All legal documents

Hivsy legal

Data Processing Addendum

This Data Processing Addendum (“DPA”) applies when Hivsy processes Customer Personal Data on behalf of a customer under the Terms of Service or an order form.

Effective

This DPA is incorporated into the agreement automatically. If signed terms or approved international-transfer clauses are required, contact privacy@hivsy.com before submitting regulated data.

1. Definitions and scope

“Customer Personal Data” means personal data contained in Customer Data that Hivsy processes on the customer’s behalf. “Data Protection Law” means privacy and data-protection law applicable to that processing. “Controller,” “processor,” “business,” “service provider,” “personal data,” “processing,” and “data subject” have the meanings given by applicable Data Protection Law.

This DPA applies for the duration of the agreement and prevails over conflicting data-processing terms in the Terms of Service. It does not apply to data for which Hivsy independently determines the purposes and means of processing, such as account administration, billing, security, and Hivsy’s own service communications; the Privacy Policy governs that data.

2. Roles and documented instructions

The customer is a controller or processor, and Hivsy is a processor or service provider for Customer Personal Data. The customer instructs Hivsy to process Customer Personal Data to provide, secure, support, and improve the Services; prevent abuse; comply with the agreement; and follow additional lawful instructions agreed in writing. Hivsy will not sell Customer Personal Data, retain, use, or disclose it outside the business relationship, or combine it with data received from another source except as permitted by applicable law.

If Hivsy believes an instruction violates Data Protection Law, it may suspend that instruction and notify the customer unless prohibited by law. If law requires processing beyond the customer’s instructions, Hivsy will notify the customer before processing unless legally prohibited.

3. Customer obligations

  • Comply with Data Protection Law and provide all required notices and choices.
  • Have a valid lawful basis for Customer Personal Data and for every instruction given to Hivsy.
  • Use the Services and available controls in a manner appropriate to the nature and risk of the data.
  • Respond to data-subject requests and configure retention, access, tracking, suppression, and deletion choices appropriately.
  • Do not provide sensitive or specially regulated data unless the Services and a written agreement expressly support it.

4. Confidentiality and security

Hivsy will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as needed for their duties. Hivsy will maintain technical and organizational measures appropriate to the risk, taking into account the state of the art, implementation cost, processing scope and context, and potential impact on people.

  • Identity, authentication, authorization, tenant-isolation, and least-privilege controls.
  • Encrypted transport for supported web, API, webhook, and email connections; protected storage of passwords, API credentials, DKIM keys, and webhook secrets appropriate to their function.
  • Logging, monitoring, rate limiting, anti-abuse protections, vulnerability maintenance, and incident-response procedures.
  • Availability, backup, recovery, and change-management practices appropriate to the Services.
  • Processes to review and improve safeguards based on risk and operational experience.

5. Subprocessors

The customer generally authorizes Hivsy to use subprocessors to provide the Services. Hivsy will impose data-protection obligations that are materially consistent with this DPA and remains responsible for each subprocessor’s performance of those obligations. Hivsy will make current subprocessor information available on request and, where required, give reasonable advance notice of a new subprocessor that processes Customer Personal Data.

A customer may object on reasonable data-protection grounds by contacting privacy@hivsy.com within the notice period. The parties will work in good faith on a reasonable solution. If none is available, the customer may stop the affected processing or terminate the affected Services, subject to the agreement.

6. Assistance and data-subject requests

Taking into account the nature of the processing and information available, Hivsy will provide reasonable assistance with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations required by Data Protection Law. If Hivsy receives a request about Customer Personal Data, it will ordinarily direct the person to the customer and will not independently respond unless authorized or legally required.

7. Personal data incidents

Hivsy will notify the customer without undue delay after confirming a breach of security that causes accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Hivsy will provide available information reasonably needed for the customer’s legal obligations and take reasonable steps to contain, investigate, and mitigate the incident. Notification is not an admission of fault or liability.

8. Return and deletion

During the agreement, the customer may use available features to access or export Customer Data. After termination or a valid deletion instruction, Hivsy will delete or return Customer Personal Data within a commercially reasonable period unless law requires retention. Data may remain temporarily in protected backups and security records until overwritten under normal cycles; it will remain protected and will not be used for another purpose.

9. Compliance information and audits

Hivsy will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient and Data Protection Law gives the customer an audit right, the customer may request a narrowly scoped audit no more than once annually, unless a confirmed incident or regulator requires otherwise. Audits must protect confidentiality, avoid disruption, use an independent qualified auditor, and be at the customer’s cost. The parties will agree reasonable scope, timing, and security requirements in advance.

10. International transfers

Hivsy will use a transfer mechanism recognized by applicable Data Protection Law when Customer Personal Data is transferred to a country that is not recognized as providing adequate protection. Where required, the parties will enter the applicable controller-to-processor or processor-to-processor standard contractual clauses and any required local addendum. Hivsy will implement supplementary measures appropriate to the transfer risk.

Annex A — Details of processing

ItemDetails
Subject matterEmail delivery and receipt, audience and template management, automations, analytics, suppressions, webhooks, domain management, and related support and security.
DurationFor the term of the Services and the limited retention period described in this DPA and the Privacy Policy.
Nature and purposeCollecting, storing, organizing, retrieving, transmitting, delivering, securing, troubleshooting, deleting, and otherwise processing data to provide the customer-configured Services.
Data subjectsCustomer users and representatives; the customer’s contacts, recipients, senders, end users, and correspondents; and people whose data appears in message content or attachments.
Personal dataNames, email addresses, contact attributes, identifiers, message content and attachments, inbound messages, delivery and engagement events, IP and device information, support data, and customer-configured metadata.
Sensitive dataNot intended. The customer must not submit sensitive or specially regulated data unless expressly supported by a written agreement.
FrequencyContinuous or customer-initiated, depending on use of the Services.

11. Contact

Data-protection notices, requests for transfer terms, and questions about this DPA may be sent to privacy@hivsy.com.

Questions about this document? Email privacy@hivsy.com.