HookFeed Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the HookFeed Terms of Service (the "Agreement") between HookFeed LLC ("HookFeed," "we," "us") and the customer entity that is party to the Agreement ("Customer," "you"). This DPA applies to the extent that HookFeed processes Personal Data on behalf of Customer in the course of providing the Services.
In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
1. DEFINITIONS
In this DPA, the following terms have the meanings set out below. Capitalized terms not defined in this DPA have the meanings given in the Agreement.
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including (as applicable): (a) the General Data Protection Regulation (EU) 2016/679 ("EU GDPR"); (b) the EU GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018 and the UK Data Protection Act 2018 ("UK GDPR"); (c) the Swiss Federal Act on Data Protection ("Swiss DPA"); (d) the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"); and (e) any other applicable US state privacy law.
"Controller" means the entity that determines the purposes and means of the processing of Personal Data. For the purposes of this DPA, Customer is the Controller.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"EEA" means the European Economic Area.
"Inbound Data" means webhook payloads and other event data transmitted to HookFeed by Customer or by third-party services at Customer's direction.
"Personal Data" means any information relating to an identified or identifiable natural person that is contained within Inbound Data or otherwise processed by HookFeed on behalf of Customer in connection with the Services.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
"Processor" means the entity that processes Personal Data on behalf of the Controller. For the purposes of this DPA, HookFeed is the Processor.
"Processing" (and "process," "processed," etc.) means any operation or set of operations performed on Personal Data, whether or not by automated means.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission.
"Sub-processor" means any third party engaged by HookFeed to process Personal Data on behalf of Customer.
2. SCOPE AND ROLES
2.1 Scope
This DPA applies to the processing of Personal Data by HookFeed on behalf of Customer in connection with the provision of the Services under the Agreement.
2.2 Roles
Customer is the Controller; HookFeed is the Processor acting on behalf of Customer.
2.3 Customer Responsibilities
Customer is responsible for determining the lawful basis for processing Personal Data and for ensuring compliance with Applicable Data Protection Law.
3. DETAILS OF PROCESSING
3.1 Subject Matter and Duration
HookFeed processes Personal Data for the purpose of providing the Services to Customer.
3.2 Nature and Purpose of Processing
HookFeed processes Personal Data to ingest and store webhook payloads, extract and transform event data, generate feeds, dashboards, metrics, and deliver notifications.
3.3 Categories of Data Subjects
Data Subjects may include any individuals whose Personal Data is contained within the Inbound Data.
3.4 Types of Personal Data
The types of Personal Data processed depend on what Customer transmits to HookFeed. This may include names, email addresses, IP addresses, and other Personal Data.
3.5 Special Categories of Data
HookFeed is not designed to process special categories of Personal Data.
4. HOOKFEED'S OBLIGATIONS AS PROCESSOR
4.1 Processing Instructions
HookFeed shall process Personal Data only on documented instructions from Customer, unless required to do otherwise by applicable law.
4.2 Confidentiality
HookFeed shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality.
4.3 Security
HookFeed shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized processing.
4.4 Sub-processors
Customer provides general authorization for HookFeed to engage Sub-processors to process Personal Data.
4.5 Assistance with Data Subject Rights
HookFeed shall assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
4.6 Assistance with Customer's Compliance Obligations
HookFeed shall assist Customer in ensuring compliance with Customer's obligations under Applicable Data Protection Law.
5. PERSONAL DATA BREACH
5.1 Notification
HookFeed shall notify Customer without undue delay after becoming aware of a Personal Data Breach.
5.2 Content of Notification
The notification shall include a description of the nature of the Personal Data Breach.
5.3 Cooperation
HookFeed shall cooperate with Customer in the investigation and remediation of any Personal Data Breach.
5.4 Limitations
HookFeed's obligation to report or respond to a Personal Data Breach is not an acknowledgment of fault.
6. DATA SUBJECT REQUESTS
6.1 Assistance
If Customer receives a request from a Data Subject, HookFeed shall provide reasonable assistance.
6.2 Response Time
HookFeed shall respond to Customer's requests for assistance within ten (10) business days.
7. INTERNATIONAL DATA TRANSFERS
7.1 Location of Processing
HookFeed processes and stores Personal Data in the United States.
7.2 Transfer Mechanism for EEA, UK, and Swiss Data
The parties agree that such transfers shall be governed by the Standard Contractual Clauses.
7.3 EU-U.S. Data Privacy Framework
If HookFeed certifies under the EU-U.S. Data Privacy Framework, such certification may serve as a valid transfer mechanism.
7.4 Alternative Transfer Mechanisms
The parties shall cooperate in good faith to implement an alternative lawful transfer mechanism.
8. AUDITS
8.1 Information and Audit Rights
HookFeed shall make available to Customer all information necessary to demonstrate compliance with this DPA.
8.2 Audit Procedures
Customer shall provide HookFeed with at least thirty (30) days prior written notice of any audit request.
8.3 Supervisory Authority Audits
HookFeed shall cooperate with any supervisory authority or regulatory body with jurisdiction over Customer's processing activities.
9. DATA RETENTION AND DELETION
9.1 Retention
HookFeed shall retain Personal Data only as long as necessary to provide the Services.
9.2 Deletion on Termination
Upon termination of the Agreement, HookFeed shall delete all Personal Data upon Customer's request.
9.3 Exceptions
HookFeed may retain Personal Data as required by applicable law.
10. US STATE PRIVACY LAW PROVISIONS
10.1 CCPA/CPRA
To the extent that HookFeed processes Personal Data that constitutes "personal information" under the CCPA/CPRA, HookFeed shall comply with applicable provisions of the CCPA/CPRA.
10.2 Other US State Privacy Laws
To the extent that HookFeed processes Personal Data subject to other US State Privacy Laws, HookFeed shall assist Customer in meeting its obligations under such laws.
11. GENERAL
11.1 Order of Precedence
In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
11.2 Liability
Each party's total aggregate liability under this DPA shall be subject to the limitations of liability set out in the Agreement.
11.3 Amendments
HookFeed may update this DPA from time to time to reflect changes in Applicable Data Protection Law.
11.4 Contact
Questions about this DPA may be directed to privacy@hookfeed.com.
APPENDIX A — DETAILS OF PROCESSING
This Appendix forms part of the SCCs (Annex I).
A. List of Parties
Data Exporter (Controller):
- Name: The Customer entity identified in the Agreement
- Role: Controller
Data Importer (Processor):
- Name: HookFeed LLC
- Address: 8605 Santa Monica Blvd #74803, West Hollywood, CA 90069
- Role: Processor
B. Description of Transfer
- Categories of Data Subjects: Customer's customers, users, subscribers, contacts, employees.
- Categories of Personal Data: Determined by Customer based on what is transmitted via webhook payloads.
- Frequency of Transfer: Continuous, event-driven.
- Nature of Processing: Ingestion, storage, extraction, filtering, transformation, analysis, display, alerting.
- Purpose of Processing: To provide the Services described in the Agreement.
- Retention Period: As specified in the Agreement based on Customer's plan tier.
APPENDIX B — TECHNICAL AND ORGANIZATIONAL MEASURES
HookFeed implements and maintains the following technical and organizational measures for the protection of Personal Data:
Encryption:
- All data in transit encrypted via TLS/HTTPS
- All data at rest encrypted
Access Controls:
- Employee access to Personal Data limited to authorized personnel
- Two-factor authentication for infrastructure access
Network Security:
- CDN and DDoS protection via Cloudflare
AI Processing:
- AI service providers prohibited from using customer data for model training.
APPENDIX C — LIST OF SUB-PROCESSORS
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure and data storage | United States |
| Anthropic PBC | AI-powered event analysis | United States |
| Cloudflare, Inc. | Network security | United States |
| Help Scout, Inc. | Customer support | United States |
| Heroku (Salesforce, Inc.) | Application hosting | United States |
| Hex Technologies, Inc. | Data collaboration | United States |
| PostHog, Inc. | Product analytics | United States |
| Postmark (ActiveCampaign, LLC) | Email delivery | United States |
| Sentry (Functional Software, Inc.) | Error tracking | United States |
| Stripe, Inc. | Payment processing | United States |