Data Processing Agreement (DPA)
Last updated: 23 August 2026
This Data Processing Agreement (GDPR Art. 28) forms part of the Terms of Service for Hivexel Compliance. It applies when the customer organisation (the “Controller”) uses the Service and Hivexel (the “Processor”) processes Customer Data on the Controller’s instructions. Contact: [email protected].
1. Roles and subject matter
The Controller determines the purposes and means of processing Customer Data. The Processor processes that data only to provide the Service (hosting, display, sending alerts the Controller configures, backups and technical support) and according to the documented instructions in this DPA and the product.
This DPA does not cover account, billing and marketing data of the platform user, for which Hivexel is the controller — see the Privacy Policy.
2. Nature, purpose and categories
- Nature: SaaS hosting, file storage, sending alert and digest emails the Controller configures, exports the Controller requests.
- Purpose: enabling the Controller to track its organisation’s compliance obligations and evidence.
- Data subjects: employees, contractors, supplier contacts and invited users — as entered by the Controller.
- Data categories: professional identity and contact details, employment or equipment data the Controller records, file metadata and the contents of uploaded documents.
- Special categories: the Service allows storage of evidence the Controller chooses to upload, including occupational medical-fitness certificates (health data) or identity documents. The Processor does not require those categories by default; the Controller must upload them only if it has a ground under GDPR Art. 9 (and applicable labour / H&S law) and has informed the data subjects.
- Duration: while the organisation account exists plus the residual period in the deletion clause.
3. Instructions
The Processor follows the Controller’s instructions given through the Service (create, edit, delete, export, invite users, configure alerts) and by email to [email protected]. It will refuse instructions that breach the GDPR and will tell the Controller, unless EU or national law forbids that.
The Controller is solely responsible for ensuring its instructions are lawful, including the legal basis for special-category data and information of data subjects (Arts. 13 and 14).
4. Confidentiality and personnel
Persons authorised to process Customer Data are bound to confidentiality and access it only as needed (support, operations, security).
5. Security (Art. 32)
The Processor applies measures appropriate to the risk, including: HTTPS, authentication, logical isolation between organisations (RLS), role-based access, and file delivery only to authenticated users of the organisation. The Controller must manage roles and invites on a least-privilege basis and protect its credentials.
6. Subprocessors
The Controller generally authorises use of the subprocessors below, which are required to provide the Service. The Processor will impose equivalent obligations on them and remains liable for their acts. Material changes to the list will be announced by email or in-product with reasonable notice; the Controller may object on substantiated grounds and, ultimately, terminate the Service.
- Supabase — authentication, PostgreSQL database and file storage;
- DigitalOcean — application hosting;
- Stripe — payments and invoicing (mainly commercial-relationship data; may process organisation identifiers);
- Brevo — transactional and alert email;
- Inngest — background jobs (reminders, imports, digest);
- Cloudflare — Turnstile (anti-bot on sign-in/sign-up);
- PostHog (EU region when configured) — server-side product events, without document contents;
- Google Ireland / Google LLC — Analytics and Ads, only if the account user has accepted non-essential cookies;
- Sentry — application error diagnostics, if configured, with sensitive fields filtered.
Some of these providers may process data outside the EEA, using standard contractual clauses and, where available, an EU region. The concrete database region is the one configured on the production project.
7. Assistance to the Controller
The Processor helps the Controller respond to data-subject requests to the extent the Service allows (the Controller can access, rectify and delete most Customer Data in the interface). Requests that reach us and concern Customer Data are forwarded to the Controller, unless the law requires otherwise.
The Processor also assists, taking into account the nature of the processing, with Arts. 32 to 36 (security, DPIA, prior consultation) on reasonable request. Extraordinary work beyond normal product use may be scoped and quoted.
8. Personal-data breach
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, with the information reasonably available for the Controller to meet Art. 33. Notice is sent to the organisation owner’s email and/or a contact the Controller designates.
9. Return and deletion
During the contract the Controller may export reports and download documents through the Service. After termination, on a request to [email protected] within 30 days, the Processor will provide a reasonable export of Customer Data then available. It will then delete or anonymise Customer Data from production systems, except where the law requires retention (for example invoices) or backups that expire in the normal cycle (typically within 90 days).
10. Information and audits
The Processor will make available the information needed to demonstrate compliance with this DPA and will allow reasonable audits by the Controller (or an independent auditor bound to confidentiality), with at least 15 business days’ written notice, at most once per year unless there is an incident, during business hours, without disrupting the Service or accessing other customers’ data. Security reports from the Processor or its providers may replace an on-site audit when they are adequate to the risk.
11. Liability
Liability of the parties under this DPA follows the limitation clause in the Terms of Service, without prejudice to what the GDPR assigns to each party as controller or processor vis-à-vis data subjects or authorities.
12. Precedence and version
If there is a conflict on data protection, this DPA prevails over the Terms. Version 2026-08-23.2. Governing law and courts: those of the Terms of Service.