1. Parties
This DPA is between you (the Controller) and Heirloom, Inc. (the Processor). It is incorporated by reference into our Terms of Service.
2. Subject matter & duration
We process personal data on your behalf to provide the memoir capture, AI processing, storage, and delivery services described in our Terms. Processing continues for as long as your account is active, plus any retention period.
3. Nature & purpose of processing
- Account management (auth, billing, support).
- Voice transcription and translation.
- AI-assisted memoir chapter generation.
- Email communication.
- Usage analytics (aggregated).
- Fraud prevention.
4. Categories of data subjects
- Account holders (Controllers).
- Memoir subjects (parents, grandparents, relatives).
- Invited family members (read-only viewers).
- Creator program participants.
5. Categories of personal data
- Identity: name, email, phone, locale.
- Billing: billing address, partial card info via Stripe.
- Content: memoir answers, voice recordings, photos, video.
- Derived: transcripts, translations, AI-generated chapters, voice likeness models.
- Technical: IP, browser, device, timestamps.
6. Sub-processors
Current sub-processor list (we maintain a current list at /legal/privacy):
| Name | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe, Inc. | Payments | USA | PCI-DSS, SCCs |
| Resend | Transactional email | USA | SOC 2, SCCs |
| Deepgram | Voice transcription | USA | SOC 2, no retention |
| Anthropic | AI text generation | USA | SOC 2, no retention, no training |
| Cloudflare | CDN, DNS | Global | ISO 27001, SCCs |
| Railway / AWS | Application hosting | USA (optional EU) | SOC 2, ISO 27001, SCCs |
We give 30 days notice before adding or replacing a sub-processor. You may object; if we cannot accommodate, you may terminate for cause.
7. International transfers
We rely on the EU Standard Contractual Clauses (2021/914) for transfers outside the EEA, supplemented by additional safeguards (encryption, access controls). UK transfers are covered by the UK International Data Transfer Addendum.
8. Security
- TLS 1.3 in transit; AES-256 at rest.
- Role-based access control; least privilege.
- Annual penetration testing.
- Incident response program with 72-hour breach notification.
- See Security page for full controls.
9. Data subject rights
We assist you (Controller) in responding to data subject requests (access, rectification, erasure, portability) within 10 business days. Full DSAR tooling is available in your admin settings.
10. Breach notification
We will notify you without undue delay, and in any case within 72 hours, of any confirmed personal data breach. Notification includes nature of breach, affected data categories, estimated number of subjects affected, remediation steps.
11. Audit rights
Controllers (Family plan and above) may audit our compliance once per year with 30 days notice, or rely on our SOC 2 Type II report (available under NDA; target completion Q4 2026).
12. Return or deletion of data
On termination, we provide 30 days to export all data via your dashboard or API. After 30 days, we delete personal data except as required for legal retention (billing records, audit logs).
13. Liability
DPA-specific liability is as set forth in the Terms of Service §10 (Limitation of Liability).
How to sign the DPA
By accepting our Terms of Service, you accept this DPA as incorporated by reference. Enterprise customers may request a counter-signed copy at privacy@theheirloom.ai.