
Data processing agreement
Last updated 28 August 2026
Read this first. If you are an individual member, this page is probably not the one you want. For your own membership we are the controller, not a processor, and what governs your data is the privacy policy. Nothing here changes it or takes anything away from it.
This page is for an organisation that provides GROW Moment to its people and decides why they are using it. In that arrangement the organisation is the controller, we process on its instructions, and Article 28 GDPR requires a written agreement. These are the terms of that agreement, plus the sub-processor list we are obliged to publish.
1Parties, and what triggers this
Processor: Kasparas Maniušis, of Vytauto Žalakevičiaus g. 13-13, LT-10109 Vilnius, Lithuania, operator of growmoment.app.
Controller: the organisation that has entered into a written order or agreement with us for memberships supplied to its personnel.
These terms apply only where such an agreement exists and only to the personal data processed under it. To put them in place, write to info@growmoment.app. Execution formalities and any negotiated variations are satisfied by a counter-signed DPA executed electronically.
2What is processed, and for how long
| Subject matter | Providing GROW Moment: a daily check-in practice, a personal protocol, an AI coach reply, and community surfaces |
|---|---|
| Duration | For the term of the agreement, plus the retention periods in the privacy policy |
| Nature and purpose | Storage, retrieval, computation of protocol targets, generation of coach replies and story headlines, publication to community surfaces where the data subject has chosen it, sending reminder and account emails, billing |
| Categories of data subject | The organisation’s personnel who hold a membership |
| Categories of personal data | Identity and contact data; authentication data; daily levels and notes; protocol base and derived targets; day-plan entries; community posts; billing references |
| Special categories | Data concerning health (the body figures in the protocol base, and whatever a member chooses to write in a free-text daily note), processed only on the data subject’s own explicit consent, given to us directly — an organisation cannot consent on their behalf. Biometric data is no longer collected: the liveness check and face template were removed from the service, and the enrolments taken while it existed are held only until their own deletion deadlines |
3Our obligations
- Instructions. We process only on the controller’s documented instructions, of which this agreement and the order are the whole. If an instruction appears to breach data protection law, we will say so and may decline it. If EU or member-state law obliges us to process otherwise, we will tell the controller first unless that law forbids it.
- Confidentiality. Everyone we authorise to touch the data is bound by confidentiality and works on a need-to-know basis.
- Security. We keep appropriate technical and organisational measures under Article 32 — encryption in transit and at rest, host-scoped signed session cookies, an edge that closes API routes by default, least-privilege access to production, and encrypted backups. Details on request under NDA.
- Assistance. We help the controller answer data subject requests, and with Articles 32 to 36 — security, breach notification, and impact assessments — proportionately to the information we hold.
- Breach. We notify the controller without undue delay after becoming aware of a personal data breach affecting its data, with what we know at the time and updates as we learn more.
- Deletion or return. At the end of the agreement we delete or return the personal data at the controller’s choice, except where law requires us to keep it. The minimal post-deletion archive described in the privacy policy is one such case.
- Audit. We make available the information needed to demonstrate compliance and allow audits, including inspections, by the controller or an auditor it mandates. Scope, frequency and cost: annually upon 30 days written notice, during normal business hours and subject to customary confidentiality obligations.
4Sub-processors
The controller gives general authorisation for us to engage the sub-processors listed below. We impose data protection obligations on each of them no less protective than these, and we remain fully liable to the controller for their performance.
We will give notice before adding or replacing a sub-processor, and the controller may object on reasonable data protection grounds within 14 calendar days from written notice.
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services | Storage of the face images produced by the liveness check that used to run at signup. No new images are created — the check has been removed from the product | For members who joined while the check existed: the reference and audit images it produced, and a numeric face template. Nothing is captured now | European Union — Frankfurt (AWS eu-central-1) |
| Shared face register | Historical. This product no longer enrols or matches faces — the check was removed. Templates enrolled while it ran remain in a register that is shared with sibling products rather than copied per product, which is why the entry stays until they are erased | For members enrolled while the check ran: the numeric face template derived from it. Not the images — those stay in this product’s own storage. Nothing new is enrolled. | European Union — Frankfurt (AWS eu-central-1), processed under a Joint Controller Agreement (Art. 26 GDPR) |
| Neon | Managed PostgreSQL — the application database | Everything the product stores: account, check-ins, notes, protocol, forum posts, billing references | European Union — Frankfurt (AWS eu-central-1) |
| Google (Firebase Authentication) | Sign-in, password handling and email verification | Email address, password (hashed by Firebase — never seen by us), sign-in metadata | Google infrastructure, subject to Google’s regional terms |
| Stripe | Payment processing and subscription management | Name and email you give at checkout, card details (handled entirely by Stripe), billing country, invoices | Ireland and the United States |
| OpenAI | Generating the coach reply, the story headline, your nickname and your avatar | The content of the note you are sending, the context Aris is given with it, and your avatar prompt — unaccompanied by your name, email or account id | United States |
| Cloudflare (R2) | Object storage for avatar and profile images | Your avatar image and its style asset | Cloudflare’s network |
| Vercel | Hosting, edge routing and Speed Insights | Request metadata — IP address, user agent, the URL requested, and anonymous page-timing measurements | Global edge network |
| Amazon Web Services (Amazon SES) | Sending the reminder, streak, verification and billing emails | Your email address and the content of the message sent to you | European Union — Frankfurt (AWS eu-central-1) |
5Transfers outside the EEA
Where a sub-processor above sits outside the EEA, the transfer relies on the European Commission’s Standard Contractual Clauses (Decision 2021/914), incorporated into our agreement with that sub-processor, together with encryption in transit and at rest.
The module, the annexes and the transfer impact assessment for each route are maintained on file and available to the controller upon request under NDA.
6A boundary this agreement does not cross
An employer does not get to read a member’s notes
A member’s daily note and their protocol base belong to the member. An organisation that pays for a membership does not thereby acquire access to them, and we will not provide it — not in aggregate, not by export, not by admin console. What an organisation may receive is limited to what it needs to administer the seats: seat counts, activation status, and aggregated platform activity metrics only — never individual check-in notes or protocol inputs.
The same applies to health data. It is given to us by the individual, on their own account, and cannot be instructed into existence by a controller. If an organisation instructs us to process it, we will decline under §3.
7Precedence, and contact
Where these terms conflict with the order or with the terms of service, these terms prevail on matters of data protection and the others prevail on everything else. Where they conflict with the Standard Contractual Clauses, the Clauses prevail.
Data protection and commercial: info@growmoment.app.