Legal
Data Processing Agreement (DPA) Reference Hub
Last updated: May 4, 2026 · Finalized Enforcement Edition
For institutional, corporate, and large-scale church users requiring a formal Data Processing Agreement (DPA) under GDPR Article 28, the following architecture lists our data sub-processors and security configurations.
1. Authorized Sub-Processor Ledger
To deliver real-time cloud automations and lookup utilities, ACE routes encrypted, non-PII metadata through the following corporate endpoints:
- GitHub Inc. (USA): App distribution infrastructure and automated version lookup queries.
- Anthropic PBC (USA): Contextual analysis, song taxonomy extraction, and semantic lyric lookups via API.
- ACRCloud (China/Global): Mathematical audio fingerprint hashing and identification routines.
- Google LLC (USA): OAuth processing and two-way data sync paths for ACE Schedule users utilizing Google Calendar profiles.
- Stripe, Inc. (USA/EU): Cloud billing infrastructure, recurring subscription token management, and PCI-compliant financial transaction execution.
2. High-Performance Hardware Isolation Note
ACE runs its live presentation audio parsing natively via CoreML and Apple Silicon frameworks. It does not transfer raw audio over the web. This design achieves standard compliance out-of-the-box by avoiding the transmission of personal data to external clouds.