1. Definitions
Customer means the organisation or household entering into the Stresfri terms of service. Processor means Stresfri Enterprise Ltd. Personal Data, Data Subject, Processing, Controller, and Subprocessor have the meanings given in the UK GDPR and EU GDPR.
2. Roles & scope
The Customer is the Controller. Stresfri is the Processor and processes Personal Data solely on the Customer's documented instructions, being the Terms of Service, this DPA, and any lawful written instruction from the Customer's admin user.
3. Nature and purpose of processing
Stresfri processes Personal Data to provide a shared household calendar, chores, meal plans, lists, and AI composer as described at /features. Processing includes collection, storage, retrieval, structuring by the AI composer, notification delivery, and deletion on request.
4. Duration of processing
The duration of processing is the term of the Customer's subscription plus a 30 day grace period for retrieval, after which all Personal Data is erased in accordance with Section 9.
5. Categories of Data Subject & Personal Data
See Annex 1.
6. Security measures
Stresfri implements and maintains the following technical and organisational measures (details in Annex 2):
- End to end encryption in transit (TLS 1.3).
- Encryption at rest for all databases and backups (AES-256).
- Access control on the principle of least privilege.
- MFA required for all Stresfri staff accessing production.
- Quarterly access reviews and immediate access removal on offboarding.
- Continuous vulnerability scanning and monthly patch cycles.
- SOC 2 Type I completed; Type II audit in progress.
7. Subprocessors
Customer authorises Stresfri to engage the subprocessors listed in Annex 3 (currently Supabase, Cloudflare, Anthropic, OpenAI for Whisper transcription, and Resend for transactional email). Stresfri will give Customer 14 days' notice before adding or replacing a subprocessor and publish an up-to-date list at this URL.
8. International transfers
Personal Data is stored in the EU (Frankfurt) or the UK (London) by default. Where transfers outside the EEA/UK are necessary (e.g. Anthropic in the US for AI inference), Stresfri relies on Standard Contractual Clauses and the UK IDTA as applicable, with supplementary measures per the EDPB Recommendations.
9. Deletion & return of data
On termination or expiry of the underlying agreement, or at the Customer's written request, Stresfri shall delete or return all Personal Data within 30 days, including copies held by subprocessors. Backups are purged within a further 30 days on their rolling schedule.
10. Data Subject rights
Stresfri provides functionality for the Customer to fulfil Data Subject rights (access, rectification, erasure, portability, restriction, objection) through the app. For requests received directly by Stresfri, we notify the Customer without undue delay and, unless legally required to respond directly, forward to the Customer.
11. Incidents
Stresfri notifies the Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach, providing all information reasonably necessary for the Customer to meet its obligations under Articles 33-34 GDPR.
12. Audits
Stresfri provides the Customer with all information necessary to demonstrate compliance and permits audits, including inspections, by the Customer or a mutually agreed auditor, up to once per year, on 30 days' written notice, subject to reasonable confidentiality obligations. Stresfri's most recent SOC 2 report satisfies the audit right by default.
13. Governing law
This DPA is governed by the laws of England and Wales for UK Customers and by the laws of the Republic of Ireland for EEA Customers, with jurisdiction of the courts of London and Dublin respectively.
Annex 1, Data Subjects and Personal Data
Data Subjects
- Customer's employees / staff / members with a Stresfri account.
- Children of Customer's members, where added by their parent or legal guardian.
- Extended household members (grandparents, carers) invited into a household.
Categories of Personal Data
- Account identifiers: email, hashed password, display name.
- Household state: events, chores, meals, list items, photo attachments.
- Notification tokens: push subscription endpoints, mobile device tokens.
- Payment metadata (never card numbers): Stripe customer ID, plan.
- Usage metrics tied to a user ID for billing and troubleshooting.
- Children's data (COPPA / GDPR-K categories): first name, age, chores, points ledger. Never used for advertising or AI training.
Annex 2, Security measures
See the summary in Section 6. Full detail available under NDA on request to security@stresfri.com.
Annex 3, Current subprocessors
- Supabase (Ireland/EU), primary database, auth, storage.
- Cloudflare (global), Workers, CDN, DDoS.
- Anthropic (United States), AI composer inference under zero retention DPA.
- OpenAI (United States), Whisper audio transcription for the voice composer.
- Resend (United States), transactional email delivery.
- Sentry (United States), error monitoring (scrubbed of user PII).
- Expo (United States), mobile push token distribution.
Version 1.0, last updated 12 September 2026. This DPA is a template offered in good faith; a countersigned version is available on request to legal@stresfri.com.
