Legal

Data Processing Agreement

Last updated August 8, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Use between Epstein Enterprises, LLC (“Cuelist,” “we,” “us”) and the customer that has agreed to those Terms (“Customer,” “you”). It applies wherever Cuelist processes personal data on your behalf, and it applies automatically to educational, institutional, and other organizational accounts. No signature is required for it to take effect, though we will countersign a copy on request at support@thecuelist.com.

1. Definitions

“Personal data,” “processing,” “controller,” “processor,” “data subject,” and “personal data breach” have the meanings given in the EU General Data Protection Regulation (“GDPR”). “UK GDPR” means the GDPR as retained in United Kingdom law. “Data protection law” means the GDPR, the UK GDPR, and any other privacy or data protection law applicable to the processing described here. “Customer Data” means personal data that Cuelist processes on your behalf under the Terms of Use.

2. Roles of the parties

For Customer Data, you are the controller and Cuelist is the processor. You are responsible for the accuracy and lawfulness of the Customer Data you provide, and for having a lawful basis to provide it to us. Where Cuelist determines the purposes and means of processing for its own account, such as billing records or securing the Service, Cuelist acts as a controller and its Privacy Notice applies.

3. Scope and instructions

Cuelist processes Customer Data only on your documented instructions, which comprise the Terms of Use, this DPA, and your configuration and use of the Service. Cuelist will not process Customer Data for its own purposes, will not sell it, and will not use it to train machine learning models. If Cuelist is required by law to process Customer Data other than on your instructions, it will inform you before doing so unless that law forbids it. Cuelist will tell you if, in its opinion, an instruction infringes data protection law.

4. Confidentiality

Cuelist ensures that anyone authorized to process Customer Data is bound by an obligation of confidentiality, and limits access to those who need it to provide or support the Service.

5. Security

Cuelist implements the technical and organizational measures described in Annex II to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Cuelist may update those measures over time provided the level of protection is not reduced.

6. Sub-processors

You give Cuelist general authorization to engage the sub-processors listed in Annex III, and to engage others in future. Cuelist imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for their performance.

Cuelist maintains its current list of sub-processors on its service providers page. Cuelist will give at least thirty (30) days’ notice before adding a new sub-processor, by email to the account’s administrative contact. If you reasonably object to a new sub-processor on data protection grounds within that period, you may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid fees for the remaining term, which is the sole remedy for such an objection.

The Notes List. If, and only if, you hold a dual subscription, script structure you create in Cuelist is transferred to The Notes List. The Notes List is a separate controller with its own agreement with you, not a sub-processor acting on Cuelist’s behalf, and its own privacy policy governs that data once transferred. If you do not hold a dual subscription, no Customer Data is transferred to The Notes List.

7. Assisting with data subject rights

The Service provides tools that let you access, correct, export, and delete Customer Data directly. Where those tools are not sufficient, Cuelist will provide reasonable assistance, taking into account the nature of the processing, to help you respond to a data subject exercising their rights. If a data subject contacts Cuelist directly about Customer Data, Cuelist will refer them to you rather than respond substantively, unless legally required to do otherwise.

8. Personal data breach

Cuelist will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, and the measures taken or proposed. Where the full picture is not available at once, Cuelist will provide information in phases as it is established. Cuelist maintains a written incident response procedure covering detection, assessment, notification, and remediation.

9. Impact assessments

Cuelist will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, to the extent these relate to Cuelist’s processing and the information is not otherwise available to you, including through this DPA and the service providers page.

10. Deletion and return

You may export your projects from within the Service at any time. On termination or expiry, and at your choice, Cuelist will delete or return Customer Data. Where you have not made a choice, Cuelist retains project data so that your account can be restored, as described in the Terms of Use, and will delete it on written request.

Backups. Deletion removes data from the live Service promptly. Because backups cannot be selectively edited without compromising their integrity, deleted data persists in backups until those backups expire on their normal rotation. The longest retention period is 98 days, which is therefore the maximum period after which deleted Customer Data is no longer held in any form. Backups are encrypted and access-controlled, and are used only to restore the Service.

11. Audits and information

On written request, and no more than once in any twelve-month period unless required by a supervisory authority or following a personal data breach, Cuelist will make available the information reasonably necessary to demonstrate compliance with this DPA. This includes responding to a reasonable security questionnaire, such as a HECVAT, and providing the sub-processor list, security measures, and breach history. Given the scale of the Service, on-site audits are not offered by default; where data protection law requires an audit that this documentation cannot satisfy, the parties will agree its scope, timing, and cost in advance.

12. International transfers

Cuelist is operated from the United States, and Customer Data is stored on servers in the United States. Where Customer Data is transferred out of the European Economic Area, the United Kingdom, or Switzerland, the parties rely on the European Commission’s Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference and completed by Annexes I to III, together with the UK International Data Transfer Addendum where UK law applies. Where a sub-processor is certified under the EU-US Data Privacy Framework, that certification may also be relied upon.

13. Education customers and FERPA

Where you are an educational institution subject to the Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99) and Customer Data includes personally identifiable information from education records, Cuelist acts as a “school official” with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B). Cuelist:

  • performs an institutional service for which the institution would otherwise use its own employees;
  • is under the direct control of the institution with respect to the use and maintenance of education records;
  • uses education records only for the purpose for which the disclosure was made; and
  • does not re-disclose personally identifiable information from education records except as permitted by FERPA and authorized by the institution.

Cuelist does not use education records to advertise or market to students, and does not sell them.

14. General

This DPA takes effect when you accept the Terms of Use and continues while Cuelist processes Customer Data. Where it conflicts with the Terms of Use, this DPA governs for matters of data protection. Any liability under this DPA is subject to the limitations in the Terms of Use, except where data protection law does not permit those limitations to apply. If any provision is held invalid, the remainder continues in effect.

Annex I. Description of the processing

Subject matter. Provision of Cuelist, a collaborative script annotation service for live performance.

Duration. The term of your subscription, plus the retention and backup periods described in Section 10.

Nature and purpose. Hosting, storing, displaying, transmitting, and backing up scripts and the annotations made on them; authenticating users; sharing projects with collaborators; providing support; and billing.

Categories of data subject. Your account administrators, staff, faculty, students, and any collaborator invited to a project.

Categories of personal data.

  • Identity and contact data: name, email address, and optional profile photograph.
  • Account data: subscription tier, seat assignment, role, and permissions.
  • Content data: uploaded scripts and scores, and the cues, notes, annotations, layers, and script structure created on them, together with the identity of the user who created each.
  • Collaboration data: project membership, invitations sent, and presence information while a project is open.
  • Technical data: IP address, country derived from it, browser and operating system, and log records of access to the Service.
  • Support data: correspondence with Cuelist and its contents.
  • Billing data: transaction records. Card numbers are handled by Stripe and are never received or stored by Cuelist.

Special category data. None is requested or required. You should not upload special category data to the Service.

Frequency. Continuous, for the duration of the subscription.

Annex II. Technical and organizational measures

  • Encryption in transit. All access to the Service is over HTTPS with TLS.
  • Encryption at rest. Customer Data is stored on Google Cloud Platform and Firebase, which encrypt data at rest by default.
  • Authentication. Email and password or Google Sign-In, managed by Firebase Authentication. Credentials are not stored by Cuelist. Users can review and revoke their active sessions from their account.
  • Authorization. Access to projects is governed by per-project membership and per-layer permissions set by the project owner, enforced by server-side security rules on both the database and file storage.
  • Administrative access. Access to production systems is limited to personnel who require it, through Google Cloud identity and access management.
  • Payment data. Card details are collected and stored by Stripe, a PCI DSS Level 1 service provider. Cuelist never receives full card numbers.
  • Backups. Point-in-time recovery with seven (7) days of coverage; daily backups retained fifteen (15) days; weekly backups retained ninety-eight (98) days. Backups are encrypted and access-controlled.
  • Resilience. The Service runs on Google Cloud managed infrastructure with the availability and redundancy characteristics of that platform.
  • Incident response. Cuelist maintains a written procedure for detecting, assessing, notifying, and remediating security incidents, including the notification obligation in Section 8.
  • Data minimization. Cuelist requests only the information needed to provide the Service. Website analytics are cookieless and do not identify individuals.
  • Deletion. Account and project deletion is available to users directly, subject to the backup rotation described in Section 10.

Annex III. Sub-processors

Sub-processor Location Purpose
Google Cloud Platform United States Hosting of uploaded scripts and scores
Firebase (Google) United States Database, authentication, and real-time collaboration
Firebase Hosting (Google) United States Serving the website and application
Stripe, Inc. United States Payment processing and billing records
Mailgun (Sinch) United States Account, invitation, and support email
Cloudflare, Inc. United States Cookieless website analytics
Formspree, Inc. United States Contact and support form delivery
Mailchimp (Intuit) United States Newsletter delivery, where a user has subscribed

The current list is maintained on the service providers page. YouTube is used to host tutorial videos in our documentation and does not process Customer Data.

Contact

Questions about this DPA, requests for a countersigned copy, and security questionnaires should go to support@thecuelist.com, or:

Epstein Enterprises, LLC
Attention: Data Protection
350 Santa Inez Way
La Cañada, CA 91011 USA