Zum Inhalt springen

DATA PROCESSING ADDENDUM

LegalHuoPuo Data Processing Addendum

Just a click

View Contents
Important note:

This document does not constitute legal advice, a compliance certification, a security certification, an audit result, or a guarantee of legal compliance.

1. Purpose and Incorporation

This Data Processing Addendum ("DPA") governs the processing of personal data by HuoPuo, LLC ("HuoPuo") on behalf of the customer identified in the applicable Order ("Customer") in connection with the Software and related services.

This DPA forms part of, and is incorporated by reference into, the applicable Order and the HuoPuo End User License Agreement ("EULA"). Where the parties have executed a separate negotiated data processing agreement, that agreement governs the subject matter it covers.

This DPA applies only where and to the extent HuoPuo processes personal data on behalf of Customer. It does not apply to personal data that Customer processes solely within its own environment where HuoPuo has no access, nor to data for which HuoPuo determines its own purposes as described in the HuoPuo Privacy Notice.

2. Definitions

TermMeaning
Applicable Data Protection LawData protection and privacy laws that apply to a party's processing under this DPA, which may include UAE Federal Decree-Law No. 45 of 2021, the Saudi Personal Data Protection Law, applicable United States federal and state privacy laws, and any other law that applies to the relevant processing.
ControllerThe party that determines the purposes and means of processing personal data, or the equivalent role under Applicable Data Protection Law.
ProcessorThe party that processes personal data on behalf of a Controller, or the equivalent role under Applicable Data Protection Law.
Customer Personal DataPersonal data contained within Customer Data that HuoPuo processes on behalf of Customer under this DPA.
Data SubjectAn identified or identifiable natural person to whom Customer Personal Data relates.
Personal Data BreachA breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by HuoPuo.
SubprocessorA third party engaged by HuoPuo to process Customer Personal Data on HuoPuo's behalf under this DPA.
ProcessingAny operation performed on personal data, whether or not by automated means.

Capitalized terms not defined in this DPA have the meaning given in the EULA or the applicable Order.

3. Roles of the Parties

The parties' data protection roles are determined by the actual processing activities and by Applicable Data Protection Law, not by contractual label alone.

  • ▪Customer acts as Controller, or the equivalent role, in respect of Customer Personal Data. Where Customer is itself a processor for a third party, Customer acts as processor and HuoPuo acts as subprocessor, and Customer confirms it has the authority to engage HuoPuo on those terms.

  • ▪HuoPuo acts as Processor, or the equivalent role, in respect of Customer Personal Data processed on Customer's behalf.

  • ▪HuoPuo acts as an independent Controller, or the equivalent role, in respect of account, billing, license status, deployment identity, entitlement, security, website, and operational data that HuoPuo determines and uses for its own legitimate administrative, security, fraud-prevention, product-integrity, service-delivery, and legal-compliance purposes, as described in the HuoPuo Privacy Notice. That processing is outside the scope of this DPA.

4. Scope and Nature of Processing

HuoPuo does not host Customer production systems and does not obtain standing administrative or infrastructure access to Customer-controlled environments. Customer determines and controls where the HuoPuo system is deployed.

Accordingly, HuoPuo processes Customer Personal Data only in defined circumstances, principally where Customer provides information to HuoPuo or instructs HuoPuo to perform a service. The subject matter, duration, nature, purpose, categories of personal data, and categories of data subjects are set out in Annex 1.

5. Customer Instructions

HuoPuo processes Customer Personal Data only on Customer's documented instructions, including as set out in this DPA, the EULA, the applicable Order, a support request, a written authorization, or a Customer-managed configuration, unless required otherwise by law to which HuoPuo is subject.

Where HuoPuo is required by law to process Customer Personal Data other than on Customer's instructions, HuoPuo will inform Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

HuoPuo will inform Customer if, in HuoPuo's reasonable opinion, an instruction infringes Applicable Data Protection Law. HuoPuo may suspend performance of the affected instruction until it is amended, confirmed, or withdrawn. HuoPuo is not obliged to provide legal advice and does not assume responsibility for Customer's compliance obligations.

HuoPuo will not sell Customer Personal Data, will not share it for cross-context behavioral advertising, and will not retain, use, or disclose it for any purpose other than performing the services described in this DPA and the applicable Order, or as otherwise permitted by Applicable Data Protection Law.

HuoPuo will not use Customer Personal Data to train, fine-tune, or improve any artificial intelligence or machine learning model, whether HuoPuo's or a third party's, unless Customer first provides explicit, affirmative consent through an authorized administrative control or written agreement identifying the relevant purpose and data use.

6. Customer Responsibilities

  • ▪Customer is responsible for the lawfulness, accuracy, quality, and content of Customer Personal Data, and for establishing and documenting its own lawful basis for processing.

  • ▪Customer is responsible for providing required notices to, and obtaining required consents from, its own data subjects.

  • ▪Customer is responsible for configuring the Software, AI features, permissions, roles, retention settings, and administrative settings lawfully.

  • ▪Customer is responsible for identifying any data-localization, data-residency, sector-specific, restricted-connectivity, or in-country hosting requirement that applies to it, and for stating that requirement in the applicable Order so the deployment can be configured accordingly.

  • ▪Customer will minimize, redact, anonymize, or pseudonymize support materials before submitting them to HuoPuo where reasonably practicable, and will not submit passwords, private keys, authentication secrets, full payment card credentials, or CVV/CVC values through ordinary support channels.

7. Confidentiality of Personnel

HuoPuo ensures that personnel authorized to process Customer Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory, and that access is limited to those who require it to perform the services.

HuoPuo provides appropriate data protection and security awareness training to personnel with access to Customer Personal Data.

8. Security Measures

HuoPuo implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to data subjects.

A description of those measures is set out in Annex 2. HuoPuo may update the measures from time to time provided that the overall level of protection is not materially reduced.

Customer is responsible for the security of Customer-controlled environments, including infrastructure, network, endpoint, access management, credential protection, and backup configuration, except where HuoPuo expressly assumes a specific obligation in a written agreement.

9. Subprocessors

Customer provides general written authorization for HuoPuo to engage Subprocessors to process Customer Personal Data, subject to this Section.

HuoPuo imposes on each Subprocessor, by written contract, data protection obligations that are no less protective than those in this DPA to the extent applicable to the services that Subprocessor performs. HuoPuo remains responsible to Customer for the performance of each Subprocessor's obligations.

HuoPuo maintains a list of Subprocessors, published as the HuoPuo Subprocessor List and reproduced in summary at Annex 3. HuoPuo will provide notice of the addition or replacement of a Subprocessor before that Subprocessor begins processing Customer Personal Data, by updating the Subprocessor List or by another reasonable means, allowing Customer a reasonable period to object.

Customer may object to a new Subprocessor on reasonable data protection grounds by notifying HuoPuo in writing within thirty (30) days of notice. The parties will discuss the objection in good faith. If no reasonable resolution is reached, Customer may terminate the affected part of the applicable Order for the affected services, and any refund is determined by the applicable Order.

10. Assistance with Data Subject Rights

Taking into account the nature of the processing, HuoPuo will provide reasonable assistance to Customer, by appropriate technical and organizational measures and insofar as possible, in responding to requests from data subjects to exercise their rights under Applicable Data Protection Law.

Where HuoPuo receives a request directly from a data subject relating to Customer Personal Data, HuoPuo will not respond to the substance of the request other than to acknowledge receipt and, where appropriate, direct the data subject to Customer. HuoPuo will inform Customer of the request without undue delay, unless prohibited by law.

Where Customer cannot reasonably fulfill a request through the functionality available to it in the Software, HuoPuo will provide reasonable assistance at Customer's request. HuoPuo may charge a reasonable fee for assistance that materially exceeds ordinary support, unless charging is prohibited by Applicable Data Protection Law.

11. Personal Data Breach

HuoPuo will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data processed by HuoPuo.

The notification will include, to the extent then known and insofar as reasonably available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a point of contact for further information. Where information is not available at the time of notification, HuoPuo will provide it in phases as it becomes available.

HuoPuo will take reasonable steps to contain, investigate, and mitigate the breach, and will provide reasonable cooperation and information to enable Customer to meet its own notification obligations to regulators or data subjects.

A notification or response by HuoPuo under this Section is not an acknowledgment of fault or liability.

Customer is responsible for determining whether the breach requires notification to a regulator or to data subjects under Applicable Data Protection Law, and for making any such notification.

12. Assistance with Assessments and Consultations

Taking into account the nature of the processing and the information available to HuoPuo, HuoPuo will provide reasonable assistance to Customer with data protection impact assessments and, where required, prior consultations with a competent supervisory authority, in each case in relation to processing performed by HuoPuo under this DPA.

HuoPuo may charge a reasonable fee for assistance that materially exceeds ordinary support, unless charging is prohibited by Applicable Data Protection Law.

13. Return and Deletion

On expiry or termination of the applicable Order, and at Customer's election, HuoPuo will return or delete Customer Personal Data that HuoPuo holds and processes on Customer's behalf, subject to the export and archival provisions of the EULA and to any retention required by law.

Where HuoPuo does not hold or control Customer Personal Data because it resides solely in a Customer-controlled deployment, deletion and return are matters for Customer.

HuoPuo may retain Customer Personal Data to the extent required by applicable law, and for the limited periods described in the HuoPuo Privacy Notice and the Support Data Retention and Secure Disposal Schedule. Data retained on that basis remains subject to the protections of this DPA for as long as it is retained.

Data deleted from active systems may persist in protected backups until the relevant backup cycle expires. Residual backup copies are protected and are not restored or processed for ordinary business purposes.

14. Audits and Information

HuoPuo will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which HuoPuo may satisfy by providing documentation, policy summaries, security materials, completed questionnaires, or third-party reports where available.

Where the information provided is not reasonably sufficient, Customer may request an audit no more than once in any twelve-month period, unless required more frequently by a competent supervisory authority or following a Personal Data Breach affecting Customer Personal Data.

An audit is subject to reasonable prior written notice of at least thirty (30) days, conduct during normal business hours, a scope limited to processing performed under this DPA, appropriate confidentiality undertakings, and reasonable measures to minimize disruption.

An audit does not extend to source code, encryption mechanisms, license control mechanisms, security-sensitive materials, contractor identities, other customers' data, or HuoPuo confidential information not necessary to demonstrate compliance with this DPA. Customer bears its own audit costs and HuoPuo's reasonable costs of supporting the audit, unless the audit reveals material non-compliance by HuoPuo.

15. International Transfers

Where Applicable Data Protection Law restricts cross-border transfers of Customer Personal Data, the parties will rely on an appropriate lawful transfer mechanism, such as an adequacy decision, standard contractual clauses, a transfer addendum, an approved certification, explicit consent where permitted, or another valid mechanism recognized under that law.

Where Customer requires that Customer Personal Data remain within a specified country or region, Customer must state that requirement in the applicable Order so that the deployment and any support arrangements can be configured accordingly. HuoPuo is not responsible for a localization requirement that Customer has not stated in the Order.

16. Jurisdiction-Specific Terms

16.1 United Arab Emirates

Where UAE Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data applies to the processing, HuoPuo acts as processor in respect of Customer Personal Data and will process it in accordance with Customer's documented instructions, maintain appropriate security measures, assist Customer with data subject requests, notify Customer of a personal data breach, and comply with the transfer conditions recognized under that law and its implementing provisions.

16.2 Kingdom of Saudi Arabia

Where the Saudi Personal Data Protection Law and its implementing regulations apply to the processing, HuoPuo acts as processor and will process Customer Personal Data in accordance with Customer's instructions and the requirements of that law, including its conditions on transfers of personal data outside the Kingdom. Customer remains responsible for its own registration, notification, and other controller obligations under that law.

16.3 United States

Where applicable United States state privacy laws apply to the processing, HuoPuo acts as a processor or service provider, as applicable. HuoPuo will not sell Customer Personal Data, will not share it for cross-context behavioral advertising, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the services, and will not combine it with personal information received from another source except as permitted by that law.

HuoPuo will notify Customer if HuoPuo determines that it can no longer meet its obligations under the applicable state privacy law, and will cooperate with reasonable steps to stop and remediate unauthorized use.

16.4 Other jurisdictions

Where a data protection law of another jurisdiction applies to the processing, including where Customer is established in or directs the processing from that jurisdiction, the parties will comply with the mandatory requirements of that law in respect of the affected processing, and will execute any additional terms or transfer mechanism reasonably required to do so.

17. Liability

Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the EULA and the applicable Order, except to the extent Applicable Data Protection Law does not permit such exclusion or limitation.

Nothing in this DPA limits a data subject's rights under Applicable Data Protection Law, or the powers of a competent supervisory authority.

18. Order of Precedence

In the event of a conflict regarding the processing of personal data, the following order applies: a separately executed negotiated data processing agreement between the parties; then this DPA; then the applicable Order; then the EULA; then other HuoPuo privacy or legal materials.

For all subject matter other than the processing of personal data, the order of precedence set out in the EULA applies.

19. Term and Survival

This DPA takes effect on the effective date of the applicable Order and continues for as long as HuoPuo processes Customer Personal Data on Customer's behalf.

Provisions that by their nature should survive, including confidentiality, security, return and deletion, audit records, liability, and precedence, survive expiry or termination for as long as HuoPuo retains Customer Personal Data.

20. Contact

  • ▪Website: https://www.huopuo.com

  • ▪Legal / Privacy Contact: legal@huopuo.com

  • ▪Security Contact: security@huopuo.com

Annex 1 Details of Processing

ItemDescription
Subject matterProvision of the HuoPuo Software and related support, implementation, migration, backup restoration, and export assistance services under the applicable Order.
DurationFor the term of the applicable Order, and for any retention period described in the HuoPuo Privacy Notice, the Support Data Retention and Secure Disposal Schedule, or required by law.
Nature and purposeHosting-independent software provision; technical support and troubleshooting based on information the Customer chooses to provide; implementation and configuration assistance; migration and data conversion assistance; backup restoration and export assistance; security and product-integrity operations.
Categories of personal dataBusiness contact data of Customer personnel and Authorized Users; account, license, entitlement and support-status data; personal data contained in support materials that Customer chooses to submit, such as logs, screenshots, diagnostic reports, configuration exports, sample files and extracts; personal data contained in Customer databases where Customer instructs HuoPuo to assist with migration, restoration or export.
Special categoriesHuoPuo does not require special categories of personal data. Customer should not submit them through ordinary support channels unless a specific secure process has been agreed in writing.
Categories of data subjectsCustomer personnel, Authorized Users, administrators, contractors and, where present in Customer Data submitted to HuoPuo, Customer's own customers, employees, suppliers and other individuals whose data Customer processes.
Frequency of processingOccasional and instruction-driven, principally in response to a support request, implementation activity, migration, restoration or export request.

Annex 2 Technical and Organizational Measures

HuoPuo maintains measures appropriate to the nature of its services. Because HuoPuo does not host Customer production environments, several measures below describe controls applied to HuoPuo's own systems and to information Customer submits to HuoPuo.

AreaMeasures
Access controlRole-based access to internal systems; access limited to personnel who require it; individual accounts; authentication controls; removal of access on role change or departure.
No standing customer accessHuoPuo does not use VPN, SSH, remote desktop, remote-control software, privileged Customer accounts, unattended support agents, standing support accounts, or back-door access to Customer environments.
EncryptionEncryption in transit for HuoPuo systems and support channels; encryption of protected deployment artifacts, appliances, protected backups and license materials as applicable to the deployment model.
Support data handlingSupport materials are limited to what Customer submits; minimization and redaction are requested; sensitive diagnostic information is deleted on an accelerated schedule as described in the Support Data Retention and Secure Disposal Schedule.
Logging and monitoringSecurity event logging, access logging, diagnostic logging and monitoring of HuoPuo systems, retained for security, integrity and audit purposes.
Product integrityLicense validation, deployment identity verification, tamper detection, integrity checks and controlled deployment mechanisms.
PersonnelConfidentiality obligations; data protection and security awareness training; defined responsibilities for security and privacy.
Subprocessor governanceWritten contracts imposing protective terms; assessment before engagement; published Subprocessor List.
Backup and recoveryProtected backups of HuoPuo systems; documented recovery processes; residual backup copies protected and not used for ordinary business purposes.
Incident responseDefined process for identifying, containing, investigating and reporting security incidents, including notification to affected customers.
Secure disposalSecure deletion, destruction, anonymization or rendering inaccessible at the end of the applicable retention period, using methods appropriate to the storage technology and sensitivity.

HuoPuo does not claim any certification, audit result, penetration-test outcome, or compliance attestation by describing these measures. Any such claim would be made only where expressly stated in a written agreement and supported by the relevant evidence.

Annex 3 Subprocessors

The current list of Subprocessors is published as the HuoPuo Subprocessor List. The summary below reflects the position at the version date of this DPA and is subject to update in accordance with Section 9.

SubprocessorPurposeApplies to
Website hosting or infrastructure providerHosting and operation of the HuoPuo public website.HuoPuo public website only; not Customer production hosting.
CloudflareWebsite network security and performance.HuoPuo public website only.
StripePayment processing, billing, refunds, disputes and fraud prevention.Customer-facing payment processing.
GoogleWebsite analytics and advertising measurement for the HuoPuo public website.HuoPuo public website only; not Customer Personal Data processed under this DPA.
Meta / WhatsAppOptional general business communications where WhatsApp is used.Optional communications channel only.

Systems operated directly by HuoPuo, including internal customer relationship management, support ticketing, monitoring, logging and backup systems, are not separate third-party Subprocessors. Providers of Customer-controlled environments selected by Customer are not HuoPuo Subprocessors merely because Customer uses them to host or operate the Software.

HuoPuo — Just a click

Version 1.00 · October 1, 2026