SongCraft
AI · Lyric Studio

DPA

Data Processing Agreement

This page summarises SongCraft's standard DPA. Enterprise customers can request a fully-executed DPA on company letterhead from privacy@songcraft.app.

1. Roles

Customer is the data controller. SongCraft is the data processor for personal data processed on customer's behalf within the studio.

2. Scope of processing

  • Subject matter: AI-assisted lyric writing & arrangement.
  • Duration: for the term of customer's subscription, plus a 30-day deletion window.
  • Nature & purpose: hosting, AI inference, payment processing.
  • Categories of data subjects: customer's authorised users.
  • Categories of personal data: account identifiers, lyrics, chat transcripts, billing data.

3. Sub-processors

See the up-to-date list on the GDPR page. We notify customers of new sub-processors at least 30 days in advance.

4. Security measures (Annex II)

  • Encryption at rest (AES-256) and in transit (TLS 1.3).
  • Row-level security on all tenant data.
  • Least-privilege access; production access logged.
  • Routine vulnerability scans and dependency updates.
  • Incident response: critical breach notification within 72 hours.

5. International transfers

Standard Contractual Clauses (Module 2) apply where personal data is transferred outside the EEA/UK.

6. Audit rights

Customers may request our SOC 2 / ISO summaries (when available) and compliance attestations once per year, free of charge.

7. Sign a custom DPA

For an executed DPA, email privacy@songcraft.app with your company details. We typically return a signed PDF within 3 business days.

Last updated: June 2026