Legal

Data Processing Addendum

Version: September 18, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in the applicable agreement, order form, pilot agreement, or subscription (“Customer”) and HardLabs Technologies, Inc. (“HardLabs”).

1. Scope

This DPA applies where HardLabs Processes Personal Data on behalf of Customer in connection with the Services.

Where applicable:

  • Customer acts as Controller or Processor;
  • HardLabs acts as Processor or Service Provider.

HardLabs may act as an independent Controller for limited business information it processes for its own purposes, including account administration, business communications, security, and legal compliance.

2. Definitions

“Data Protection Law” means applicable privacy and data-protection laws, including where applicable:

  • Regulation (EU) 2016/679 (“GDPR”);
  • UK GDPR;
  • UK Data Protection Act 2018;
  • Swiss data-protection law;
  • California Consumer Privacy Act, as amended (“CCPA”);
  • other applicable U.S. state privacy laws.

“Customer Personal Data” means Personal Data Processed by HardLabs on behalf of Customer through the Services.

“Subprocessor” means a third party engaged by HardLabs to Process Customer Personal Data on HardLabs' behalf.

3. Instructions

HardLabs will Process Customer Personal Data only:

  1. to provide the Services;
  2. according to Customer's documented instructions;
  3. as described in the Agreement and this DPA;
  4. as required by applicable law.

Customer instructs HardLabs to Process Customer Personal Data as necessary to provide functionality requested through the Services.

If HardLabs reasonably believes an instruction violates applicable Data Protection Law, HardLabs may notify Customer and suspend the relevant Processing while the parties resolve the issue.

4. Confidentiality

HardLabs will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations.

Access will be restricted to persons who reasonably need such access for operational, support, security, or legal purposes.

5. Security

HardLabs will maintain technical and organizational measures appropriate to the nature of the Services and risk presented by the Processing.

Measures may include:

  • access controls;
  • authenticated accounts;
  • transport encryption;
  • provider-native encryption at rest;
  • logical separation of customer information;
  • restricted production access;
  • secrets-management practices;
  • software-development controls;
  • security logging;
  • vulnerability and dependency management;
  • incident-response procedures.

HardLabs may update these controls provided the overall level of protection is not materially reduced.

6. Security Incidents

HardLabs will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

Where reasonably available, notice will include:

  • nature of the incident;
  • affected categories of information;
  • affected Data Subjects where known;
  • likely consequences;
  • remediation steps;
  • relevant contact information.

Notification does not constitute an admission of liability.

7. Subprocessors

Customer provides HardLabs with general authorization to engage Subprocessors.

HardLabs' current Subprocessors are maintained at:

https://hardlabs.io/legal/subprocessors

HardLabs will impose appropriate contractual data-protection obligations on Subprocessors.

HardLabs remains responsible for Subprocessor Processing to the extent required by applicable Data Protection Law.

Where required by law or an applicable customer agreement, HardLabs will provide reasonable notice of material new Subprocessors.

Customer may submit reasonable data-protection objections to:

aga@hardlabs.io

8. Current Infrastructure

Depending on Customer's use of the Services, Customer Personal Data may be Processed through providers including:

  • Vercel;
  • Cloudflare R2;
  • Clerk;
  • OpenAI;
  • Anthropic.

Business communications may also be processed using Google Workspace.

Google Analytics and Microsoft Clarity are intended for website analytics rather than Processing confidential Customer Content within authenticated product workflows.

9. Data Subject Requests

Taking into account the nature of the Processing, HardLabs will provide reasonable assistance to Customer in responding to valid Data Subject requests.

If HardLabs receives a request relating to Customer Personal Data and can identify Customer as the Controller, HardLabs may direct the requesting individual to Customer.

10. DPIAs and Regulatory Assistance

Taking into account the nature of the Processing and information available to HardLabs, HardLabs will provide reasonable assistance with legally required:

  • data-protection impact assessments;
  • regulatory consultations;
  • investigations concerning HardLabs Processing.

11. Government Requests

Where legally permitted, HardLabs will notify Customer if HardLabs receives legally binding government process requiring disclosure of Customer Personal Data.

HardLabs will evaluate such requests and disclose only information legally required.

12. Return and Deletion

Following termination of the applicable Services or upon Customer's valid request, HardLabs will delete or return Customer Personal Data unless applicable law requires retention.

Information may remain temporarily in backups or technical systems until removed through ordinary deletion cycles.

Any retained information remains subject to this DPA while retained.

13. Compliance Information and Audits

HardLabs will provide information reasonably necessary to demonstrate compliance with this DPA.

Where commercially reasonable, HardLabs may satisfy requests through:

  • security documentation;
  • architecture information;
  • questionnaires;
  • provider documentation;
  • third-party reports or certifications available to HardLabs.

If additional audit rights are legally required, audits will:

  • occur upon reasonable notice;
  • take place during normal business hours;
  • avoid unreasonable operational disruption;
  • remain subject to confidentiality;
  • not expose another customer's information.

Unless required following a material incident or by a regulator, Customer may not conduct more than one such audit in any 12-month period.

14. International Data Transfers

Where Customer Personal Data subject to the GDPR is transferred to a country without an applicable adequacy decision, the parties will use an appropriate transfer mechanism.

This may include the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 (“EU SCCs”).

Module Two

Module Two applies where Customer is a Controller and HardLabs is a Processor.

Module Three

Module Three applies where Customer acts as a Processor and HardLabs acts as a subprocessor.

Where required:

  • Clause 7 docking applies;
  • Clause 9 Option 2 general authorization applies;
  • Clause 11 optional dispute language does not apply;
  • Annex I is completed using Annex I below;
  • Annex II is completed using Annex II below;
  • Annex III consists of HardLabs' current Subprocessor List.

If this DPA conflicts with mandatory provisions of the EU SCCs, the SCCs control.

15. United Kingdom

Where applicable to a restricted UK transfer, the parties will incorporate the then-current UK International Data Transfer Addendum or other lawful UK transfer mechanism.

16. Switzerland

Where Swiss data-protection law applies, the EU SCCs will be interpreted with modifications necessary under Swiss law.

17. U.S. State Privacy Requirements

To the extent HardLabs acts as a processor, contractor, or service provider under applicable U.S. privacy law, HardLabs will:

  • Process personal information only for permitted purposes;
  • not sell Customer Personal Data;
  • not share Customer Personal Data for cross-context behavioral advertising;
  • not retain, use, or disclose Customer Personal Data outside permitted business purposes;
  • provide the level of privacy protection required by applicable law;
  • notify Customer if HardLabs determines it can no longer meet applicable statutory obligations.

18. Liability

Liability under this DPA is subject to the applicable Agreement's liability limitations except where applicable law prohibits such limitation.

19. Order of Precedence

In the event of conflict:

  1. mandatory Data Protection Law controls;
  2. applicable SCCs or mandatory transfer instruments control;
  3. this DPA controls;
  4. the Agreement controls.

Annex I — Details of Processing

Data Exporter

The Customer identified in the applicable Agreement.

Role: Controller or Processor, as applicable.

Data Importer

HardLabs Technologies, Inc.255 Berry Street Apt 517San Francisco, CA 94158United States

Contact: aga@hardlabs.io

Role: Processor or subprocessor, as applicable.

Subject Matter

Provision of HardLabs hardware and firmware development, simulation, analysis, testing, debugging, automation, hosting, storage, and related functionality.

Duration

For the duration of the Services and any limited period required for deletion, backup, legal compliance, or dispute resolution.

Categories of Data Subjects

May include:

  • Customer employees;
  • Customer contractors;
  • consultants;
  • authorized account users;
  • individuals whose information is incidentally contained in Customer Content.

Categories of Personal Data

May include:

  • name;
  • business email;
  • account identifier;
  • authentication metadata;
  • IP address;
  • device information;
  • usage and technical logs;
  • support communications;
  • Personal Data incidentally contained in Customer Content.

Sensitive Data

The Services are not designed for special-category or highly regulated personal information.

Customer should not intentionally submit such information unless HardLabs has agreed in writing to appropriate additional safeguards.

Processing Activities

Processing may include:

  • collection;
  • transmission;
  • storage;
  • organization;
  • retrieval;
  • analysis;
  • automated processing;
  • AI inference;
  • simulation;
  • logging;
  • troubleshooting;
  • deletion.

Annex II — Technical and Organizational Measures

HardLabs uses a cloud-based architecture with specialist infrastructure providers.

Authentication

User authentication and account management are provided through Clerk.

Hosting

Application deployment and hosting are provided through Vercel.

Object Storage

Customer technical files and other stored objects may be stored using Cloudflare R2.

AI Processing

Relevant Customer Content may be sent to commercial/API services from OpenAI or Anthropic when required by a Customer-requested operation.

Access Control

HardLabs limits internal access to production systems and Customer Content according to operational need.

Encryption

HardLabs uses encrypted network transport for production Services and relies on provider-supported encryption for stored data where applicable.

Customer Separation

HardLabs designs the Services so that ordinary application functionality does not allow one customer to access another customer's Customer Content.

Secrets

Production credentials and secrets are restricted and are not intended to be stored directly in public source-code repositories.

Security Updates

HardLabs maintains its software and dependencies and addresses material security vulnerabilities according to risk.

Incident Management

HardLabs maintains processes for investigating and responding to suspected security incidents.

Security incidents should be reported to:

adam@hardlabs.io

Annex III — Subprocessors

The current Subprocessor list is maintained at:

https://hardlabs.io/legal/subprocessors