Governance
Data Processing Addendum
For teams and businesses where StoryHelm processes personal data on your behalf, our standard DPA sets out the controller and processor roles, security commitments, subprocessor terms, and the EU and UK transfer clauses. Here is what it covers and how to put one in place.
Effective: · Last updated: This document's own dates. No other paper moves them.
Contents
5 sections · about 5 min read
Your DPA at a glance
A courtesy, not the contract
If your business or team uses StoryHelm in a way that has us process personal data on your behalf, you may need a signed Data Processing Addendum. Ours is built around Article 28 of the EU and UK GDPR, sets out the controller and processor roles, lists our subprocessors, and covers international transfers with Standard Contractual Clauses and the UK IDTA. This page is a plain-language summary, and requesting the DPA is as simple as emailing us.
Where this note and the sections below disagree, the sections govern.
This page summarizes StoryHelm's standard Data Processing Addendum (DPA) and explains how to request and execute it. It is a plain-language overview to help you decide whether your organization needs a DPA and to show what ours covers.
The signed DPA is the operative agreement. Where this summary and the executed DPA differ, the executed DPA governs. The DPA supplements, and forms part of, the StoryHelm Terms of Service between you and StoryHelm.
You likely need a signed DPA in place with StoryHelm if your business or team uses StoryHelm in a way that has us process personal data on your behalf. Common examples:
- A Studio team that invites collaborators, so StoryHelm processes your collaborators' names, email addresses, and account activity on your behalf.
- Any customer that is a data controller subject to the EU GDPR, the UK GDPR, or a comparable data-protection law, where StoryHelm acts as your processor.
- A business or organization with internal policy, procurement, or compliance requirements that call for a written processing agreement.
The DPA is available to any customer in this position on the Writer, Author, Series, or Studio plan. It is not gated behind a separate or higher tier, and there is no "Enterprise" plan you need to buy to obtain one.
If you are an individual author using StoryHelm only for your own manuscripts, with no collaborators and no other people's personal data involved, you generally do not need a separate DPA. Our Privacy Policy already governs how we handle your account and manuscript data.
The StoryHelm DPA is built around the requirements of Article 28 of the EU and UK GDPR and reflects how the product actually works. In plain terms, it covers:
- Roles. You are the controller of the personal data you put into StoryHelm. StoryHelm is the processor that handles that data on your documented instructions to provide the service.
- Article 28 obligations. StoryHelm processes personal data only on your instructions, for the purpose of providing manuscript-intelligence analysis, hosting, and related features, and not for any independent purpose of our own.
- Confidentiality. Personnel authorized to process your data are bound by confidentiality obligations.
- Security measures. StoryHelm maintains technical and organizational measures including encryption in transit (TLS 1.2 or higher), encryption at rest, and access controls on production systems. The current detail lives on our Security page, and StoryHelm is working toward SOC 2 Type II.
- Subprocessors. StoryHelm uses a defined set of subprocessors to deliver the service, including DigitalOcean for hosting and Anthropic, PBC for Claude-powered analysis and translation. The current list is published at /subprocessors. The DPA gives general authorization for these subprocessors and commits StoryHelm to give you at least 30 days' notice before adding or replacing one, so you have a chance to object.
- Breach notification. StoryHelm notifies you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own notification obligations.
- Data-subject requests. StoryHelm assists you, taking into account the nature of the processing, in responding to requests from individuals to exercise their rights (access, correction, deletion, and similar).
- Return and deletion of data. On termination, StoryHelm returns or deletes the personal data processed on your behalf, at your choice, subject to any legal retention obligations described in our Privacy Policy.
- Audit rights. The DPA provides for audit and inspection rights, satisfied in the first instance through our documentation, security information, and any third-party reports or certifications we maintain.
One point worth stating plainly: StoryHelm reads and analyzes manuscripts and never writes the author's prose. When you run analysis or translation, your prose is sent to StoryHelm's servers on DigitalOcean and onward to Anthropic, PBC's Claude API to be analyzed. Neither StoryHelm nor Anthropic, PBC trains any model on your work; Anthropic, PBC's commercial API does not train on inputs or outputs by default. The DPA records these commitments.
StoryHelm is hosted in the United States, and our subprocessors are currently located in the United States. Where the DPA covers personal data transferred from the European Economic Area, the United Kingdom, or Switzerland, it incorporates the appropriate transfer mechanisms:
- The EU Standard Contractual Clauses (the European Commission module-based SCCs) for transfers subject to the EU GDPR.
- The UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs, for transfers subject to the UK GDPR.
These clauses are incorporated into the DPA itself, so a single signature puts the transfer safeguards in place. We do not currently promise EU or other regional data residency at rest; transfers are handled through the SCCs and the UK IDTA rather than by keeping data in a specific region.
The process is intentionally simple:
- Email privacy@storyhelm.com and ask for the StoryHelm DPA. Let us know your account or organization name and the plan you are on.
- We send you our standard DPA, with the EU SCCs and UK IDTA already incorporated, for review.
- You sign, we counter-sign, and the executed addendum becomes part of your agreement with StoryHelm. No change to your plan or pricing is required.
If your data-protection team needs to start from our paper, the standard DPA is the fastest path. If you have questions before requesting it, you can also reach our legal team at legal@storyhelm.com.
Remember: this page is a summary. The DPA you sign is the binding agreement, and it controls in the event of any conflict with this overview.
Related policies
StoryHelm
Privacy & data requests: privacy@storyhelm.com · Legal: legal@storyhelm.com · Registered mailing address available on request.
Effective July 5, 2026 · Last updated July 6, 2026. We notify you of material changes in-app and by email; continued use after an update constitutes acceptance.

