Data Processing Agreement (DPA)
Version 1.0, effective 22 September 2026
Parties and classification
This Data Processing Agreement (the „DPA“) is entered into between you as a customer of the cori services (the „Controller“) and
cori Tech GmbH
Friedhofstr. 15
67378 Zeiskam, Rhineland-Palatinate
Germany
Local court of Landau in der Pfalz, HRB 34400
Email: info@getcori.app
(the „Processor“). For the purposes of this DPA, the Controller is the body that opens a cori account for a choir, an organisation or a comparable group and uses it to administer the data of its members, typically the association, parish, school or sponsoring organisation.
This DPA sets out the data protection obligations of the parties for those processing operations that we carry out on your instructions. It supplements the agreement between the parties on the use of the cori services (the „Main Agreement“), consisting of the Terms of Use and the service description you selected.
Precedence: In the event of a conflict between this DPA and the Main Agreement, this DPA prevails in so far as the processing of personal data is concerned. In particular, the limitations of liability in the Main Agreement do not restrict liability under Article 82 GDPR or under Section 13 of this DPA.
Conclusion: This DPA forms part of the Main Agreement. It applies as soon as you use the cori services to administer the data of the members of your choir or organisation, and it is referenced when a cori subscription is taken out. It is concluded in text form within the meaning of Article 28(9) GDPR; a handwritten signature is not required. Each version carries a version number and a date; on request we will confirm which version is authoritative for your agreement.
Earlier versions of this document remain authoritative for the period during which they applied. The version currently in force is available at https://cori.music/avv.
Table of contents
1. SUBJECT MATTER AND DURATION
The subject matter of this DPA is the processing of personal data that we carry out on behalf of and on the instructions of the Controller in the course of providing the cori services. Details of the nature, purpose, types of data and categories of data subjects are set out in Annex 1.
The duration of this DPA matches the term of the Main Agreement. It ends automatically when the Main Agreement ends, without any need for separate termination. The obligations under Section 5 (Confidentiality) and Section 11 (Return and deletion) survive the end of the agreement.
2. NATURE, SCOPE AND PURPOSE OF PROCESSING
We process personal data solely for the purpose of providing the services agreed in the Main Agreement: administering choirs and organisations, providing sheet music, recordings and practice material, managing appointments, recording attendance, enabling communication within the group, and the associated technical operations such as storage, conversion, synchronisation, backup and delivery to members’ devices.
Allocation of roles: Not every processing operation connected with the cori services is processing on your behalf. Annex 1, Section 4 sets out which operations make you the Controller and us the Processor, and which operations we carry out as Controller in our own right on our own legal basis. This DPA does not apply to the latter; our Privacy Policy does.
No processing for our own purposes takes place under this DPA, in particular no profiling and no advertising.
3. RIGHTS AND OBLIGATIONS OF THE CONTROLLER
You remain the controller of the data processed on your behalf within the meaning of Article 4(7) GDPR. You are responsible for the lawfulness of the processing and for safeguarding the rights of data subjects, in particular for having a legal basis and for meeting the information obligations under Articles 13 and 14 GDPR towards your members.
Instructions are generally issued in text form to info@getcori.app. The settings and functions you use within the services also constitute instructions, for example adding and removing members, defining roles and permissions, uploading material and triggering a data export or deletion.
The contact person for data protection is the person who administers the organisation or choir within the services. You may name a different contact person at any time in text form. This does not create any obligation to appoint a data protection officer; whether such an obligation exists follows solely from Article 37 GDPR and Section 38 BDSG.
4. OBLIGATIONS OF THE PROCESSOR
We process personal data only on documented instructions from the Controller, including with regard to transfers to third countries, unless we are required to process by Union or Member State law. In such a case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
If we consider that an instruction infringes data protection law, we will inform you without undue delay. We are entitled to suspend the execution of the instruction concerned until you confirm or amend it.
We maintain a record of all categories of processing activities under Article 30(2) GDPR and make the parts relating to you available on request.
We have appointed a data protection officer where a statutory obligation to do so exists, and will provide the contact details on request.
5. CONFIDENTIALITY
We only use persons for processing who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That obligation continues after the end of their activity.
Access to production data follows the principle of necessity and is logged.
6. SECURITY OF PROCESSING
We take the technical and organisational measures required under Article 32 GDPR. The measures in place at the time this agreement is concluded are described in Annex 2.
We may adapt those measures over time, in particular to the state of the art. The level of protection achieved must not fall below the level described. We document material changes and make them available in the current version of Annex 2.
7. SUB-PROCESSORS
You grant us general authorisation to engage further processors. The sub-processors engaged at the time this agreement is concluded are listed in Annex 3 with their name, service and place of processing.
If we intend to engage an additional sub-processor or replace an existing one, we will inform you at least 30 days in advance in text form, by email to the contact address on file or by notice within the services. You may object to the change within 30 days of receiving that information on data protection grounds.
If you object, the parties will seek a solution together. If none is found and we cannot provide the service without the sub-processor concerned, you are entitled to terminate the Main Agreement with effect from the date the change takes effect. We will refund any fees paid in advance on a pro rata basis for the unused remainder of the term.
Where an immediate change is necessary to safeguard the security or availability of the data, for example in the event of a security incident, an outage or the insolvency of a sub-processor, we may make the change without observing the notice period. In that case we will inform you without undue delay after the change. Your right to object and the right of termination under this section remain unaffected.
We impose data protection obligations on each sub-processor that correspond to the obligations under this DPA, and remain responsible to you for its conduct.
8. ASSISTANCE WITH DATA SUBJECT RIGHTS
We assist you by appropriate technical and organisational measures in fulfilling requests by data subjects under Articles 12 to 23 GDPR, in particular requests for access, rectification, erasure, restriction of processing and data portability.
Where the services provide functions for access, export, rectification and deletion, our assistance consists of making those functions available. Where further effort is required, we will provide it and will inform you of any charge before we act.
If a data subject contacts us directly, we will forward the request to you without undue delay and will not answer it ourselves in so far as it concerns processing carried out on your behalf.
9. PERSONAL DATA BREACHES AND ASSISTANCE
We will inform you without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting data processed on your behalf. The notification will describe, to the extent available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken and proposed.
We assist you in meeting your obligations under Articles 33 and 34 GDPR and, where required, with a data protection impact assessment under Article 35 GDPR and prior consultation under Article 36 GDPR.
Irrespective of the above, we will take the necessary measures without undue delay to secure the data and mitigate any adverse effects.
10. EVIDENCE AND AUDIT RIGHTS
We make available to you all information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allow for and contribute to audits, including inspections.
Evidence is provided primarily by self-assessment, by the documentation of the measures set out in Annex 2, and by existing certifications or audit reports, including those of our sub-processors.
Where that evidence is not sufficient in an individual case, you may request an on-site audit or an audit by an auditor appointed by you who is not a competitor of ours. The audit must be announced 14 days in advance, must take place during normal business hours and must not unreasonably interfere with our operations. In the absence of a specific cause, one audit per calendar year is provided for; in the event of a personal data breach or an order by a supervisory authority, this right exists additionally on a case-by-case basis.
Audits without specific cause that go beyond the provision of the evidence described above may be charged on a time and materials basis. We will inform you of the amount before starting.
11. RETURN AND DELETION
After the end of the processing services we will delete all personal data processed on your behalf or return it, at your choice. You must inform us of your choice no later than 30 days after the end of the agreement. If you make no choice, we delete the data.
Deletion from production systems takes place within 90 days of the end of the agreement or of your instruction. Data in backup copies is overwritten in the course of the regular rotation cycle, at the latest after 12 months. Until then it remains blocked and is used solely for restoration in the event of a failure.
Before deletion we will, on request, provide you with an export of the data processed on your behalf in a common, machine-readable format.
Data is retained beyond these periods only where Union or Member State law requires it. In that case further processing is limited to the purpose prescribed by law.
12. PROCESSING IN THIRD COUNTRIES
Processing generally takes place within the European Union or the European Economic Area. The place of processing for each sub-processor is stated in Annex 3.
Where processing takes place in a third country in an individual case, this occurs only on the basis of an adequacy decision under Article 45 GDPR, such as certification under the EU-US Data Privacy Framework, or on the basis of the standard contractual clauses under Article 46(2)(c) GDPR together with supplementary measures. The applicable basis is stated for each entry in Annex 3.
We do not transfer data to a third country without one of these bases.
13. LIABILITY
The parties are liable under Article 82 GDPR for damage caused to a data subject by processing that does not comply with data protection law. That liability cannot be excluded or limited by contract.
Clarification regarding the Main Agreement: The exclusions and limitations of liability in the Terms of Use, in particular those relating to data loss and unauthorised access, do not apply to liability under Article 82 GDPR or to breaches of this DPA. Any waiver of claims for loss of or damage to data does not apply to data processed on your behalf.
14. TERM, TERMINATION AND AMENDMENTS
This DPA runs with the Main Agreement and ends with it. This DPA cannot be terminated separately while the Main Agreement remains in force, because the services cannot be provided without processing personal data.
We may amend this DPA where necessary to adapt it to a change in the law, to decisions of supervisory authorities or courts, or to changed technical circumstances. We will inform you of amendments at least 30 days before they take effect, in text form, stating the points that have changed.
If an amendment puts you at a disadvantage, you may object within 30 days. In that case you are entitled to terminate the Main Agreement with effect from the date the amendment takes effect. Any waiver of separate notification of changes provided for in the Terms of Use does not apply to this DPA.
15. FINAL PROVISIONS
Amendments and additions to this DPA must be made in text form. This also applies to any waiver of this form requirement.
Should any provision of this DPA be or become invalid, the validity of the remaining provisions is unaffected. The parties will replace the invalid provision with a valid one that comes closest to its commercial and data protection purpose.
German law applies. The arbitration and dispute resolution provisions of the Terms of Use do not apply to disputes arising from this DPA; the ordinary courts have jurisdiction.
ANNEX 1: SUBJECT MATTER OF THE PROCESSING
1. Nature and purpose of the processing
Collection, storage, organisation, alteration, retrieval, use, disclosure to authorised members of the group, alignment, restriction, erasure and destruction. The purpose is to provide the cori services to your group: member administration, rehearsal organisation, provision of sheet music and practice material, appointment management, attendance recording, communication within the group and learning progress.
2. Categories of data subjects
- Members of your group, including minors where you admit them
- Persons leading and administering your group
- Guests and interested persons to whom you grant temporary access
- Contact persons named by you
3. Types of personal data
- Master data: name, email address, phone number where provided, profile picture
- Group data: membership, role and permissions, voice part and voice group, joining and leaving dates
- Organisational data: appointments, acceptances and declines, attendance, setlists, tasks
- Content data: sheet music, audio and video recordings, texts and comments uploaded by you or your members
- Communication data: messages within the group
- Usage and progress data from the practice features, in so far as it is visible to the group
- Voice and singing recordings as a special category of personal data under Article 9 GDPR, in so far as they are capable of identifying a person
4. Allocation of responsibilities
Processing on your behalf under this DPA covers all operations that you control as a group: adding and removing members, assigning roles and voice parts, appointments and attendance, uploaded material, communication within the group and the resulting analyses for your group.
cori Tech GmbH acts as controller in its own right for the user account itself and the contractual relationship with the individual person: registration, authentication, account settings, billing, fraud prevention, product improvement and direct communication with the user. The basis for this is the contractual relationship with that person, not your instruction. Details are set out in our Privacy Policy.
This DPA does not establish joint controllership under Article 26 GDPR, and the parties do not intend it to.
ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES
Measures under Article 32 GDPR, as at 22 September 2026.
1. Confidentiality
- Physical access control: the systems are operated in data centres run by our sub-processors. These are certified to ISO 27001 or equivalent and have physical access control, video surveillance and visitor management. We do not operate server rooms of our own.
- System access control: authentication via individual accounts, two-factor authentication for administrative access, password policies, automatic lockout after failed attempts.
- Data access control: role and permission model based on least privilege, separate development and production environments, logging of administrative access.
- Separation control: tenant separation at application level, each group sees only the data assigned to it. Test data is not derived from production data.
- Pseudonymisation: internal identifiers instead of clear names where the function allows.
2. Integrity
- Transfer control: transport encryption using TLS on all connections between device, application and storage. Encryption of data at rest in the database and object storage.
- Input control: logging of security-relevant changes to accounts, roles and permissions with timestamp and originating account.
- Signed, expiring access links for media instead of publicly reachable addresses.
3. Availability and resilience
- Regular automated backups with a defined rotation cycle.
- Redundant storage of content data at the object storage provider.
- Monitoring of availability and error rates, alerting on incidents.
- Restoration procedures documented and tested.
4. Procedures for review and evaluation
- Data protection management: record of processing activities, assessment of new features for data protection implications before release.
- Commissioned processing control: written agreements with all sub-processors, assessment before engagement, ongoing monitoring.
- Incident management: defined reporting path, assessment and documentation of security incidents.
- Data protection by default: visibility of member data is limited to the respective group.
- Updating of dependencies in use, monitoring of known vulnerabilities.
ANNEX 3: SUB-PROCESSORS
As at 22 September 2026. Changes are announced in accordance with Section 7 of this DPA.
- Amazon Web Services EMEA SARL, Luxembourg
Service: operation of the application servers and the database on virtual servers (EC2); object storage for sheet music, audio and video files (S3); serverless processing for sheet music recognition (Lambda); model endpoints for automatic lyrics transcription (SageMaker); sending of transactional email (SES); managed database service (RDS) for the tickets.cori.music ticket shop only.
Place of processing: European Union, Frankfurt am Main region (eu-central-1). - Google Ireland Limited, Ireland (Firebase, Google Maps)
Service: authentication and sign-in, push notifications, crash reports, remote configuration, map display for locations.
Place of processing: European Union with possible processing in the United States. Basis: EU-US Data Privacy Framework and standard contractual clauses. - Stripe Payments Europe Limited, Ireland
Service: processing of payments and subscriptions, invoicing, fraud prevention.
Place of processing: European Union with possible processing in the United States. Basis: EU-US Data Privacy Framework and standard contractual clauses.
Note: for payment processing Stripe is also a controller in its own right in respect of its statutory obligations.
We operate the applications themselves on the virtual servers named above. This applies in particular to container management, the database of the cori services, the support and ticketing system and the sending of information emails. Those applications are not separate sub-processors and are therefore not listed individually here.
ANNEX 4: SUPPLEMENT FOR CHURCH CONTROLLERS
This annex applies in addition where you as Controller are subject to German church data protection law, that is the Data Protection Act of the Protestant Church in Germany (DSG-EKD) or the Act on Church Data Protection of the Catholic Church (KDG). You will tell us at the time of conclusion whether that is the case.
In that case the following applies in addition:
- References to Article 28 GDPR in this DPA apply accordingly to Section 30 DSG-EKD or Section 29 KDG.
- We undertake to comply with the requirements of the applicable church data protection law in so far as they go beyond the GDPR.
- In respect of the data processed on your behalf we submit to the supervision of the competent church data protection authority and grant it the same rights of information and inspection that Section 10 of this DPA grants you.
- Personal data breaches are notified in accordance with Section 9 of this DPA even where the notification obligation follows church law.
- Engaging further sub-processors requires that they too can be bound to church data protection law.
In the event of a conflict between this annex and the remainder of this DPA, this annex prevails in so far as church data protection law applies.
CONTACT
Please direct questions about this agreement, the allocation of roles or the technical and organisational measures to:
cori Tech GmbH
Friedhofstr. 15
67378 Zeiskam, Rhineland-Palatinate
Germany
Email: info@getcori.app