Life365Hub

Life365Hub — Data Processing Addendum

Effective: September 12th, 2026 · Version 1.1

Data Processing Addendum — GDPR, CCPA, and international data protection compliance for Life365Hub.

This DPA applies where and only to the extent that Life365Hub processes “Personal Data” subject to the GDPR, the CCPA, or other applicable data protection legislation. This Addendum is incorporated into and forms part of the Terms of Service and Privacy Policy of Life365Hub, both available at https://life365hub.com.

1. Scope and Applicability

This DPA applies where and only to the extent that Life365Hub processes Personal Data subject to the GDPR, CCPA, or other applicable data protection legislation.

2. Roles of the Parties

Customer as Controller. The user acts as the Data Controller for all Personal Data stored within their vaults. The user determines the purpose and means of processing their own Personal Data.

Life365Hub as Processor (Limited). Because all vault content is encrypted entirely within the user’s browser — using XChaCha20-Poly1305 authenticated encryption — before it is ever transmitted to Life365Hub’s infrastructure, Life365Hub’s role as a Data Processor is limited to storing and serving back encrypted ciphertext. Life365Hub has no technical ability to access, read, modify, or process the plaintext Personal Data contained within vaults. All Personal Data within vaults remains under the exclusive cryptographic control of the Controller at all times.

Sub-processors. Life365Hub engages the following sub-processors, each limited to the specific function described:

None of these sub-processors have any technical ability to decrypt vault content. Authentication is not delegated to any sub-processor — it is implemented directly by Life365Hub using session tokens and server-side verification on every request, rather than a third-party identity or “security rules” product.

Sub-processor Updates: Life365Hub will notify users at least 14 days prior to engaging any new sub-processor by updating its online sub-processor list or via email notification, giving users an opportunity to object before data is transferred.

3. Technical and Organizational Measures

The Service implements the following measures appropriate to the risk:

4. International Data Transfers

Storage location: Neon’s database region (US East 1: Northern Virginia, USA), Cloudflare R2’s storage location (US East 1: Northern Virginia, USA), and Resend’s infrastructure is hosted on Amazon Web Services (AWS), primarily in the US East (Northern Virginia) region.

Transfer mechanism. Transfers of Personal Data from the EEA or UK to the United States are governed by the Standard Contractual Clauses (SCCs) as adopted by the European Commission.

Sub-processor compliance. Life365Hub relies on the respective Data Processing Addenda and SCCs published by Neon, Cloudflare, Vercel, Stripe, and Resend for infrastructure and payment-level compliance.

Reduced transfer risk. Because vault contents are encrypted client-side before transfer and Life365Hub holds no decryption keys, the practical risk to data subjects from international transfer of vault ciphertext is materially lower than for transfers of plaintext Personal Data.

5. Data Subject Rights

Life365Hub will assist the Controller in fulfilling requests from data subjects (including EU/UK users) regarding:

This is distinct from, and does not alter, Life365Hub’s separate account-inactivity and storage-retention policy described in the Terms of Service, which governs accounts that become inactive or fall out of compliance with their storage tier without an active deletion request having been made. That policy provides a substantially longer, multi-stage retention period specifically because it applies to accounts where no explicit request to delete anything has been made. The 30-day erasure timeline in this section applies only where a data subject has affirmatively requested deletion.

Important limitation. Because the Service operates on a zero-knowledge basis, Life365Hub cannot provide plaintext copies of vault Personal Data to the user, a third party, or a requesting authority — including law enforcement — other than by the vault owner’s own action using their own password. This technical limitation reduces Life365Hub’s exposure under GDPR’s “risk to rights and freedoms” framework, as the Service is not technically capable of enabling unauthorized access to vault Personal Data.

6. Personal Data Breach Notification

In the event of a security incident affecting Personal Data, Life365Hub will notify the Controller and relevant supervisory authorities within 72 hours of discovery, consistent with GDPR Article 33.

Because all vault content is stored as XChaCha20-Poly1305 encrypted ciphertext and Life365Hub holds no decryption keys, a breach of Life365Hub’s infrastructure alone would expose only ciphertext that is computationally infeasible to decrypt without the affected user’s own password. Account metadata (such as email addresses) is not encrypted in this way and would be subject to standard breach notification obligations if affected.

7. Contact

For data protection and privacy inquiries:

Life365Hub — Data Protection Officer
Email: contact@life365hub.com
Website: https://life365hub.com