Legal

Terms & Conditions

Last updated: August 2026

1. Introduction

These Terms and Conditions ("Terms") govern your use of the stAAAge platform ("Platform"), operated by Rhythm Labs Pty Ltd (ABN 20 677 653 637) ("Staaage", "we", "us", "our"). By creating an account or using the Platform, you ("Organisation", "you", "your") agree to be bound by these Terms.

The Platform provides event management software including supplier onboarding, advancing workflows, credential management, communications, ticketing, site planning, and related services.

2. Definitions

TermMeaning
OrganisationThe entity that creates and manages an account on the Platform
Authorised UserAny individual granted access to the Platform by an Organisation (team members, admins)
SupplierAny third party (artist, vendor, volunteer, sponsor, media, etc.) who submits information via the Platform
Organisation DataAll data, documents, files, content, and configurations uploaded or created by the Organisation or its Suppliers
EventA festival, event, or project managed through the Platform
Access PortalThe supplier-facing portal through which Suppliers interact with the Organisation

3. Account Registration and Access

3.1. You must provide accurate and complete information when creating an account. You are responsible for maintaining the confidentiality of your account credentials.

3.2. You are responsible for all activities that occur under your account and the accounts of your Authorised Users.

3.3. You must be at least 18 years of age and have the legal authority to bind the Organisation to these Terms.

3.4. You must not share accounts between individuals. Each Authorised User must have their own account.

4. Data Ownership and Intellectual Property

4.1. Your Data, Your Ownership. All Organisation Data remains the sole property of the Organisation. Staaage does not claim any ownership rights over Organisation Data.

4.2. Licence to Staaage. You grant Staaage a limited, non-exclusive, worldwide licence to host, store, process, and display Organisation Data solely for the purpose of providing the Platform services to you.

4.3. Platform IP. The Platform, including its software, design, features, documentation, and branding, is and remains the intellectual property of Staaage. Nothing in these Terms transfers any Platform IP to you.

4.4. Feedback. If you provide suggestions, feature requests, or other feedback about the Platform, Staaage may use this feedback without obligation to you.

4.5. Data Export. You may export your Organisation Data at any time during an active subscription via the Platform's export tools. Upon request, Staaage will provide reasonable assistance with data export for a period of 28 days following account suspension or termination.

5. Data Security and Storage

5.1. Organisation Data is stored securely on Google Cloud Platform (GCP) infrastructure, in the australia-southeast1 (Sydney) region unless otherwise specified.

5.2. Staaage implements industry-standard security measures including:

  • Encryption at rest and in transit (TLS 1.2+)
  • Firebase Authentication for identity management
  • Role-based access controls
  • Audit logging of administrative actions
  • Regular security reviews

5.3. Staaage will promptly notify the Organisation of any confirmed data breach affecting Organisation Data, and will cooperate with the Organisation in investigating and remediating the breach.

5.4. Staaage does not access, review, or use Organisation Data except as necessary to provide the Platform services, comply with applicable law, or respond to support requests initiated by the Organisation.

6. Subscription and Payment

6.1. Access to the Platform is provided on a subscription basis. Pricing, billing frequency, and included features are set out in your subscription plan.

6.2. All fees are quoted in Australian Dollars (AUD) unless otherwise agreed.

6.3. Invoices are due within 14 days of issue unless otherwise stated on the invoice.

Payment Failure — Graduated Lockout

TimelineAccess Level
Days 1–28 (grace period)Full access continues. Staaage will send payment reminders at days 7, 14, and 21.
Days 29–90 (restricted)Read-only access. No new content, communications, or automations. Existing data remains accessible.
Days 91–365 (archived)All data is archived and access is suspended. Contact support@staaage.com to request access or arrange payment. Reactivation fee may apply.
After 12 months (deletion)All Organisation Data is permanently deleted. This is irreversible.

6.5. Staaage will provide written notice at each stage transition (restriction, archival, and prior to deletion). The Organisation will receive at least 30 days' notice before permanent deletion.

6.6. The Organisation may reactivate their account at any time before deletion by settling outstanding invoices and any applicable reactivation fees.

7. Service Level Agreement (SLA)

7.1. Uptime Commitment. Staaage commits to 99.5% monthly uptime for the Platform, measured as total minutes in the calendar month minus downtime, divided by total minutes in the month.

7.2. Exclusions. The following are excluded from uptime calculations:

  • Scheduled maintenance (with at least 24 hours' advance notice, performed outside peak hours where possible)
  • Emergency maintenance required to address security vulnerabilities
  • Force majeure events (natural disasters, pandemic, war, government action)
  • Third-party service outages (GCP, Firebase, SendGrid, internet providers)
  • Issues caused by the Organisation's own systems, network, or equipment

7.3. Service Credits. If monthly uptime falls below the committed SLA, the Organisation is entitled to service credits as follows:

Monthly UptimeService Credit
99.0% – 99.49%5% of monthly subscription fee
95.0% – 98.99%15% of monthly subscription fee
Below 95.0%30% of monthly subscription fee

7.4. Service credits are applied to the next billing cycle and must be requested within 30 days of the affected period. Credits do not exceed 30% of the monthly fee and are not redeemable for cash.

7.5. Incident Response. Staaage will use commercially reasonable efforts to respond to service incidents within the following timeframes:

SeverityDescriptionResponse Time
CriticalPlatform completely unavailableWithin 1 hour
HighMajor feature unavailable, no workaroundWithin 4 hours
MediumFeature impaired, workaround availableWithin 1 business day
LowMinor issue, cosmetic defectWithin 3 business days

7.6. Communication. During service incidents, Staaage will provide status updates via email to Organisation administrators. A public status page may also be maintained at the discretion of Staaage.

7.7. Support Hours. Technical support is available via support@staaage.com during Australian Eastern Standard Time (AEST/AEDT) business hours, Monday to Friday, 9:00 AM – 5:00 PM. Critical incidents are monitored 24/7.

8. Acceptable Use

8.1. You agree not to use the Platform to:

  • Upload or distribute unlawful, harmful, threatening, abusive, defamatory, or objectionable content
  • Collect or process personal information in violation of applicable privacy laws
  • Attempt to gain unauthorised access to any part of the Platform or its infrastructure
  • Reverse engineer, decompile, or disassemble any part of the Platform
  • Use the Platform for any purpose other than legitimate event management
  • Send unsolicited commercial communications (spam) via the Platform's messaging features
  • Exceed reasonable usage limits or attempt to disrupt the Platform's performance

8.2. Staaage reserves the right to suspend or terminate accounts that violate this acceptable use policy, with or without notice depending on the severity of the violation.

9. Supplier and Participant Data

9.1. The Organisation acts as the data controller for all personal information collected from Suppliers via the Platform (application forms, documents, compliance materials, etc.).

9.2. Staaage acts as a data processor, processing Supplier data on the Organisation's behalf and in accordance with the Organisation's instructions.

9.3. The Organisation is responsible for:

  • Ensuring it has a lawful basis to collect and process Supplier personal information
  • Providing appropriate privacy notices to Suppliers
  • Responding to data access, correction, or deletion requests from Suppliers
  • Complying with all applicable privacy legislation (including the Australian Privacy Act 1988 and, where applicable, the EU General Data Protection Regulation)

9.4. Staaage will:

  • Process Supplier data only as instructed by the Organisation and as necessary to provide the Platform services
  • Not sell, rent, or share Supplier data with third parties for marketing purposes
  • Assist the Organisation in responding to data subject requests where reasonably practicable
  • Delete or return Supplier data upon termination of the Organisation's subscription, subject to the data retention schedule in clause 6

10. GDPR Compliance

10.1. Where the Organisation or its Suppliers are located in the European Economic Area (EEA), United Kingdom, or Switzerland, and the processing of personal data is subject to the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the UK GDPR, the following additional provisions apply:

10.1.1 Roles and Lawful Basis

The Organisation is the data controller under Article 4(7) GDPR. Staaage is the data processor under Article 4(8). The Organisation must determine and document its lawful basis for processing (e.g. consent, legitimate interest, or contractual necessity) before collecting personal data via the Platform.

10.1.2 Data Processing Agreement

These Terms serve as the data processing agreement between the Organisation (controller) and Staaage (processor) as required by Article 28 GDPR. Staaage will:

  • Process personal data only on documented instructions from the Organisation
  • Ensure that persons authorised to process personal data have committed to confidentiality
  • Implement appropriate technical and organisational security measures (Article 32)
  • Not engage another processor without prior written authorisation from the Organisation (sub-processors are listed in clause 11)
  • Assist the Organisation in fulfilling its obligations under Articles 15–22 (data subject rights), Article 32 (security), Articles 33–34 (breach notification), and Articles 35–36 (DPIA)
  • At the Organisation's choice, delete or return all personal data after the end of the provision of services
  • Make available to the Organisation all information necessary to demonstrate compliance with Article 28

10.1.3 International Transfers

Primary data storage is in Australia (GCP australia-southeast1). Where personal data is transferred outside the EEA (e.g. to sub-processors in the United States), Staaage ensures adequate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission
  • Sub-processor adherence to recognised frameworks (SOC 2, ISO 27001)
  • Supplementary measures where required by Schrems II guidance

10.1.4 Data Subject Rights

Staaage will assist the Organisation in responding to data subject requests under Articles 15–22 GDPR, including the right of access, rectification, erasure, restriction, portability, and objection. Requests from data subjects should be directed to the Organisation as data controller.

10.1.5 Data Protection Impact Assessments

Where required by Article 35 GDPR, Staaage will provide the Organisation with reasonable assistance in conducting Data Protection Impact Assessments relating to the Platform's processing activities.

10.1.6 Breach Notification

Staaage will notify the Organisation without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting Organisation Data, as required by Article 33 GDPR.

11. Sub-processors

11.1. Staaage uses the following sub-processors to provide the Platform:

Sub-processorPurposeLocation
Google Cloud Platform (GCP)Infrastructure, hosting, database (Firestore), file storage (Cloud Storage)Australia (Sydney)
Firebase (Google)Authentication, real-time database, Cloud FunctionsAustralia (Sydney)
SendGrid (Twilio)Transactional email deliveryUnited States
StripePayment processing (for ticketing features)Global

11.2. Staaage will notify the Organisation of any material changes to sub-processors. The Organisation may object to a new sub-processor within 30 days of notification.

12. Limitation of Liability

12.1. To the maximum extent permitted by law, Staaage's total aggregate liability arising from or related to these Terms or the Platform shall not exceed the total fees paid by the Organisation in the 12 months immediately preceding the event giving rise to the claim.

12.2. Staaage shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business, or goodwill.

12.3. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for fraud, death or personal injury caused by negligence, or statutory consumer guarantees under the Australian Consumer Law.

13. Indemnification

13.1. The Organisation agrees to indemnify, defend, and hold harmless Staaage and its directors, officers, employees, and contractors from and against any claims, losses, damages, liabilities, and expenses (including reasonable legal fees) arising from:

  • The Organisation's use of the Platform
  • The Organisation's breach of these Terms
  • The Organisation's collection, use, or disclosure of personal information via the Platform
  • Any dispute between the Organisation and its Suppliers

14. Termination

14.1. Either party may terminate these Terms by providing 30 days' written notice.

14.2. Staaage may terminate or suspend access immediately if the Organisation:

  • Materially breaches these Terms and fails to remedy the breach within 14 days of notice
  • Becomes insolvent, enters administration, or is wound up
  • Uses the Platform in a way that threatens the security or integrity of the Platform

14.3. Upon termination:

  • The Organisation may export Organisation Data within 28 days
  • After 28 days, Organisation Data will be handled in accordance with the data retention schedule in clause 6
  • All licences granted under these Terms immediately cease

15. Changes to Terms

15.1. Staaage may update these Terms from time to time. We will provide at least 30 days' notice of material changes via email to the Organisation's primary contact.

15.2. Continued use of the Platform after the effective date of updated Terms constitutes acceptance of those Terms.

15.3. If the Organisation does not agree to updated Terms, it may terminate its subscription in accordance with clause 14.

16. Governing Law and Disputes

16.1. These Terms are governed by and construed in accordance with the laws of South Australia, Australia.

16.2. The parties submit to the non-exclusive jurisdiction of the courts of South Australia.

16.3. Before commencing court proceedings, the parties agree to attempt to resolve disputes in good faith through negotiation for a period of at least 30 days.

17. General

17.1. Entire Agreement. These Terms, together with the Privacy Policy and any subscription agreement, constitute the entire agreement between the parties.

17.2. Severability. If any provision of these Terms is found to be invalid or unenforceable, the remaining provisions continue in full force and effect.

17.3. Assignment. The Organisation may not assign its rights or obligations under these Terms without Staaage's prior written consent. Staaage may assign its rights in connection with a merger, acquisition, or sale of all or substantially all of its assets.

17.4. Waiver. Failure to enforce any right under these Terms does not constitute a waiver of that right.

17.5. Notices. Notices under these Terms may be sent by email to the Organisation's primary contact email address or to support@staaage.com for notices to Staaage.

Contact

Rhythm Labs Pty Ltd (ABN 20 677 653 637)

Email: support@staaage.com

Website: staaage.com