Legal

Data Processing Agreement

How Theatrio handles personal data on your theatre's behalf — who is responsible for what, who helps us run the service, and what happens to your data.

Last updated: August 2026

1.What this agreement covers

This Data Processing Agreement (DPA) forms part of our Terms & Conditions. It applies whenever Theatrio processes personal data on your theatre's behalf — for example the audience or member details that appear in documents you upload to Theatre Memory™, or contact details in a newsletter list.

It is written in plain English but is intended to meet the requirements of Article 28 of the UK GDPR. No signature is needed: it applies automatically to every account.

The processor under this agreement is Theatrio, a UK sole trader business at 4 Barton Court, Parkham, Bideford, EX39 5RJ, United Kingdom, contactable at info@theatrio.co.uk.

2.Controller and processor responsibilities

  • Your theatre is the controller for content and personal data you upload. You decide what to upload, you confirm you have the right to do so, and you handle your own members' privacy notices and consents.
  • Theatrio is the processor for that content. We only process it to deliver the service — storing it, generating marketing content from it, and supporting you.
  • Theatrio is a controller for our own account and billing data, which is covered by our Privacy Policy rather than this DPA.

We will assist you, at reasonable cost, with data subject requests, impact assessments and regulator enquiries that relate to data we process for you.

3.Customer instructions

We process personal data only on your documented instructions. Your instructions are: use the platform as described in our documentation and Terms, plus any specific written request you send us.

If we believe an instruction would break the law, we will tell you rather than act on it. We will not use your data for our own purposes, and we will never sell it.

4.Sub-processors

We use a small number of carefully chosen providers to run Theatrio. Each is bound by written terms at least as protective as this DPA.

  • Cloud hosting, database, storage and authentication — our managed infrastructure provider.
  • AI providers — OpenAI, Anthropic and Google, used only to generate requested content, and contractually prevented from training public models on your data.
  • Stripe — subscription payments and billing.
  • Email delivery — transactional emails such as sign-in and password resets.

We will give reasonable notice before adding or replacing a sub-processor. If you reasonably object, you may end your subscription and we will refund any unused prepaid period.

5.Security measures

We apply appropriate technical and organisational measures, including:

  • Encryption in transit (TLS) and encryption at rest
  • Row-level access controls so each theatre only sees its own data
  • Hashed password storage and session-based authentication
  • Least-privilege access for staff, with access only where necessary to support you
  • Logging, monitoring and regular dependency updates

Our Security page describes these in more detail. All personnel with access are bound by confidentiality obligations.

6.International transfers

Some sub-processors operate outside the UK. Where personal data is transferred, we rely on UK adequacy regulations, the UK International Data Transfer Addendum, or Standard Contractual Clauses, together with any additional safeguards needed to keep protection equivalent to the UK GDPR.

7.Data return and deletion

  • You can export or delete your content from within the app at any time.
  • When your subscription ends, we delete or anonymise the personal data we process for you — normally within 30 days — unless the law requires us to keep it.
  • Backups containing deleted data cycle out shortly afterwards under our normal retention schedule.
  • We will confirm deletion in writing if you ask.

8.Data breaches

If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and within 72 hours of becoming aware, including what we know about the nature of the breach, likely consequences and steps taken.

We will help you meet your own notification duties to affected individuals and the ICO. Report anything suspicious to info@theatrio.co.uk.

9.Records and audit

We keep records of our processing activities and will provide reasonable information to help you verify our compliance. Where an on-site audit is needed, we ask for reasonable notice and that it does not disrupt other customers.

Business details

Business name
Theatrio
Legal status
UK sole trader (not a limited company)
Business address
4 Barton Court, Parkham, Bideford, EX39 5RJ, United Kingdom
Contact email
info@theatrio.co.uk