Life365Hub — Data Processing Addendum
Effective: September 12th, 2026 · Version 1.1
Data Processing Addendum — GDPR, CCPA, and international data protection compliance for Life365Hub.
This DPA applies where and only to the extent that Life365Hub processes “Personal Data” subject to the GDPR, the CCPA, or other applicable data protection legislation. This Addendum is incorporated into and forms part of the Terms of Service and Privacy Policy of Life365Hub, both available at https://life365hub.com.
1. Scope and Applicability
This DPA applies where and only to the extent that Life365Hub processes Personal Data subject to the GDPR, CCPA, or other applicable data protection legislation.
2. Roles of the Parties
Customer as Controller. The user acts as the Data Controller for all Personal Data stored within their vaults. The user determines the purpose and means of processing their own Personal Data.
Life365Hub as Processor (Limited). Because all vault content is encrypted entirely within the user’s browser — using XChaCha20-Poly1305 authenticated encryption — before it is ever transmitted to Life365Hub’s infrastructure, Life365Hub’s role as a Data Processor is limited to storing and serving back encrypted ciphertext. Life365Hub has no technical ability to access, read, modify, or process the plaintext Personal Data contained within vaults. All Personal Data within vaults remains under the exclusive cryptographic control of the Controller at all times.
Sub-processors. Life365Hub engages the following sub-processors, each limited to the specific function described:
- Neon — Function: Database hosting (account metadata, encrypted vault records). Access to plaintext vault content: None.
- Vercel — Function: Application hosting. Access to plaintext vault content: None.
- Cloudflare R2 — Function: Encrypted media storage. Access to plaintext vault content: None.
- Stripe — Function: Payment processing (billing, subscription management). Access to plaintext vault content: Not applicable — receives only account email and billing/subscription status; full payment details are handled directly by Stripe under its own PCI-DSS compliance and privacy practices.
- Resend — Function: Transactional email delivery (account verification). Access to plaintext vault content: None — Resend only ever processes the recipient’s email address and the verification email’s own content (a single-use, time-limited link); it has no access to vault data at any point.
None of these sub-processors have any technical ability to decrypt vault content. Authentication is not delegated to any sub-processor — it is implemented directly by Life365Hub using session tokens and server-side verification on every request, rather than a third-party identity or “security rules” product.
Sub-processor Updates: Life365Hub will notify users at least 14 days prior to engaging any new sub-processor by updating its online sub-processor list or via email notification, giving users an opportunity to object before data is transferred.
3. Technical and Organizational Measures
The Service implements the following measures appropriate to the risk:
- Client-side encryption. All vault content is encrypted with XChaCha20-Poly1305 entirely within the user’s browser before reaching any server. No plaintext Personal Data ever leaves the user’s device.
- Key derivation. The user’s password is transformed into encryption keys using Argon2id, a memory-hard key derivation function deliberately chosen for its resistance to GPU- and ASIC-accelerated brute-force attacks. Parameters: memory cost 19*1024 (~19 MiB, matching OWASP baseline recommendation), time cost 2, parallelism 1. Life365Hub cannot decrypt stored ciphertext under any circumstance, including under compulsion, because it never possesses the key material required to do so.
- Zero-knowledge architecture. Life365Hub holds no cryptographic keys capable of decrypting vault contents. This is an architectural property of the system, not a policy commitment that could be reversed.
- Access control. Every request to account data is authenticated and authorized server-side against the requesting user’s verified session before any data is returned; there is no path by which one account’s data is accessible to another.
- Transport security. All data in transit is protected by HTTPS/TLS.
- Legacy access controls. Where a user opts into legacy/escrow features, access by a designated trusted contact requires that contact’s own explicit prior acceptance and is gated by a multi-stage, time-delayed process that the account owner can cancel at any time by logging in.
4. International Data Transfers
Storage location: Neon’s database region (US East 1: Northern Virginia, USA), Cloudflare R2’s storage location (US East 1: Northern Virginia, USA), and Resend’s infrastructure is hosted on Amazon Web Services (AWS), primarily in the US East (Northern Virginia) region.
Transfer mechanism. Transfers of Personal Data from the EEA or UK to the United States are governed by the Standard Contractual Clauses (SCCs) as adopted by the European Commission.
Sub-processor compliance. Life365Hub relies on the respective Data Processing Addenda and SCCs published by Neon, Cloudflare, Vercel, Stripe, and Resend for infrastructure and payment-level compliance.
Reduced transfer risk. Because vault contents are encrypted client-side before transfer and Life365Hub holds no decryption keys, the practical risk to data subjects from international transfer of vault ciphertext is materially lower than for transfers of plaintext Personal Data.
5. Data Subject Rights
Life365Hub will assist the Controller in fulfilling requests from data subjects (including EU/UK users) regarding:
- Right of access and portability. Providing a copy of account metadata and encrypted vault data in a machine-readable format. Note that because vault content is encrypted client-side, any exported ciphertext remains unreadable without the user’s own password — Life365Hub cannot provide a plaintext export on the user’s behalf.
- Right to rectification. Correcting inaccurate account metadata held by Life365Hub (e.g., email address).
- Right to erasure — active request. Where a user (or their authorized representative) submits a valid, explicit erasure request — including through the self-service deletion request available from the user’s Account Security page — or closes their account and confirms deletion, Life365Hub will delete all associated account data and vault contents within 30 days of the request, consistent with our obligations under GDPR Article 17 and applicable law. A pending request may be cancelled by the user at any time before that 30-day period completes.
This is distinct from, and does not alter, Life365Hub’s separate account-inactivity and storage-retention policy described in the Terms of Service, which governs accounts that become inactive or fall out of compliance with their storage tier without an active deletion request having been made. That policy provides a substantially longer, multi-stage retention period specifically because it applies to accounts where no explicit request to delete anything has been made. The 30-day erasure timeline in this section applies only where a data subject has affirmatively requested deletion.
Important limitation. Because the Service operates on a zero-knowledge basis, Life365Hub cannot provide plaintext copies of vault Personal Data to the user, a third party, or a requesting authority — including law enforcement — other than by the vault owner’s own action using their own password. This technical limitation reduces Life365Hub’s exposure under GDPR’s “risk to rights and freedoms” framework, as the Service is not technically capable of enabling unauthorized access to vault Personal Data.
6. Personal Data Breach Notification
In the event of a security incident affecting Personal Data, Life365Hub will notify the Controller and relevant supervisory authorities within 72 hours of discovery, consistent with GDPR Article 33.
Because all vault content is stored as XChaCha20-Poly1305 encrypted ciphertext and Life365Hub holds no decryption keys, a breach of Life365Hub’s infrastructure alone would expose only ciphertext that is computationally infeasible to decrypt without the affected user’s own password. Account metadata (such as email addresses) is not encrypted in this way and would be subject to standard breach notification obligations if affected.
7. Contact
For data protection and privacy inquiries:
Life365Hub — Data Protection Officer
Email: contact@life365hub.com
Website: https://life365hub.com