Terms & Conditions
Last updated: August 2026
1. Introduction
These Terms and Conditions ("Terms") govern your use of the stAAAge platform ("Platform"), operated by Rhythm Labs Pty Ltd (ABN 20 677 653 637) ("Staaage", "we", "us", "our"). By creating an account or using the Platform, you ("Organisation", "you", "your") agree to be bound by these Terms.
The Platform provides event management software including supplier onboarding, advancing workflows, credential management, communications, ticketing, site planning, and related services.
2. Definitions
| Term | Meaning |
|---|---|
| Organisation | The entity that creates and manages an account on the Platform |
| Authorised User | Any individual granted access to the Platform by an Organisation (team members, admins) |
| Supplier | Any third party (artist, vendor, volunteer, sponsor, media, etc.) who submits information via the Platform |
| Organisation Data | All data, documents, files, content, and configurations uploaded or created by the Organisation or its Suppliers |
| Event | A festival, event, or project managed through the Platform |
| Access Portal | The supplier-facing portal through which Suppliers interact with the Organisation |
3. Account Registration and Access
3.1. You must provide accurate and complete information when creating an account. You are responsible for maintaining the confidentiality of your account credentials.
3.2. You are responsible for all activities that occur under your account and the accounts of your Authorised Users.
3.3. You must be at least 18 years of age and have the legal authority to bind the Organisation to these Terms.
3.4. You must not share accounts between individuals. Each Authorised User must have their own account.
4. Data Ownership and Intellectual Property
4.1. Your Data, Your Ownership. All Organisation Data remains the sole property of the Organisation. Staaage does not claim any ownership rights over Organisation Data.
4.2. Licence to Staaage. You grant Staaage a limited, non-exclusive, worldwide licence to host, store, process, and display Organisation Data solely for the purpose of providing the Platform services to you.
4.3. Platform IP. The Platform, including its software, design, features, documentation, and branding, is and remains the intellectual property of Staaage. Nothing in these Terms transfers any Platform IP to you.
4.4. Feedback. If you provide suggestions, feature requests, or other feedback about the Platform, Staaage may use this feedback without obligation to you.
4.5. Data Export. You may export your Organisation Data at any time during an active subscription via the Platform's export tools. Upon request, Staaage will provide reasonable assistance with data export for a period of 28 days following account suspension or termination.
5. Data Security and Storage
5.1. Organisation Data is stored securely on Google Cloud Platform (GCP) infrastructure, in the australia-southeast1 (Sydney) region unless otherwise specified.
5.2. Staaage implements industry-standard security measures including:
- Encryption at rest and in transit (TLS 1.2+)
- Firebase Authentication for identity management
- Role-based access controls
- Audit logging of administrative actions
- Regular security reviews
5.3. Staaage will promptly notify the Organisation of any confirmed data breach affecting Organisation Data, and will cooperate with the Organisation in investigating and remediating the breach.
5.4. Staaage does not access, review, or use Organisation Data except as necessary to provide the Platform services, comply with applicable law, or respond to support requests initiated by the Organisation.
6. Subscription and Payment
6.1. Access to the Platform is provided on a subscription basis. Pricing, billing frequency, and included features are set out in your subscription plan.
6.2. All fees are quoted in Australian Dollars (AUD) unless otherwise agreed.
6.3. Invoices are due within 14 days of issue unless otherwise stated on the invoice.
Payment Failure — Graduated Lockout
| Timeline | Access Level |
|---|---|
| Days 1–28 (grace period) | Full access continues. Staaage will send payment reminders at days 7, 14, and 21. |
| Days 29–90 (restricted) | Read-only access. No new content, communications, or automations. Existing data remains accessible. |
| Days 91–365 (archived) | All data is archived and access is suspended. Contact support@staaage.com to request access or arrange payment. Reactivation fee may apply. |
| After 12 months (deletion) | All Organisation Data is permanently deleted. This is irreversible. |
6.5. Staaage will provide written notice at each stage transition (restriction, archival, and prior to deletion). The Organisation will receive at least 30 days' notice before permanent deletion.
6.6. The Organisation may reactivate their account at any time before deletion by settling outstanding invoices and any applicable reactivation fees.
7. Service Level Agreement (SLA)
7.1. Uptime Commitment. Staaage commits to 99.5% monthly uptime for the Platform, measured as total minutes in the calendar month minus downtime, divided by total minutes in the month.
7.2. Exclusions. The following are excluded from uptime calculations:
- Scheduled maintenance (with at least 24 hours' advance notice, performed outside peak hours where possible)
- Emergency maintenance required to address security vulnerabilities
- Force majeure events (natural disasters, pandemic, war, government action)
- Third-party service outages (GCP, Firebase, SendGrid, internet providers)
- Issues caused by the Organisation's own systems, network, or equipment
7.3. Service Credits. If monthly uptime falls below the committed SLA, the Organisation is entitled to service credits as follows:
| Monthly Uptime | Service Credit |
|---|---|
| 99.0% – 99.49% | 5% of monthly subscription fee |
| 95.0% – 98.99% | 15% of monthly subscription fee |
| Below 95.0% | 30% of monthly subscription fee |
7.4. Service credits are applied to the next billing cycle and must be requested within 30 days of the affected period. Credits do not exceed 30% of the monthly fee and are not redeemable for cash.
7.5. Incident Response. Staaage will use commercially reasonable efforts to respond to service incidents within the following timeframes:
| Severity | Description | Response Time |
|---|---|---|
| Critical | Platform completely unavailable | Within 1 hour |
| High | Major feature unavailable, no workaround | Within 4 hours |
| Medium | Feature impaired, workaround available | Within 1 business day |
| Low | Minor issue, cosmetic defect | Within 3 business days |
7.6. Communication. During service incidents, Staaage will provide status updates via email to Organisation administrators. A public status page may also be maintained at the discretion of Staaage.
7.7. Support Hours. Technical support is available via support@staaage.com during Australian Eastern Standard Time (AEST/AEDT) business hours, Monday to Friday, 9:00 AM – 5:00 PM. Critical incidents are monitored 24/7.
8. Acceptable Use
8.1. You agree not to use the Platform to:
- Upload or distribute unlawful, harmful, threatening, abusive, defamatory, or objectionable content
- Collect or process personal information in violation of applicable privacy laws
- Attempt to gain unauthorised access to any part of the Platform or its infrastructure
- Reverse engineer, decompile, or disassemble any part of the Platform
- Use the Platform for any purpose other than legitimate event management
- Send unsolicited commercial communications (spam) via the Platform's messaging features
- Exceed reasonable usage limits or attempt to disrupt the Platform's performance
8.2. Staaage reserves the right to suspend or terminate accounts that violate this acceptable use policy, with or without notice depending on the severity of the violation.
9. Supplier and Participant Data
9.1. The Organisation acts as the data controller for all personal information collected from Suppliers via the Platform (application forms, documents, compliance materials, etc.).
9.2. Staaage acts as a data processor, processing Supplier data on the Organisation's behalf and in accordance with the Organisation's instructions.
9.3. The Organisation is responsible for:
- Ensuring it has a lawful basis to collect and process Supplier personal information
- Providing appropriate privacy notices to Suppliers
- Responding to data access, correction, or deletion requests from Suppliers
- Complying with all applicable privacy legislation (including the Australian Privacy Act 1988 and, where applicable, the EU General Data Protection Regulation)
9.4. Staaage will:
- Process Supplier data only as instructed by the Organisation and as necessary to provide the Platform services
- Not sell, rent, or share Supplier data with third parties for marketing purposes
- Assist the Organisation in responding to data subject requests where reasonably practicable
- Delete or return Supplier data upon termination of the Organisation's subscription, subject to the data retention schedule in clause 6
10. GDPR Compliance
10.1. Where the Organisation or its Suppliers are located in the European Economic Area (EEA), United Kingdom, or Switzerland, and the processing of personal data is subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the UK GDPR, the following additional provisions apply:
10.1.1 Roles and Lawful Basis
The Organisation is the data controller under Article 4(7) GDPR. Staaage is the data processor under Article 4(8). The Organisation must determine and document its lawful basis for processing (e.g. consent, legitimate interest, or contractual necessity) before collecting personal data via the Platform.
10.1.2 Data Processing Agreement
These Terms serve as the data processing agreement between the Organisation (controller) and Staaage (processor) as required by Article 28 GDPR. Staaage will:
- Process personal data only on documented instructions from the Organisation
- Ensure that persons authorised to process personal data have committed to confidentiality
- Implement appropriate technical and organisational security measures (Article 32)
- Not engage another processor without prior written authorisation from the Organisation (sub-processors are listed in clause 11)
- Assist the Organisation in fulfilling its obligations under Articles 15–22 (data subject rights), Article 32 (security), Articles 33–34 (breach notification), and Articles 35–36 (DPIA)
- At the Organisation's choice, delete or return all personal data after the end of the provision of services
- Make available to the Organisation all information necessary to demonstrate compliance with Article 28
10.1.3 International Transfers
Primary data storage is in Australia (GCP australia-southeast1). Where personal data is transferred outside the EEA (e.g. to sub-processors in the United States), Staaage ensures adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission
- Sub-processor adherence to recognised frameworks (SOC 2, ISO 27001)
- Supplementary measures where required by Schrems II guidance
10.1.4 Data Subject Rights
Staaage will assist the Organisation in responding to data subject requests under Articles 15–22 GDPR, including the right of access, rectification, erasure, restriction, portability, and objection. Requests from data subjects should be directed to the Organisation as data controller.
10.1.5 Data Protection Impact Assessments
Where required by Article 35 GDPR, Staaage will provide the Organisation with reasonable assistance in conducting Data Protection Impact Assessments relating to the Platform's processing activities.
10.1.6 Breach Notification
Staaage will notify the Organisation without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting Organisation Data, as required by Article 33 GDPR.
11. Sub-processors
11.1. Staaage uses the following sub-processors to provide the Platform:
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Infrastructure, hosting, database (Firestore), file storage (Cloud Storage) | Australia (Sydney) |
| Firebase (Google) | Authentication, real-time database, Cloud Functions | Australia (Sydney) |
| SendGrid (Twilio) | Transactional email delivery | United States |
| Stripe | Payment processing (for ticketing features) | Global |
11.2. Staaage will notify the Organisation of any material changes to sub-processors. The Organisation may object to a new sub-processor within 30 days of notification.
12. Limitation of Liability
12.1. To the maximum extent permitted by law, Staaage's total aggregate liability arising from or related to these Terms or the Platform shall not exceed the total fees paid by the Organisation in the 12 months immediately preceding the event giving rise to the claim.
12.2. Staaage shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business, or goodwill.
12.3. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for fraud, death or personal injury caused by negligence, or statutory consumer guarantees under the Australian Consumer Law.
13. Indemnification
13.1. The Organisation agrees to indemnify, defend, and hold harmless Staaage and its directors, officers, employees, and contractors from and against any claims, losses, damages, liabilities, and expenses (including reasonable legal fees) arising from:
- The Organisation's use of the Platform
- The Organisation's breach of these Terms
- The Organisation's collection, use, or disclosure of personal information via the Platform
- Any dispute between the Organisation and its Suppliers
14. Termination
14.1. Either party may terminate these Terms by providing 30 days' written notice.
14.2. Staaage may terminate or suspend access immediately if the Organisation:
- Materially breaches these Terms and fails to remedy the breach within 14 days of notice
- Becomes insolvent, enters administration, or is wound up
- Uses the Platform in a way that threatens the security or integrity of the Platform
14.3. Upon termination:
- The Organisation may export Organisation Data within 28 days
- After 28 days, Organisation Data will be handled in accordance with the data retention schedule in clause 6
- All licences granted under these Terms immediately cease
15. Changes to Terms
15.1. Staaage may update these Terms from time to time. We will provide at least 30 days' notice of material changes via email to the Organisation's primary contact.
15.2. Continued use of the Platform after the effective date of updated Terms constitutes acceptance of those Terms.
15.3. If the Organisation does not agree to updated Terms, it may terminate its subscription in accordance with clause 14.
16. Governing Law and Disputes
16.1. These Terms are governed by and construed in accordance with the laws of South Australia, Australia.
16.2. The parties submit to the non-exclusive jurisdiction of the courts of South Australia.
16.3. Before commencing court proceedings, the parties agree to attempt to resolve disputes in good faith through negotiation for a period of at least 30 days.
17. General
17.1. Entire Agreement. These Terms, together with the Privacy Policy and any subscription agreement, constitute the entire agreement between the parties.
17.2. Severability. If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions continue in full force and effect.
17.3. Assignment. The Organisation may not assign its rights or obligations under these Terms without Staaage's prior written consent. Staaage may assign its rights in connection with a merger, acquisition, or sale of all or substantially all of its assets.
17.4. Waiver. Failure to enforce any right under these Terms does not constitute a waiver of that right.
17.5. Notices. Notices under these Terms may be sent by email to the Organisation's primary contact email address or to support@staaage.com for notices to Staaage.