A baseline Data Processing Addendum, ready to sign.
This is our baseline DPA. Family-plan customers can sign it as it stands, and Enterprise customers can negotiate it through counsel. The ten sections below are a short preview of the bound document, and three lines in its Annex II are deliberately left open because we won't warrant something we haven't done yet.
Version: 2026-Q2GDPR + UK GDPR + LGPDSCC 2021/914 + UK DTA
If we can’t keep a promise yet, it gets written here first.
The PDF is built from the same source as the preview below. What you download matches what you see here. Counsel reviews the final version before publication.
Preview
Ten sections, at a glance.
1. Definitions
Plain-language definitions of Controller, Processor, Sub-processor, Personal Data, Processing, Special Category Data, and Data Subject, aligned with GDPR Article 4 and UK GDPR.
2. Subject matter and duration
The processing covered by this DPA is the performance of the Confinity service. Duration tracks the underlying service agreement.
3. Nature and purpose of processing
Confinity processes customer personal data to provide the service: authentication, memory storage and retrieval, messaging, billing, and customer support.
4. Categories of data subjects and personal data
Customer, authorised users of the customer, contributors to a memorial created by the customer. Data categories: identifiers, account metadata, entry bodies, voice samples (ephemeral), contributor names.
5. Sub-processor engagement
Confinity engages sub-processors listed at /trust/centre/subprocessors. New sub-processors that touch customer content trigger a 14-day notice window to the customer.
6. International transfers
Transfers outside the EEA / UK rely on the Standard Contractual Clauses (2021/914) + UK DTA as appropriate. SCC modules per sub-processor are listed on the Sub-processors page and in /legal/scc-dta.
7. Security measures
TLS in transit, least-privilege access, MFA on admin consoles, a written incident-response plan with a 30-minute paging ladder. Three lines in Annex II are left open on purpose and have to be filled in before anybody signs: encryption at rest, restore-drill cadence, and the date of the first external penetration test. We'd rather hand you a template with three honest gaps in it than one that warrants something we haven't done.
8. Data-subject requests
Confinity assists the customer in responding to data-subject requests within the 30-day statutory window. DSARs can be raised at /app/settings/privacy or by email to privacy@confinity.com.
9. Personal data breach
Confinity notifies the customer without undue delay, and in any event inside 72 hours of becoming aware of a personal data breach. GDPR Article 33.
10. Deletion and return
On termination, Confinity returns customer data in an open export format and deletes remaining copies inside 30 days. Copies sitting in hosting-platform backups age out on that platform's retention setting. Annex II leaves that figure open until it's confirmed.
How to sign
For Family plans, download the PDF and sign it. That's your side done. Return it to privacy@confinity.com and we'll counter-sign inside five business days. For Enterprise plans, talk to us before signing.
More honesty
Looking for more?
The Trust Centre indexes every honest document we publish, and the binding legal ones sit below it.