Data Processing Agreement
This Data Processing Agreement (DPA) governs how Chef Life Media LLC processes Personal Data on behalf of customers using The StaffApp™. It describes our obligations under GDPR, UK GDPR, CCPA/CPRA, and other Applicable Data Protection Laws, and sets out the subprocessors we use, the security measures we maintain, and the Standard Contractual Clauses for international transfers.
1. Introduction and Parties
This Data Processing Agreement (“DPA“) is entered into by and between:
Chef Life Media LLC, a North Carolina limited liability company with its principal place of business at 65 Merrimon Avenue, Suite 1153, Asheville, North Carolina 28801 (“Processor,” “Company,” “we,” or “us“); and
The customer organization identified in the Order Form or account registration that links to or incorporates this DPA (“Controller,” “Customer,” or “you“).
Processor and Controller are each a “Party” and collectively the “Parties.”
2. Purpose and Scope
2.1 Relationship to the Agreement
This DPA supplements and forms part of the Terms of Service between the Parties governing use of The StaffApp™ (the “Agreement“). In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.
2.2 Purpose
This DPA sets out the terms under which Processor processes Personal Data on behalf of Controller in connection with Controller’s use of the Service, and establishes the rights and obligations of each Party in accordance with Applicable Data Protection Laws.
2.3 Scope
This DPA applies to all Personal Data processed by Processor on behalf of Controller in connection with the Service.
3. Definitions
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. For purposes of this DPA:
- Applicable Data Protection Laws means all laws and regulations applicable to the processing of Personal Data under this DPA, including without limitation: the EU General Data Protection Regulation 2016/679 (“GDPR“), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA“), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, and other U.S. state privacy laws, each as amended.
- Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given in GDPR. For U.S. state laws, equivalent terms (e.g., Business, Service Provider, Consumer, Personal Information) have the meanings given in such laws and are used interchangeably where context requires.
- Customer Content has the meaning given in the Agreement and, to the extent it contains Personal Data, is subject to this DPA.
- Data Subject Request means a request by a Data Subject to exercise their rights under Applicable Data Protection Laws.
- Standard Contractual Clauses or SCCs means the standard contractual clauses approved by the European Commission for the transfer of Personal Data from controllers or processors established in the European Economic Area to processors established in third countries, as amended from time to time.
- Subprocessor means any third party engaged by Processor to process Personal Data on behalf of Controller.
4. Role of the Parties
4.1 Controller and Processor Roles
For the purposes of Applicable Data Protection Laws with respect to Personal Data submitted to the Service by or on behalf of Controller:
- Controller is the Controller of the Personal Data
- Processor is a Processor of the Personal Data, acting on Controller’s documented instructions
Under CCPA/CPRA, Processor acts as a “Service Provider” (not a “third party” as those terms are defined in CCPA/CPRA).
4.2 Controller’s Responsibilities
Controller represents, warrants, and covenants that:
- (a) Controller has, and will maintain throughout the term, a lawful basis under Applicable Data Protection Laws for each category of Personal Data processed through the Service, including but not limited to employment-related personal data of Controller’s workforce;
- (b) Controller has provided all notices and obtained all consents, authorizations, and permissions required by Applicable Data Protection Laws for Processor to process the Personal Data for the purposes described in this DPA, including any consents required under the Illinois Biometric Information Privacy Act (“BIPA“), the Texas Capture or Use of Biometric Identifier Act (“CUBI“), or similar laws if Controller enables voice dictation or other features processing biometric or biometric-adjacent data;
- (c) Controller’s instructions to Processor regarding the processing of Personal Data comply with Applicable Data Protection Laws;
- (d) The Personal Data provided to Processor is accurate, lawfully obtained, and limited to what is necessary for the purposes of the Service;
- (e) Controller will respond to Data Subject Requests directed to Controller, and Controller remains the primary point of contact for Data Subjects whose Personal Data is processed through the Service.
4.3 Processor’s Obligations
Processor will:
- (a) Process Personal Data only for the purposes described in Exhibit A and only in accordance with Controller’s documented instructions, including as set out in the Agreement and this DPA, unless otherwise required by applicable law;
- (b) Inform Controller if, in Processor’s opinion, an instruction infringes Applicable Data Protection Laws, without obligation to perform legal analysis on Controller’s behalf;
- (c) Ensure that persons authorized to process the Personal Data are bound by confidentiality obligations;
- (d) Implement appropriate technical and organizational measures as described in Exhibit C;
- (e) Assist Controller with its obligations under Applicable Data Protection Laws as described in this DPA;
- (f) Not sell, rent, or share Personal Data (as “sell” and “share” are defined under CCPA/CPRA), and not retain, use, or disclose Personal Data for any purpose other than the specific purpose of performing the Service described in the Agreement and this DPA;
- (g) Not combine Personal Data received from Controller with Personal Data from other sources except to the extent reasonably necessary to detect security incidents, protect against malicious or illegal activity, or as otherwise permitted under CCPA/CPRA for a Service Provider;
- (h) Not use Personal Data for training of any artificial intelligence or machine learning model, whether operated by Processor or any third party, and ensure that Subprocessors do not do so with respect to Personal Data processed on Controller’s behalf.
5. Processing Details
5.1 Nature and Purpose of Processing
The nature, purpose, categories of data, and categories of data subjects are described in Exhibit A.
5.2 Duration of Processing
Processing continues for the term of the Agreement and for any period thereafter during which Processor retains Personal Data, as described in Section 11.
5.3 Controller Instructions
Controller’s use of the Service as described in the Agreement and the Service documentation constitutes Controller’s documented instructions to Processor regarding the processing of Personal Data. Additional instructions outside the scope of the Service require the Parties’ mutual written agreement and may be subject to additional fees.
6. Subprocessors
6.1 General Authorization
Controller grants Processor general authorization to engage Subprocessors to process Personal Data, subject to the requirements of this Section 6.
6.2 Current Subprocessors
The Subprocessors engaged by Processor as of the effective date of this DPA are listed in Exhibit B.
6.3 Subprocessor Obligations
Processor will:
- (a) Enter into a written contract with each Subprocessor that imposes data protection obligations substantially equivalent to those in this DPA;
- (b) Remain liable to Controller for acts and omissions of Subprocessors as if those acts and omissions were Processor’s own;
- (c) Conduct reasonable due diligence on each Subprocessor before engagement and periodically thereafter.
6.4 Changes to Subprocessors
Processor will notify Controller at least thirty (30) days in advance of engaging a new Subprocessor or replacing an existing Subprocessor that will process Personal Data. Notification will be provided via email to the Account Owner, via in-application notice, or via posting to a publicly accessible Subprocessor list page, at Processor’s discretion.
6.5 Right to Object
Controller may object in writing to the engagement of a new Subprocessor within fifteen (15) days of Processor’s notice, on reasonable data protection grounds. If Controller objects, the Parties will work together in good faith to resolve the objection. If no resolution is reached within thirty (30) days of Controller’s objection, Controller may terminate the portions of the Service that cannot be provided without the objected-to Subprocessor, with a pro-rated refund for prepaid fees covering the period after termination.
7. Security
7.1 Technical and Organizational Measures
Processor will implement and maintain the technical and organizational security measures described in Exhibit C to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
7.2 Updates to Measures
Processor may update the measures in Exhibit C from time to time, provided the updates do not materially reduce the overall level of protection.
7.3 Security Assessments
Upon reasonable request and not more than once per year, Processor will make available to Controller documentation reasonably demonstrating compliance with the obligations in this DPA. Such documentation may include security policies, summary audit reports, or attestations from independent auditors. More granular audits require Processor’s prior written agreement and may be subject to reasonable conditions, including non-disclosure and cost reimbursement.
8. Personal Data Breaches
8.1 Notification
Processor will notify Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Controller’s Personal Data.
8.2 Information Provided
Processor’s notification will include, to the extent known at the time:
- A description of the nature of the breach
- The categories and approximate number of Data Subjects affected
- The categories and approximate volume of Personal Data records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
If complete information is not available within the 72-hour window, Processor will provide initial notification with available information and supplement as additional information becomes known.
8.3 Assistance
Processor will reasonably assist Controller with:
- Investigating and documenting the breach
- Notifying Supervisory Authorities and Data Subjects where required under Applicable Data Protection Laws
- Preventing recurrence
8.4 Controller Notifications
Notification to Controller under this Section does not constitute an acknowledgment by Processor of fault or liability.
9. Data Subject Requests
9.1 Assistance
Taking into account the nature of the processing, Processor will reasonably assist Controller in responding to Data Subject Requests by:
- (a) Providing tools within the Service to enable Controller to access, correct, export, or delete Personal Data
- (b) Forwarding to Controller without undue delay any Data Subject Request received directly by Processor, unless Applicable Data Protection Laws require Processor to respond directly
- (c) Responding, where Controller requests, to Supervisory Authority inquiries relating to Controller’s processing
9.2 Direct Requests to Processor
Where a Data Subject contacts Processor directly regarding Personal Data processed on behalf of Controller, Processor will:
- (a) Inform the Data Subject that Controller is the primary point of contact
- (b) Route the request to Controller
- (c) Not respond substantively to the request without Controller’s authorization, except to the extent required by Applicable Data Protection Laws
9.3 Costs
Processor will provide reasonable assistance under this Section at no additional charge. Extraordinary assistance (for example, technical work outside standard Service tools) may be subject to reasonable fees agreed in advance.
10. International Data Transfers
10.1 Transfer Mechanism
Processor and its Subprocessors process Personal Data in the United States and in other jurisdictions as described in Exhibit B.
10.2 Standard Contractual Clauses
To the extent the processing of Personal Data involves transfer from the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing adequate protection, the Parties agree that the Standard Contractual Clauses set out in Exhibit D are incorporated by reference and form part of this DPA. In the event of a conflict between this DPA and the SCCs, the SCCs prevail with respect to such transfers.
10.3 UK Transfers
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU SCCs applies and is incorporated by reference.
10.4 Swiss Transfers
For transfers from Switzerland, the SCCs apply with the modifications set out by the Swiss Federal Data Protection and Information Commissioner.
11. Term, Return, and Deletion
11.1 Term
This DPA takes effect on the effective date stated above and continues for the term of the Agreement.
11.2 Export
For a period of thirty (30) days following termination or expiration of the Agreement (“Export Grace Period,” Day 1–30 post-cancellation), Controller may export Personal Data through Service tools or by request to Processor.
11.3 Deletion
Following the Export Grace Period, Personal Data enters a dormant retention state (Day 31–90 post-cancellation) during which it is not actively processed. No later than ninety (90) days after termination or expiration of the Agreement (Day 91), Processor will permanently delete Personal Data from active production systems, except where Applicable Data Protection Laws or a documented legal hold require longer retention.
11.4 Backups
Personal Data in Processor’s backup systems will be deleted in the ordinary course of backup rotation, typically within thirty-five (35) days after deletion from active systems. Personal Data remaining on backups during this period will not be actively processed and will remain subject to this DPA.
11.5 Certification
Upon written request, Processor will provide Controller with written certification of deletion.
12. Liability
The liability of each Party under this DPA is subject to the limitations of liability set forth in the Agreement, except where Applicable Data Protection Laws prohibit such limitation. For the avoidance of doubt, the total liability of each Party under this DPA and the Agreement, when combined, shall not exceed the cap set in the Agreement, calculated on a single-cap basis.
13. General Provisions
13.1 Order of Precedence
In the event of a conflict between the documents governing the relationship between the Parties, the order of precedence is:
- This DPA (for matters relating to Personal Data)
- The Agreement (for all other matters)
- The Privacy Policy
- The Order Form
13.2 Amendments
This DPA may be amended by written agreement of the Parties. Processor may amend the Exhibits to this DPA (including the Subprocessor list in Exhibit B and the security measures in Exhibit C) from time to time in accordance with the procedures set out in this DPA.
13.3 Regulatory Changes
If Applicable Data Protection Laws change in a manner that requires modifications to this DPA, the Parties will negotiate in good faith to update the DPA.
13.4 Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force.
13.5 Governing Law
This DPA is governed by the law specified in the Agreement, except that provisions relating to GDPR matters are governed by the law specified in the SCCs where the SCCs apply.
13.6 Counterparts and Electronic Signatures
This DPA may be executed in counterparts and by electronic signature, each of which is deemed an original.
13.7 Entire Agreement
This DPA, together with the Agreement and the Exhibits, constitutes the entire agreement between the Parties regarding the processing of Personal Data and supersedes all prior understandings on that subject.
14. Execution
The Parties agree to the terms of this DPA as of the effective date.
Chef Life Media LLC (Processor)
By: ___________________________
Name: Chef Adam M Lamb
Title: Founder
Date: ________________
Controller
By: ___________________________
Name: ________________________
Title: ________________________
Organization: _________________
Date: ________________
Exhibit A — Description of Processing
A.1 Subject Matter of Processing
Provision of a staff development software-as-a-service platform, including onboarding plan management, manager check-in documentation, progressive discipline documentation with audit trails, AI-assisted coaching (DevCoach), and optional voice dictation.
A.2 Duration of Processing
For the term of the Agreement and for the retention periods described in Section 11 of the DPA and the Privacy Policy.
A.3 Nature of Processing
Collection, storage, access, use, disclosure to Subprocessors as described in Exhibit B, transmission, erasure, and destruction of Personal Data as necessary to provide the Service.
A.4 Purpose of Processing
To provide the Service to Controller in accordance with the Agreement, including:
- Enabling Controller’s authorized users to create and manage staff records
- Generating and storing onboarding plans, check-in notes, and disciplinary documentation
- Providing AI-assisted coaching suggestions through DevCoach
- Transcribing voice input into text where voice dictation is enabled and used by Controller’s authorized users
- Providing customer support to Controller
- Maintaining the security and integrity of the Service
A.5 Categories of Data Subjects
- Controller’s current and former employees, contractors, and workers whose records are entered into the Service
- Controller’s job applicants (if Controller uses the Service for pre-hire tracking)
- Controller’s authorized users (managers, administrators, and other personnel with Service access)
A.6 Categories of Personal Data
Depending on Controller’s use of the Service, categories may include:
Identifiers and contact information
- Name, employee ID, email address, phone number
- Role, department, position, location
- Hire date, termination date
Employment performance data
- Onboarding plans, progress, and observations
- Manager check-in notes and feedback
- Performance observations and ratings (where Controller uses such features)
- Disciplinary records, corrective actions, written warnings, audit trails
- Records of conversations and interactions documented by managers
Authentication data (for authorized users)
- Username, hashed password, authentication tokens
- Access logs and session data
Voice data (only where voice dictation is enabled and used)
- Audio of the dictating authorized user’s voice, processed ephemerally and not stored
- Transcripts of voice input
AI interaction data
- Prompts submitted to DevCoach and generated outputs
- Metadata about AI interactions (user, timestamp, feature used)
Special categories of data (GDPR Article 9)
The Service is not designed for the intentional processing of special categories of Personal Data. However, Controllers may inadvertently include such data in free-text fields (for example, mention of an accommodation in a check-in note). Controllers are responsible for providing any additional lawful bases and safeguards required for such data.
A.7 Frequency of Processing
Continuous, for the duration of the Agreement.
Exhibit B — List of Subprocessors
The current version of this list is maintained at https://thestaffdevapp.com/legal/subprocessors/. In the event of a discrepancy, the published list prevails.
| Subprocessor | Purpose | Location of Processing | Description |
|---|---|---|---|
| Supabase Inc. | Database, authentication, object storage | United States (us-east-1) | Primary backend data storage and authentication platform |
| Vercel Inc. | Application hosting, edge compute, serverless functions | Global (primarily US) | Hosting platform for the Service application |
| Anthropic PBC | Large language model provider for DevCoach | United States | AI model powering the coaching assistant; operates under zero-training commitments for API-submitted data |
| Deepgram Inc. | Speech-to-text transcription | United States | Voice dictation transcription; operates under zero-retention configuration; audio not stored or used for training |
| ElevenLabs Inc. | Text-to-speech synthesis (DevCoach Listen feature) | United States | Synthesizes spoken audio from DevCoach AI response text using a licensed custom voice model of Chef Adam M. Lamb. Receives only the AI-generated response text (not the user’s prompt). Subject to ElevenLabs’ standard operational log retention per their published DPA; not used for model training on Processor’s plan tier. ElevenLabs maintains SOC 2 Type 2, ISO 27001:2022, ISO 27701:2019, ISO/IEC 42001:2023 (AI management systems), HIPAA, GDPR, and CCPA/CPRA certifications and attestations. Audio is streamed to the user’s browser and not stored by Processor. |
| Resend, Inc. | Transactional email delivery | United States | Email delivery for account and Service notifications (password resets, check-in notifications, billing receipts) |
| Stripe Inc. | Payment processing | United States | Processes subscription payments |
| SiteGround Hosting Ltd. | Marketing website hosting | US (WordPress marketing site only; does not process Customer Content) | Hosts the marketing website only; does not process Customer Content |
Note: Subprocessors that process marketing website data (SiteGround, any analytics tools) do not process Customer Content from the application at app.thestaffdevapp.com and are listed for completeness.
Exhibit C — Technical and Organizational Measures
Processor implements and maintains the following technical and organizational measures to protect Personal Data:
C.1 Access Control
- Role-based access controls within the Service
- Row-level security at the database layer isolating each Controller’s data from every other Controller’s data
- Unique user accounts with strong password requirements
- Multi-factor authentication available for authorized users and required for administrative access to production systems
- Principle of least privilege applied to Processor personnel access to production systems
- Access logs retained for security monitoring and audit
C.2 Encryption
- Data encrypted in transit using TLS 1.2 or higher for all connections to and from the Service
- Data encrypted at rest using AES-256 or equivalent for all databases and object storage
- Secure key management through Supabase and cloud provider key management services
C.3 Network Security
- Application hosted on modern cloud infrastructure with network-layer protections
- Web application firewall protections at the edge
- Rate limiting applied to authentication and API endpoints
- Regular dependency scanning for known vulnerabilities
C.4 Availability and Resilience
- Database backups performed automatically by the underlying platform
- Disaster recovery plan covering restoration of Service following major incidents
- Monitoring and alerting on Service availability and performance
C.5 Secure Development
- Source code maintained in version-controlled repositories with access restrictions
- Dependency management and regular updates
- Security-relevant changes reviewed before deployment to production
- Separation of development and production environments
C.6 Personnel
- Confidentiality obligations bind all personnel with access to Personal Data
- Access to production systems is limited to personnel with a demonstrated business need
- Access is revoked promptly when personnel no longer require it
C.7 Subprocessor Management
- Due diligence conducted before engaging Subprocessors
- Written contracts with each Subprocessor imposing data protection obligations
- Periodic review of Subprocessor security posture
C.8 Voice Data Specific Measures
Where Controller or Controller’s authorized users engage voice-related features:
Voice dictation (speech-to-text, Deepgram):
- Audio transmitted over TLS directly from the authorized user’s browser to Processor’s Edge Function
- Audio forwarded to Deepgram under a zero-retention configuration
- Audio held in memory only for the duration of transcription; not written to persistent storage
- Only transcription metadata (user, timestamp, duration, character count) is retained for audit and rate-limiting purposes; the audio and transcript content are not retained in association with audit metadata
DevCoach voice output (text-to-speech, ElevenLabs):
- When a user activates the Listen feature on a DevCoach response, only the AI-generated response text is transmitted over TLS to ElevenLabs; the user’s prompt is not transmitted
- ElevenLabs synthesizes audio using a licensed custom voice model of Chef Adam M. Lamb and streams the audio back to the user’s browser
- Audio is not stored by Processor; metadata-only records (user, timestamp, character count) are retained for audit and rate-limiting purposes
- Unlike voice dictation, this path does not operate under a zero-retention configuration: ElevenLabs may retain the submitted text and generated audio in operational logs under their standard retention policy (typically ~30 days). ElevenLabs does not use submitted content to train their models on Processor’s plan tier. Controllers with stricter zero-logging requirements should contact Processor to discuss enterprise-tier arrangements with ElevenLabs.
C.9 Incident Response
- Documented security incident response procedures
- Breach notification procedures aligned with Section 8 of the DPA
- Post-incident review and remediation process
C.10 Ongoing Improvements
Processor continuously evaluates and improves security measures based on threat landscape, industry practices, and the nature of the Personal Data processed. Material changes that reduce the level of protection will not be made without Controller notice.
Exhibit D — Standard Contractual Clauses
The following elections apply pending finalization with engaged counsel for customers who trigger EEA/UK/Swiss transfer scenarios. These provisional elections reflect common defaults for U.S.-based processors and are intended to provide a workable transfer framework until a customer-specific execution is countersigned.
For transfers of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to Processor in the United States, the Parties agree that the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 (or any successor clauses) are incorporated by reference into this DPA.
The applicable module is Module Two: Transfer Controller to Processor.
The following elections and annexes apply to the SCCs:
Clause 7 (Docking Clause)
The optional docking clause does not apply.
Clause 9 (Use of Subprocessors)
Option 2: General Written Authorization. Processor has general authorization to engage Subprocessors in accordance with Section 6 of this DPA. Processor will inform Controller of intended changes concerning the addition or replacement of Subprocessors at least thirty (30) days in advance, giving Controller sufficient time to object before the engagement.
Clause 11 (Redress)
The optional independent dispute resolution language does not apply.
Clause 17 (Governing Law)
These SCCs are governed by the law of Ireland.
Clause 18 (Forum and Jurisdiction)
Disputes arising from the SCCs will be resolved by the courts of Ireland.
Annex I.A (List of Parties)
Data Exporter: the Controller identified in the Agreement.
Data Importer: Chef Life Media LLC, 65 Merrimon Avenue, Suite 1153, Asheville, North Carolina 28801, United States. Contact: privacy@thestaffdevapp.com.
Annex I.B (Description of Transfer)
As set out in Exhibit A of this DPA.
Annex I.C (Competent Supervisory Authority)
The supervisory authority of the EU Member State in which the Controller is established, or as otherwise required by the SCCs.
Annex II (Technical and Organizational Measures)
As set out in Exhibit C of this DPA.
Annex III (List of Subprocessors)
As set out in Exhibit B of this DPA.
UK Addendum
For transfers from the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office is incorporated by reference, with:
- Table 1 (Parties): as set out in the Agreement and this DPA
- Table 2 (Selected SCCs): the EU SCCs above, Module Two
- Table 3 (Annex Information): as set out in the Exhibits to this DPA
- Table 4 (Ending this Addendum): neither party may end the Addendum as set out in Section 19 of the Mandatory Clauses
Swiss Addendum
For transfers from Switzerland, the SCCs apply with the following modifications specified by the Swiss Federal Data Protection and Information Commissioner:
- References to GDPR are interpreted as references to the Swiss Federal Act on Data Protection
- References to EU Member States are interpreted to include Switzerland
- The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner
- The governing law for Swiss transfers is Swiss law
Questions about this DPA?
Privacy and data protection: privacy@thestaffdevapp.com
Legal: legal@thestaffdevapp.com
General support: support@thestaffdevapp.com
Chef Life Media LLC
65 Merrimon Avenue, Suite 1153
Asheville, NC 28801
828-688-0080
Stay Tall & Frosty. Lead from the Heart.
