Skip to main content
For families who want their stories to last. learn about the founding circle.
← Trust Centre
Honest posture

DPA template

A baseline Data Processing Addendum, ready to sign.

This is our baseline DPA. Family-plan customers can sign it as it stands, and Enterprise customers can negotiate it through counsel. The ten sections below are a short preview of the bound document, and three lines in its Annex II are deliberately left open because we won't warrant something we haven't done yet.
Version: 2026-Q2GDPR + UK GDPR + LGPDSCC 2021/914 + UK DTA

If we can’t keep a promise yet, it gets written here first.

Download

Get the PDF. Sign it as it stands.

Download DPA template (PDF)
PDF · 13 KB · 5 pages
Last revised: 2026-04-23
The PDF is built from the same source as the preview below. What you download matches what you see here. Counsel reviews the final version before publication.

Preview

Ten sections, at a glance.

  1. 1. Definitions

    Plain-language definitions of Controller, Processor, Sub-processor, Personal Data, Processing, Special Category Data, and Data Subject, aligned with GDPR Article 4 and UK GDPR.
  2. 2. Subject matter and duration

    The processing covered by this DPA is the performance of the Confinity service. Duration tracks the underlying service agreement.
  3. 3. Nature and purpose of processing

    Confinity processes customer personal data to provide the service: authentication, memory storage and retrieval, messaging, billing, and customer support.
  4. 4. Categories of data subjects and personal data

    Customer, authorised users of the customer, contributors to a memorial created by the customer. Data categories: identifiers, account metadata, entry bodies, voice samples (ephemeral), contributor names.
  5. 5. Sub-processor engagement

    Confinity engages sub-processors listed at /trust/centre/subprocessors. New sub-processors that touch customer content trigger a 14-day notice window to the customer.
  6. 6. International transfers

    Transfers outside the EEA / UK rely on the Standard Contractual Clauses (2021/914) + UK DTA as appropriate. SCC modules per sub-processor are listed on the Sub-processors page and in /legal/scc-dta.
  7. 7. Security measures

    TLS in transit, least-privilege access, MFA on admin consoles, a written incident-response plan with a 30-minute paging ladder. Three lines in Annex II are left open on purpose and have to be filled in before anybody signs: encryption at rest, restore-drill cadence, and the date of the first external penetration test. We'd rather hand you a template with three honest gaps in it than one that warrants something we haven't done.
  8. 8. Data-subject requests

    Confinity assists the customer in responding to data-subject requests within the 30-day statutory window. DSARs can be raised at /app/settings/privacy or by email to privacy@confinity.com.
  9. 9. Personal data breach

    Confinity notifies the customer without undue delay, and in any event inside 72 hours of becoming aware of a personal data breach. GDPR Article 33.
  10. 10. Deletion and return

    On termination, Confinity returns customer data in an open export format and deletes remaining copies inside 30 days. Copies sitting in hosting-platform backups age out on that platform's retention setting. Annex II leaves that figure open until it's confirmed.

How to sign

For Family plans, download the PDF and sign it. That's your side done. Return it to privacy@confinity.com and we'll counter-sign inside five business days. For Enterprise plans, talk to us before signing.

More honesty

Looking for more?

The Trust Centre indexes every honest document we publish, and the binding legal ones sit below it.