Back to Hytribe
Enterprise onboarding · Appendix

Data Processing Agreement

An overview of the DPA we sign with enterprise customers. This page summarises the structure and our positions — the executable document is provided on request under NDA.

How to use this page
The clauses below describe Hytribe's default positions. Many enterprise customers prefer their own DPA paper — we're happy to review yours quickly because our positions here are already resolved.
Clause 1–2

Parties, scope and subject matter

FieldPosition
ControllerYou (the customer)
ProcessorHytribe Inc.
Subject matterFormation of member groups ("tribes") and associated facilitation.
DurationTerm of the Services Agreement plus the deletion period in Clause 8.
Nature and purposeCollection, storage, enrichment, vector embedding, matching, and delivery of facilitation messages.
Categories of data subjectMembers of your community.
Categories of personal dataPseudonymous user identifier, display name, interests, goals, engagement tier, availability, timezone, onboarding responses.
Special categoriesNone. Wellbeing / psychological assessment data is disabled at tenant level and not processed on your behalf.
Clause 3–5

Processor obligations, sub-processors and security

  • Process personal data only on your documented instructions.
  • Personnel authorised to process are bound by confidentiality.
  • Implement the technical and organisational measures in Annex A.
  • Assist you with data-subject rights requests, DPIAs and regulator consultations.
  • Make available the information necessary to demonstrate compliance.
  • General authorisation for the sub-processors in Annex B, with 30 days' notice before adding or replacing any sub-processor.
  • Remain liable for the acts and omissions of sub-processors.
Clause 6

Personal data breach

We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, and provide the information reasonably required for you to meet your own notification obligations.

Clause 7

International transfers

Where personal data is transferred outside the EEA or UK, transfers are governed by the current Standard Contractual Clauses (or the UK IDTA / Addendum, as applicable), incorporated by reference. Sub-processor regions are listed in Annex B and on the Security page.

Clause 8

Deletion and return

On termination, at your election we delete or return all personal data within 30 days, including data held by sub-processors, save where retention is required by law. Deletion includes derived data such as vector embeddings — see the Retention & Deletion Policy.

Clause 9

Audit

We make available the information necessary to demonstrate compliance and allow audits by you or your appointed auditor, no more than once per year on reasonable notice, subject to confidentiality. Between audits we accept written questionnaires and share available third-party attestations under NDA.

Clause 10

Liability

Liability caps, carve-outs and indemnities are negotiated inside the Services Agreement. We accept uncapped liability for breach of confidentiality and for wilful misconduct, with a super-cap for data-protection breaches; standard liability otherwise. Detailed positions shared with counsel during review.

Annex A

Technical and organisational measures

Populated from the Security & Data Handling Pack — implemented controls only. Highlights:

  • TLS 1.2+ for all API traffic; HSTS enforced on customer surfaces.
  • Per-community API keys, hashed at rest, revocable immediately.
  • Tenant isolation by community_id, enforced at the application layer.
  • Managed database encryption at rest (AES-256 class) via Neon.
  • Least-privilege access; Hytribe personnel access is logged.
  • Automated dependency and secret scanning on every build.
  • Documented incident response with a 72-hour notification window.
Annex B

Authorised sub-processors

NamePurposeLocation
RailwayApplication hostingUS
NeonDatabaseUS / EU (per tenant)
OpenAIProfile embeddingsUS
AnthropicEnrichment and facilitationUS
ResendTransactional emailUS
Request the executable DPA
We'll share the current DPA (and your questionnaire response) under NDA.
Contact legal