1. When a DPA is relevant

A Data Processing Addendum may be required when Hyfens processes personal data on an organization’s documented instructions while providing Cloud. It does not replace the Terms, Privacy Policy, security obligations, or customer responsibility for lawful collection and use of application and end-user data.

The direct account, billing, security, and service relationship may involve Hyfens acting as a controller or independent business. The final DPA must define the roles for each processing purpose instead of assuming one role applies to every data category.

2. Required contract topics

Hyfens does not claim that this summary is a signed DPA or that it satisfies a customer’s jurisdiction-specific requirements.

  • documented processing instructions, purpose, data categories, and data-subject categories;
  • confidentiality, security measures, least-privilege access, incident assistance, and subprocessor controls;
  • assistance with rights requests, deletion, export, breach response, audits, and regulatory obligations;
  • international transfers and the safeguards used for each relevant processing location; and
  • return, deletion, backup retention, and end-of-service handling.

3. Request and precedence

Contact support@hyfens.com or the Enterprise contract contact to request the current DPA and security schedule. A signed, customer-specific or standard approved DPA controls only after execution and does not authorize providers, data, or processing outside its scope.

Back to legal and policy index