Data Protection Roles and Limited Processor Terms
Last updated: September 8, 2026
Purpose and role allocation
This document explains the data-protection roles that apply when gigiii is used. It is not a statement that Moore World Wide Enterprises, LLC ("gigiii", "we", "us") is a processor for every use of the platform.
gigiii determines the essential purposes and means of processing needed to operate, secure, moderate, improve and meet legal obligations for the marketplace. For those activities, gigiii is an independent controller. Our Privacy Policy describes that processing.
Members normally decide independently why and how they use another member's information after it is disclosed to them. In that situation, the members are normally separate controllers. Nothing in these terms creates a joint-controller relationship.
The processor terms below apply only where all of the following are true: (1) a member is a controller of personal data about another person; (2) gigiii processes that data solely to provide a requested platform function; and (3) gigiii acts on that member's documented instructions. A tailored written agreement is required where the intended processing is broader or materially different.
Limited processing terms
For the limited processing described above, the member is the Controller and Moore World Wide Enterprises, LLC is the Processor. These terms form an agreement under Article 28 GDPR when they apply.
Subject matter, duration and purpose
The subject matter is the provision of the relevant gigiii marketplace feature, such as storing and displaying booking-related contact, profile or event information supplied by the Controller. Processing starts when the Controller supplies the data and continues for the membership and any legally required retention period. The purpose is to provide the feature requested by the Controller, not to use the data for an unrelated purpose.
The processing may include collection, recording, organisation, storage, retrieval, consultation, transmission to authorised recipients, restriction, anonymisation and deletion. It may concern professional identity and contact details, profile and booking information, communications, availability, agreement metadata and technical logs. It may concern the Controller's personnel, representatives, performers, venue contacts, guests or other contacts whose information the Controller supplies. The Controller remains responsible for its instructions, legal basis, notices to data subjects and the accuracy of the data it provides.
The service is not designed for special-category data under Article 9 GDPR or criminal-offence data under Article 10 GDPR. The Controller must not provide those data unless a separate written agreement and appropriate safeguards have been agreed.
Instructions and confidentiality
gigiii shall process the relevant personal data only on the Controller's documented instructions, including instructions concerning transfers to a third country or international organisation, unless Union or Member State law requires processing. Where legally permitted, gigiii shall inform the Controller before processing required by that law.
Persons authorised by gigiii to process personal data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
Security
gigiii shall implement appropriate technical and organisational measures under Article 32 GDPR, taking account of the risks of the processing. These measures include access controls and role-based permissions, encryption in transit, encrypted managed storage where supported by the provider, authentication protections, logging and incident-response procedures, and backup and recovery measures appropriate to the service. gigiii may improve these measures, but will not materially reduce their overall protection for the processing without a lawful basis and prior notice where required.
Sub-processors
The Controller gives general written authorisation for the providers listed on our Sub-processors and Service Providers page. gigiii will give at least 30 days' prior notice by email and on that page before adding or replacing a sub-processor that processes the Controller's data. The Controller may object on reasonable data-protection grounds during that period. If the parties cannot resolve a justified objection, the Controller may stop using the affected feature or terminate it.
gigiii shall bind each sub-processor to data-protection obligations that are no less protective for the relevant processing than those in these terms, and remains responsible for that sub-processor's performance of those obligations.
Assistance, incidents and audits
Taking account of the nature of processing and the information available, gigiii shall provide reasonable assistance for the Controller's obligations under GDPR Chapter III and Articles 32 to 36. If gigiii receives a request directly from a data subject concerning Controller data, it shall forward the request to the Controller unless legally required to respond.
gigiii shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data and provide available information needed for the Controller's assessment and notification duties.
On reasonable written request, gigiii shall make available information necessary to demonstrate compliance with these terms and permit audits, including inspections by the Controller or an independent auditor bound by confidentiality. Routine audits are limited to once per calendar year, on at least 30 days' notice, during normal business hours and without unreasonable disruption. This does not limit a regulator's powers or an audit reasonably required after a material incident.
End of processing and transfers
At the Controller's choice on termination of the affected feature, gigiii shall return or delete Controller data, unless Union or Member State law requires retention. Data held in backup systems will be protected and removed through ordinary backup rotation; where restored, it will be deleted again unless retention is legally required.
Where the limited processing involves a transfer outside the EEA, gigiii shall use a lawful Chapter V transfer mechanism. The current providers, locations and transfer information are published on our Sub-processors and Service Providers page. These terms do not themselves execute the EU Standard Contractual Clauses; where SCCs are required, the parties must identify the appropriate module and complete the required annexes separately.
Contact
Questions about these terms or data protection can be sent to gdpr@gigiii.com or hello@gigiii.com.