Data Processing Agreement
Last updated: 26 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Hespera AI, LLC ("Hespera") and the client ("Client") and applies where Hespera processes personal data on the Client's behalf.
1. Definitions and precedence
1.1. "GDPR" means Regulation (EU) 2016/679; "UK GDPR" means that Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland. "Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in Article 4 GDPR.
1.2. In the event of conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data. The Standard Contractual Clauses prevail over this DPA.
2. Roles of the parties
2.1. Where Hespera is a processor. In respect of Client Data — the content the Client uploads or generates, and the personal data of the Client's own customers, contacts and staff processed through the Service — the Client is the controller and Hespera is the processor.
2.2. Where Hespera is a controller. In respect of account data — identity and contact details of the Client's users, authentication events, subscription and payment records, support correspondence, and technical logs generated by the operation of the Service — Hespera is a controller in its own right, and the Privacy Policy applies. This DPA does not govern that processing.
2.3. The Client warrants that it has a lawful basis for the processing it instructs, and that it has provided any notice and obtained any consent required from its own data subjects.
3. Instructions
3.1. Hespera processes personal data only on the Client's documented instructions, which comprise this DPA, the Terms of Service, and the Client's use of the functions of the Service.
3.2. Hespera notifies the Client if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend the affected processing until the instruction is withdrawn or confirmed.
3.3. Where Hespera is required by Union or Member State law to process personal data otherwise than on the Client's instructions, it informs the Client of that requirement before processing, unless that law prohibits such information on important grounds of public interest.
4. Confidentiality
Hespera ensures that persons authorised to process personal data are bound by an obligation of confidentiality that survives the end of their engagement, and that access is limited to those who require it to perform their duties.
5. Security
5.1. Hespera implements the technical and organisational measures set out in Annex 2, which are appropriate to the risk within the meaning of Article 32 GDPR.
5.2. Hespera may amend those measures provided the level of protection is not reduced. The current version is published with this DPA.
6. Sub-processors
6.1. The Client gives general authorisation for the engagement of sub-processors. The current list is published at hespera.ai/subprocessors and forms Annex 3.
6.2. Hespera gives at least thirty (30) days' notice before a new sub-processor begins processing, and the Client may object on reasonable data-protection grounds within that period. Where the objection cannot be resolved, the Client may terminate the affected part of the Service and receive a refund of Fees paid for the unused remainder of the Billing Period. Where a sub-processor must be replaced urgently because it has ceased to operate or has become a security risk, notice is given as soon as reasonably practicable instead, and the Client's right to object runs from that notice.
6.3. Hespera imposes on each sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Client for the performance of each sub-processor's obligations.
7. Data subject rights
7.1. Taking into account the nature of the processing, Hespera assists the Client by appropriate technical and organisational measures, insofar as possible, in fulfilling the Client's obligation to respond to requests to exercise data subject rights.
7.2. The Service enables the Client to access, correct and erase personal data within its Account, and to download its catalogue and projects. Where a request cannot be satisfied by those means, including a request for a copy of data in a portable form, Hespera assists on request.
7.3. Where a data subject addresses a request directly to Hespera in respect of Client Data, Hespera does not respond to it substantively but forwards it to the Client without undue delay.
8. Personal data breach
8.1. Hespera notifies the Client without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Client Data.
8.2. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the information is not available at once, it is provided in phases without further undue delay.
8.3. Hespera does not notify a supervisory authority or data subject on the Client's behalf unless required by law or instructed by the Client in writing.
9. Data protection impact assessments
Hespera provides the Client, on request and taking into account the nature of processing and the information available to it, with reasonable assistance in carrying out data protection impact assessments and prior consultations under Articles 35 and 36 GDPR.
10. Deletion and return
10.1. On termination of the Terms of Service the Client may export Client Data through the Service.
10.2. Hespera deletes Client Data within thirty (30) days of termination, save where Union or Member State law requires storage for longer. Account deletion requested within the Service is subject to the same period, during which the Client may reverse it.
10.3. Copies present in routine backups are overwritten as the backup cycle rotates, and in any event within thirty (30) days, and remain protected by the measures in Annex 2 until then.
11. Audit
11.1. Hespera makes available to the Client the information necessary to demonstrate compliance with Article 28 GDPR.
11.2. The Client may audit that compliance no more than once in any twelve-month period, on thirty (30) days' written notice, during business hours, subject to confidentiality, without access to the data of other clients, and at its own cost. Hespera may satisfy an audit request by providing an independent third-party report where one is available.
11.3. An additional audit may be conducted where required by a supervisory authority or following a personal data breach affecting the Client.
12. International transfers
12.1. Where Hespera or a sub-processor processes personal data outside the European Economic Area, the transfer is made pursuant to the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914, which are incorporated by reference.
12.2. For the purposes of those Clauses: (a) Module Two applies where the Client is a controller, and Module Three where the Client is itself a processor; (b) the Client is the data exporter and Hespera the data importer; (c) the optional docking clause in Clause 7 applies; (d) in Clause 9, Option 2 (general written authorisation) applies, with the notice period stated in Article 6.2; (e) the optional wording in Clause 11 does not apply; (f) in Clause 17, Option 1 applies and the Clauses are governed by the law of Ireland; (g) in Clause 18, disputes are resolved by the courts of Ireland; and (h) Annexes I, II and III of the Clauses are populated by Annexes 1, 2 and 3 of this DPA.
12.3. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the Information Commissioner applies to the Clauses. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Federal Data Protection and Information Commissioner.
13. Liability and term
13.1. This DPA takes effect when the Client first uses the Service and remains in force for as long as Hespera processes personal data on the Client's behalf.
13.2. The limitations of liability in the Terms of Service apply to this DPA, save that nothing limits liability which cannot be limited under applicable data protection law.
Annex 1 — Details of the processing
Subject matter. Provision of the Service described in the Terms of Service.
Duration. The term of the Terms of Service, plus the deletion period in Article 10.
Nature and purpose. Hosting, storage, transmission, generation, transformation and display of content; operation of catalogue, storefront, orders, messaging and analytics functions at the Client's direction.
Categories of data subjects. The Client's users and staff; the Client's customers and prospective customers; individuals appearing in or identifiable from content the Client uploads.
Categories of personal data. Identity and contact details; account and authentication data; order, payment and delivery data; correspondence and message content; images, video and audio which may contain likenesses and voices; usage and device data.
Special categories. None are required by the Service. The Client is responsible for any special category data it chooses to submit, and instructs Hespera to process it on the same terms.
Annex 2 — Technical and organisational measures
Every measure listed here is implemented. Measures that are planned but not yet in place are not listed.
Separation of clients. Isolation between clients is enforced by the database itself and not by application code alone. The identity of the client is established server-side from a signed context and is never taken from data supplied by the browser.
Access control. Access follows the principle of least privilege and is granted by role. Administrative access by Hespera staff is separated from client access, holds its own credentials, and cannot be exercised with a client's credentials or a client's with a staff member's.
Authentication. Two-factor authentication is available to clients and mandatory for staff accounts with administrative access.
Encryption. Personal data is encrypted in transit. The database and the media store encrypt stored data at rest. Credentials for third-party services stored on behalf of a client are, in addition, encrypted using a current industry-standard algorithm, with the key held outside the database.
Logging and accountability. Administrative actions by staff, including refused attempts, are written to an audit record that cannot be altered after the fact. Requests can be traced across services for the purpose of investigating incidents.
Deletion. Account deletion is reversible for thirty (30) days and is then carried out irreversibly. Deleted content passes through a recoverable state before permanent removal.
Data location. The database, the application server and the media store are located in the European Economic Area. Onward transfers are limited to the sub-processors listed in Annex 3.
Availability. The database is backed up by the hosting provider at least once a day, and backups are retained for no more than thirty (30) days.
Annex 3 — Sub-processors
The list published at hespera.ai/subprocessors, as amended from time to time in accordance with Article 6.