Legal
Data Processing Addendum
Version: September 18, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in the applicable agreement, order form, pilot agreement, or subscription (“Customer”) and HardLabs Technologies, Inc. (“HardLabs”).
1. Scope
This DPA applies where HardLabs Processes Personal Data on behalf of Customer in connection with the Services.
Where applicable:
- Customer acts as Controller or Processor;
- HardLabs acts as Processor or Service Provider.
HardLabs may act as an independent Controller for limited business information it processes for its own purposes, including account administration, business communications, security, and legal compliance.
2. Definitions
“Data Protection Law” means applicable privacy and data-protection laws, including where applicable:
- Regulation (EU) 2016/679 (“GDPR”);
- UK GDPR;
- UK Data Protection Act 2018;
- Swiss data-protection law;
- California Consumer Privacy Act, as amended (“CCPA”);
- other applicable U.S. state privacy laws.
“Customer Personal Data” means Personal Data Processed by HardLabs on behalf of Customer through the Services.
“Subprocessor” means a third party engaged by HardLabs to Process Customer Personal Data on HardLabs' behalf.
3. Instructions
HardLabs will Process Customer Personal Data only:
- to provide the Services;
- according to Customer's documented instructions;
- as described in the Agreement and this DPA;
- as required by applicable law.
Customer instructs HardLabs to Process Customer Personal Data as necessary to provide functionality requested through the Services.
If HardLabs reasonably believes an instruction violates applicable Data Protection Law, HardLabs may notify Customer and suspend the relevant Processing while the parties resolve the issue.
4. Confidentiality
HardLabs will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations.
Access will be restricted to persons who reasonably need such access for operational, support, security, or legal purposes.
5. Security
HardLabs will maintain technical and organizational measures appropriate to the nature of the Services and risk presented by the Processing.
Measures may include:
- access controls;
- authenticated accounts;
- transport encryption;
- provider-native encryption at rest;
- logical separation of customer information;
- restricted production access;
- secrets-management practices;
- software-development controls;
- security logging;
- vulnerability and dependency management;
- incident-response procedures.
HardLabs may update these controls provided the overall level of protection is not materially reduced.
6. Security Incidents
HardLabs will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Where reasonably available, notice will include:
- nature of the incident;
- affected categories of information;
- affected Data Subjects where known;
- likely consequences;
- remediation steps;
- relevant contact information.
Notification does not constitute an admission of liability.
7. Subprocessors
Customer provides HardLabs with general authorization to engage Subprocessors.
HardLabs' current Subprocessors are maintained at:
https://hardlabs.io/legal/subprocessors
HardLabs will impose appropriate contractual data-protection obligations on Subprocessors.
HardLabs remains responsible for Subprocessor Processing to the extent required by applicable Data Protection Law.
Where required by law or an applicable customer agreement, HardLabs will provide reasonable notice of material new Subprocessors.
Customer may submit reasonable data-protection objections to:
8. Current Infrastructure
Depending on Customer's use of the Services, Customer Personal Data may be Processed through providers including:
- Vercel;
- Cloudflare R2;
- Clerk;
- OpenAI;
- Anthropic.
Business communications may also be processed using Google Workspace.
Google Analytics and Microsoft Clarity are intended for website analytics rather than Processing confidential Customer Content within authenticated product workflows.
9. Data Subject Requests
Taking into account the nature of the Processing, HardLabs will provide reasonable assistance to Customer in responding to valid Data Subject requests.
If HardLabs receives a request relating to Customer Personal Data and can identify Customer as the Controller, HardLabs may direct the requesting individual to Customer.
10. DPIAs and Regulatory Assistance
Taking into account the nature of the Processing and information available to HardLabs, HardLabs will provide reasonable assistance with legally required:
- data-protection impact assessments;
- regulatory consultations;
- investigations concerning HardLabs Processing.
11. Government Requests
Where legally permitted, HardLabs will notify Customer if HardLabs receives legally binding government process requiring disclosure of Customer Personal Data.
HardLabs will evaluate such requests and disclose only information legally required.
12. Return and Deletion
Following termination of the applicable Services or upon Customer's valid request, HardLabs will delete or return Customer Personal Data unless applicable law requires retention.
Information may remain temporarily in backups or technical systems until removed through ordinary deletion cycles.
Any retained information remains subject to this DPA while retained.
13. Compliance Information and Audits
HardLabs will provide information reasonably necessary to demonstrate compliance with this DPA.
Where commercially reasonable, HardLabs may satisfy requests through:
- security documentation;
- architecture information;
- questionnaires;
- provider documentation;
- third-party reports or certifications available to HardLabs.
If additional audit rights are legally required, audits will:
- occur upon reasonable notice;
- take place during normal business hours;
- avoid unreasonable operational disruption;
- remain subject to confidentiality;
- not expose another customer's information.
Unless required following a material incident or by a regulator, Customer may not conduct more than one such audit in any 12-month period.
14. International Data Transfers
Where Customer Personal Data subject to the GDPR is transferred to a country without an applicable adequacy decision, the parties will use an appropriate transfer mechanism.
This may include the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 (“EU SCCs”).
Module Two
Module Two applies where Customer is a Controller and HardLabs is a Processor.
Module Three
Module Three applies where Customer acts as a Processor and HardLabs acts as a subprocessor.
Where required:
- Clause 7 docking applies;
- Clause 9 Option 2 general authorization applies;
- Clause 11 optional dispute language does not apply;
- Annex I is completed using Annex I below;
- Annex II is completed using Annex II below;
- Annex III consists of HardLabs' current Subprocessor List.
If this DPA conflicts with mandatory provisions of the EU SCCs, the SCCs control.
15. United Kingdom
Where applicable to a restricted UK transfer, the parties will incorporate the then-current UK International Data Transfer Addendum or other lawful UK transfer mechanism.
16. Switzerland
Where Swiss data-protection law applies, the EU SCCs will be interpreted with modifications necessary under Swiss law.
17. U.S. State Privacy Requirements
To the extent HardLabs acts as a processor, contractor, or service provider under applicable U.S. privacy law, HardLabs will:
- Process personal information only for permitted purposes;
- not sell Customer Personal Data;
- not share Customer Personal Data for cross-context behavioral advertising;
- not retain, use, or disclose Customer Personal Data outside permitted business purposes;
- provide the level of privacy protection required by applicable law;
- notify Customer if HardLabs determines it can no longer meet applicable statutory obligations.
18. Liability
Liability under this DPA is subject to the applicable Agreement's liability limitations except where applicable law prohibits such limitation.
19. Order of Precedence
In the event of conflict:
- mandatory Data Protection Law controls;
- applicable SCCs or mandatory transfer instruments control;
- this DPA controls;
- the Agreement controls.
Annex I — Details of Processing
Data Exporter
The Customer identified in the applicable Agreement.
Role: Controller or Processor, as applicable.
Data Importer
HardLabs Technologies, Inc.255 Berry Street Apt 517San Francisco, CA 94158United StatesContact: aga@hardlabs.io
Role: Processor or subprocessor, as applicable.
Subject Matter
Provision of HardLabs hardware and firmware development, simulation, analysis, testing, debugging, automation, hosting, storage, and related functionality.
Duration
For the duration of the Services and any limited period required for deletion, backup, legal compliance, or dispute resolution.
Categories of Data Subjects
May include:
- Customer employees;
- Customer contractors;
- consultants;
- authorized account users;
- individuals whose information is incidentally contained in Customer Content.
Categories of Personal Data
May include:
- name;
- business email;
- account identifier;
- authentication metadata;
- IP address;
- device information;
- usage and technical logs;
- support communications;
- Personal Data incidentally contained in Customer Content.
Sensitive Data
The Services are not designed for special-category or highly regulated personal information.
Customer should not intentionally submit such information unless HardLabs has agreed in writing to appropriate additional safeguards.
Processing Activities
Processing may include:
- collection;
- transmission;
- storage;
- organization;
- retrieval;
- analysis;
- automated processing;
- AI inference;
- simulation;
- logging;
- troubleshooting;
- deletion.
Annex II — Technical and Organizational Measures
HardLabs uses a cloud-based architecture with specialist infrastructure providers.
Authentication
User authentication and account management are provided through Clerk.
Hosting
Application deployment and hosting are provided through Vercel.
Object Storage
Customer technical files and other stored objects may be stored using Cloudflare R2.
AI Processing
Relevant Customer Content may be sent to commercial/API services from OpenAI or Anthropic when required by a Customer-requested operation.
Access Control
HardLabs limits internal access to production systems and Customer Content according to operational need.
Encryption
HardLabs uses encrypted network transport for production Services and relies on provider-supported encryption for stored data where applicable.
Customer Separation
HardLabs designs the Services so that ordinary application functionality does not allow one customer to access another customer's Customer Content.
Secrets
Production credentials and secrets are restricted and are not intended to be stored directly in public source-code repositories.
Security Updates
HardLabs maintains its software and dependencies and addresses material security vulnerabilities according to risk.
Incident Management
HardLabs maintains processes for investigating and responding to suspected security incidents.
Security incidents should be reported to:
Annex III — Subprocessors
The current Subprocessor list is maintained at: