Legal
Data Processing Agreement
The Article 28 GDPR terms on which HAPP processes personal data on your behalf, including the EU Standard Contractual Clauses. It forms part of the Terms of Use and takes effect when you accept them — no separate signature is required.
- Version
- Version 1.0 — effective 27 August 2026
- Company
- Happ
- Contact
- [email protected]
This Data Processing Agreement forms part of the Terms of Use and takes effect automatically when You accept them. No separate signature is required. If Your organisation needs a counter-signed copy, or a copy naming a different HAPP contracting entity, write to [email protected].
Parties and scope
This Data Processing Agreement (the "DPA") is concluded between:
- Saloid Viacheslav Oleksandrovych, a sole entrepreneur registered in Ukraine under the Law of Ukraine "On State Registration of Legal Entities, Individual Entrepreneurs, and Public Organizations", Taxpayer Identification Number 3628308118, state registration record number 544422567292 dated 12 January 2022, registered address 47 Ilfa i Petrova str., apartment 116, Odesa, 65122, Ukraine ("HAPP", "We", "Us"), acting as Processor; and
- You, the User as defined in the Terms of Use ("Customer"), acting as Controller.
Contact for data protection matters: [email protected]. Contact for contractual notices: [email protected]. Telephone: +380 99 482 95 73.
In the event of a conflict between this DPA and the Terms of Use, this DPA prevails in respect of the Processing of Personal Data. In the event of a conflict between this DPA and the Standard Contractual Clauses incorporated under Section 10, the Standard Contractual Clauses prevail.
1. Definitions
1.1. "GDPR" means Regulation (EU) 2016/679.
1.2. "Data Protection Law" means the GDPR, the UK GDPR and the Data Protection Act 2018 where applicable, the Swiss Federal Act on Data Protection where applicable, the Law of Ukraine "On Personal Data Protection", and any other data protection or privacy law applicable to the Processing under this DPA.
1.3. "Customer Personal Data" means Personal Data contained in Customer Data that HAPP Processes on behalf of the Customer.
1.4. "Customer Data" means all data, content and configuration that the Customer or its End Users submit to, or that is generated through the Customer's use of, the Platform — including message content, call audio, transcripts, assistant prompts, knowledge base content, contact records and integration payloads.
1.5. "End User" means a natural person who interacts with the Customer's AI assistant through any channel enabled by the Platform (telephony, WhatsApp, Telegram, Instagram, Facebook Messenger, Viber, web chat, widget, or otherwise), referred to as "Subscriber" in the Terms of Use.
1.6. "Sub-processor" means any processor engaged by HAPP to Process Customer Personal Data.
1.7. "Restricted Transfer" means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland to a third country not covered by an adequacy decision.
1.8. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.9. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR.
2. Roles and scope
2.1. Roles. In respect of Customer Personal Data, the Customer acts as Controller and HAPP acts as Processor. Where the Customer itself acts as a processor for a third-party controller, HAPP acts as sub-processor and the Customer warrants that it has that controller's authority to enter into this DPA on its behalf and to give the instructions set out here.
2.2. HAPP as independent Controller. HAPP acts as an independent Controller in respect of the Personal Data of the Customer's own personnel and account holders that HAPP Processes to operate the commercial relationship — account registration and authentication data, billing records, support correspondence, platform telemetry and security logs. That Processing is governed by the Privacy Notice and not by this DPA.
2.3. Subject matter and duration. The subject matter of the Processing is the provision of the Platform and Services. The Processing continues for as long as the Customer's Account exists and for the deletion period set out in Section 12.
2.4. Details of Processing. The categories of Data Subjects, categories of Personal Data, nature and purposes of the Processing and retention periods are set out in Annex I.
3. Instructions
3.1. Documented instructions. HAPP shall Process Customer Personal Data only on documented instructions from the Customer. The Terms of Use, this DPA including its Annexes, and the Customer's configuration and use of the Platform through its Account constitute the Customer's complete documented instructions. HAPP shall not Process Customer Personal Data for any other purpose.
3.2. No sale, no advertising, no model training. HAPP shall not sell Customer Personal Data, shall not Process it for advertising or marketing purposes, and shall not use it to train, fine-tune or otherwise develop or improve any artificial intelligence or machine learning model, whether HAPP's own or a third party's. HAPP contracts with its artificial intelligence Sub-processors on terms that exclude the use of Customer Personal Data for the training or improvement of their models.
3.3. Service improvement. HAPP may Process aggregated or anonymised data derived from the Processing to operate, secure, monitor and improve the Platform, provided that such data is anonymised so that it can no longer be attributed to the Customer, any End User or any other identifiable natural person, and cannot be re-identified. Any provision of the Terms of Use purporting to grant HAPP broader rights over Customer Personal Data is superseded by this Section in respect of Customer Personal Data.
3.4. Unlawful instructions. HAPP shall inform the Customer without undue delay if, in HAPP's opinion, an instruction infringes Data Protection Law, and may suspend the affected instruction until it is confirmed, amended or withdrawn.
3.5. Customer responsibilities. The Customer is responsible for: (a) the lawfulness of the Processing it instructs, including establishing and maintaining a valid legal basis; (b) giving End Users all information required by Articles 13 and 14 GDPR, including that they are interacting with an artificial intelligence system and that calls and messages are recorded and transcribed; (c) obtaining any consent required under applicable telecommunications, call-recording or e-privacy law in the jurisdictions in which it deploys the Assistant; (d) the accuracy of Customer Data; and (e) not submitting special categories of Personal Data within the meaning of Article 9 GDPR, or Personal Data relating to criminal convictions and offences, unless the Parties have first agreed additional measures in writing.
4. Confidentiality and personnel
4.1. HAPP shall ensure that any person authorised to Process Customer Personal Data is bound by a written obligation of confidentiality that survives the end of their engagement, and Processes that data only as far as necessary to perform their duties.
4.2. Access to Customer Personal Data is limited to personnel who require it, on a role-based, least-privilege basis, and all such access is logged.
4.3. Personnel receive data protection and information security training appropriate to their role, at onboarding and at least annually thereafter.
5. Security
5.1. HAPP shall implement and maintain the technical and organisational measures set out in Annex II to ensure a level of security appropriate to the risk, taking Article 32 GDPR into account.
5.2. HAPP may update Annex II from time to time, provided no update materially reduces the overall level of security afforded to Customer Personal Data.
5.3. Security standards. HAPP operates an information security programme aligned to ISO/IEC 27001:2022 and monitored on a continuous-control basis. HAPP does not currently hold an ISO/IEC 27001 certificate or a SOC 2 report, and makes no representation of certified compliance with any standard except as stated in this Section. HAPP will publish notice when certification is obtained.
6. Sub-processors
6.1. General authorisation. The Customer grants HAPP general authorisation to engage Sub-processors. The current list is published at happ.tools/subprocessors and forms Annex III of this DPA as it stands from time to time.
6.2. Flow-down. HAPP shall impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor's performance.
6.3. Notice of changes. HAPP shall give at least 30 (thirty) days' notice of the intended addition or replacement of a Sub-processor by updating happ.tools/subprocessors. Customers may subscribe to email notice of changes at that page.
6.4. Objection. The Customer may object to a new Sub-processor on reasonable data protection grounds by written notice within the 30-day period. The Parties shall discuss the objection in good faith. If HAPP cannot provide the Services without the Sub-processor and cannot offer a commercially reasonable alternative, either Party may terminate the affected Services on written notice, and HAPP shall refund any prepaid fees covering the period after termination.
6.5. Artificial intelligence Sub-processors. The Customer acknowledges that the Services require the transmission of message text, call transcripts and assistant instructions to language model and speech providers, and that this transmission is an inherent and necessary part of the Services. Such providers are engaged on terms excluding the use of Customer Personal Data for model training, and on zero-retention or limited-retention terms, as recorded at happ.tools/subprocessors.
6.6. Integration Sub-processors. Telephony, messenger, CRM and booking providers receive Customer Personal Data only where the Customer connects the corresponding integration. Connecting an integration is the Customer's documented instruction to transmit the relevant data to that provider. Where the Customer does not connect it, no Customer Personal Data is transmitted to it.
7. Data subject rights
7.1. HAPP shall, to the extent the Customer cannot do so through the Platform, assist the Customer in responding to requests from Data Subjects exercising their rights under Chapter III GDPR.
7.2. The Platform enables the Customer to access, export, correct and delete Customer Personal Data relating to an End User without HAPP's involvement. The Customer shall use those functions in the first instance.
7.3. If HAPP receives a request directly from a Data Subject in respect of Customer Personal Data, HAPP shall not respond to it substantively, and shall forward it to the Customer without undue delay and in any event within 5 (five) business days, unless prohibited by law.
7.4. Assistance under this Section is provided at no charge, save where requests are manifestly excessive or repetitive, in which case HAPP may charge its reasonable documented costs on prior written notice.
8. Personal Data Breach
8.1. HAPP shall notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 (twenty-four) hours of becoming aware of it.
8.2. The notification shall include, to the extent then known: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information cannot be provided at once, HAPP shall provide it in phases without further undue delay.
8.3. HAPP shall not notify a Supervisory Authority or Data Subject on the Customer's behalf, or identify the Customer in such a notification, without the Customer's prior written instruction, unless required by law.
8.4. HAPP shall document all Personal Data Breaches and take reasonable commercial steps to remediate them.
9. Audit and assistance
9.1. HAPP shall make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, Annex II, and any third-party audit reports or certifications HAPP holds.
9.2. The Customer may audit HAPP's compliance no more than once in any 12-month period, and additionally following a Personal Data Breach affecting Customer Personal Data or on the documented instruction of a Supervisory Authority. The Customer shall give at least 30 days' prior written notice, audit during business hours, avoid unreasonable disruption and bear its own costs. HAPP may require the auditor to sign a non-disclosure agreement and may withhold information relating to other customers, HAPP's pricing, or matters protected by legal privilege.
9.3. HAPP shall reasonably assist with data protection impact assessments and prior consultation with a Supervisory Authority, where these relate to the Processing under this DPA and the Customer cannot reasonably obtain the information itself.
10. International transfers
10.1. Storage location. Customer Personal Data is stored at rest in the European Union (Frankfurt, eu-central-1). HAPP shall not change the storage region without at least 60 days' prior notice.
10.2. HAPP as a Ukraine-established Processor. HAPP is established in Ukraine, which is not the subject of an adequacy decision under Article 45 GDPR. HAPP's access to Customer Personal Data from Ukraine is therefore a Restricted Transfer, and the SCCs incorporated below apply to it.
10.3. Onward transfers. Certain Sub-processors Process Customer Personal Data outside the EEA, principally in the United States, as recorded at happ.tools/subprocessors. HAPP has put in place the transfer mechanism identified there for each.
10.4. Incorporation of the SCCs. For each Restricted Transfer from the Customer to HAPP, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module. Where the Customer is a Controller, Module Two (Controller to Processor) applies. Where the Customer is itself a processor acting for a third-party controller, Module Three (Processor to Processor) applies.
- Parties. The data exporter is the Customer; the data importer is HAPP. The Parties section above populates Annex I.A of the SCCs.
- Optional clauses. Clause 7 (docking clause) applies. In Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in Section 6.3. In Clause 11(a), the optional independent dispute resolution paragraph does not apply. In Clause 17, the SCCs are governed by the law of Ireland. In Clause 18(b), the courts of Ireland are the chosen forum.
- Liability. In Clause 12, the limitations of liability in the Terms of Use apply between the Parties, save that nothing limits liability towards Data Subjects under Clause 12(a) or any liability that cannot be limited under Data Protection Law.
- Annexes. Annex I.A, I.B and I.C of the SCCs are populated by Annex I of this DPA; Annex II of the SCCs by Annex II; and the Clause 9 list of Sub-processors by happ.tools/subprocessors.
- Competent Supervisory Authority. For Annex I.C, the competent Supervisory Authority is that of the Member State in which the Customer is established, or, where the Customer is not established in the EEA and has appointed an Article 27 representative, that of the Member State in which the representative is established.
10.5. UK and Switzerland. Where the transfer is subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued under s.119A of the Data Protection Act 2018, which is incorporated by reference; references to the courts and supervisory authority are read as references to the courts of England and Wales and the Information Commissioner's Office. Where the transfer is subject to the Swiss Federal Act on Data Protection, references to the GDPR are read as references to that Act and the competent authority is the Federal Data Protection and Information Commissioner.
10.6. Government access requests. HAPP shall, unless legally prohibited: notify the Customer of any legally binding request by a public authority for disclosure of Customer Personal Data; challenge requests that are unlawful under Data Protection Law or applicable law; and disclose only the minimum necessary. HAPP documents its assessment of such requests and makes the documentation available on request. As at the effective date of this DPA, HAPP has received no such request and no order prohibiting it from disclosing that fact.
10.7. Transfer impact assessment. HAPP shall, on request, provide the information needed to carry out a transfer impact assessment in respect of the transfers in Sections 10.2 and 10.3, including the legal regime applicable to HAPP and the supplementary measures in Annex II.
11. Ukrainian law
11.1. HAPP Processes Customer Personal Data in accordance with the Law of Ukraine "On Personal Data Protection" in addition to the GDPR. Where the two impose different requirements, HAPP applies the more protective.
12. Deletion and return
12.1. On termination of the Customer's Account, or at any earlier time on the Customer's written request, HAPP shall, at the Customer's election, delete or return Customer Personal Data and delete existing copies.
12.2. Deletion from active production systems completes within 30 (thirty) days of the Customer's election or, absent an election, of termination. Encrypted backups are overwritten on a rolling cycle and fully purged within 6 (six) months of deletion from production. Vector embeddings derived from Customer Personal Data are purged on the same cascade as the source records.
12.3. HAPP may retain Customer Personal Data to the extent and for as long as required by applicable law, keeping it confidential, isolated from active Processing, and Processed only for the purpose requiring its retention.
12.4. HAPP shall certify deletion in writing on request.
13. Liability, term and general
13.1. Liability. The limitations and exclusions of liability in the Terms of Use apply to this DPA, save that they do not limit either Party's liability to Data Subjects, or any liability that cannot lawfully be limited.
13.2. Term. This DPA takes effect when the Customer accepts the Terms of Use and continues for as long as HAPP Processes Customer Personal Data.
13.3. Amendment. HAPP may amend this DPA where required to comply with Data Protection Law, a decision of a competent authority, or a change to the SCCs, on 30 days' notice published on this page. Any other amendment materially reducing the Customer's rights requires 30 days' notice by email, and the Customer may terminate before it takes effect.
13.4. Severability. If any provision of this DPA is held invalid, the remainder continues in effect.
13.5. Governing law. This DPA is governed by the law stated in the Terms of Use, save that the SCCs are governed as stated in Section 10.4 and that nothing displaces the mandatory application of Data Protection Law.
Annex I — Description of the Processing
Populates Annex I.A, I.B and I.C of the Standard Contractual Clauses.
A. Parties
Data exporter (Controller): the Customer. Activities relevant to the transfer: operating a business that uses the HAPP Assistant to conduct automated voice and text communications with its own customers and prospects.
Data importer (Processor): HAPP, as identified in the Parties section above. Activities relevant to the transfer: providing and operating the HAPP Assistant platform, including message and call handling, transcription, artificial intelligence response generation, storage, analytics and technical support.
B. Description of the transfer
Categories of Data Subjects.
- End Users: natural persons who call, message or otherwise interact with the Customer's assistant.
- The Customer's personnel: employees, contractors and agents who use the Platform or are named in Customer Data.
- Third parties named by End Users in the course of a conversation.
Categories of Personal Data.
| Channel / activity | Personal Data |
|---|---|
| Voice calls (telephony) | Phone number, call metadata (time, duration, direction, outcome), call audio, transcript, AI-generated summary and analysis |
| Name, phone number, profile avatar, message content, media, timestamps | |
| Telegram | Name, username, phone number where shared, avatar, message text, media files |
| Instagram and Facebook Messenger | Name, avatar, message content, links to shared stories or reels |
| Viber | Name, phone number, message content, media |
| Web chat and widget | Session identifier, IP address, message content, any contact details volunteered |
| Assistant configuration and knowledge base | Any Personal Data the Customer places in prompts, knowledge base documents or tool definitions |
| CRM, booking and export integrations | Contact records, lead, booking and order data as configured by the Customer |
| Transactional notifications | Email address and phone number, where the Customer configures notifications |
| Derived data | Vector embeddings of conversation content, treated as Personal Data; conversation labels, scores and analysis output |
Special categories of Personal Data. None instructed. Section 3.5(e) prohibits the Customer from submitting special categories without a prior written agreement on additional measures. HAPP acknowledges that free-text conversations may incidentally contain such data; where this occurs HAPP applies the measures in Annex II without differentiation and Processes it for no additional purpose. Where the Customer has enabled HAPP Labs computer vision features, the Processing may include video streams and vehicle registration plates; any biometric identification use case requires a separate written agreement.
Frequency of the transfer. Continuous, on a transaction basis, for as long as the Account exists.
Nature and purpose. Collection, recording, storage, transcription, translation, structuring, retrieval, transmission to artificial intelligence Sub-processors for response generation and speech synthesis, transmission to integration Sub-processors the Customer has connected, display in the Customer's dashboard, analysis and reporting, deletion — all to provide the Services the Customer instructs.
Retention period.
| Data | Retention |
|---|---|
| Call audio and recordings | Until the Customer deletes the call record, integration, company or account |
| Media files received via messengers | Until the Customer deletes the conversation, integration, company or account |
| Transcripts, message content, conversation records | Until the Customer deletes the conversation, integration, company or account |
| Vector embeddings | Purged on the same cascade as the source record |
| Platform and security logs | 90 days |
| Aggregated, non-identifying metrics | 12 months |
| Backups | Overwritten on a rolling cycle; fully purged within 6 months |
C. Competent supervisory authority
As determined under Section 10.4 of this DPA.
Annex II — Technical and organisational measures
Populates Annex II of the Standard Contractual Clauses.
1. Pseudonymisation and encryption
- Encryption in transit: TLS 1.3 for all API, web and integration traffic; SRTP/TLS for voice media.
- Encryption at rest: AES-256-GCM for databases, object storage and backups.
- Secrets held in a managed secret store and injected at runtime, never in source code or configuration.
- Vector embeddings are not human-readable and are held under the same access controls and deletion cascade as the source records.
- Telemetry and logs are pseudonymised; message and call content is excluded from application logs.
2. Confidentiality, integrity, availability and resilience
- Network segmentation between public-facing services, application services and data stores; data stores are reachable only from the application tier and an allowlist of administrative addresses.
- Role-based access control with least privilege; administrative access requires multi-factor authentication.
- All access to production data is logged; logs are retained for 90 days.
- Managed PostgreSQL with automated backups and point-in-time recovery.
- Infrastructure and application monitoring with alerting; alerts route to a monitored channel.
- Deletion of stored files and derived vectors on the same cascade as the source record.
- Edge protection: DDoS mitigation and TLS termination at the CDN layer.
3. Restoration of availability and access
- Automated daily encrypted backups; point-in-time recovery for the primary database.
- Documented restore procedure, tested at least annually.
- Target recovery point objective 24 hours; target recovery time objective 8 hours.
4. Testing and evaluation of effectiveness
- Continuous compliance monitoring across infrastructure and endpoint controls.
- Dependency and container vulnerability scanning in the CI pipeline, triaged by severity.
- Code review required on every change to production; automated test suite gating deployment.
- Annual review of this Annex and of the underlying risk assessment.
5. Identification, authentication and access
- Platform authentication by password with strength enforcement, or OAuth 2.0 via Google or Apple; multi-factor authentication available and enforced for administrative roles.
- Session management with server-side invalidation; API access by scoped, revocable tokens.
- Joiner-mover-leaver process for internal accounts; access revoked on the day an engagement ends.
6. Data minimisation and quality
- Only the categories in Annex I.B are collected; call audio and messenger media are discarded within 24 hours.
- The Customer controls which channels and integrations are active and can delete any record from the dashboard.
7. Accountability and organisational measures
- Written internal information security and data protection policies, acknowledged by all personnel.
- Confidentiality agreements with all personnel and contractors.
- Security and data protection training at onboarding and annually.
- Record of Processing Activities maintained under Article 30 GDPR.
- Documented Personal Data Breach response procedure with the timelines in Section 8.
- Sub-processor due diligence before engagement and on material change.
8. Supplementary measures for third-country transfers
- Data at rest remains in the European Union; access from Ukraine is remote, logged, over encrypted channels and limited to authorised personnel.
- Artificial intelligence Sub-processors are engaged on terms excluding model training, and on zero-retention terms where offered; otherwise retention is limited to the provider's abuse-monitoring period.
- Only the data necessary for the specific request is transmitted to artificial intelligence Sub-processors; call audio and media files are not transmitted to language model providers.
- Documented policy of challenging unlawful government access requests and notifying the Customer as set out in Section 10.6.
9. Measures required of Sub-processors
Each Sub-processor is contractually required to maintain measures no less protective than those in this Annex, and to notify HAPP of any Personal Data Breach without undue delay.
Annex III — Sub-processors
The current list of Sub-processors, naming each provider, the service it performs, the Personal Data it Processes, its processing location and the transfer mechanism relied on, is published at happ.tools/subprocessors and forms part of this DPA. That page is the authoritative list and prevails over any copy.