Data Processing Agreement
An overview of the DPA we sign with enterprise customers. This page summarises the structure and our positions — the executable document is provided on request under NDA.
Parties, scope and subject matter
| Field | Position |
|---|---|
| Controller | You (the customer) |
| Processor | Hytribe Inc. |
| Subject matter | Formation of member groups ("tribes") and associated facilitation. |
| Duration | Term of the Services Agreement plus the deletion period in Clause 8. |
| Nature and purpose | Collection, storage, enrichment, vector embedding, matching, and delivery of facilitation messages. |
| Categories of data subject | Members of your community. |
| Categories of personal data | Pseudonymous user identifier, display name, interests, goals, engagement tier, availability, timezone, onboarding responses. |
| Special categories | None. Wellbeing / psychological assessment data is disabled at tenant level and not processed on your behalf. |
Processor obligations, sub-processors and security
- Process personal data only on your documented instructions.
- Personnel authorised to process are bound by confidentiality.
- Implement the technical and organisational measures in Annex A.
- Assist you with data-subject rights requests, DPIAs and regulator consultations.
- Make available the information necessary to demonstrate compliance.
- General authorisation for the sub-processors in Annex B, with 30 days' notice before adding or replacing any sub-processor.
- Remain liable for the acts and omissions of sub-processors.
Personal data breach
We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, and provide the information reasonably required for you to meet your own notification obligations.
International transfers
Where personal data is transferred outside the EEA or UK, transfers are governed by the current Standard Contractual Clauses (or the UK IDTA / Addendum, as applicable), incorporated by reference. Sub-processor regions are listed in Annex B and on the Security page.
Deletion and return
On termination, at your election we delete or return all personal data within 30 days, including data held by sub-processors, save where retention is required by law. Deletion includes derived data such as vector embeddings — see the Retention & Deletion Policy.
Audit
We make available the information necessary to demonstrate compliance and allow audits by you or your appointed auditor, no more than once per year on reasonable notice, subject to confidentiality. Between audits we accept written questionnaires and share available third-party attestations under NDA.
Liability
Liability caps, carve-outs and indemnities are negotiated inside the Services Agreement. We accept uncapped liability for breach of confidentiality and for wilful misconduct, with a super-cap for data-protection breaches; standard liability otherwise. Detailed positions shared with counsel during review.
Technical and organisational measures
Populated from the Security & Data Handling Pack — implemented controls only. Highlights:
- TLS 1.2+ for all API traffic; HSTS enforced on customer surfaces.
- Per-community API keys, hashed at rest, revocable immediately.
- Tenant isolation by
community_id, enforced at the application layer. - Managed database encryption at rest (AES-256 class) via Neon.
- Least-privilege access; Hytribe personnel access is logged.
- Automated dependency and secret scanning on every build.
- Documented incident response with a 72-hour notification window.
Authorised sub-processors
| Name | Purpose | Location |
|---|---|---|
| Railway | Application hosting | US |
| Neon | Database | US / EU (per tenant) |
| OpenAI | Profile embeddings | US |
| Anthropic | Enrichment and facilitation | US |
| Resend | Transactional email | US |