Porchlight for Communities

Data Processing Addendum

Version 1.0 (2026-06-21) · Effective June 21, 2026. This Data Processing Addendum (“DPA”) forms part of the Terms of Service between the Customer (“Controller”) and Levelbrook Consulting, which operates Porchlight (“Processor,” “we”). It governs our processing of personal data on the Customer's behalf and applies where data-protection law (such as the GDPR/UK GDPR, the CCPA/CPRA, or similar laws) applies to that processing.

1. Roles of the parties

The Customer is the controller (or, under the CCPA, the “business”) of resident and family personal data, and Porchlight is the processor (or “service provider”). The Customer determines the purposes and means of the processing; Porchlight processes the data only as described in this DPA and on the Customer's documented instructions, including those given through the use of the Service.

2. Scope and subject matter of processing

  • Subject matter: provision of the Porchlight life-story interview and family-connection service.
  • Duration: for the term of the Terms of Service, plus the limited retention and deletion period described below.
  • Nature and purpose: hosting, recording, transcription, AI summarization, storage, transmission, notification, and display of content to authorized users, as needed to provide the Service.
  • Categories of data subjects: the Customer's residents, those residents' family members, and the Customer's staff users.
  • Categories of personal data: audio recordings and their transcripts; AI-generated summaries, highlights, and tags; resident profile facts (such as hometown, marital or military history) provided by the Customer; family contact details (name, email, phone, relationship); and staff account data. Recordings may include special-category / sensitive personal data that residents choose to share in their stories.

3. Customer instructions and warranties

Porchlight will process personal data only on the Customer's documented instructions, unless required by law (in which case we will inform the Customer unless legally prohibited). The Customer warrants that it has a lawful basis and has obtained all consents and authorizations required to collect the personal data and to instruct us to process it — including consent to record residents where required — and that its instructions comply with applicable law. The Customer is responsible for the accuracy and legality of the personal data it provides.

4. Confidentiality

Porchlight ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and access the data only as needed to provide and support the Service.

5. Security

Porchlight implements and maintains appropriate technical and organizational measures to protect personal data, taking into account the risk and the sensitivity of the data. These include encryption of data in transit, role-based access controls so users see only what they are authorized to see, hashed credentials for staff accounts, token-gated (and optionally password-protected) family access, logical separation of each community's data, and reasonable monitoring and backup practices.

6. Subprocessors

The Customer authorizes Porchlight to engage subprocessors to provide the Service. We impose data-protection obligations on each subprocessor that are substantially the same as those in this DPA, and we remain responsible for their performance. Current categories of subprocessors are: cloud hosting; speech-to-text transcription; the AI model provider that selects questions and writes summaries; email and SMS notification providers; and the payment processor. We will make a current list available on request and give the Customer reasonable notice of new subprocessors so the Customer may object on reasonable data-protection grounds.

7. Data subject requests

Taking into account the nature of the processing, Porchlight will assist the Customer with appropriate technical and organizational measures, insofar as possible, in responding to requests by data subjects to exercise their rights (access, correction, deletion, restriction, portability, and objection). If a data subject contacts Porchlight directly about Customer Data, we will refer them to the Customer.

8. Personal data breach

Porchlight will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably available to help the Customer meet its own notification obligations. Porchlight will take reasonable steps to mitigate and remediate the breach.

9. Assistance and compliance

Taking into account the nature of processing and the information available to us, Porchlight will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with supervisory authorities, where required by law.

10. International transfers

Porchlight and its subprocessors may process personal data in the United States and other countries. Where a transfer is subject to data-transfer restrictions, the parties will rely on an appropriate transfer mechanism (such as the EU Standard Contractual Clauses or the UK Addendum), which are incorporated by reference to the extent required.

11. Return and deletion of data

On termination of the Service, and on the Customer's request, Porchlight will, at the Customer's choice, make Customer Data available for export and then delete it within a commercially reasonable period, except to the extent retention is required by law, and with particular care given to preserved resident stories as described in the Terms. Backups are deleted in the ordinary course of our backup cycle.

12. Audits

Porchlight will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, subject to confidentiality and reasonable advance notice, conducted no more than once per year unless required by a supervisory authority.

13. CCPA-specific terms

To the extent the CCPA/CPRA applies, Porchlight acts as a “service provider” and will not sell or share personal information, will not retain, use, or disclose it except to perform the Service or as permitted by the CCPA, and will not combine it with data from other sources except as permitted. Porchlight certifies that it understands and will comply with these restrictions.

14. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA governs. This DPA does not require a separate signature: it is accepted together with the Terms of Service when the Customer signs up, and applies for the duration of the Service.

15. Contact

Data-protection questions and requests under this DPA can be sent to levelbrookteam@gmail.com (Levelbrook Consulting / Porchlight).