Legal
Data Processing Addendum
Last updated: 11 July 2026
This Data Processing Addendum (“DPA”) forms part of the InteScene Terms of Service and applies whenever you (or the organisation you act for, the “Customer”) use the Service to process personal data about other people, such as cast, crew, drivers, and suppliers (“Customer Personal Data”). For that data the Customer is the controller and InteScene Ltd is the processor under UK GDPR Article 28 (and EU GDPR where applicable). A countersigned copy of this DPA is available on request from support@intescene.com.
1. Subject Matter and Duration
InteScene processes Customer Personal Data to provide the production management features of the Service (breakdowns, scheduling, call sheets, logistics, check-in, onboarding forms, continuity, reports, and related collaboration), for as long as the Customer’s account and projects exist, plus the deletion grace periods described in the Privacy Policy.
2. Nature and Categories of Data
- Data subjects: cast, crew, extras, drivers, suppliers, and other production personnel whose details the Customer enters or collects via the Service.
- Categories of data: names, contact details, agent details, roles, availability dates, call times and attendance, travel and accommodation bookings, rates and contract terms, photographs (including continuity reference photos), and free-text production notes.
- Special category data: the Service allows the Customer to record dietary requirements and allergies for catering purposes. The Customer is responsible for ensuring an Article 9 condition applies (typically the explicit consent of the individual, e.g. via the self-service onboarding form) before recording such data.
3. InteScene’s Obligations as Processor
- Process Customer Personal Data only to provide the Service and on the Customer’s documented instructions (the Customer’s configuration and use of the Service constitute those instructions), unless required otherwise by law.
- Ensure persons authorised to process the data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, database row-level security scoped to project membership, role-based access controls, audit logging, and tested backup and recovery procedures.
- Engage subprocessors only under data protection terms no less protective than this DPA. The current list is published at intescene.app/subprocessors.html; we update that page and notify account holders before material changes, and the Customer may object on reasonable data protection grounds.
- Taking into account the nature of the processing, assist the Customer in responding to data subject rights requests concerning Customer Personal Data (access, rectification, erasure, restriction, portability, objection).
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably required for the Customer’s own notification obligations.
- Assist the Customer, where reasonably required, with data protection impact assessments and prior consultations relating to the Service.
- Delete Customer Personal Data on project deletion or account closure in line with the retention periods in the Privacy Policy (including copies held by collaboration subprocessors), unless retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, which may be satisfied by written responses and summaries of independent assessments where available.
4. International Transfers
Where Customer Personal Data is transferred outside the UK or EEA by InteScene or its subprocessors, the transfer is protected by an adequacy decision, Standard Contractual Clauses with the UK Addendum or IDTA, and/or the provider’s certification under the EU-US Data Privacy Framework, as recorded per provider on the subprocessors page.
5. Customer Responsibilities
- Have a lawful basis for the Customer Personal Data you enter or collect through the Service, and provide any required privacy information to the individuals concerned.
- Obtain any consents required for special category data (e.g. dietary/allergy information) and for photographs of individuals, including before enabling AI analysis of continuity photos.
- Use the Service’s access controls (roles, view permissions, restricted documents, share-link settings) appropriately for the sensitivity of your production’s data.
6. General
This DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails. Questions: support@intescene.com.