Data Processing Agreement

Art. 28 GDPR. Version 1.1. Effective August 11, 2026.

This data processing agreement ("DPA") is made between you, the customer (the "Controller"), and Heplon UG (haftungsbeschränkt) i.G., Kolonnenstraße 8, 10827 Berlin (the "Processor").

It supplements the agreement under which the Processor makes its product (the "Service") available to the Controller, whether that is our Terms of Service or a separate written agreement (the "Main Agreement"). It forms part of the Main Agreement and is accepted at the same time and in the same way.

It applies for as long as the Processor processes personal data on the Controller's behalf, and takes precedence over the Main Agreement in matters of personal data.

1. Subject and scope

  1. Subject and purpose. Operating the Service for the Controller. Duration. The term of the Main Agreement. Nature of processing. Storage, retrieval, analysis and automated action on data held in the systems the Controller connects to the Service.
  2. Categories of data subjects. The Controller's employees and contractors, and individuals who happen to be named in the connected systems, including personnel of the Controller's own customers.
  3. Types of personal data. Any personal data contained in the systems the Controller connects to the Service, such as in source code and application logs, for example names and account identifiers appearing in them. The Controller will not introduce special categories of personal data within the meaning of Art. 9 GDPR.
  4. Controller's authority. Where the Controller acts as a processor for a third party in respect of personal data made available to the Processor, the Controller warrants that it is authorised to engage the Processor as a sub-processor on the terms of this DPA.

2. Instructions

  1. The Processor processes personal data only on the Controller's documented instructions. The Main Agreement and this DPA constitute the initial instruction. Further instructions may be given in writing, including by email.
  2. The initial instruction covers operating, supporting, troubleshooting and adapting the Service for the Controller, and the Processor imposes the same limits on the sub-processors listed in Annex 2. The Processor may create and use anonymised data derived from the processing to operate, secure and improve the Service. Such data does not permit the identification of any data subject and is not personal data.
  3. The Processor will inform the Controller if it considers an instruction to infringe data protection law, and may suspend the affected processing until the instruction is confirmed.

3. Processor obligations

  1. Confidentiality. Persons authorised by the Processor to process the personal data are bound to confidentiality and are granted access only where needed for the purposes in section 2.2.
  2. Security. The Processor implements and maintains the technical and organisational measures set out in Annex 1 (Art. 32 GDPR) and will not materially reduce them during the term.
  3. Personal data breaches. The Processor notifies the Controller without undue delay after becoming aware of a personal data breach, providing the information the Controller needs to meet its obligations under Art. 33 and 34 GDPR.
  4. Assistance. The Processor assists the Controller, so far as reasonable and taking into account the nature of the processing, with requests from data subjects and with the Controller's obligations under Art. 32 to 36 GDPR. It forwards any data subject request it receives directly to the Controller without undue delay and does not respond to it itself.
  5. Deletion. On termination of the Main Agreement the Processor deletes the Controller's personal data within 30 days, except where EU or Member State law requires it to be kept, and confirms the deletion in writing on request. Copies held in routine backups are deleted as those backups expire, and access and security logs are deleted at the end of the retention period stated in Annex 1. Both remain subject to this DPA for as long as they are held.
  6. Records and audits. The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR. Audits are conducted by way of documentation and written questions. During the term of the Main Agreement an on-site inspection takes place only where there is specific cause, such as a personal data breach affecting the Controller's data. An inspection is carried out on 30 days notice, during business hours, no more than once a year, at the Controller's cost, limited to what is relevant to the processing under this DPA, and not by a competitor of the Processor.

4. Sub-processors

  1. The Controller grants general authorisation for the sub-processors listed in Annex 2. The Processor imposes on each of them data protection obligations equivalent to those in this DPA and remains fully responsible for their performance.
  2. The Processor informs the Controller in writing before engaging a new sub-processor or replacing an existing one. The Controller may object on reasonable data protection grounds within 14 days. If the parties cannot resolve the objection, either party may terminate the Main Agreement.

5. International transfers

Processing takes place within the European Union. Where a sub-processor processes personal data outside the EU or EEA, the Processor ensures a valid basis under Chapter V GDPR, such as an adequacy decision or the EU Standard Contractual Clauses together with any necessary supplementary measures, and provides evidence of it on request.

6. Notices

  1. Notices under this DPA, including the breach notification under section 3.3, are given in writing, including by email, to the contacts below. Either party may change its contact by notice to the other.
  2. Processor. security@heplon.com
  3. Controller. The administrators registered on the Controller's Heplon account. The Controller keeps those contact details current.

7. Liability and final provisions

Art. 82 GDPR governs claims by data subjects and the apportionment of liability between the parties under it. Contractual liability between the parties for breaches of this DPA follows the limitations of liability in the Main Agreement. In all other respects the provisions of the Main Agreement apply. Amendments must be in writing. German law applies. The place of jurisdiction is Berlin.

Annex 1: Technical and organisational measures

Access control
Administrative access requires multi-factor authentication, is granted on a least-privilege basis and only to named individuals, and is logged. No shared accounts are used.
Encryption
TLS 1.2 or higher in transit. AES-256 at rest for storage, databases, and backups. Credentials and keys are held in a managed secrets store.
Separation
Your data is logically separated from that of other customers and is accessible only to those authorised under section 3.1.
Logging and monitoring
Access to the Service and to production systems is logged and retained for 90 days.
Organisational measures
Personnel are bound to confidentiality and briefed on data protection on joining. Access is revoked on departure. Incidents follow a documented response procedure with the notification path in section 3.3.
Availability
Backups are encrypted, expire within 35 days, and restore procedures are tested quarterly.
Deletion
Your data is destroyed within 30 days of the end of the term. Backup copies are deleted as they expire, within a further 35 days.

Annex 2: Approved sub-processors

Sub-processor Purpose Location
Amazon Web Services EMEA SARL Hosting, storage and backup of the Service, and model inference via Amazon Bedrock. European Union
TensorX Ltd. Model inference. European Union

No other sub-processor processes Controller personal data in providing the Service. In particular, model inference runs only with the providers listed above, and no data is passed to any other model provider.

Contact

Questions about this DPA, and requests for a countersigned copy, can be sent to hello@heplon.com.