HookFeed Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the HookFeed Terms of Service (the "Agreement") between HookFeed LLC ("HookFeed," "we," "us") and the customer entity that is party to the Agreement ("Customer," "you"). This DPA applies to the extent that HookFeed processes Personal Data on behalf of Customer in the course of providing the Services.

In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.

1. DEFINITIONS

In this DPA, the following terms have the meanings set out below. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including (as applicable): (a) the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); (b) the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 ("UK GDPR"); (c) the Swiss Federal Act on Data Protection ("Swiss DPA"); (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); and (e) any other applicable US state privacy law.

"Controller" means the entity that determines the purposes and means of the processing of Personal Data. For the purposes of this DPA, Customer is the Controller.

"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.

"EEA" means the European Economic Area.

"Inbound Data" means webhook payloads and other event data transmitted to HookFeed by Customer or by third-party services at Customer's direction.

"Personal Data" means any information relating to an identified or identifiable natural person that is contained within Inbound Data or otherwise processed by HookFeed on behalf of Customer in connection with the Services.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

"Processor" means the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, HookFeed is the Processor.

"Processing" (and "process," "processed," etc.) means any operation or set of operations performed on Personal Data, whether or not by automated means.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission.

"Sub-processor" means any third party engaged by HookFeed to process Personal Data on behalf of Customer.

2. SCOPE AND ROLES

2.1 Scope

This DPA applies to the processing of Personal Data by HookFeed on behalf of Customer in connection with the provision of the Services under the Agreement.

2.2 Roles

Customer is the Controller; HookFeed is the Processor acting on behalf of Customer.

2.3 Customer Responsibilities

Customer is responsible for determining the lawful basis for processing Personal Data and for ensuring compliance with Applicable Data Protection Law.

3. DETAILS OF PROCESSING

3.1 Subject Matter and Duration

HookFeed processes Personal Data for the purpose of providing the Services to Customer.

3.2 Nature and Purpose of Processing

HookFeed processes Personal Data to ingest and store webhook payloads, extract and transform event data, generate feeds, dashboards, metrics, and deliver notifications.

3.3 Categories of Data Subjects

Data Subjects may include any individuals whose Personal Data is contained within the Inbound Data.

3.4 Types of Personal Data

The types of Personal Data processed depend on what Customer transmits to HookFeed. This may include names, email addresses, IP addresses, and other Personal Data.

3.5 Special Categories of Data

HookFeed is not designed to process special categories of Personal Data.

4. HOOKFEED'S OBLIGATIONS AS PROCESSOR

4.1 Processing Instructions

HookFeed shall process Personal Data only on documented instructions from Customer, unless required to do otherwise by applicable law.

4.2 Confidentiality

HookFeed shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality.

4.3 Security

HookFeed shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized processing.

4.4 Sub-processors

Customer provides general authorization for HookFeed to engage Sub-processors to process Personal Data.

4.5 Assistance with Data Subject Rights

HookFeed shall assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

4.6 Assistance with Customer's Compliance Obligations

HookFeed shall assist Customer in ensuring compliance with Customer's obligations under Applicable Data Protection Law.

5. PERSONAL DATA BREACH

5.1 Notification

HookFeed shall notify Customer without undue delay after becoming aware of a Personal Data Breach.

5.2 Content of Notification

The notification shall include a description of the nature of the Personal Data Breach.

5.3 Cooperation

HookFeed shall cooperate with Customer in the investigation and remediation of any Personal Data Breach.

5.4 Limitations

HookFeed's obligation to report or respond to a Personal Data Breach is not an acknowledgment of fault.

6. DATA SUBJECT REQUESTS

6.1 Assistance

If Customer receives a request from a Data Subject, HookFeed shall provide reasonable assistance.

6.2 Response Time

HookFeed shall respond to Customer's requests for assistance within ten (10) business days.

7. INTERNATIONAL DATA TRANSFERS

7.1 Location of Processing

HookFeed processes and stores Personal Data in the United States.

7.2 Transfer Mechanism for EEA, UK, and Swiss Data

The parties agree that such transfers shall be governed by the Standard Contractual Clauses.

7.3 EU-U.S. Data Privacy Framework

If HookFeed certifies under the EU-U.S. Data Privacy Framework, such certification may serve as a valid transfer mechanism.

7.4 Alternative Transfer Mechanisms

The parties shall cooperate in good faith to implement an alternative lawful transfer mechanism.

8. AUDITS

8.1 Information and Audit Rights

HookFeed shall make available to Customer all information necessary to demonstrate compliance with this DPA.

8.2 Audit Procedures

Customer shall provide HookFeed with at least thirty (30) days prior written notice of any audit request.

8.3 Supervisory Authority Audits

HookFeed shall cooperate with any supervisory authority or regulatory body with jurisdiction over Customer's processing activities.

9. DATA RETENTION AND DELETION

9.1 Retention

HookFeed shall retain Personal Data only as long as necessary to provide the Services.

9.2 Deletion on Termination

Upon termination of the Agreement, HookFeed shall delete all Personal Data upon Customer's request.

9.3 Exceptions

HookFeed may retain Personal Data as required by applicable law.

10. US STATE PRIVACY LAW PROVISIONS

10.1 CCPA/CPRA

To the extent that HookFeed processes Personal Data that constitutes "personal information" under the CCPA/CPRA, HookFeed shall comply with applicable provisions of the CCPA/CPRA.

10.2 Other US State Privacy Laws

To the extent that HookFeed processes Personal Data subject to other US State Privacy Laws, HookFeed shall assist Customer in meeting its obligations under such laws.

11. GENERAL

11.1 Order of Precedence

In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.

11.2 Liability

Each party's total aggregate liability under this DPA shall be subject to the limitations of liability set out in the Agreement.

11.3 Amendments

HookFeed may update this DPA from time to time to reflect changes in Applicable Data Protection Law.

11.4 Contact

Questions about this DPA may be directed to privacy@hookfeed.com.

APPENDIX A — DETAILS OF PROCESSING

This Appendix forms part of the SCCs (Annex I).

A. List of Parties

Data Exporter (Controller):

  • Name: The Customer entity identified in the Agreement
  • Role: Controller

Data Importer (Processor):

  • Name: HookFeed LLC
  • Address: 8605 Santa Monica Blvd #74803, West Hollywood, CA 90069
  • Role: Processor

B. Description of Transfer

  • Categories of Data Subjects: Customer's customers, users, subscribers, contacts, employees.
  • Categories of Personal Data: Determined by Customer based on what is transmitted via webhook payloads.
  • Frequency of Transfer: Continuous, event-driven.
  • Nature of Processing: Ingestion, storage, extraction, filtering, transformation, analysis, display, alerting.
  • Purpose of Processing: To provide the Services described in the Agreement.
  • Retention Period: As specified in the Agreement based on Customer's plan tier.

APPENDIX B — TECHNICAL AND ORGANIZATIONAL MEASURES

HookFeed implements and maintains the following technical and organizational measures for the protection of Personal Data:

Encryption:

  • All data in transit encrypted via TLS/HTTPS
  • All data at rest encrypted

Access Controls:

  • Employee access to Personal Data limited to authorized personnel
  • Two-factor authentication for infrastructure access

Network Security:

  • CDN and DDoS protection via Cloudflare

AI Processing:

  • AI service providers prohibited from using customer data for model training.

APPENDIX C — LIST OF SUB-PROCESSORS

Sub-processor Purpose Location
Amazon Web Services, Inc. Cloud infrastructure and data storage United States
Anthropic PBC AI-powered event analysis United States
Cloudflare, Inc. Network security United States
Help Scout, Inc. Customer support United States
Heroku (Salesforce, Inc.) Application hosting United States
Hex Technologies, Inc. Data collaboration United States
PostHog, Inc. Product analytics United States
Postmark (ActiveCampaign, LLC) Email delivery United States
Sentry (Functional Software, Inc.) Error tracking United States
Stripe, Inc. Payment processing United States