Legal notice
Data Processing Addendum
How Hello. I Am Here. processes personal data, including subprocessors, security, and deletion.
1. Scope
These notices are effective as of September 16, 2026. They apply to https://hello-i-am-here.com, The Couch, companion care, vibe rooms, listener sits, and related software, copy, audio, and artwork (the "Service"). The operator is Hello. I Am Here.. Questions: info@hello-i-am-here.com.
This DPA applies when we process personal data in connection with the Service. For consumer sits, we are the controller. If an organization contracts us to host sits for its people, that organization is the controller and we are the processor for that engagement.
2. Nature and purpose
Subject matter: listener matching, scheduling, room chat, companion journals, Couch mail, File Cabinet records, and payment references.
Duration: the term of the Service plus the retention periods in the Privacy Policy.
Types of data: identifiers, contact data, sit content, and limited location data if a user requests local resources.
Data subjects: clients, guests, listeners, and staff.
3. Instructions and confidentiality
When we act as processor, we process only on documented instructions, keep sit content confidential, and require the same of persons authorized to process it.
4. Subprocessors
Current subprocessors: Cloudflare (hosting, routing, email send/receive); MongoDB Atlas (records database, when MONGODB_URI is configured); Stripe (payments and Connect). We will require subprocessors to protect data at a level consistent with this DPA. Email ${LEGAL_CONTACT_EMAIL} for an updated list.
5. Security
We use HTTPS, access-controlled Couch logins, watermarking and screenshot deterrents on the Service, least-privilege staff roles, and encrypted transport to processors. No online service is perfectly secure. You must also protect devices used to join a sit.
6. Breach notice
If we confirm a personal-data breach affecting the Service, we will notify affected controllers or users without undue delay and include facts we reasonably know: nature, likely consequences, and measures taken.
7. Assistance, deletion, and audit
We will assist with data-subject requests that come through the Service. On termination of a processor engagement we will delete or return processed sit data except where law requires retention. Reasonable security summaries are available to a contracting controller on written request.
8. International transfers
If data is transferred outside the originating country, we rely on the processor's lawful transfer mechanism (including standard contractual clauses where used by Cloudflare, MongoDB, or Stripe).