Data Processing Addendum

Version
v2
Effective
Last reviewed

View change history

Data Processing Addendum (DPA)

This Data Processing Addendum ("DPA") forms part of the Agreement between Hael Ltd ("Processor", "we") and the Customer ("Controller", "you") and reflects the parties' agreement on Processing of Personal Data in accordance with Article 28 of the UK GDPR and EU GDPR.

If there is a conflict between this DPA and the rest of the Agreement, this DPA prevails on data-protection matters.

1. Definitions

Capitalised terms have the meanings given in the GDPR. "Applicable Data Protection Law" means the UK GDPR, the UK Data Protection Act 2018, the EU GDPR, and any other data-protection law applicable to the Processing.

2. Roles and scope

The Controller appoints the Processor to Process Personal Data solely on the Controller's documented instructions, including with regard to international transfers. The Agreement and the Controller's use of the Service constitute the Controller's initial documented instructions.

3. Subject-matter, duration, nature and purpose

  • Subject matter: Provision of the Hael AI governance and audit platform
  • Duration: Term of the Agreement plus the deletion window in section 12
  • Nature and purpose: Hosting, storage, retrieval, analysis, and audit logging of Controller data for the purpose of AI governance, evidence, and compliance
  • Categories of data subjects: Controller's authorised Users; individuals identified within governance records the Controller uploads
  • Categories of Personal Data: Account data, authentication data, usage logs; content submitted by the Controller

4. Processor obligations

The Processor will:

  1. Process Personal Data only on documented instructions from the Controller
  2. Ensure persons authorised to Process Personal Data are bound by confidentiality
  3. Implement appropriate technical and organisational measures set out in Annex II
  4. Engage Sub-processors only in accordance with section 5
  5. Assist the Controller, taking into account the nature of Processing, with data-subject requests, DPIAs, and prior consultation with supervisory authorities
  6. Notify the Controller of Personal Data Breaches in accordance with section 9
  7. Make available all information reasonably necessary to demonstrate compliance and allow audits (section 10)
  8. Delete or return Personal Data at the end of the Agreement (section 12)
  9. Not use Personal Data to train shared or third-party AI models

5. Sub-processors

The Controller grants the Processor general authorisation to engage Sub-processors. The current list is published at /sub-processors.

Before engaging a new Sub-processor, the Processor will give the Controller at least 30 days' advance notice via the RSS feed at /sub-processors/feed.rss and the email subscriber list. The Controller may object on reasonable data-protection grounds within the notice period; the parties will work in good faith to resolve the objection, failing which the Controller may terminate the affected Service for material breach without penalty.

The Processor imposes data-protection terms on each Sub-processor no less protective than those in this DPA and remains liable for the acts and omissions of its Sub-processors.

6. International transfers

Where Personal Data is transferred outside the UK / EEA to a country without an adequacy decision, the parties agree that:

  • The EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) are incorporated by reference, with Module Two (Controller-to-Processor) applying between the Controller and Processor, and Module Three (Processor-to-Processor) applying between the Processor and any onward Sub-processor.
  • The UK International Data Transfer Addendum (B1.0) to the EU SCCs applies for UK transfers.
  • A documented Transfer Impact Assessment is completed where required.

Docking clause, optional clauses, and Annexes are populated from the Agreement, this DPA (Annexes I and II), and the current sub-processors list.

7. Assistance with data-subject requests

Taking into account the nature of Processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as this is possible, to respond to requests to exercise data-subject rights.

8. Records

The Processor maintains records of Processing activities in accordance with Article 30(2) GDPR and makes them available on reasonable request.

9. Personal Data Breach notification

The Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Controller Personal Data, and will provide information reasonably necessary to enable the Controller to meet its own notification obligations.

10. Audit rights

Once per 12-month period (or more frequently following a Personal Data Breach or on the reasonable request of a supervisory authority), the Controller may audit the Processor's compliance with this DPA on 30 days' written notice, during normal business hours, subject to reasonable confidentiality and security controls. The Processor may satisfy this obligation by providing an up-to-date independent audit or penetration-test report and completed security questionnaires (CAIQ / SIG Lite).

11. Sub-processor breaches

The Processor is liable for the acts and omissions of its Sub-processors to the same extent as it is liable for its own acts and omissions under this DPA.

12. Deletion and return

On termination or expiry of the Agreement, the Processor will:

  • Make Customer Data available for export for 30 days
  • Delete Customer Data within 90 days thereafter, subject to legal-hold or retention obligations
  • Certify deletion on request

13. Governing law

This DPA is governed by the same law as the Agreement, unless Applicable Data Protection Law requires otherwise.

Annex I — Details of Processing

| Item | Value | | --- | --- | | Controller | The Customer identified in the Order Form | | Processor | Hael Ltd | | Subject matter | AI governance, audit, and evidence tooling | | Duration | Term of the Agreement + deletion window (section 12) | | Nature and purpose | Hosting, storage, retrieval, analysis, audit logging | | Categories of data subjects | Authorised Users; individuals identified in Controller-submitted governance records | | Categories of Personal Data | Account, authentication, usage, Controller-submitted content | | Special categories | None intentionally Processed | | Frequency | Continuous, for the duration of the Agreement | | Retention | Per section 12 and the Agreement |

Annex II — Technical and organisational measures

  • Encryption: TLS 1.3 in transit; AES-256 at rest
  • Access control: Least-privilege RBAC with separation of duties; MFA enforced for production and admin access
  • Tenant isolation: Row-Level Security on every multi-tenant table, validated by an automated cross-tenant attack suite gated in CI
  • Audit logging: Tamper-evident SHA-256 hash-chained audit log with 7-year retention and regulator-friendly export
  • Monitoring: 24/7 security monitoring with SIEM and alerting on defined signals
  • Testing: Third-party penetration testing on a defined annual cadence; quarterly internal control assessments
  • Vendor management: Documented sub-processor security review before engagement
  • Personnel: Background checks on personnel with production access; confidentiality obligations
  • Resilience: Documented BCP/DR with tested RTO/RPO targets
  • Data minimisation and no-training: Customer Data is not used to train shared or third-party AI models

Annex III — Sub-processors

The current list is maintained at /sub-processors and updated with at least 30 days' advance notice of changes.

A signed PDF copy of this DPA is available on request from dpo@hael.ai.

Need a copy for procurement? Download the versioned PDF.Download PDF
Need a counter-signed copy? Email dpo@hael.ai — we sign and return within 2 business days.