Data Processing Agreement (DPA)
Standard Contractual Clauses for enterprise customers
1. Scope
This DPA applies when Hebza processes Personal Data on behalf of a Customer under a subscription agreement, in accordance with GDPR Article 28 and equivalent regulations.
2. Roles
Customer: Data Controller. Hebza: Data Processor.
3. Processing Purposes
- Provision of the Service (agents, workflows, builder)
- Storage of Customer content
- Audit logging and security
- Support and incident response
4. Categories of Data Subjects
Customer's employees, contractors, customers, and end users as determined by Customer's use of the Service.
5. Security Measures
- Encryption at rest (Fernet/AES-128) and in transit (TLS 1.3)
- Role-based access control (RBAC) with 6 roles and 15 permissions
- Session tracking, revocation, and login throttling
- Approval workflows for destructive operations
- Isolated execution (shell sandbox, browser sandbox)
- Full audit events table with retention per plan
- Data residency in EU (Hetzner) or self-hosted option
6. Sub-Processors
Current sub-processors (with 30 days notice of changes):
- Hetzner Online GmbH — hosting (EU)
- DeepInfra — AI inference (US, EU region available)
- Anthropic, OpenAI, Google — optional AI providers
- Stripe — payment processing
7. Data Subject Rights
Hebza assists Customer in responding to data subject requests (access, rectification, erasure, portability, objection) within 5 business days.
8. International Transfers
Transfers outside EEA are covered by European Commission Standard Contractual Clauses (2021/914).
9. Audit Rights
Customer may audit Hebza's compliance annually with 30 days notice. Alternatively, Hebza provides SOC 2 Type II reports when available.
10. Breach Notification
Hebza notifies Customer without undue delay (within 72 hours) upon becoming aware of a Personal Data Breach.
11. Deletion / Return
Upon termination, Hebza deletes or returns Personal Data within 30 days, except where retention is legally required.
12. Contact
dpa@hebza.io