Legal
Data Processing Addendum
Version v1 — Beta — pending counsel review
1. Roles
HumanWealthDesign ("HWD", "we") operates the platform you use to calculate Human Design charts, store client records, and run coaching sessions. When you (the "Coach") use HWD to store information about your clients (names, birth data, generated charts, AI chat transcripts, notes), you are the Data Controller for that information and HWD is the Data Processor. You decide what client data enters the platform; HWD processes it on your behalf according to this DPA.
2. Sub-processors
HWD uses the following sub-processors to deliver the platform:
- Supabase — primary database, file storage, authentication.
- Anthropic — large language model (Claude) for AI chat and reading generation. Chart data and chat content are sent to Anthropic at the time of each request. Processed under Anthropic's commercial API terms; not used to train Anthropic's models.
- Stripe — payment processing and subscription billing.
- Mux — video hosting and signed playback for gate-content and course videos.
- Postmark / Resend (transactional email) — magic-link and notification email delivery.
- Vercel — application hosting.
We'll give 30 days' notice via email before adding or replacing a sub-processor that handles your clients' personal data.
3. Subscription cancellation and data retention
If your HD Coach subscription cancels, you retain access for 60 days to export your full client roster as CSV via the dashboard. After 60 days, your coach-client association rows are deleted; the chart records themselves are retained (anonymized with respect to your coaching relationship) and remain accessible to the individuals they describe should they ever interact with HWD directly.
4. Client deletion requests
If one of your clients requests deletion of their data, you must comply within 30 days. HWD will delete the relevant records within 7 days of receiving the forwarded request from you (or directly from the client, if they emailsupport@humanwealthdesign.com).
5. Data portability
You can export your entire client database to CSV at any time from/dashboard/export. The export includes client name, birth data, chart attributes, and creation timestamps. AI chat transcripts are available on request.
6. Security
- Data at rest is encrypted via Supabase (AES-256).
- Data in transit is encrypted via HTTPS/TLS.
- Database row-level security (RLS) restricts access to your own records.
- No passwords or API credentials are stored in plaintext.
- Service-role credentials are never exposed to the browser.
7. Breach notification
In the event of a security incident affecting your client data, HWD will notify you within 72 hours of becoming aware of the incident.
8. AI / model interaction
Each Revan AI chat turn sends the relevant portions of the client's chart and the conversation context to Anthropic's API. Anthropic processes these payloads under its commercial terms and does not retain them for model training. HWD does not sell client data to any party.
9. Minors
If you calculate or store charts for clients under 18 years of age, you warrant that you have obtained the consent of a parent or legal guardian. HWD does not make any independent representation about its suitability for processing minors' data.
10. Updates to this DPA
We'll notify you by email if we update this DPA in a material way. You may be asked to re-accept the new version on next login. The version of the DPA you accepted is recorded against your coach account.
