What we take on
Data protection is a matter of trust. We provide the software your school runs on every day, and we take responsibility for everything within our control. None of the following is a statement of intent: each point is written into our Data Processing Agreement and is enforceable against us.
- We process your data only for you. No purposes of our own, no disclosure, no sale, no advertising, no training of AI models.
- We stay in Europe. The application, its databases and its backups run in a data centre in Frankfurt am Main, and our support team accesses them only from within the European Union.
- We secure the platform. Encrypted connections, a separate database for every school, a role and permission system, daily automatic backups, continuous security updates.
- We are liable for our suppliers. Every subprocessor is contractually bound to the same obligations, and we answer to you for their conduct as for our own.
- We notify you of any incident within 48 hours, with everything you need for your own notification to the supervisory authority. A contractual deadline, not an aspiration.
- We help you with access, rectification and erasure requests — at no cost, as long as the effort stays reasonable.
- We submit to your audit. Evidence on request, and an on-site inspection once a year.
- Your data is yours. You can export all of it at any time, and when the contract ends you decide whether we return it or delete it.
Who is responsible for what
The GDPR assigns the roles: you, the dance school, are the controller, because you decide what data you collect about your pupils and why. We are your processor and handle that data only on your instructions.
This division is not a shifting of responsibility. It means you keep control of your data and we cannot take it out of your hands. We are liable to you for the security of the platform, and we are directly liable to data subjects under Art. 82 GDPR — a liability nobody takes off us and which we do not exclude by contract.
You can read the full Data Processing Agreement here. It forms part of our contractual relationship and is the basis for your own record of processing activities.
What data is processed
Master and contact data of pupils, parents and teachers; course and enrolment data; attendance; payments and invoices; SEPA mandates; and the notes you enter yourself.
Two categories deserve explicit mention, because they carry stronger protection:
Health-related data (Art. 9 GDPR). If you manage medical fitness certificates, the application stores whether one exists and when it expires. That is a special category of personal data. The certificate document itself sits in your own cloud storage, not with us. You can switch this function off entirely, and then none of it is collected.
Minors. The great majority of data subjects are children and young people. Obtaining the consent of legal guardians is your responsibility — particularly for publishing photos and videos, where German law applies § 22 KUG alongside the GDPR. The application helps: you can record per pupil whether consent is on file, and before a gallery is published the software shows how many of the pupils it would reach have no consent recorded.
Data subject rights
Requests for access, rectification, erasure, restriction or portability go to you, not to us. If someone contacts us directly, we forward the request to you and do not answer it ourselves.
The application gives you the tools: search across all records, editing, export and permanent deletion of individual people. Where that is not enough, we assist you at no extra cost as long as the effort stays reasonable.
Retention and deletion
We keep nothing that is not needed. After the contract ends, access is blocked, the data stays blocked for 30 days, and it is then returned or permanently deleted at your choice — backups included.
Bear in mind your own commercial and tax retention obligations (in Germany § 147 AO and § 257 HGB): invoices and accounting records must be kept for several years, and you must export them before deletion.
Data breaches
If we become aware of a personal data breach, we inform you within 48 hours with everything you need for your own notification to the supervisory authority. That deadline is in the DPA; it is not a statement of intent.
Where processing takes place
Exclusively within the European Union, in a data centre in Frankfurt am Main. Transfers to third countries are listed individually, with their legal basis, in our list of subprocessors.
Your own accounts
When you connect your cloud storage, Stripe, Zoom or your own mail server, those accounts stay yours. That is deliberate: your invoices and medical certificates sit with you rather than with us, and you keep access to them even if you stop using our service one day.
Because they are your accounts, you need a data processing agreement with each of those providers. We tell you exactly which ones, and we point out where this usually goes wrong — a private Google account, for instance, is not sufficient for pupils’ data; you need a business account. We will help you set it up: just ask.
Contact
privacy@dancemasterpro.com
