Legal

Data Processing Agreement

GDPR Article 28 & CCPA-compliant terms for how we handle data on your behalf.

1. Parties

This DPA is between you (the Controller) and Heirloom, Inc. (the Processor). It is incorporated by reference into our Terms of Service.

2. Subject matter & duration

We process personal data on your behalf to provide the memoir capture, AI processing, storage, and delivery services described in our Terms. Processing continues for as long as your account is active, plus any retention period.

3. Nature & purpose of processing

4. Categories of data subjects

5. Categories of personal data

6. Sub-processors

Current sub-processor list (we maintain a current list at /legal/privacy):

NamePurposeLocationSafeguards
Stripe, Inc.PaymentsUSAPCI-DSS, SCCs
ResendTransactional emailUSASOC 2, SCCs
DeepgramVoice transcriptionUSASOC 2, no retention
AnthropicAI text generationUSASOC 2, no retention, no training
CloudflareCDN, DNSGlobalISO 27001, SCCs
Railway / AWSApplication hostingUSA (optional EU)SOC 2, ISO 27001, SCCs

We give 30 days notice before adding or replacing a sub-processor. You may object; if we cannot accommodate, you may terminate for cause.

7. International transfers

We rely on the EU Standard Contractual Clauses (2021/914) for transfers outside the EEA, supplemented by additional safeguards (encryption, access controls). UK transfers are covered by the UK International Data Transfer Addendum.

8. Security

9. Data subject rights

We assist you (Controller) in responding to data subject requests (access, rectification, erasure, portability) within 10 business days. Full DSAR tooling is available in your admin settings.

10. Breach notification

We will notify you without undue delay, and in any case within 72 hours, of any confirmed personal data breach. Notification includes nature of breach, affected data categories, estimated number of subjects affected, remediation steps.

11. Audit rights

Controllers (Family plan and above) may audit our compliance once per year with 30 days notice, or rely on our SOC 2 Type II report (available under NDA; target completion Q4 2026).

12. Return or deletion of data

On termination, we provide 30 days to export all data via your dashboard or API. After 30 days, we delete personal data except as required for legal retention (billing records, audit logs).

13. Liability

DPA-specific liability is as set forth in the Terms of Service §10 (Limitation of Liability).

How to sign the DPA

By accepting our Terms of Service, you accept this DPA as incorporated by reference. Enterprise customers may request a counter-signed copy at privacy@theheirloom.ai.