Data Processing Addendum (DPA)
Last Updated: March 2026
This Data Processing Addendum forms part of the Terms of Service for the MyDailyDay application operated by Pewter Software Ltd.
1. Roles and Legal Basis
1.1 Data Controller and Processors
Pewter Software Ltd acts as the Data Controller for user personal data. Third-party providers such as Supabase, Firebase, and RevenueCat act as Data Processors.
1.2 Legal Basis for Processing (UK GDPR)
We process personal data under the following legal bases:
- Contract Performance: Account creation, app functionality, subscription management
- Legitimate Interests: Service improvement, crash reporting, fraud prevention, system security
- Consent: Push notifications, optional social features (friends, couples)
2. Categories of Data Processed
The following categories of data may be processed:
- Email addresses
- Display names
- Authentication identifiers
- Device push notification tokens
- Account relationships
- Subscription entitlement information
- Aggregated productivity statistics
3. Purpose of Processing
Data is processed solely for the purposes of:
- Operating the application
- Providing account authentication
- Enabling social features
- Managing subscriptions
- Sending push notifications
- Monitoring technical performance and crashes
4. Security Measures
We implement appropriate safeguards including:
- Encrypted local storage
- Secure authentication providers
- Restricted database access
- Managed infrastructure providers
- TLS encryption for data in transit
5. Data Retention
Personal data is retained only as long as necessary to operate the service. Upon account deletion:
- Personal identifiers are removed
- Associated relationships are deleted
A non-identifiable internal record may remain for auditing and abuse prevention.
6. Data Transfers
Infrastructure providers may process data in multiple jurisdictions, including the European Economic Area. Providers are selected that offer appropriate safeguards under UK GDPR.
7. User Rights
Users may request:
- Access to their personal data
- Correction of inaccurate information
- Deletion of personal data
Requests may be submitted to: pewtersoftware@gmail.com
8. Updates
This DPA may be updated periodically to reflect changes in services or legal requirements.