Hired Hands legal

Data Processing Agreement

Effective July 4, 2026

This Data Processing Agreement (“DPA”) describes how Hired Hands processes personal data on your organization's behalf — as the data processor described in our Privacy Policy — when you use the product to run AI agents against your own knowledge and your customers' conversations.

Pending legal review
This page is a working template that reflects how the product actually processes data today. It is not yet a counter-signed legal agreement. If your organization requires an executed DPA (including Standard Contractual Clauses for EU/UK transfers), email legal@hiredhands.dev and we will issue one for signature.

1. Roles

For personal data your organization submits to configure and operate your agents — and personal data your own end users share in conversations with your agents — you are the data controller and Hired Hands is the data processor. This DPA applies only to that processing. For your own account and billing data, Hired Hands acts as an independent controller, as described in the Privacy Policy.

2. Subject matter, nature, and duration

AspectDetail
Subject matterHosting and running AI agents (chat, content drafting, monitoring) on data you provide
DurationFor as long as your subscription is active, plus any retention period you configure
Nature of processingStorage, chunking/embedding for retrieval, generation of AI replies, notification delivery
PurposeOperating the agents you configure — no other use
Categories of data subjectsYour team members, and your own customers/website visitors who message your agents
Categories of personal dataNames, emails, and message content submitted to an agent; business knowledge you upload (policies, pricing, FAQs) may itself contain personal data if you include it

3. Processor obligations

  • Process personal data only on your documented instructions — configuring and running the agents you set up — and never for our own purposes or to train third-party models.
  • Ensure anyone we allow to access the data (employees, contractors) is bound by confidentiality.
  • Implement the technical and organizational security measures described in Section 5.
  • Assist you in responding to data subject requests (Section 6) and in meeting your own security, breach-notification, and impact-assessment obligations.
  • Delete or return personal data at the end of the relationship, per your data retention and deletion controls(in-app: Settings → Data & privacy), except where law requires retention (e.g., invoices).
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

We use the sub-processors listed on our Subprocessors page (Supabase, Vercel, OpenAI, Stripe, Resend, plus any integration you personally connect), which mirrors the table in our Privacy Policy. Each is bound by a data processing agreement no less protective than this one. We will update that page when a sub-processor changes and, for material changes, notify account owners by email.

5. Security measures

  • Row-level security enforcing tenant isolation — one organization’s data is never queryable by another’s session.
  • Service-role-only storage for secrets (connection credentials, API keys) — never returned by any API after they’re saved.
  • Encryption in transit (TLS) and at rest.
  • An immutable audit log of privileged account and data actions.
  • Role-based access control limiting who on your team can export or delete data.

Full detail on our Security page.

6. Assistance with data subject rights

Your Data & privacy settings(in-app: Settings → Data & privacy) let you export a complete, machine-readable copy of your organization’s data on demand, and delete conversation transcripts or erase the organization entirely — supporting access, portability, and erasure requests from your own customers without waiting on us. For anything those controls don’t cover, email privacy@hiredhands.dev.

7. Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting your organization’s data, with enough information for you to meet your own notification obligations.

8. International transfers

Our infrastructure runs in the United States (AWS us-east-1 via Supabase; Vercel’s global edge for static assets only — data processing stays in-region). Where a transfer of EU/UK personal data requires a transfer mechanism, we will execute the Standard Contractual Clauses on request — contact legal@hiredhands.dev.

9. Liability & precedence

This DPA supplements the Terms of Service. Liability for processing under this DPA is governed by the limitations in the Terms. If a signed, counter-party-specific DPA is executed, its terms control over this page.