Data Processing Agreement.
Version 2.0 — June 2026.
This Data Processing Agreement ("DPA") is incorporated into the Dappiehub Terms of Service between Dappiehub ("Processor") and the subscribing organisation ("Controller"). It sets out terms for processing personal data on behalf of the Controller in connection with the Dappiehub AI-powered workflow automation platform, in accordance with Article 28 of the UK GDPR.
1. Definitions
Controller — the subscribing organisation. Processor — Dappiehub. Personal Data — any information relating to an identified or identifiable person processed through the Platform. Sub-Processor — any third party engaged by Dappiehub to process Personal Data, including AI providers.
2. Scope and Nature of Processing
Processing covers storage, retrieval, AI-assisted content generation, email notifications and display within the Platform workspace, for the duration of the Controller's subscription plus any legally required retention period.
3. Processor Obligations
- Process Personal Data only on documented instructions from the Controller
- Ensure confidentiality obligations on all authorised personnel
- Implement appropriate technical and organisational security measures
- Assist the Controller with data subject rights requests and breach obligations
- Delete or return Personal Data at the end of services, at the Controller's election
- Notify the Controller within 48 hours of becoming aware of a breach
4. AI Processing
- AI providers act solely as Sub-Processors and are bound by equivalent obligations
- Personal Data is transmitted to AI providers only to the extent necessary to fulfil the specific request
- Contractual safeguards restrict use of Controller data for model training
5. Sub-Processors
| Sub-Processor | Service | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | Ireland |
| Netlify, Inc. | Platform hosting and CDN | EU / United States |
| Anthropic, PBC | AI-assisted content generation via API | United States |
| Stripe, Inc. | Payment processing | EU / United States |
| Resend, Inc. | Transactional email delivery | United States |
| Google LLC | Optional OAuth authentication | EU / United States |
The Processor will give 14 days' written notice of any new Sub-Processor via dappiehub.com/trust/subprocessors, with a right for the Controller to object on reasonable data protection grounds.
6. International Data Transfers
Transfers outside the UK/EEA use Standard Contractual Clauses or the UK IDTA.
7. Customer Data Ownership
The Controller retains full ownership of all Personal Data. The Processor acquires no ownership rights beyond the limited licence necessary to operate the Platform, terminating on deletion or return of data.
8. Controller Obligations
The Controller warrants it has a lawful basis for all Personal Data inputted into the Platform and has obtained all required consents from data subjects.
9. Data Subject Rights
The Processor assists the Controller with rights requests and forwards any direct requests within 5 business days.
10. Personal Data Breaches
Notification within 48 hours, full breach detail, and cooperation on investigation and remediation.
11. Deletion and Return of Data
Data is deleted or returned within 30 days of termination, with written certification. Billing records are retained 7 years regardless.
12. Audit Rights
The Controller may, on 30 days' notice, request compliance documentation or conduct an audit at their own cost.
13. Liability
Governed by the limitations in the Terms of Service, apportioned by respective responsibility for any joint breach.
14. Governing Law
England and Wales.
15. Order of Precedence
This DPA prevails over the Terms of Service for data protection matters in the event of conflict.
16. Updates
Material changes notified at least 14 days in advance by email.