DPA
Data Processing Agreement
This page summarises SongCraft's standard DPA. Enterprise customers can request a fully-executed DPA on company letterhead from privacy@songcraft.app.
1. Roles
Customer is the data controller. SongCraft is the data processor for personal data processed on customer's behalf within the studio.
2. Scope of processing
- Subject matter: AI-assisted lyric writing & arrangement.
- Duration: for the term of customer's subscription, plus a 30-day deletion window.
- Nature & purpose: hosting, AI inference, payment processing.
- Categories of data subjects: customer's authorised users.
- Categories of personal data: account identifiers, lyrics, chat transcripts, billing data.
3. Sub-processors
See the up-to-date list on the GDPR page. We notify customers of new sub-processors at least 30 days in advance.
4. Security measures (Annex II)
- Encryption at rest (AES-256) and in transit (TLS 1.3).
- Row-level security on all tenant data.
- Least-privilege access; production access logged.
- Routine vulnerability scans and dependency updates.
- Incident response: critical breach notification within 72 hours.
5. International transfers
Standard Contractual Clauses (Module 2) apply where personal data is transferred outside the EEA/UK.
6. Audit rights
Customers may request our SOC 2 / ISO summaries (when available) and compliance attestations once per year, free of charge.
7. Sign a custom DPA
For an executed DPA, email privacy@songcraft.app with your company details. We typically return a signed PDF within 3 business days.
Last updated: June 2026