Youphony, effective 2 September 2026
Provided for business customers who need one. Most individual users do not. If you are a company using Youphony with your employees' accounts, or a school, this is the document your legal team will ask for. Draft, and not yet signable. A DPA is a contract, not a policy, and signing one commits Youphony to obligations it must actually be able to perform. Several below are not yet operational, customer-directed deletion and return, audit evidence, a documented incident-response path, and subprocessor flow-down all need to exist as working processes first. Do not sign this until each clause names something the company can demonstrate, and have an attorney review it before you do.
For personal data that you (the Customer) provide or cause to be processed through Youphony on behalf of your own users, you act as the controller and Youphony acts as the processor.
For data Youphony collects to run its own business, your account details billing, support correspondence, Youphony is the controller and its Privacy Policy applies.
| Subject matter | Providing the Youphony music generation service |
| Duration | For the term of the agreement, plus the deletion grace period |
| Nature and purpose | Storing account credentials and saved project recipes; delivering the service |
| Types of personal data | Email address, age band, display name (optional), saved project data, IP address (transient) |
| Categories of data subject | Your authorized users |
| Special category data | Youphony asks for none and is not designed to hold any. It cannot inspect what a Customer types into a project title or sends for transcription, so this is an instruction to the Customer, not a technical guarantee. Customer must not submit special category data. |
Youphony will:
otherwise by law, in which case we will tell you first unless the law forbids it.
our Security Overview and incorporated here.
list; you may object by terminating.
assessments, and consultations with authorities.
breach affecting your data.
retention is legally required.
compliance, and allow audits on reasonable notice, no more than annually except after a breach.
The current list is published at https://youphony.app/legal/subprocessors. We will give notice before adding one. Each is bound by terms no less protective than these.
Described in our Security Overview, which forms part of this Addendum. Notably: passwords hashed with a memory-hard function and a per-deployment secret; session tokens stored only as hashes; TLS in transit; card data never held by us; project data stored as a compact recipe rather than rendered audio.
Youphony currently serves users in the United States and restricts access from the EU and UK. If that changes, transfers will be governed by an appropriate mechanism and this Addendum will be updated with the relevant module and transfer impact assessment before any EU/UK data is processed.
Liability under this Addendum is subject to the limitations in the Terms of Service, except where applicable law does not permit that.
If this Addendum conflicts with the Terms of Service on the processing of personal data, this Addendum prevails.
Youphony
Signature: ______________________ Date: ____________
Name: ______________________ Title: ____________
Customer
Signature: ______________________ Date: ____________
Name: ______________________ Title: ____________