Data Processing Agreement (DPA / PUB-avtal)
Version: 1.1.1
Effective date: 2026-05-22
Parties
Processor: Stellar Ally AB, org. nr 559562-9899, VAT no. SE559562989901, Sweden ("Stellar Ally AB")
Controller: You, the user of Songs for Gifts, acting as the data controller for any personal data about your recipient that you enter into the service.
Contact for data protection matters: open the support chat (chat icon in the bottom-right of any page).
Background
When you use Songs for Gifts to create a personalised song for someone, you enter personal data about that person (their name, personal characteristics, and optionally their image). Under GDPR, you are the data controller for that recipient's personal data and Stellar Ally AB is your data processor, acting on your documented instructions (your form submission).
This agreement governs that processing relationship.
1. Subject matter and purpose
Stellar Ally AB processes personal data you provide solely for the purpose of generating an AI-personalised song and video as instructed by you via the service form.
2. Duration
This agreement applies for the duration of your use of the service plus the applicable retention periods described in the Privacy Policy and Terms of Use.
3. Nature of the processing
- Storing your form inputs and optional image temporarily while your song is generated.
- Passing your inputs (including the image, if provided) to AI music generation services to produce the song and video.
- Delivering the output to you via a shareable link.
- Deleting personal context and images on the schedule described in the Terms of Use (72 hours for unpaid; 60 days for paid).
4. Types of personal data
- Recipient name and personal characteristics as entered by you
- Optional uploaded image (may depict the recipient or other individuals)
- Your sender email address (optional)
No special category data. Personal data falling under GDPR Article 9 (data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data processed to uniquely identify a person, health data, or data concerning a person's sex life or sexual orientation) is not expected or permitted as input to the service. You must not upload images intended to capture biometric identifiers, medical records, or other special category data, and you must not include such data in the text fields. The service is not designed to process special category data, and processing such data may be terminated without notice.
5. Categories of data subjects
- Gift recipients (when their personal details are entered by you)
- You, the sender (your email if provided)
6. Obligations of the parties
6.1 Stellar Ally AB as processor
Stellar Ally AB shall:
- Process only on your instructions. Your form submission is the documented instruction. We will not process the data for any other purpose.
- Confidentiality. Ensure all personnel involved in processing are bound by confidentiality obligations.
- Security. Apply appropriate technical and organisational measures (see Section 8).
- Sub-processors. Use only the sub-processors listed in Section 7. We will inform you of any intended changes to the sub-processor list, giving you the opportunity to object.
- Data subject rights. Assist you in responding to data subject rights requests from your recipient (access, erasure, portability, etc.) to the extent technically possible.
- Deletion or return. Delete or return all personal data on request, and delete it on the schedule described in the Terms of Use.
- Audit. Provide information necessary to demonstrate compliance with this agreement.
- Personal data breach notification. Notify you without undue delay — and, where feasible, no later than 72 hours after becoming aware — of any personal data breach affecting personal data we process on your behalf. Notification will be sent to the email address(es) we have on file for your account (sender email and/or Stripe customer email) and will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures we have taken or propose to take.
6.2 You as controller
As the data controller for personal information you enter about your recipient (or any other third party), you are responsible for:
- Lawful basis. Ensuring you have a lawful basis under GDPR — typically consent — for the personal data you enter. In particular: a photo of an identifiable person is personal data, and that person's consent is the usual lawful basis for using their photo for this purpose.
- Data minimisation. Entering only the personal data necessary to generate the song. The service works well with a first name and a general description; specific identifiers (full name, address, employer, ID numbers, etc.) are neither required nor recommended. See Terms of Use §3.
- Accuracy. Keeping the information you submit accurate.
- Transparency to the data subject. Where required, informing your recipient that you used a service like Songs for Gifts to generate something with their personal details.
- Responding to data subject rights requests directed at you (as controller) by your recipient. Stellar Ally AB will assist with the technical side (deletion, export) under §6.1.5 above.
7. Sub-processors
| Sub-processor |
Country |
Purpose |
Safeguard / policy |
| Google Cloud (incl. Gemini Enterprise Agent Platform, formerly Vertex AI) |
EU (Frankfurt) |
API hosting and AI music generation |
Google DPA; SCCs. AI use subject to Google's Generative AI Prohibited Use Policy; generated audio carries the SynthID watermark |
| Render |
EU (Frankfurt region) |
Static website hosting |
Render DPA; SCCs |
| Stripe |
Ireland / US |
Payment processing |
Stripe DPA; SCCs |
| Cloudflare |
EU / US edge |
Bot protection |
Cloudflare DPA; SCCs |
| Crisp |
EU (France) |
In-app customer support chat |
Crisp DPA; EU data residency |
Where transfers to countries outside the EU/EEA occur (Stripe US, Cloudflare US edge), they are protected by EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914, incorporated into each sub-processor's Data Processing Addendum with us. Copies of the relevant SCCs are available upon request via the support chat.
8. Technical and organisational measures (TOMs)
- Encryption in transit: All data in transit is encrypted using industry-standard protocols.
- Encryption at rest: All stored data is encrypted at rest.
- Access control: Role-based access control with least-privilege principles; no broad administrative access.
- Media access control: All stored media is access-controlled; no public access to stored files.
- Audit logging: Request logging is in place; no personal data is written to log payloads.
- IP anonymisation: IP addresses are anonymised before any storage; raw IPs are never persisted.
- Incident response: Documented procedure in place.
- Regular security testing: Ongoing post-launch.
9. Governing law
This agreement is governed by Swedish law and the General Data Protection Regulation (GDPR) as applicable in Sweden.
10. Acceptance
You accept this DPA by using the service. Acceptance is recorded in our systems when you take your first meaningful action (generation or checkout) as described in the Terms of Use.
Stellar Ally AB · Songs for Gifts · songsforgifts.com