service (the "Principal Agreement"), and forms part of that agreement.

Where the Processor determines its own purposes — account administration, billing, security, its own website — it acts as controller, and the privacy policy governs instead. This agreement does not cover that processing.

2. Definitions

GDPR means Regulation (EU) 2016/679. Personal data, processing, controller, processor, data subject, personal data breach and supervisory authority carry the meanings given to them there. Sub-processor means a processor engaged by the Processor to carry out processing on behalf of the Controller.

3. Scope and duration

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex I, Part B, as Article 28(3) requires.

This agreement takes effect when the Controller first uses the service, or on the date of signature below if it is executed separately, and continues for as long as the Processor processes personal data on the Controller's behalf. Clauses that by their nature should survive — confidentiality, deletion, liability — survive termination.

4. Documented instructions

The Processor processes personal data only on the Controller's documented instructions, including as to transfers to a third country, unless required to do otherwise by Union or member state law — in which case it informs the Controller of that requirement before processing, unless the law forbids it on important grounds of public interest.

The Controller's documented instructions are: this agreement, the Principal Agreement, and the configuration and actions the Controller and its authorised users perform inside the product — creating projects, uploading material, creating and scoping client logins, enabling downloads, deleting content.

The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law, and may suspend that instruction until it is withdrawn or amended.

5. Personnel

The Processor ensures that every person authorised to process the personal data is bound by an obligation of confidentiality, is subject to appropriate training, and has access only to the data they need to do their job. Production access is limited to named individuals, is logged, and is withdrawn when it is no longer required.

6. Security measures

The Processor implements and maintains the technical and organisational measures set out in Annex II, which are designed to meet Article 32 having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing as well as the risk to data subjects.

Measures may be updated, provided the level of security is not reduced. The current measures are described in more detail on the security page.

7. Sub-processors

The Controller gives the Processor general written authorisation to engage sub-processors. Those currently engaged are listed in Annex III.

The Processor gives the Controller at least 30 days' notice by email before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the service and receive a pro-rata refund of prepaid fees.

The Processor imposes on each sub-processor, by contract, data protection obligations no less protective than those in this agreement, and remains fully liable to the Controller for the sub-processor's performance.

8. Data subject requests

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests to exercise data subject rights under Chapter III GDPR.

In practice most of this is self-service: the Controller can search, export, correct and delete material, gallery logins and viewing records from inside the product without asking us. Where a request cannot be met that way, the Processor helps within a reasonable period and at no charge for a proportionate volume of requests.

If a data subject contacts the Processor directly about data processed on the Controller's behalf, the Processor does not respond substantively. It forwards the request to the Controller without undue delay and tells the data subject that it has.

9. Further assistance

Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with Articles 32 to 36 GDPR: security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments and prior consultation.

10. Personal data breach

The Processor notifies the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting personal data processed on the Controller's behalf.

The notification describes, so far as it is known at the time:

  • the nature of the breach, including the categories and approximate number of data subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address it and to mitigate its effects;
  • a contact point for further information.

Where the full picture is not available within 48 hours, the Processor sends what it has and follows up in phases. The Processor does not notify a supervisory authority or a data subject on the Controller's behalf unless the Controller asks it to in writing.

11. Return and deletion

At the Controller's choice, the Processor deletes or returns all personal data processed on the Controller's behalf at the end of the provision of services, and deletes existing copies, unless Union or member state law requires it to be stored.

The mechanics, stated plainly:

  • The workspace remains available in read-only form for 30 days after the service ends, so the Controller can export everything.
  • After that period the workspace is deleted: the storage subtree holding the material is removed from disk and the database rows are deleted.
  • Copies held in encrypted backups expire on a rolling 30-day cycle. Until they expire they are not accessible for any operational purpose and are used only for disaster recovery.
  • The Processor certifies deletion in writing on request.

12. Audits

The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates.

Audits are limited to once in any twelve-month period unless a breach or a supervisory authority makes another necessary, require 30 days' written notice, take place in working hours, must not disrupt the service or compromise another customer's confidentiality, and are subject to confidentiality undertakings. The Processor may satisfy an audit request by providing documentation, written answers or a current third-party report where that reasonably addresses the Controller's questions.

13. Transfers

Personal data processed under this agreement is stored and processed in Germany and is not transferred outside the European Economic Area, except as recorded in Annex III. Where a transfer to a third country does take place, it is made only under a valid Article 46 safeguard — in practice the European Commission's Standard Contractual Clauses — together with any supplementary measures the transfer risk assessment requires.

14. Liability and precedence

The liability provisions of the Principal Agreement apply to this agreement and to any claim arising from it.

If this agreement conflicts with the Principal Agreement on a data protection matter, this agreement prevails. If it conflicts with Standard Contractual Clauses entered into between the parties, those clauses prevail.

Annex I

The processing

Part A — Parties

Controller — to be completed by the customer

Legal entity name
[ customer legal entity name ]
Registered address
[ street, postcode, city, country ]
Contact for data protection matters
[ name, role, email ]
Scout Lane workspace
[ workspace address ]

Processor — founder to complete before launch

Legal entity name
[ legal entity name ]
Registered address
[ street, postcode, city, country ]
Company registration number
[ registration number and register ]
VAT number
[ VAT number ]
Contact for data protection matters
[ confirm: privacy@scoutlane.com ]

Part B — Description of the processing

Description of the processing under Article 28(3)
Subject matter Provision of the Scout Lane client gallery, review, field upload and delivery platform.
Duration For the term of the Principal Agreement, plus the 30-day export window and the backup expiry described in clause 11.
Nature of the processing Storage, organisation, structuring, generation of derivatives (thumbnails, preview sizes, video poster frames), retrieval, display to authorised viewers, packaging into ZIP downloads, recording of viewing activity and feedback, backup, and erasure.
Purpose Enabling the Controller to deliver production material to its own clients and crew under controlled access, and to receive their selections, likes and notes.
Categories of data subject The Controller's staff users; the Controller's clients and other invited viewers; people appearing in or identifiable from uploaded material — cast, crew, models, members of the public captured in scouting images; people named in uploaded documents such as call sheets and casting lists.
Types of personal data Names, work email addresses, roles and password hashes of staff users; usernames, display names, permissions and password hashes of gallery logins; photographic and video images of identifiable people; names and contact details appearing inside uploaded documents; project, client and folder names; notes and comments written by viewers; viewing records comprising session start and duration, items viewed, liked, annotated and downloaded, device class, browser user agent and a salted hash of the IP address.
Special category data Not intentionally processed. The service is not designed for special category data and the Controller undertakes not to upload it, save that photographs may incidentally reveal characteristics such as ethnic origin — which is inherent in casting material and is processed under the Controller's own lawful basis.
Frequency Continuous, for the duration of the Principal Agreement.

Part C — Competent supervisory authority

The supervisory authority competent for the Controller, determined under Article 55 GDPR by reference to the Controller's place of establishment.

Annex II

Technical and organisational measures

The measures the Processor has implemented under Article 32. They are described in engineering detail on the security page.

Pseudonymisation and minimisation

  • Viewer IP addresses are stored only as a keyed, salted hash. Raw IP addresses are never written to the database.
  • Session tokens are stored only as a keyed HMAC-SHA-256 digest, so a database copy contains nothing replayable.
  • Passwords are stored only as Argon2id hashes — 64 MiB memory cost, three passes, two lanes, 16-byte salt, 32-byte output.
  • Only the fields the product needs are collected; there is no third-party enrichment, profiling or advertising identifier anywhere in the system.

Confidentiality

  • Every database query that touches customer data is scoped to a single workspace identifier taken from the authenticated principal, independently of any row identifier supplied by the request.
  • Storage is partitioned per workspace on disk; path construction is centralised and every resolved path is validated against the storage root, so a crafted key cannot escape its subtree.
  • Gallery logins can be scoped to named categories or folders; the same access rule is applied by the gallery, the media route and the download builder.
  • Media is served through short-lived HMAC-signed links bound to the storage key, an expiry and the requesting session. ZIP archives are served through one-shot links.
  • All media responses carry Cache-Control: private, so no shared cache or proxy may retain a copy.
  • Role-based access inside a workspace: owner, administrator and member, with destructive operations restricted to administrators and billing to owners.
  • Administrative actions are recorded in an audit log.

Integrity and availability

  • TLS 1.2 and 1.3 for all connections, with HSTS and automated certificate renewal.
  • Encryption at rest for database backups.
  • Nightly database backups with continuous write-ahead log archiving for point-in-time recovery, retained 30 days, with rehearsed restores.
  • Media held on redundant storage with a second copy kept separately from the primary volume; originals are immutable after upload and derivatives are regenerable.
  • Soft deletion followed by a background purge of the underlying bytes.
  • Login throttling, per-route rate limiting on every unauthenticated endpoint, and upload size and type validation.

Organisational measures

  • Production access limited to named individuals, logged, and revoked when no longer required.
  • Confidentiality obligations in every staff and contractor agreement.
  • Documented procedure for personal data breaches, including the 48-hour notification in clause 10.
  • Written sub-processor agreements imposing equivalent obligations.
  • Review of these measures at least annually and after any material change to the architecture.

Annex III

Sub-processors

Authorised as at the date at the top of this document.

Authorised sub-processors
Sub-processor Processing carried out Location Transfer safeguard
IONOS SE Hosting of the application servers, database, media storage and backups. All customer data at rest. Germany None required — processing stays within the EEA
Stripe Payments Europe, Ltd. Subscription billing, card processing and invoicing. Billing contact details only; no project material. Ireland, with onward transfer to the United States Standard Contractual Clauses
[ transactional email provider ] Delivery of invitations, password resets, download-ready notifications and service email. Recipient name and email address only. [ EU region — to be confirmed ] [ to be confirmed ]

The email provider row is a placeholder pending the founder's final choice of relay and must be completed before this agreement is offered for signature.

Execution

Signatures

Signed for and on behalf of the parties by their duly authorised representatives. A countersigned copy can be requested through the contact form.

Controller — the customer

Entity
Name
Position
Signature
Date

Processor — Scout Lane

Entity
Name
Position
Signature
Date

Last updated 12 September 2026. See also the terms of service and the privacy policy.