Data Processing Agreement
Your fan list is yours. This sets out who is responsible for what.
Trust & safety
Need help?
Last updated: 21 August 2026
Your list, and who is responsible
If you use GigXchange to build and email a fan list, this agreement covers that list — who is responsible for it, what we do with it, who else touches it, and how long we keep it. It forms part of our Terms of Service. Use the chips below to jump to any section.
GigXchange is currently in beta. These terms are subject to change as the platform evolves. We will notify registered users of any material changes via email. By using the platform during the beta period, you acknowledge that features, policies, and terms may be updated without prior notice.
In short
You build a list of people who want to hear from you. You decide who is on it and what you send. We store the list and deliver the mail.
That makes you the data controller and us your data processor. UK GDPR requires that arrangement to be written down, and this is it. It is the same structure every mailing-list service uses.
Three things follow from it, and they are the ones worth knowing:
- Everyone on your list must have given you permission. Not us — you.
- Your list is never ours. We do not market to it, sell it, or add your fans to any GigXchange list.
- You can take it or delete it whenever you like. Leaving takes your list with you.
Everything below is the detail behind those three sentences.
1. What this covers
This agreement applies to fan data — the names, email addresses and subscription details of the people on a member’s own mailing list, together with the date and method by which each was added.
It applies between you (the member holding the list) and Eclipse Labs AI Ltd, trading as GigXchange, company number 17177477, registered at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
It does not cover personal data for which GigXchange is itself responsible — your own account details, bookings, payments, our public directories, or the GigXchange mailing list. Those are covered by our Privacy Policy.
Terms such as “controller”, “processor”, “personal data” and “personal data breach” have the meanings given in the UK GDPR. “Data protection law” means the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).
2. Who is responsible for what
You are the controller of your fan list. We are your processor.
You decide the purposes: who receives your emails, what they say, and when they are sent. We decide only the technical means by which the service runs.
For the avoidance of doubt, the operational limits we apply to every member alike — how often you can send, how many people can be added in a period, anti-abuse checks, the format of outbound mail, and deletion after prolonged account dormancy — are features of the service. They do not make us a controller of your list.
Where we process personal data as a controller in our own right, this agreement does not apply and our Privacy Policy governs instead.
3. What you are responsible for
Permission. You confirm that you have a lawful basis — and, where PECR requires it, consent — for every address on your list and every message you send.
Imported addresses. Where you upload or import addresses obtained outside GigXchange, you confirm that each person gave you permission to email them and has not withdrawn it. We record that confirmation at the point of import, and you accept that the record may be produced as evidence if there is ever a complaint or a regulator asks.
Telling people. Where you obtained someone’s address from a source other than that person, data protection law requires you to tell them you hold it and where it came from. Emails we send on your behalf carry a line explaining how the recipient came to be on your list, plus a one-click unsubscribe — but that assists you, it does not discharge your obligation.
Lawful instructions. Your instructions to us must not require us to process personal data in breach of data protection law.
No unsolicited marketing. You must not use fan mailing to send unsolicited marketing, and you must follow the conduct rules in our Terms of Service.
4. What we are responsible for
4.1 We act only on your instructions. We process your fan list only as instructed by you through your use of the service and this agreement, unless the law requires otherwise — in which case we will tell you first, unless the law forbids that.
4.2 Confidentiality. Anyone with access to fan data is bound by an appropriate duty of confidentiality.
4.3 Security. We maintain the technical and organisational measures set out in section 9.
4.4 Sub-processors. We engage others only on the terms in section 5.
4.5 Helping with requests from your fans. We assist you in responding to people exercising their data protection rights. In practice we provide a self-service tool through which anyone can obtain a copy of the data held about them — including, where their address was imported, who imported it and the confirmation that member gave — and a one-click unsubscribe in every message.
4.6 Helping with security and breach duties. We assist you with your obligations on security, breach notification, impact assessments and consultation, to the extent the information is available to us.
4.7 Breach notification. If we become aware of a personal data breach affecting your fan list we will tell you without undue delay, with the information you need to meet your own obligations.
4.8 Deletion and return. When you stop using the service, or on your written request, we delete or return the fan data and delete our copies unless the law requires us to keep them. You can also delete individual fans, or the entire list, yourself at any time.
4.9 Demonstrating compliance. We make available the information you reasonably need to satisfy yourself that we meet Article 28, and will contribute to audits. We may do this by providing security documentation or written answers, and may charge reasonable costs for anything more extensive.
4.10 Unlawful instructions. If we think an instruction of yours breaches data protection law, we will tell you.
5. Others who help us deliver the service
You give us general authorisation to use sub-processors. Each is bound to obligations no less protective than these, and we remain responsible to you for what they do.
| Company | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, serverless functions, file storage | EU (West) |
| Resend | Email delivery | United States |
| Cloudflare | Delivery network, DNS, edge security | Global edge |
We will give you reasonable notice before adding or replacing a sub-processor by updating this list. If you object on reasonable data protection grounds we will discuss it in good faith; if that reaches no resolution, you may stop using the affected part of the service.
6. Data leaving the UK
Some of the companies above are outside the United Kingdom. We do not transfer fan data outside the UK unless an appropriate safeguard under Chapter V of the UK GDPR is in place — an adequacy decision, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
Email delivery through Resend involves a transfer to the United States, covered by a UK IDTA. Cloudflare operates a global edge network under its data processing addendum.
7. When we can suspend fan mailing
We may suspend your access to fan mailing, or a particular send, if we reasonably believe you are in breach of section 3 — or if your messages generate a rate of spam complaints, bounces or unsubscribes that threatens whether GigXchange mail reaches anyone at all.
We will tell you if we suspend, and where we can, what is needed to lift it.
Mail sent through the service goes out from a GigXchange domain. Under PECR the sender of a message carries regulatory responsibility for it, which is why this section exists: what one member sends affects every other member’s ability to reach their audience.
8. The processing, in detail
Set out as Article 28(3) requires.
| Subject matter | Storing your fan list and delivering email from you to that list |
|---|---|
| Duration | While your account is active, subject to section 10 |
| Nature and purpose | Collection, storage, organisation, retrieval, use and erasure, so that you can communicate with your own audience |
| Personal data | Name; email address; date added; how the address was obtained (direct sign-up or your import); subscription and unsubscribe status; a hashed identifier derived from the sign-up connection (no raw IP address is stored); where relevant, a link to your import confirmation |
| Data subjects | People who subscribed to your list, or whose address you imported. Most have no GigXchange account |
| Special category data | None. Fan lists must not be used for special category data |
9. How your list is protected
- Access control at the data layer. Row-level security restricts each member to their own list. No browser-facing role can insert or update fan records; every write passes through a server-side function that checks ownership.
- One controlled path per action. Sign-up, import, sending and unsubscribe each have a single guarded server route. Ad-hoc writes from a browser are not possible.
- Anti-abuse on sign-up. Limits per email address, per signed-in user, per originating connection and per target member, so a list cannot be populated by automated means.
- Sending is controlled server-side. Recipients are determined by our servers from your own list, with unsubscribed addresses excluded — the list is never taken from the browser. Sending frequency is enforced the same way.
- Sender integrity. Your mail carries your own profile identity. No member can send mail bearing GigXchange’s branding.
- Minimal technical identifiers. Where a connection identifier is recorded as evidence it is stored as a one-way hash. Raw IP addresses are not stored.
- Encryption. Data is encrypted in transit and at rest.
- Deletion cascades. Deleting your account deletes your fan list and the associated import confirmations.
10. How long we keep it
We keep your fan list for as long as your account is active.
If your account is inactive for 24 consecutive months we will delete your fan list, and we will tell you before that happens. A fan list has no continuing purpose once you have stopped using it. This is not a limit on how long you may keep an engaged subscriber while you are active — there is none.
Deleting your GigXchange account deletes your fan list immediately.
If someone unsubscribes we do not delete their record. We keep it in unsubscribed form so that the address cannot be added back to your list.
11. General, and how to reach us
This agreement forms part of our Terms of Service, and their provisions on liability, governing law and jurisdiction apply. Where the two conflict on the processing of fan data, this agreement takes precedence. If any part is held invalid, the rest continues.
Data protection contact: privacy@gigxchange.app
Eclipse Labs AI Ltd is registered with the UK Information Commissioner’s Office under reference ZC132441. You may complain to the ICO at any time.
See also: Terms of Service · Privacy Policy













