Data Processing Agreement
USING THIS DPA
This DPA has 2 parts: (1) the Key Terms on this Cover Page and (2) the Common Paper DPA Standard Terms Version 1.1 posted at commonpaper.com/standards/data-processing-agreement/1.1 (“DPA Standard Terms”), which is incorporated by reference. If there is any inconsistency between the parts of the DPA, the Cover Page will control over the DPA Standard Terms. Capitalized and highlighted words have the meanings given on the Cover Page. However, if the Cover Page omits or does not define a highlighted word, the default meaning will be “none” or “not applicable” and the correlating clause, sentence, or section does not apply to this DPA. All other capitalized words have the meanings given in the DPA Standard Terms or the Agreement.
Key Terms
The key legal terms of the DPA are as follows:
Agreement
This DPA supplements the following agreement:
https://www.hexahq.ai/terms-of-service/
Approved Subprocessors
https://www.hexahq.ai/subprocessors.html
Provider Security Contact
support@hexahq.ai
Security Policy
As defined in the Agreement.
Changes to the Agreement
Service Provider Relationship
To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
Restricted Transfers
Governing Member State
EEA Transfers: Ireland
UK Transfers: England and Wales
Annex I(A) List of Parties
Data Exporter
Name: the Customer signing this DPA
Activities relevant to transfer: See Annex 1(B)
Role: Controller
Data Importer
Name: the Provider signing this DPA
Contact person: Jeremy Schiff, CEO
Address: 2030 Vallejo Street, #205, San Francisco, California 94123, United States of America
Activities relevant to transfer: See Annex 1(B)
Role: Processor
Annex I(B) Description of Transfer and Processing Activities
Service
The Service is:
HexaHQ is a cloud-based governed action layer that gives the AI tools Customer uses access to shared company knowledge, workflows, and connected applications. HexaHQ enables authorized AI clients to perform actions across connected business systems under Customer-configured permissions and approval policies, with credential management and an audit trail.
Categories of Data Subjects
Customer's end users or customers
Customer's employees
Categories of Personal Data
Name
Contact information such as email, phone number, or address
Professional or biographic information such as resume or CV
Transactional information such as account information or purchases
User activity and analysis such as device information or IP address
Any personal data contained in Customer-provided knowledge, instructions, communications, files, workflows, or connected third-party applications, as determined and submitted or made accessible by Customer.
Special Category Data
Is special category data (as defined in Article 9 of the GDPR) Processed?
No
Frequency of Transfer
Continuous
Nature and Purpose of Processing
Receiving data, including collection, accessing, retrieval, recording, and data entry
Holding data, including storage, organization, and structuring
Using data, including analysis, consultation, testing, automated decision making, and profiling
Protecting data, including restricting, encrypting, and security testing
Sharing data, including disclosure, dissemination, allowing access, or otherwise making available
Returning data to the data exporter or data subject
Duration of Processing
Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.
Annex I(C)
Competent Supervisory Authority
The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
Annex II
Technical and Organizational Security Measures
See Security Policy
Pseudonymization and encryption of personal data:
Customer Personal Data is encrypted in transit using industry-standard transport encryption and encrypted at rest using encryption provided by Provider’s cloud infrastructure and managed data-storage services. Provider may use additional separation, tokenization, or pseudonymization where appropriate, but does not represent that all Customer Personal Data is pseudonymized.
Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services:
Provider maintains administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, availability, and resilience of its systems and services. These safeguards include access controls, encryption, logging and monitoring, vulnerability management, backup and recovery procedures, incident response processes, change management, and personnel security practices, as further described in Provider’s Security Policy.
Ability to restore the availability of and access to the Customer Personal Data in a timely manner following a physical or technical incident:
Provider uses managed cloud infrastructure with backup, redundancy, and recovery capabilities designed to restore availability of and access to Customer Personal Data following accidental loss, corruption, or a physical or technical incident. Provider maintains documented incident response and disaster recovery procedures and periodically reviews or tests relevant recovery processes.
User identification and authorization process and protection:
Users authenticate using either an email address and password or supported identity providers, such as Google. Passwords are subject to minimum security requirements, stored using secure one-way hashing, and are not stored in plaintext. When users authenticate through an identity provider, authentication is subject to the security controls configured for that account, which may include multi-factor authentication. Access to Customer accounts and connected applications is governed by assigned roles, permissions, and Customer-configured authorization policies. Authentication tokens and connected-service credentials are encrypted at rest. Administrative access is limited to authorized personnel as necessary to operate and support the Service.
Protecting Customer Personal Data during transmission (in transit):
Customer Personal Data is protected in transit using industry-standard encrypted transport protocols, including HTTPS/TLS, when transmitted between users, Provider’s systems, connected third-party services, and subprocessors. Provider requires encrypted connections for production services where supported and does not intentionally transmit Customer Personal Data over unencrypted public networks.
Protecting Customer Personal Data during storage (at rest):
Customer Personal Data is encrypted at rest using encryption provided by Provider’s cloud infrastructure and managed storage services. Access is restricted through logical access controls and limited to authorized personnel and systems with a legitimate need to operate and support the Service. Customer data is logically segregated between customer accounts.
Events logging:
Provider maintains event logging and audit records to support security monitoring, troubleshooting, auditing, and incident response. Logged events include cloud infrastructure and administrative activity, resource configuration changes, network activity, application and deployment logs, service health events, database logs and metrics, and product-level records of workflow execution and authorization decisions. Logs are stored in managed logging and storage services with access controls, encryption, defined retention periods, and integrity protections. Provider uses automated security monitoring and alerting to identify suspicious activity and material changes to its environment. Logging and monitoring configurations are maintained through version-controlled infrastructure configuration.
Systems configuration, including default configuration:
Provider manages system configuration through version-controlled infrastructure and application configuration. Production infrastructure is provisioned and maintained using infrastructure-as-code, with changes reviewed before deployment and applied through controlled processes. Provider uses secure default configurations where available, restricts administrative access, applies updates and patches as appropriate, and monitors system health, configuration changes, and security-relevant events. Configuration and monitoring controls are periodically reviewed and updated based on operational and security needs.
Internal IT and IT security governance and management:
Provider assigns responsibility for information security, system administration, and incident response to designated personnel. Access to production systems is limited to authorized personnel based on operational need. Security events are assessed and escalated according to their severity, with designated personnel responsible for investigation, containment, remediation, recovery, and customer notification where required. Provider maintains documented incident-response procedures and reviews security responsibilities as the Service and organization develop.
Ensuring data minimization:
Provider limits the collection and processing of Customer Personal Data to data submitted, connected, or otherwise made available by Customer and to data reasonably necessary to provide, secure, support, and operate the Service. Customers control which knowledge, applications, permissions, and data sources are connected to the Service. Provider limits internal access based on operational need and deletes or de-identifies Customer Personal Data when it is no longer required, subject to applicable contractual, backup, security, and legal retention requirements.
Ensuring limited data retention:
Provider retains Customer Personal Data only for as long as reasonably necessary to provide, secure, support, and operate the Service, comply with legal obligations, resolve disputes, and enforce agreements. Upon termination or expiration of the applicable agreement, Provider will delete or return Customer Personal Data in accordance with the agreement and Customer instructions, subject to limited retention in backups, security logs, and records required by law. Data retained in backups is protected from ordinary use and deleted through Provider’s standard backup lifecycle.
Ensuring accountability:
Provider assigns responsibility for maintaining and reviewing its security controls and documents material security-related changes through version-controlled systems and infrastructure configuration. Provider reviews security events, system configurations, access controls, dependencies, and operational issues as part of its development and maintenance processes.
Allowing data portability and erasure:
Customers can access, export, correct, and delete Customer Personal Data through available Service functionality or support requests. Individuals seeking to exercise privacy rights regarding Customer Personal Data must contact the Customer that provided or controls the data. Provider will reasonably assist Customer with such requests as required by the DPA. Data is deleted from active systems and expires through standard backup-retention processes.
Other Changes to the DPA Standard Terms
Additional modifications or customizations
Provider and Customer have not changed the DPA Standard Terms except for the details on the Cover Page above. By signing this Cover Page, each party agrees to enter into this DPA as of the last date of signature below.
PROVIDER: Salesbot Labs, Inc.
CUSTOMER:
Signature
Print Name
Jeremy Schiff
Title
Chief Executive Officer
Legal Notice Address
2030 Vallejo St, #205
San Francisco, California 94123
United States of America
Date