Data Processing Addendum for "Web Radio Players" Analytics

This Data Processing Addendum ("DPA") is entered into by and between Enocus Limited, a company registered in the United Kingdom with Company No. 16482583, and its office address at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom ("Processor") and the Subscriber ("Controller") and is incorporated into the Subscription Service Agreement ("Agreement") for the "Web Radio Players" Service.

1. Definitions

Terms such as "Personal Data", "Data Subject", "Processing", "Controller", and "Processor" shall have the meanings ascribed to them in the General Data Protection Regulation (EU) 2016/679 ("GDPR").

  • Controller: The Subscriber using the Service to process End-User Data.
  • Processor: Enocus Limited, a company providing the Service to the Controller.
  • End-User Data: Personal Data of the Controller's end-users (i.e., listeners) processed through the analytics features of the Service.
  • Service: The "Web Radio Players" Software-as-a-Service product.

2. Scope and Purpose of Processing

  • Subject-Matter: The processing of End-User Data to provide analytics services to the Controller.
  • Duration: For the term of the Controller's subscription to the Service under the Agreement.
  • Nature and Purpose: To collect and present analytics data to the Controller, such as the country of listeners, duration of listening sessions, and feature interactions, to help the Controller understand product usage and improve their services. The processing is initiated and controlled by the Controller, who must enable the analytics feature within the Service.
  • Categories of Data Subjects: End-users (listeners) of the Controller's audio stream.
  • Types of Personal Data: IP address (for geographical location derivation), browser/device user agent, and a unique identifier stored in a cookie (if enabled by the Controller).

3. Processor's Obligations

Processor agrees to:

  1. Process End-User Data only on the documented instructions of the Controller.
  2. Ensure that all personnel authorized to process End-User Data are subject to a strict duty of confidentiality.
  3. Implement and maintain appropriate technical and organizational security measures to protect End-User Data.
  4. Not engage any other processor ("Sub-processor") without the Controller's prior specific or general written authorization. The Controller provides general authorization for the Processor to engage Sub-processors (e.g., cloud hosting providers).
  5. Assist the Controller with appropriate technical and organizational measures for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights.
  6. Assist the Controller in ensuring compliance with its obligations regarding data security and breach notifications.
  7. Upon termination of the Agreement, delete or return all End-User Data to the Controller.
  8. Make available to the Controller all information necessary to demonstrate compliance with this DPA.

4. Controller's Obligations

Controller represents and warrants that it shall:

  1. Comply with all applicable data protection laws in its use of the Service.
  2. Have a valid lawful basis (e.g., consent, legitimate interest) for the collection and processing of all End-User Data through the Service.
  3. Provide a clear, comprehensive, and legally compliant privacy policy to its end-users that accurately describes the data collection practices.
  4. Be solely responsible for responding to all data rights requests from its end-users.

This DPA is effective as of the date the Subscriber agrees to the Agreement.

Enocus Limited,
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: [email protected]

Last Updated: June 10, 2025