Hawi Agents — Data Processing Agreement
Effective 23 August 2026
Last Updated: 23 August 2026 Effective Date: 23 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Hawi Inc, trading as Hawi Agents (“Hawi”, “we”, “us”, “our”, or “Processor”) and the customer accepting or entering into this DPA (“Customer”, “you”, “your”, or “Controller”) concerning Customer's use of the Hawi Services.
This DPA applies where Hawi processes Personal Data on behalf of Customer in connection with the Services.
This DPA supplements and forms part of the Hawi Terms and Conditions, Enterprise Agreement, Order Form or other agreement governing Customer's use of Hawi (the “Main Agreement”).
---
1. PARTIES
1.1 Processor
Hawi Inc Trading as Hawi Agents
Registered office: [INSERT REGISTERED ADDRESS]
Company number: [INSERT COMPANY NUMBER]
Privacy contact: [INSERT PRIVACY EMAIL]
Legal contact: [INSERT LEGAL EMAIL]
Security contact: [INSERT SECURITY EMAIL]
1.2 Controller
The Customer identified in:
- the applicable Hawi Account;
- Order Form;
- Enterprise Agreement;
- subscription;
- or other Main Agreement
is the Controller for purposes of this DPA to the extent it determines the purposes and means of processing Customer Personal Data.
---
2. PURPOSE OF THIS DPA
The purpose of this DPA is to establish the parties' responsibilities concerning Personal Data processed by Hawi on behalf of Customer.
It is intended to address applicable requirements including, where relevant:
- UK GDPR;
- the Data Protection Act 2018;
- amendments resulting from applicable UK data legislation;
- EU GDPR;
- applicable ePrivacy laws;
- and equivalent processor-contract requirements under other Data Protection Laws.
---
3. DEFINITIONS
For this DPA:
“Applicable Data Protection Law” means data-protection and privacy law applicable to the processing covered by this DPA.
“Controller” has the meaning given under Applicable Data Protection Law and includes the Customer where it determines the purposes and means of processing Customer Personal Data.
“Customer Personal Data” means Personal Data processed by Hawi on behalf of Customer through the Services.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“EU GDPR” means Regulation (EU) 2016/679.
“Personal Data” or “Personal Information” means information relating to an identified or identifiable individual and any equivalent concept under Applicable Data Protection Law.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
“Processing” and related expressions have the meanings given under Applicable Data Protection Law.
“Processor” means Hawi where it processes Customer Personal Data on behalf of Customer.
“Restricted Transfer” means a transfer of Personal Data requiring a recognised international-transfer safeguard under Applicable Data Protection Law.
“Services” means the Hawi services supplied under the Main Agreement.
“Subprocessor” means another processor appointed by Hawi to process Customer Personal Data on Hawi's behalf.
“Supervisory Authority” means a competent data-protection regulator, including the UK Information Commissioner's Office where applicable.
“UK GDPR” means the UK version of the General Data Protection Regulation as incorporated into UK law and amended from time to time.
---
4. PRECEDENCE
If this DPA conflicts with the Main Agreement concerning the protection or processing of Customer Personal Data, this DPA prevails to the extent of the conflict.
If applicable mandatory Data Protection Law imposes a higher requirement, that law prevails.
An executed negotiated DPA or enterprise data-protection addendum may replace this standard DPA if it expressly states that it does so.
---
5. ROLES OF THE PARTIES
5.1 Customer as Controller
Customer acts as Controller where Customer determines:
- why Customer Personal Data is processed;
- which Data Subjects are involved;
- what information is submitted;
- which Agents may access it;
- what third-party integrations are connected;
- retention choices available to Customer;
- and the business purposes of the processing.
5.2 Hawi as Processor
Hawi acts as Processor where Hawi processes Customer Personal Data solely to:
- provide the Services;
- execute Customer instructions;
- operate authorised Agents;
- host Customer information;
- facilitate authorised integrations;
- provide Workspace functionality;
- provide voice or communication functionality;
- process Customer files;
- perform support;
- secure the Services;
- and fulfil related processor obligations.
5.3 Hawi as independent Controller
This DPA does not apply to processing for which Hawi determines its own purposes and means as an independent Controller.
Such processing may include, where applicable:
- Hawi Account administration;
- Customer relationship management;
- fraud prevention for Hawi;
- legal compliance;
- billing administration;
- tax records;
- enforcement of Hawi's Terms;
- security of Hawi's own systems;
- legal claims;
- and other activities described in the Hawi Privacy Policy.
---
6. CUSTOMER INSTRUCTIONS
Customer instructs Hawi to process Customer Personal Data as reasonably necessary to:
- provide the Services;
- perform functionality selected by Customer;
- operate Customer-configured Agents;
- use authorised Subprocessors;
- make authorised Restricted Transfers;
- respond to Customer support requests;
- secure Customer's use of the Services;
- and comply with documented instructions provided through Hawi's supported functionality.
The Main Agreement, this DPA, Account settings, Workspace configuration, Agent instructions, API requests and written support instructions collectively constitute Customer's documented instructions.
---
7. PROCESSING ONLY ON DOCUMENTED INSTRUCTIONS
Hawi will process Customer Personal Data only on documented instructions from Customer unless Applicable Law requires otherwise.
If Hawi is legally required to process Customer Personal Data contrary to or outside Customer's instructions, Hawi will inform Customer of that legal requirement before processing unless applicable law prohibits such notice.
---
8. UNLAWFUL INSTRUCTIONS
Hawi is not required to carry out an instruction that it reasonably believes would violate Applicable Data Protection Law.
If Hawi believes an instruction violates Applicable Data Protection Law, Hawi may:
- notify Customer;
- request clarification;
- suspend the affected processing;
- or decline the instruction
to the extent reasonably necessary.
---
9. CUSTOMER RESPONSIBILITIES
Customer represents and warrants that:
- it has a lawful basis for processing Customer Personal Data;
- it has provided required privacy information;
- it has obtained required consents where consent is relied upon;
- its instructions comply with Applicable Data Protection Law;
- it has authority to disclose Customer Personal Data to Hawi;
- it has authority to connect third-party accounts;
- it has determined that Hawi provides sufficient guarantees appropriate to the processing;
- and it will use the Services consistently with applicable privacy law.
---
10. CUSTOMER DATA MINIMISATION
Customer should not submit Personal Data that is unnecessary for the intended Agent or business task.
Customer is responsible for determining what Personal Data its Agents require.
Customer should particularly avoid unnecessarily providing:
- passwords;
- authentication secrets;
- full payment-card information;
- special-category information;
- confidential medical information;
- children's information;
- or highly sensitive information
unless the relevant Hawi feature is designed and authorised to process it.
---
11. NATURE OF PROCESSING
Hawi's processing may include:
- collection;
- receipt;
- hosting;
- organisation;
- structuring;
- storage;
- retrieval;
- consultation;
- analysis;
- transmission;
- model processing;
- voice processing;
- communication;
- transformation;
- indexing;
- search;
- recording;
- access;
- alteration;
- deletion;
- and other processing required to deliver Customer-configured functionality.
---
12. PURPOSES OF PROCESSING
Processing may occur for purposes including:
- Account operation;
- Workspace functionality;
- Agent execution;
- Agent memory where enabled;
- file storage and processing;
- email workflows;
- calendar workflows;
- messaging;
- voice calls;
- integrations;
- customer support;
- business workflow automation;
- API operations;
- Marketplace Agent installation;
- audit and operational records;
- and security.
Hawi will not independently repurpose Customer Personal Data for unrelated purposes while acting as Processor.
---
13. DURATION OF PROCESSING
Hawi may process Customer Personal Data for:
- the duration of the Main Agreement;
- the period during which Customer uses the relevant feature;
- and any limited period after termination necessary for deletion, backup expiry or lawful return of data.
Information required by law, legal hold, fraud investigation or Hawi's independent Controller obligations may be retained separately under Hawi's Privacy Policy.
---
14. CATEGORIES OF DATA SUBJECTS
Depending on Customer's use of Hawi, Data Subjects may include:
- Customer personnel;
- employees;
- contractors;
- directors;
- officers;
- business owners;
- suppliers;
- customers;
- prospective customers;
- website visitors;
- email correspondents;
- telephone callers;
- telephone recipients;
- job applicants;
- CRM contacts;
- Marketplace participants;
- users of Customer's services;
- and other individuals whose information Customer lawfully processes through Hawi.
---
15. CATEGORIES OF PERSONAL DATA
Customer Personal Data may include:
- name;
- email address;
- telephone number;
- postal address;
- job title;
- employer;
- customer identifiers;
- correspondence;
- emails;
- messages;
- calendar events;
- appointment information;
- CRM information;
- business records;
- documents;
- uploaded files;
- call metadata;
- call audio where enabled;
- transcripts;
- IP addresses;
- device-related information;
- integration content;
- instructions;
- Agent conversations;
- API payloads;
- and other Personal Data submitted by Customer.
---
16. SPECIAL-CATEGORY DATA
Depending on Customer's configuration, the Services may technically be capable of receiving information that constitutes special-category or sensitive Personal Data.
Customer must not instruct Hawi to process such information unless:
- Customer has established an appropriate lawful basis;
- any additional condition required by law is satisfied;
- the feature is appropriate for such information;
- and Customer has implemented appropriate safeguards.
---
17. HEALTH AND WELLNESS DATA
Where Customer enables a Hawi feature specifically intended to process health, wellness or similar information, additional consent, security or regulatory requirements may apply.
Customer remains responsible for determining whether processing is lawful for Customer's intended purpose.
Hawi does not become a healthcare provider merely by processing information on Customer's instructions.
---
18. CRIMINAL-OFFENCE DATA
Customer must not use Hawi to process criminal-offence data unless:
- Customer is legally authorised to do so;
- an appropriate condition or statutory basis exists;
- and the processing is consistent with Hawi's supported Services.
---
19. CHILDREN'S DATA
Customer must not intentionally use Hawi to process children's Personal Data in violation of:
- Hawi age requirements;
- Applicable Data Protection Law;
- child-safety law;
- or Hawi policies.
If Customer lawfully processes children's Personal Data through a permitted Hawi feature, Customer is responsible for satisfying applicable transparency, lawful-basis, parental-authorisation and risk requirements.
---
20. CONFIDENTIALITY
Hawi will ensure that personnel authorised to process Customer Personal Data:
- are subject to appropriate confidentiality obligations;
- receive access only where reasonably necessary;
- and are informed of their data-protection responsibilities.
---
21. PERSONNEL ACCESS
Hawi will limit human access to Customer Personal Data according to legitimate need.
Potential reasons for access may include:
- technical support;
- incident response;
- abuse investigation;
- security;
- legal compliance;
- and authorised operational maintenance.
Access should not be provided merely out of curiosity or convenience.
---
22. SECURITY OBLIGATIONS
Hawi will implement appropriate technical and organisational measures designed to provide security appropriate to the risk.
Those measures may include, as appropriate:
- encryption;
- pseudonymisation;
- access control;
- authenticated sessions;
- database isolation;
- secure credential storage;
- logging;
- monitoring;
- backups;
- incident response;
- vulnerability management;
- secure software-development practices;
- network security;
- and service resilience.
---
23. SECURITY RISK
The parties acknowledge that appropriate security measures depend on matters including:
- nature of the Personal Data;
- sensitivity;
- volume;
- processing purpose;
- state of the art;
- implementation cost;
- likelihood of harm;
- and severity of harm.
Hawi may update its security controls over time provided that overall protection is not materially reduced without legitimate reason.
---
24. SECURITY POLICY
Hawi maintains a public Security & Trust Policy describing its general security approach.
That Security & Trust Policy does not replace Hawi's binding obligations under this DPA.
---
25. DATA ISOLATION
Hawi uses logical access controls intended to prevent unauthorised cross-customer access.
Customer Personal Data may be isolated through controls involving:
- Accounts;
- Workspaces;
- user membership;
- ownership;
- RLS;
- server-side authorisation;
- and other resource-specific checks.
---
26. ENCRYPTION
Hawi will use encryption in transit for supported production communications.
Hawi relies on infrastructure-provider and application safeguards for encryption of stored information where appropriate.
Customer acknowledges that technical encryption implementations may vary by system and provider.
---
27. AUTHENTICATION
Hawi will maintain reasonable authentication controls appropriate to protected Customer Account functionality.
Customers are responsible for:
- safeguarding passwords;
- safeguarding authentication factors;
- securing employee devices;
- and promptly reporting Account compromise.
---
28. CREDENTIALS
Hawi will take reasonable measures to protect third-party credentials and API secrets entrusted to Hawi.
Customer credentials intended for server-side use should not be exposed to ordinary client applications where avoidable.
---
29. CUSTOMER CONNECTORS
Customer may instruct Hawi to communicate with third-party services selected by Customer.
Where Customer activates a Connector, Customer instructs Hawi to transmit Customer Personal Data to and receive Customer Personal Data from that provider as required to perform the requested integration.
---
30. CUSTOMER-SELECTED THIRD PARTIES
A Customer-selected third-party provider does not automatically become Hawi's Subprocessor merely because Hawi communicates with it on Customer's instructions.
Where Customer already controls its relationship with the provider, the provider may act as:
- Customer's processor;
- an independent Controller;
- a joint Controller;
- or another legal role.
Customer remains responsible for its own relationship with Customer-selected third parties.
---
31. MODEL PROCESSING
Customer authorises Hawi to use approved model providers where required for Agent execution.
Model providers may process:
- prompts;
- relevant task context;
- Customer-provided content;
- document excerpts;
- communication content;
- and other task-relevant Customer Personal Data.
Hawi will seek to limit model-provider processing to information reasonably required for the task.
---
32. MODEL PROVIDER SELECTION
Hawi may route eligible Agent work to different approved model providers according to:
- model selected by Customer;
- Plan entitlement;
- technical availability;
- task requirements;
- reliability;
- cost;
- or other legitimate operational considerations.
Current providers may include OpenAI and Anthropic.
---
33. NO SALE OF CUSTOMER PERSONAL DATA
While acting as Processor, Hawi will not sell Customer Personal Data for monetary consideration.
Hawi will not knowingly use Customer Personal Data entrusted under this DPA for unrelated third-party behavioural advertising.
---
34. SUBPROCESSOR AUTHORISATION
Customer grants Hawi general written authorisation to appoint Subprocessors in accordance with this Section.
Hawi will maintain a Subprocessor List identifying material Subprocessors.
---
35. SUBPROCESSOR OBLIGATIONS
Before a Subprocessor materially processes Customer Personal Data on Hawi's behalf, Hawi will impose written data-protection obligations appropriate to the processing.
Where Article 28 applies, those terms will provide an equivalent level of protection concerning applicable processor obligations.
---
36. HAWI RESPONSIBILITY FOR SUBPROCESSORS
Where required by Applicable Data Protection Law, Hawi remains responsible to Customer for the performance of its Subprocessors' data-protection obligations.
---
37. NEW SUBPROCESSORS
Where required under Applicable Data Protection Law or the Main Agreement, Hawi will provide Customer with notice before a material new Subprocessor begins processing Customer Personal Data.
Notice may be provided by:
- email;
- Account notice;
- Subprocessor List update;
- or another reasonable mechanism.
---
38. CUSTOMER SUBPROCESSOR OBJECTIONS
Where Customer has a legal or contractual right to object, Customer must submit an objection within the applicable notice period.
The objection must:
- identify the Subprocessor;
- describe the legitimate data-protection concern;
- and provide sufficient detail for Hawi to assess it.
---
39. RESOLUTION OF SUBPROCESSOR OBJECTIONS
Hawi and Customer will attempt in good faith to address a reasonable objection.
Possible solutions may include:
- configuration changes;
- feature restrictions;
- alternative providers where commercially reasonable;
- or termination of the affected Service where required under the Main Agreement.
Hawi is not required to build a commercially unreasonable bespoke architecture merely to accommodate an objection.
---
40. SUBPROCESSOR LIST
Hawi's current public Subprocessor List forms part of this DPA by reference.
It may include core or feature-dependent providers such as:
- Supabase;
- Vercel;
- OpenAI;
- Anthropic;
- and other providers where applicable.
Stripe and customer-selected third parties may have different legal roles depending on the processing.
---
41. INTERNATIONAL TRANSFERS
Hawi may process Customer Personal Data in jurisdictions outside the country in which Customer is located.
Hawi will comply with applicable Restricted Transfer requirements.
---
42. UK RESTRICTED TRANSFERS
Where UK GDPR applies and Customer Personal Data is subject to a Restricted Transfer, Hawi may rely on an appropriate mechanism including:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU SCCs;
- or another lawful safeguard.
---
43. EU RESTRICTED TRANSFERS
Where EU GDPR applies, international transfers may be supported through:
- EU adequacy decisions;
- European Commission Standard Contractual Clauses;
- or another lawful transfer mechanism.
---
44. STANDARD CONTRACTUAL CLAUSES
Where the EU SCCs are required and the parties have not executed another applicable transfer mechanism, the appropriate module of the then-applicable European Commission SCCs will be incorporated into this DPA to the extent required.
Where Customer is Controller and Hawi is Processor, Module Two — Controller to Processor will ordinarily apply.
Where Customer is itself Processor and Hawi acts as Subprocessor, Module Three — Processor to Processor may apply.
---
45. UK ADDENDUM
Where required for a UK Restricted Transfer relying on EU SCCs, the parties agree that the then-current approved UK Addendum may apply to the SCCs.
The parties intend the applicable Hawi and Customer details, processing details and security measures in this DPA to populate equivalent information required by the transfer mechanism where legally permitted.
---
46. TRANSFER RISK ASSESSMENTS
Where required, Hawi will provide reasonable available information to assist Customer with an applicable transfer risk assessment or equivalent data-protection test.
Customer acknowledges that Hawi is not required to disclose information that would materially compromise:
- platform security;
- another customer's confidentiality;
- third-party confidentiality;
- or legal privilege.
---
47. GOVERNMENT ACCESS REQUESTS
Where legally permitted, Hawi will:
- assess legally binding government requests for Customer Personal Data;
- seek to limit overbroad requests where appropriate;
- and notify Customer where permitted and appropriate.
Hawi will not voluntarily provide Customer Personal Data to a government authority merely because it is requested informally, unless lawful grounds exist.
---
48. DATA SUBJECT REQUESTS
If Hawi receives a request from a Data Subject concerning Customer Personal Data for which Customer is Controller, Hawi will ordinarily direct the person to Customer unless Hawi is legally required to respond directly.
---
49. ASSISTANCE WITH DATA SUBJECT RIGHTS
Taking into account the nature of processing, Hawi will provide reasonable technical and organisational assistance to Customer to respond to Data Subject rights requests.
This may include requests involving:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- or other applicable rights.
---
50. CUSTOMER RESPONSIBILITY FOR RIGHTS REQUESTS
Customer remains responsible for:
- determining whether the request is valid;
- verifying the Data Subject where required;
- responding within statutory deadlines;
- identifying applicable exemptions;
- and communicating with the Data Subject.
Hawi does not make Customer's legal determinations unless separately agreed.
---
51. PRIVACY REQUEST FUNCTIONALITY
Where Hawi provides technical controls for:
- data export;
- correction;
- restriction;
- deletion;
- or Account erasure,
Customer may use those controls to fulfil its responsibilities.
Technical functionality does not replace Customer's legal assessment.
---
52. ASSISTANCE WITH SECURITY OBLIGATIONS
Taking into account the nature of processing and information available to Hawi, Hawi will provide reasonable assistance concerning Customer's obligations under applicable Articles 32–36 or equivalent provisions where they relate to Hawi's processing.
---
53. DPIA ASSISTANCE
Where Customer reasonably determines that a Data Protection Impact Assessment is required for Customer's use of Hawi, Hawi will provide reasonable available information concerning:
- processing;
- security;
- Subprocessors;
- data location;
- retention;
- and relevant technical controls.
Extensive bespoke consultancy may be subject to additional fees where permitted and agreed.
---
54. REGULATORY CONSULTATION
Where Customer is required to consult a Supervisory Authority concerning processing performed by Hawi, Hawi will provide reasonable assistance within Hawi's control.
---
55. PERSONAL DATA BREACH NOTICE
Hawi will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification to Customer is required under Applicable Data Protection Law.
---
56. BREACH INFORMATION
To the extent reasonably available, a breach notification may include:
- nature of the breach;
- affected categories of data;
- affected Data Subjects;
- likely consequences;
- containment measures;
- remediation;
- and a Hawi contact.
Information may be supplied in phases as the investigation develops.
---
57. NO ADMISSION
Notification of a security incident or suspected breach does not constitute an admission of fault or legal liability.
---
58. CUSTOMER INCIDENT OBLIGATIONS
Customer must promptly notify Hawi where Customer becomes aware that:
- its Hawi credentials are compromised;
- an authorised user's device is compromised;
- a Connector is compromised;
- a Customer API key has leaked;
- or Customer's acts materially affect the security of Hawi processing.
---
59. BREACH COOPERATION
The parties will reasonably cooperate concerning a Personal Data Breach where necessary to satisfy their respective legal obligations.
---
60. AUDIT INFORMATION
Hawi will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.
This may include, where available:
- security documentation;
- policies;
- Subprocessor information;
- architecture summaries;
- questionnaire responses;
- third-party audit material;
- or certifications actually held by Hawi.
---
61. AUDIT REQUESTS
Customer may audit Hawi's compliance with this DPA to the extent required under Applicable Data Protection Law.
Audits should ordinarily:
- occur no more than once annually;
- be conducted during reasonable business hours;
- be subject to confidentiality;
- avoid disrupting operations;
- avoid access to other customers' information;
- and use existing independent audit material where sufficient.
These frequency limits do not apply where additional audit is reasonably required because of a confirmed material breach or regulator instruction.
---
62. ON-SITE AUDITS
Physical inspection should be used only where existing documentation and remote assurance are insufficient to meet Customer's lawful audit requirements.
Customer must provide reasonable advance notice unless urgent circumstances justify otherwise.
Hawi may require the auditor to sign appropriate confidentiality terms.
---
63. AUDIT COSTS
Each party ordinarily bears its own audit-related costs.
If Customer requests unusually extensive, repetitive or customised audit assistance beyond Hawi's legal obligations, Hawi may charge reasonable costs where agreed in advance.
---
64. SECURITY TESTING BY CUSTOMER
Customer is not authorised by this DPA to:
- penetration-test Hawi production systems;
- scan infrastructure destructively;
- access another customer's data;
- bypass access controls;
- or conduct denial-of-service testing.
Security testing remains governed by Hawi's Security Policy or separate written authorisation.
---
65. RECORDS OF PROCESSING
Hawi will maintain records required of processors under Applicable Data Protection Law.
Customer remains responsible for its own Controller records.
---
66. DATA RETENTION
Customer Personal Data will be retained according to:
- Customer instructions;
- feature requirements;
- the Main Agreement;
- Hawi's documented retention schedule;
- and Applicable Law.
Hawi will not retain Customer Personal Data indefinitely merely because storage is technically available.
---
67. RETURN OR DELETION AT TERMINATION
Upon termination of Services and at Customer's choice where required by law, Hawi will delete or return Customer Personal Data unless Applicable Law requires continued storage.
Customer should export required information before termination where self-service export is available.
---
68. BACKUPS
Deleted Customer Personal Data may remain temporarily in encrypted or protected backup systems until the applicable backup cycle expires.
During that period, backup information will remain subject to applicable security protections and will not ordinarily be restored except for legitimate recovery purposes.
---
69. LEGAL HOLDS
Hawi may suspend deletion of information subject to a legally valid:
- litigation hold;
- regulatory preservation duty;
- court order;
- fraud investigation;
- or equivalent legal requirement.
Where legally permitted, Hawi will limit retained information to what is reasonably necessary.
---
70. END-OF-CONTRACT PROCESSING
Following termination, Hawi will not continue actively using Customer Personal Data on Customer's behalf except to:
- complete deletion;
- complete return;
- maintain protected backups;
- satisfy legal obligations;
- or address security and legal claims.
---
71. CUSTOMER EXPORT
Customer is responsible for using available export functionality before the Account becomes inaccessible.
Hawi is not required to maintain indefinite post-termination access.
---
72. AI OUTPUT AND PERSONAL DATA
Outputs generated by models may themselves contain Personal Data.
Customer remains Controller of Customer-directed use of those Outputs where applicable.
Customer should review Outputs before using them for significant decisions concerning individuals.
---
73. AUTOMATED DECISION-MAKING
Hawi does not determine on Customer's behalf whether Customer may lawfully use an Agent for automated decision-making concerning individuals.
Customer remains responsible for determining:
- whether Article 22 or equivalent rules apply;
- whether human intervention is required;
- and what notices or safeguards are necessary.
---
74. HIGH-RISK PROCESSING
If Customer uses Hawi for processing likely to create high risk to individuals, Customer should implement proportionate controls such as:
- reduced Agent permissions;
- human approval;
- DPIAs;
- audit trails;
- data minimisation;
- strict retention;
- and enhanced access controls.
---
75. AGENT INSTRUCTIONS AS CUSTOMER INSTRUCTIONS
Where an authorised Customer user instructs an Agent through Hawi, Hawi may treat the instruction as a documented processing instruction from Customer, subject to:
- Account permissions;
- Workspace permissions;
- Hawi safety rules;
- and the Main Agreement.
---
76. AUTONOMOUS AGENT PROCESSING
Where Customer enables autonomous Agent activity, Customer instructs Hawi to process Customer Personal Data as reasonably required for the Agent to execute authorised workflows within Customer's configured controls.
---
77. AGENT-TO-AGENT DELEGATION
Where Hawi allows one authorised Agent to delegate work to another, Customer authorises the necessary processing subject to the permissions of the receiving Agent and Workspace.
Hawi may prevent delegation that exceeds configured authority.
---
78. MARKETPLACE AGENTS
Where Customer installs a Marketplace Agent, Customer instructs Hawi to process Customer Personal Data through that Agent subject to the permissions Customer grants.
A third-party Marketplace Creator does not automatically receive Customer Personal Data merely because Customer installs the Creator's Agent.
If a Marketplace product requires external Creator-controlled processing, that processing must be separately disclosed where appropriate.
---
79. PRIVACY BY DESIGN
Hawi will consider data protection when materially designing or changing processing systems.
This may include:
- purpose limitation;
- access controls;
- minimisation;
- separation;
- retention;
- security;
- and user privacy controls.
---
80. DATA PROTECTION CONTACT
Questions concerning this DPA may be sent to:
[INSERT PRIVACY EMAIL]
---
81. LIABILITY
Liability under this DPA is subject to the liability framework in the Main Agreement unless Applicable Data Protection Law prohibits the relevant limitation.
Nothing in this DPA excludes liability that cannot lawfully be excluded.
---
82. INDEMNITIES
Any contractual indemnity between the parties concerning data protection will be governed by:
- the Main Agreement;
- applicable Enterprise Agreement;
- or separately negotiated terms.
This standard DPA does not create an unlimited data-protection indemnity.
---
83. THIRD-PARTY RIGHTS
Except where incorporated transfer clauses expressly grant enforceable rights to Data Subjects, no third party obtains contractual enforcement rights under this DPA unless Applicable Law provides otherwise.
---
84. GOVERNING LAW
Subject to mandatory provisions in applicable international-transfer clauses, this DPA is governed by the law governing the Main Agreement.
For Hawi's standard Terms, this will ordinarily be the laws of England and Wales.
---
85. TERMINATION
This DPA terminates automatically when Hawi no longer processes Customer Personal Data on Customer's behalf.
Provisions that by nature should survive will continue, including provisions concerning:
- confidentiality;
- deletion;
- audit information;
- liability;
- international transfers;
- and legal retention.
---
SCHEDULE 1 — DETAILS OF PROCESSING
Subject Matter
Provision of Hawi's software-based Agent, automation, collaboration, communication, integration, Marketplace, API and related Services.
Duration
For the term of the Main Agreement plus limited post-termination deletion, backup and legally required retention.
Nature of Processing
Collection, hosting, storage, organisation, retrieval, analysis, transmission, model inference, communications, Agent execution, alteration and deletion.
Purpose
To provide Customer-configured Hawi Services.
Categories of Data Subjects
May include:
- Customer personnel;
- Customer customers;
- prospects;
- suppliers;
- contractors;
- communications recipients;
- Marketplace users;
- website users;
- and other persons whose information Customer submits.
Categories of Personal Data
May include:
- identifiers;
- contact information;
- business information;
- communications;
- documents;
- calendar information;
- CRM information;
- files;
- voice information;
- Agent instructions;
- usage records;
- and other Customer-provided information.
Sensitive Data
Only where Customer lawfully submits it through an appropriate feature.
Frequency
Continuous or intermittent according to Customer's use of the Services.
---
SCHEDULE 2 — TECHNICAL AND ORGANISATIONAL MEASURES
Hawi's measures may include:
Identity and access management
- authenticated access;
- role-based permissions;
- Account membership;
- Workspace membership;
- administrative controls;
- session security.
Database security
- RLS where appropriate;
- private schemas;
- server-side authorisation;
- privileged operation controls;
- tenant isolation.
Credential security
- protected credential storage;
- server-side secrets;
- credential rotation;
- restricted exposure;
- no intentional browser exposure of server secrets.
Encryption
- TLS for supported production traffic;
- provider encryption at rest;
- protected backups.
Application security
- input validation;
- secure API design;
- dependency controls;
- type checking;
- secure deployment;
- rate limiting.
Agent security
- tool permissions;
- approval policies;
- spending limits;
- execution authorisation;
- idempotency;
- Agent loop protection;
- handoff controls.
Financial security
- verified payment events;
- server-side entitlements;
- immutable or append-oriented financial records;
- transaction limits;
- payment-provider security.
Logging and monitoring
- audit events;
- application logging;
- security monitoring;
- provider-health monitoring;
- incident investigation.
File security
- private file storage;
- access control;
- scanning or quarantine where implemented;
- file restrictions.
Resilience
- backups;
- queues;
- circuit breakers;
- workload controls;
- provider isolation;
- recovery procedures.
Organisational controls
- confidentiality obligations;
- access restriction;
- security awareness;
- incident-response processes;
- vulnerability management.
---
SCHEDULE 3 — SUBPROCESSORS
Hawi's current Subprocessor List is incorporated by reference.
The public list should identify, where relevant:
- provider;
- function;
- processing category;
- location information;
- and status.
Core or feature-dependent providers may include:
- Supabase;
- Vercel;
- OpenAI;
- Anthropic;
- Twilio where voice is enabled;
- ElevenLabs where applicable;
- and additional future approved Subprocessors.
---
SCHEDULE 4 — INTERNATIONAL TRANSFERS
Where required:
- an applicable adequacy mechanism will be preferred where available;
- otherwise applicable SCCs, IDTA or UK Addendum mechanisms may be used;
- supplementary safeguards will be considered where necessary;
- Hawi will reasonably assess relevant transfer risk;
- and Customer will provide information reasonably necessary for Customer-specific transfer assessments.
---
SCHEDULE 5 — DATA RETURN AND DELETION
Upon termination:
- Customer should export data using available functionality.
- Hawi will begin the applicable deletion process.
- active-system copies will be deleted according to the relevant retention process;
- backups may expire according to backup cycles;
- legal holds override deletion only to the necessary extent;
- billing and legal records controlled independently by Hawi may remain under the Privacy Policy;
- and deleted Customer Personal Data will not be returned to active use except where legitimately restored for recovery.
---
SCHEDULE 6 — CUSTOMER INSTRUCTIONS FOR AGENTS
Customer authorises Hawi to process Customer Personal Data when:
- a user manually starts an Agent;
- a configured schedule starts an Agent;
- a webhook starts an Agent;
- an email or calendar event triggers an Agent;
- a voice interaction activates an Agent;
- a permitted Agent delegates a task;
- or another Customer-configured trigger executes.
Customer remains responsible for choosing which data and systems the Agent may access.
---
SCHEDULE 7 — SECURITY INCIDENT CONTACTS
Hawi security: [INSERT SECURITY EMAIL]
Hawi privacy: [INSERT PRIVACY EMAIL]
Customer security contact: As specified in Customer's Account or Order Form.
Customer privacy contact: As specified in Customer's Account or Order Form.
---
SCHEDULE 8 — ARTICLE 28 COMPLIANCE SUMMARY
This DPA addresses:
- subject matter and duration;
- nature and purpose;
- categories of Personal Data;
- categories of Data Subjects;
- Customer rights and obligations;
- documented instructions;
- confidentiality;
- security;
- Subprocessors;
- Data Subject rights;
- Controller assistance;
- breach assistance;
- DPIA assistance;
- deletion/return;
- compliance information;
- audits and inspections;
- and international transfers.
END OF DATA PROCESSING AGREEMENT