STAGING · test data · Stripe TEST mode (card 4242 4242 4242 4242) · no email is sent

Legal · Porchlight

Data Processing Addendum

Last updated
Effective date
Version
1.1 (2026-09-26)

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between the Customer (the “Controller”) and Levelbrook Consulting, which operates Porchlight (the “Processor”, “Porchlight”, or “we”). It governs our processing of personal data on the Customer's behalf and applies where data-protection law, such as the GDPR or UK GDPR, the CCPA/CPRA, or similar laws, applies to that processing. Capitalized terms not defined here have the meanings given in the Terms.

1. Roles of the parties

The Customer is the controller (or, under the CCPA, the “business”) of resident and family personal data, and Porchlight is the processor (or “service provider”). The Customer determines the purposes and means of the processing; Porchlight processes the data only as described in this DPA and on the Customer's documented instructions, including instructions given through use of the Service.

2. Scope of processing

2.1

Subject matter

Provision of the Porchlight life-story interview and family-connection service.

2.2

Duration

The term of the Terms of Service, plus the limited retention and deletion period in Section 11.

2.3

Nature and purpose

Hosting, recording, transcription, AI summarization, storage, transmission, notification, printing, and display of content to authorized users, as needed to provide the Service.

2.4

Data subjects

The Customer's residents, those residents' family members, and the Customer's staff users.

2.5

Categories of personal data

Audio recordings and their transcripts; AI-generated summaries, briefings, highlights, and tags; resident profile facts provided by the Customer (such as hometown, or marital or military history); family contact details (name, email, phone, relationship); and staff account data. Recordings may include special-category or sensitive personal data that residents choose to share in their stories.

3. Customer instructions and warranties

3.1

Instructions

Porchlight will process personal data only on the Customer's documented instructions, unless the law requires otherwise, in which case we will inform the Customer unless the law prohibits it.

3.2

Customer warranties

The Customer warrants that it has a lawful basis and has obtained every consent and authorization required to collect the personal data and to instruct us to process it, including consent to record residents where required, and that its instructions comply with applicable law. The Customer is responsible for the accuracy and legality of the personal data it provides.

4. Confidentiality

Porchlight ensures that the people it authorizes to process personal data are bound by appropriate confidentiality obligations and access the data only as needed to provide and support the Service.

5. Security

Porchlight implements and maintains appropriate technical and organizational measures to protect personal data, taking into account the risks and the sensitivity of the data. These include encryption of data in transit, role-based access controls so that users see only what they are authorized to see, hashed credentials for staff accounts, private and optionally password-protected family access, logical separation of each customer's data, and reasonable monitoring and backup practices.

6. Subprocessors

6.1

Authorization

The Customer authorizes Porchlight to engage subprocessors to provide the Service. The current list, what each one touches, and the status of each provider's terms is published at our Subprocessors page.

6.2

Obligations

Porchlight will put data-protection terms in place with each subprocessor that are substantially as protective as this DPA, and remains responsible for their performance. As that page states, our transcription and AI providers are currently used under developer terms; Porchlight will have paid terms that exclude training on Customer Data in place with them before any resident's audio is processed in a live deployment.

6.3

New subprocessors

We will update the Subprocessors page and give the Customer reasonable advance notice of a new subprocessor, so that the Customer may object on reasonable data-protection grounds.

7. Data subject requests

Taking into account the nature of the processing, Porchlight will assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects to exercise their rights (access, correction, deletion, restriction, portability, and objection). If a data subject contacts Porchlight directly about Customer Data, we will refer them to the Customer.

8. Personal data breach

Porchlight will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, will provide the information reasonably available to help the Customer meet its own notification obligations, and will take reasonable steps to contain and remediate the breach.

9. Assistance

Taking into account the nature of the processing and the information available to us, Porchlight will provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities where the law requires them.

10. International transfers

Porchlight and its subprocessors may process personal data in the United States and other countries. Where a transfer is subject to data-transfer restrictions, the parties will rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or the UK Addendum), which are incorporated by reference to the extent required.

11. Return and deletion

On termination of the Service and at the Customer's request, Porchlight will, at the Customer's choice, make Customer Data available for export and then delete it within a commercially reasonable period, except to the extent the law requires retention, and with particular care for preserved resident stories as described in the Terms. Backups are deleted in the ordinary course of our backup cycle.

12. Audits

Porchlight will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to reasonable audits, subject to confidentiality and reasonable advance notice, no more than once a year unless a supervisory authority requires otherwise.

13. CCPA terms

To the extent the CCPA/CPRA applies, Porchlight acts as a “service provider” and will not sell or share personal information; will not retain, use, or disclose it except to perform the Service or as the CCPA permits; and will not combine it with data from other sources except as permitted. Porchlight certifies that it understands and will comply with these restrictions.

14. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. If this DPA and the Terms conflict about the processing of personal data, this DPA controls. This DPA does not need a separate signature: it is accepted together with the Terms of Service when the Customer signs up, and applies for as long as Porchlight processes Customer Data.