Data Processing Agreement
Effective: May 3, 2026·Last updated: May 3, 2026
DPA Version: 1.0 | GDPR Article 28 Compliant
This is a template. Seek qualified legal counsel before execution.
This Data Processing Agreement ("DPA") supplements the Hoshin Space Platform Terms of Service and governs the processing of personal data by Hoshin Space on behalf of the Controller. It is required when the Controller processes personal data of EU/EEA/UK residents through the Platform.
PARTIES
Data Controller
Complete this section for each executing business. One DPA per Controller.
- Business / Organization Legal Name:
- Registered Address:
- Contact Name and Title:
- Contact Email Address:
- Date of Execution:
Data Processor
Saldana Tech LLC, a Texas limited liability company, doing business as Hoshin Space ("Processor"), with its principal place of business at [Address pending — contact legal@hoshinspace.com], Kyle, Texas. Contact: privacy@hoshinspace.com.
1. Definitions
For the purposes of this DPA, the following definitions apply. Terms not defined here have the meanings given in the GDPR or the Platform Terms of Service.
| Term | Definition |
|---|---|
| "Controller" | The Service Provider (business) that determines the purposes and means of processing Personal Data through the Platform. |
| "Processor" | Hoshin Space (Saldana Tech LLC), which processes Personal Data on behalf of the Controller. |
| "GDPR" | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation), and as applicable, the UK GDPR and Swiss FADP. |
| "Personal Data" | Any information relating to an identified or identifiable natural person ("Data Subject") as defined in Article 4(1) GDPR. |
| "Processing" | Any operation performed on Personal Data, as defined in Article 4(2) GDPR, including collection, storage, use, disclosure, and deletion. |
| "Data Subject" | An End User (client of the Controller) or other natural person whose Personal Data is processed through the Platform. |
| "Sub-Processor" | Any third party engaged by the Processor to process Personal Data on the Processor's behalf in connection with the Platform. |
| "SCCs" | The Standard Contractual Clauses for the transfer of Personal Data to third countries adopted by the European Commission Decision 2021/914 (Module Two: Controller to Processor). |
| "Security Incident" | A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data. |
| "Services" | The field service management platform and related features provided by Hoshin Space under the Platform Terms of Service. |
2. Subject Matter and Details of Processing
2.1 Annex 1 — Processing Details
The following table constitutes Annex 1 to this DPA and describes the processing activities covered:
| Processing Element | Description |
|---|---|
| Subject matter | Processing of Personal Data of the Controller's clients (End Users) to enable client management, job scheduling, payment processing, and transactional communications through the Hoshin Space Platform. |
| Duration | For the term of the Controller's active Hoshin Space subscription, plus up to 90 days following termination for data export and deletion, unless a longer retention period is required by applicable law. |
| Nature of processing | Collection, storage, organization, structuring, retrieval, use, transmission to Sub-Processors (Stripe, email provider), erasure, and destruction. |
| Purpose of processing | Providing the Services as described in the Platform Terms of Service, including: (a) storing End User contact and payment data on behalf of Controller; (b) scheduling and recording job completions; (c) processing payments via Stripe Connect; (d) sending transactional email receipts to End Users. |
| Categories of Personal Data | Identifiers (name, email address, service address); financial data (tokenized payment card references managed by Stripe — Processor does not store raw card data); service records (job history, scheduling data, notes entered by Controller); transactional data (payment amounts, dates, receipts). |
| Categories of Data Subjects | Natural persons who are clients of the Controller and whose information is entered into the Platform by the Controller or their authorized users. |
| Special categories of data | None. The Platform is not designed to process special categories of data under GDPR Article 9. Controller must not enter health, biometric, racial/ethnic, religious, or similar sensitive data into the Platform. |
3. Obligations of the Processor
3.1 Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, which include: (a) the Platform Terms of Service; (b) this DPA; and (c) any additional written instructions provided by the Controller to privacy@hoshinspace.com.
If the Processor is required to process Personal Data under EU or Member State law to which it is subject, it shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on grounds of public interest.
If the Processor determines that an instruction infringes the GDPR or applicable law, it shall promptly inform the Controller.
3.2 Confidentiality
The Processor shall ensure that persons authorized to process the Personal Data are subject to a binding confidentiality obligation and receive appropriate data protection training. Access to Personal Data is limited to personnel who require it to perform the Services.
3.3 Security
Taking into account the state of the art, costs of implementation, nature, scope, context, and purposes of processing, and the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate:
- Pseudonymization and encryption of Personal Data in transit (TLS 1.2+) and at rest.
- Ongoing confidentiality, integrity, availability, and resilience of processing systems.
- The ability to restore availability and access to Personal Data in a timely manner following a physical or technical incident.
- A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures.
- Role-based access controls limiting employee access to Personal Data on a need-to-know basis.
- Payment card data tokenization via Stripe — the Processor does not store raw card credentials.
A summary of the Processor's current technical and organizational security measures is set out in Annex 2 (Section 8) of this DPA.
3.4 Sub-Processors
The Controller provides general authorization for the Processor to engage Sub-Processors. The current list of Sub-Processors is set out in Annex 3 (Section 9) of this DPA.
The Processor shall: (a) impose data protection obligations on Sub-Processors by contract that are at least equivalent to those in this DPA; (b) remain fully liable to the Controller for the performance of a Sub-Processor's obligations; and (c) notify the Controller of any intended addition or replacement of Sub-Processors at least 30 days in advance via email to the Controller's registered address.
The Controller may object to a new Sub-Processor in writing within 14 days of notification. If the Controller reasonably objects and the Processor cannot accommodate the objection, either party may terminate the Platform Terms of Service on 30 days' written notice without penalty.
3.5 Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures in fulfilling the Controller's obligations to respond to requests from Data Subjects exercising their rights under GDPR (Articles 15–22), including the rights of access, rectification, erasure, restriction, portability, and objection.
The Processor shall promptly notify the Controller of any Data Subject rights request received directly by the Processor relating to Personal Data processed under this DPA, without responding to the request itself unless authorized in writing by the Controller.
The Controller acknowledges that it is responsible for responding to Data Subject requests. The Processor's assistance obligations are limited to what is technically feasible within the Platform.
3.6 Data Protection Impact Assessments
The Processor shall provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments (DPIAs) and in prior consultations with supervisory authorities under GDPR Articles 35–36, to the extent the processing by the Processor is relevant to such assessments.
3.7 Audit Rights
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations of this DPA. The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or a third-party auditor mandated by the Controller, subject to the following conditions:
- Audits are conducted no more than once per 12-month period unless required by a supervisory authority.
- The Controller provides at least 30 days' written notice of any intended audit.
- Any third-party auditor is bound by a confidentiality obligation acceptable to the Processor.
- The Controller bears all costs of audits unless the audit reveals material non-compliance by the Processor.
The parties agree that the obligation to allow for audits may be satisfied by the Processor providing current third-party security certifications (e.g., SOC 2 Type II) or completed security questionnaires where available.
3.8 Security Incident Notification
In the event of a Security Incident, the Processor shall:
- Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the Security Incident, at the Controller's registered contact email address.
- Provide notification that includes, to the extent known at the time: (a) a description of the nature of the Security Incident including categories and approximate number of Data Subjects and records concerned; (b) the name and contact details of the Processor's data protection contact; (c) a description of the likely consequences; and (d) a description of measures taken or proposed to address the incident.
- Cooperate fully with the Controller in investigating the Security Incident and provide updates as additional information becomes available.
The Processor's notification obligation does not constitute an admission of fault or liability. The Controller is responsible for determining whether notification to supervisory authorities or Data Subjects is required under GDPR Articles 33–34.
3.9 Deletion and Return of Data
Upon termination or expiration of the Platform Terms of Service, or upon written request of the Controller, the Processor shall, at the Controller's election:
- Delete all Personal Data processed under this DPA within 90 days of termination, and provide written confirmation of deletion; or
- Return all Personal Data to the Controller in a commonly used machine-readable format within 30 days of termination, following which the Processor shall delete its copies within 60 days.
Notwithstanding the above, the Processor may retain Personal Data to the extent required by applicable law (e.g., financial recordkeeping requirements), provided that such data remains subject to the confidentiality and security obligations of this DPA.
4. Obligations of the Controller
The Controller represents, warrants, and agrees that:
- It has a lawful basis under GDPR Article 6 (and Article 9 where applicable) for all Personal Data it submits to the Platform for processing.
- It has provided adequate privacy notices and disclosures to Data Subjects whose Personal Data is entered into the Platform, including disclosure of the use of Hoshin Space as a service provider.
- It has obtained all required consents from Data Subjects, including any consents required for payment card storage via Stripe Connect.
- It shall not instruct the Processor to process Personal Data in a manner that would cause the Processor to violate applicable law.
- It shall not enter special categories of Personal Data (GDPR Article 9) or Personal Data relating to criminal convictions into the Platform.
- It shall notify the Processor promptly if any Data Subject revokes consent to processing or exercises rights that would require deletion or restriction of their data in the Platform.
- It is responsible for the accuracy of all Personal Data entered into the Platform.
- It shall obtain appropriate consent or authorization from End Users before enrolling their payment cards in the Platform's recurring charge feature.
5. International Data Transfers
5.1 Transfer Mechanism
The Platform infrastructure and Processor are located in the United States. Transfers of Personal Data from the EU/EEA/UK to the United States are governed by the Standard Contractual Clauses (SCCs) for Controller-to-Processor transfers (EU Commission Decision 2021/914, Module Two), which are incorporated by reference into this DPA and deemed executed upon the Controller's signature of this DPA.
Where the Controller is located in the United Kingdom, the UK International Data Transfer Addendum (IDTA) to the SCCs applies. Where the Controller is located in Switzerland, Swiss law requirements apply.
5.2 Supplementary Measures
In addition to the SCCs, the Processor implements the following supplementary measures to protect transferred data:
- Encryption of all Personal Data in transit using TLS 1.2 or higher.
- Encryption at rest for stored Personal Data on Processor's infrastructure.
- Sub-Processors (including Stripe and cloud infrastructure providers) are bound by equivalent or stronger contractual transfer mechanisms.
- Access to transferred Personal Data by Processor personnel is limited by role-based access controls and logged.
5.3 Transfer Impact Assessment
The Processor will provide the Controller with any information in its possession reasonably necessary for the Controller to conduct a transfer impact assessment (TIA) under the SCCs, upon written request to privacy@hoshinspace.com.
6. Term and Termination
This DPA is effective from the date of execution by both parties and remains in effect for the duration of the Controller's active Platform subscription.
This DPA terminates automatically upon expiration or termination of the Platform Terms of Service, subject to the survival of clauses that by their nature should survive termination, including Sections 3.9 (Deletion), 3.2 (Confidentiality), and Section 7 (Liability).
7. Liability
Each party's liability under this DPA is subject to the limitations set forth in the Platform Terms of Service. For clarity, this DPA does not expand either party's liability beyond what is set out in the Platform Terms of Service, except to the extent required by mandatory provisions of the GDPR or applicable law that cannot be contractually limited.
As between the parties, the Controller shall be responsible for fines, penalties, and third-party claims arising from the Controller's unlawful instructions or breach of its obligations under this DPA or the GDPR. The Processor shall be responsible for fines, penalties, and third-party claims arising solely from the Processor's failure to comply with its obligations under this DPA.
8. Annex 2 — Technical and Organizational Security Measures
This Annex describes the technical and organizational measures (TOMs) implemented by Hoshin Space as of the DPA effective date. These measures may be updated over time to reflect improvements in security practices, provided that the level of protection is not materially reduced.
8.1 Access Controls
- Multi-factor authentication (MFA) required for Processor personnel with access to production systems containing Personal Data.
- Role-based access controls (RBAC) ensuring each employee has access only to Personal Data necessary for their specific role.
- All access to production systems is logged with timestamps, user identifiers, and actions performed.
- Access rights are reviewed quarterly and revoked immediately upon employee departure.
8.2 Encryption
- All data in transit encrypted using TLS 1.2 or higher.
- Personal Data stored in the database is encrypted at rest using AES-256 or equivalent.
- Payment card data is not stored by the Processor; all card credentials are tokenized by Stripe.
8.3 Infrastructure Security
- Platform hosted on Vercel (application layer) and Neon PostgreSQL (database layer), both of which maintain SOC 2 Type II compliance.
- Database access restricted to application servers via VPC or private networking; no direct public database access.
- Automated vulnerability scanning of application dependencies.
- Regular security updates applied to infrastructure and application layers.
8.4 Incident Response
- Documented Security Incident response plan with defined roles and escalation paths.
- 72-hour Controller notification target for confirmed Security Incidents.
- Post-incident reviews conducted following material Security Incidents.
8.5 Organizational Measures
- Data protection training required for all personnel with access to Personal Data.
- Confidentiality obligations in all employment and contractor agreements.
- Privacy-by-design review for new Platform features that involve Personal Data.
- Annual review of this DPA and sub-processor agreements.
9. Annex 3 — Authorized Sub-Processors
As of the DPA effective date, the Processor uses the following Sub-Processors to process Personal Data in connection with the Services:
| Sub-Processor / Location | Role and Personal Data Processed |
|---|---|
| Stripe, Inc. — United States | Payment processing and Stripe Connect payouts. Processes tokenized card references, transaction amounts, and payout routing data. Transfer mechanism: Stripe Privacy Shield / SCCs. See stripe.com/privacy. |
| Vercel, Inc. — United States | Application hosting and edge delivery. Processes request logs containing IP addresses and session tokens. Transfer mechanism: SCCs. See vercel.com/legal/privacy-policy. |
| Neon, Inc. — United States | Managed PostgreSQL database hosting. Stores all Controller and End User Personal Data entered into the Platform. Transfer mechanism: SCCs. See neon.tech/privacy. |
| [Email Provider] — [Location] | Transactional email delivery (job receipts, booking confirmations). Processes End User email addresses and email content. [Update with actual provider, e.g., SendGrid/Postmark] |
The Processor will notify the Controller of any additions or replacements to this Sub-Processor list at least 30 days in advance per Section 3.4 of this DPA.
10. General Provisions
10.1 Order of Precedence
In the event of any conflict between this DPA and the Platform Terms of Service, this DPA shall prevail with respect to the processing of Personal Data of EU/EEA/UK residents. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail.
10.2 Governing Law
This DPA is governed by the law of the State of Texas, except to the extent the SCCs require application of the law of an EU Member State or the UK, in which case the relevant law applies to that portion of the DPA only.
10.3 Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions continue in full force. The parties will negotiate in good faith to replace any invalid provision with a valid provision that achieves a similar effect.
10.4 Amendments
This DPA may be amended by the Processor upon 30 days' written notice to the Controller. If the Controller does not object within 14 days of such notice, the amendment is deemed accepted. Amendments required to comply with changes in applicable law may be effective immediately upon notice.
10.5 Entire Agreement
This DPA, together with the Platform Terms of Service and the SCCs incorporated by reference, constitutes the entire agreement between the parties with respect to the processing of Personal Data and supersedes all prior agreements on that subject.
Execution
This DPA is entered into by the parties as of the date last signed below.
| DATA CONTROLLER | DATA PROCESSOR |
|---|---|
| Business Legal Name: | Saldana Tech LLC d/b/a Hoshin Space |
| Authorized Signature: | |
| Print Name and Title: | Print Name and Title: |
| Date: | Date: |
Hoshin Space (Saldana Tech LLC) | privacy@hoshinspace.com | hoshinspace.com/legal/dpa