Data Processing Agreement

Art. 28 GDPR. Version 1.2. Effective September 8, 2026.

This data processing agreement ("DPA") is made between you, the customer (the "Customer"), and Heplon UG (haftungsbeschränkt), Kolonnenstraße 8, 10827 Berlin ("Heplon").

It supplements the agreement under which Heplon makes its product (the "Service") available to the Customer, whether that is our Terms of Service or a separate written agreement (the "Main Agreement"). It forms part of the Main Agreement and is accepted at the same time and in the same way.

It applies for as long as Heplon processes personal data on the Customer's behalf, and takes precedence over the Main Agreement in matters of personal data. "Customer Personal Data" means personal data that Heplon processes on the Customer's behalf under this DPA.

For each processing activity, the Customer acts as controller or processor, as applicable, and Heplon acts correspondingly as processor or sub-processor. This DPA applies to business use of the Service in either arrangement. It does not apply to use purely for personal or household purposes where the GDPR household exemption applies.

1. Subject and scope

  1. Subject and purpose. Operating the Service for the Customer. Duration. The term of the Main Agreement. Nature of processing. Storage, retrieval, analysis and automated action on data held in the systems the Customer connects to the Service.
  2. Categories of data subjects. The Customer's employees and contractors, and individuals who happen to be named in the connected systems, including personnel of the Customer's own customers.
  3. Types of personal data. Any personal data contained in the systems the Customer connects to the Service, such as in source code and application logs, for example names and account identifiers appearing in them. The Customer will not introduce special categories of personal data within the meaning of Art. 9 GDPR.
  4. Customer's authority. Where the Customer acts as a processor for a third-party controller, the Customer warrants that it is authorised to engage Heplon as a sub-processor on the terms of this DPA, to give documented instructions on the controller's behalf, and to authorise the sub-processors and processing described here. The Customer will communicate any applicable controller instructions to Heplon.

2. Instructions

  1. Heplon processes Customer Personal Data only on the Customer's documented instructions. The Main Agreement and this DPA constitute the initial instruction. Further instructions may be given in writing, including by email.
  2. The initial instruction covers operating, supporting, troubleshooting and adapting the Service for the Customer, and verifying that the Service performs as intended. Verification includes review by a limited number of Heplon's authorised personnel of samples of the output the Service produces and of the associated processing records, such as findings, proposed fixes, the surrounding code and configuration they relate to, and telemetry about how the Service ran.
  3. Heplon does not use Customer Personal Data to train or fine-tune any machine learning model, and imposes the same restriction on the sub-processors listed in Annex 2. No copy of Customer Personal Data is retained for the purpose of developing the Service, and none is extracted from the review environment. Where review leads Heplon's personnel to improve the Service, that improvement derives from their own understanding and not from any retained copy of Customer Personal Data.
  4. Heplon may create and use aggregated statistical data about use of the Service to operate, secure and improve it. Such data does not permit the identification of any data subject and is not personal data.
  5. Heplon will inform the Customer if it considers an instruction to infringe data protection law, and may suspend the affected processing until the instruction is confirmed.

3. Heplon's obligations

  1. Confidentiality. Persons authorised by Heplon to process Customer Personal Data are bound to confidentiality and are granted access only where needed for the purposes in section 2.2.
  2. Security. Heplon implements and maintains the technical and organisational measures set out in Annex 1 (Art. 32 GDPR) and will not materially reduce them during the term.
  3. Personal data breaches. Heplon notifies the Customer without undue delay after becoming aware of a personal data breach, providing the information the Customer needs to meet its obligations under Art. 33 and 34 GDPR.
  4. Assistance. Heplon assists the Customer, so far as reasonable and taking into account the nature of the processing, with requests from data subjects and with the Customer's obligations under Art. 32 to 36 GDPR. It forwards any data subject request it receives directly to the Customer without undue delay and does not respond to it itself.
  5. Return and deletion. At the Customer's choice, on termination of the Main Agreement Heplon returns Customer Personal Data in a reasonable machine-readable format and deletes existing copies, or deletes it without return. The Customer may communicate its choice before or within 30 days after termination; if it does not, deletion is the default. Return and deletion from active systems are completed within 30 days after termination. Copies held in routine backups are deleted as those backups expire, within a further 35 days. Access and security logs are deleted at the end of the 90-day retention period stated in Annex 1. EU or Member State law may require Heplon to retain particular records. Any retained data remains protected by this DPA and is processed only for the applicable retention purpose. Heplon confirms deletion in writing on request.
  6. Records and audits. Heplon makes available to the Customer the information necessary to demonstrate compliance with Art. 28 GDPR. Audits are conducted by way of documentation and written questions. During the term of the Main Agreement an on-site inspection takes place only where there is specific cause, such as a personal data breach affecting the Customer's data. An inspection is carried out on 30 days notice, during business hours, no more than once a year, at the Customer's cost, limited to what is relevant to the processing under this DPA, and not by a competitor of Heplon.

4. Sub-processors

  1. The Customer grants general authorisation for the sub-processors listed in Annex 2. Heplon imposes on each of them data protection obligations equivalent to those in this DPA and remains fully responsible for their performance.
  2. Heplon informs the Customer in writing before engaging a new sub-processor or replacing an existing one. The Customer may object on reasonable data protection grounds within 14 days. If the parties cannot resolve the objection, either party may terminate the Main Agreement.

5. International transfers

Processing takes place within the European Union. Where a sub-processor processes personal data outside the EU or EEA, Heplon ensures a valid basis under Chapter V GDPR, such as an adequacy decision or the EU Standard Contractual Clauses together with any necessary supplementary measures, and provides evidence of it on request.

6. Notices

  1. Notices under this DPA, including the breach notification under section 3.3, are given in writing, including by email, to the contacts below. Either party may change its contact by notice to the other.
  2. Heplon. security@heplon.com
  3. Customer. The administrators registered on the Customer's Heplon account. The Customer keeps those contact details current.

7. Liability and final provisions

Art. 82 GDPR governs claims by data subjects and the apportionment of liability between the parties under it. Contractual liability between the parties for breaches of this DPA follows the limitations of liability in the Main Agreement. In all other respects the provisions of the Main Agreement apply. Amendments must be in writing. German law applies. The place of jurisdiction is Berlin.

Annex 1: Technical and organisational measures

Access control
Administrative access requires multi-factor authentication, is granted on a least-privilege basis and only to named individuals, and is logged. No shared accounts are used.
Encryption
TLS 1.2 or higher in transit. AES-256 at rest for storage, databases, and backups. Credentials and keys are held in a managed secrets store.
Separation
Your data is logically separated from that of other customers and is accessible only to those authorised under section 3.1.
Logging and monitoring
Access to the Service and to production systems is logged and retained for 90 days.
Organisational measures
Personnel are bound to confidentiality and briefed on data protection on joining. Access is revoked on departure. Incidents follow a documented response procedure with the notification path in section 3.3.
Availability
Backups are encrypted, expire within 35 days, and restore procedures are tested quarterly.
Deletion
Customer Personal Data is returned or deleted, at the Customer's choice, within 30 days of the end of the term. Backup copies are deleted as they expire, within a further 35 days.

Annex 2: Approved sub-processors

Sub-processorPurposeLocation
Amazon Web Services EMEA SARLHosting, storage and backup of the Service, and model inference via Amazon Bedrock.European Union
TensorX Ltd.Model inference.European Union

No other sub-processor processes Customer Personal Data in providing the Service. In particular, model inference runs only with the providers listed above, and no data is passed to any other model provider.

Contact

Questions about this DPA, and requests for a countersigned copy, can be sent to hello@heplon.com.