Hafych

Back to Terms and Privacy · Writer Studio product page

PART IV

BUSINESS-TO-BUSINESS DATA PROCESSING ADDENDUM

Standing addendum; applies automatically only where the conditions below are met

This DPA applies only between HAFYCH and a Business Customer, and only to the extent HAFYCH processes Customer Personal Data on documented instructions as a processor. It does not apply to Consumers, local data HAFYCH never receives, or independent processing by an app store or user-selected cloud provider.

1. Parties, Incorporation, and Precedence

This Data Processing Addendum (“DPA”) is between Nazarii Hafych, acting under the HAFYCH brand (“HAFYCH” or “Processor”), and the Business User that is a controller or processor and that obtains an App or submits Customer Personal Data for processing (“Customer”). It forms part of the Terms or applicable signed agreement.

If there is a conflict concerning Processor obligations for Customer Personal Data, this DPA controls over the general Terms. A separately signed data-processing amendment controls over this standing DPA to the extent of an express conflict.

2. Definitions

“Applicable Data Protection Law” means law governing the relevant processing, including the GDPR or UK GDPR where applicable. “Customer Personal Data” means personal data processed by HAFYCH on Customer’s documented instructions in connection with an App. “Process,” “Controller,” “Processor,” “Subprocessor,” “Personal Data Breach,” and “Data Subject” have the meanings given by Applicable Data Protection Law.

3. Roles and Instructions

Customer is controller of Customer Personal Data, or a processor authorized by its controller. HAFYCH is a processor only for processing that Customer instructs and HAFYCH accepts. HAFYCH remains an independent controller for its own support administration, security, legal claims, sanctions compliance, tax, business records, and platform relationship where it determines the purposes and means.

Customer instructs HAFYCH to process Customer Personal Data only as necessary to: provide and support the applicable App or entitlement; respond to Customer requests; protect security and prevent abuse; comply with documented lawful instructions; and perform the agreement. The agreement, App settings, support requests, and written instructions constitute Customer’s documented instructions.

HAFYCH will inform Customer if, in HAFYCH’s reasonable opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice. HAFYCH may suspend the affected processing until the parties resolve the issue and may terminate the affected service if an unlawful instruction is not withdrawn.

4. Processing Details

Required detail Standing description
Subject matter Limited processing necessary for subscription or entitlement administration, support, security, legal compliance, and any App feature through which Customer expressly sends personal data to HAFYCH.
Duration For the agreement term and the retention periods in the Privacy Policy, unless Customer lawfully instructs earlier deletion or law requires longer retention.
Nature of processing Receiving, accessing, organizing, reviewing, transmitting to approved Subprocessors, troubleshooting, securing, restricting, deleting, and returning data as necessary for the stated purposes.
Purpose Provide, support, secure, administer, and enforce the App and Customer relationship.
Data subjects Customer personnel, administrators, contractors, end users, customers, or other persons whose data Customer lawfully supplies.
Personal-data categories Contact details, organization details, purchase and entitlement data, App User IDs, technical and diagnostic information, support correspondence and attachments, and data Customer expressly provides for support.
Special categories Not intentionally requested or approved. Customer must not provide special-category, criminal-offence, child, medical, payment-card, classified, or similarly high-risk data unless HAFYCH expressly agrees in writing and the parties document lawful safeguards.

5. Customer Obligations

Customer represents and warrants that it:

6. Processor Obligations

HAFYCH will, to the extent required by Applicable Data Protection Law and proportionate to the processing:

7. Security Measures

The parties acknowledge the current architecture: HAFYCH has no ordinary User Content backend and no employees or contractors. Measures applicable to processing HAFYCH controls include:

These measures are not a certification, penetration-test result, service level, or guarantee of absolute security. Customer remains responsible for its devices, cloud providers, users, credentials, and configuration.

8. Subprocessors and Independent Providers

Customer generally authorizes the Subprocessors below for the limited functions stated. HAFYCH may replace or add a Subprocessor where reasonably necessary. Where required by law and reasonably practicable, HAFYCH will provide notice through the Website, App, or Customer contact before a material new Subprocessor begins processing Customer Personal Data. Customer’s sole remedy for a reasonable unresolved objection is to stop the affected feature or terminate the affected paid service, subject to mandatory law and accrued payment obligations.

Provider Service and data Role under this DPA
RevenueCat, Inc. Subscription management, App User IDs, purchase history, transaction and entitlement status, subscription analytics Subprocessor / service provider where processing is on HAFYCH’s behalf
Google LLC and relevant affiliates Email infrastructure used for support and legal communications; limited message and attachment data Subprocessor / service provider for HAFYCH-controlled email processing

Google Play, Google Drive, Apple file services, GitHub Pages, device manufacturers, and operating systems may act as independent controllers, user-selected providers, or separate service providers rather than HAFYCH Subprocessors for particular processing. This DPA does not make HAFYCH responsible for processing independently determined by those providers.

9. International Transfers

Where Customer Personal Data is transferred from the EEA, United Kingdom, or another restricted jurisdiction to a country without an adequacy decision and HAFYCH is responsible for the transfer, the parties will rely on applicable standard contractual clauses, a United Kingdom addendum, provider data-processing terms, or another lawful mechanism. The relevant controller-to-processor module applies where the GDPR Standard Contractual Clauses are required. This DPA incorporates the applicable mechanism by reference only to the extent legally valid and necessary.

Customer authorizes HAFYCH to enter into transfer terms with Subprocessors on Customer’s behalf where permitted. Customer will provide information reasonably necessary for a transfer assessment and will not instruct an unlawful transfer.

10. Audits and Information

HAFYCH may satisfy audit obligations first through current documentation, provider certifications, questionnaires, and written responses. If Applicable Data Protection Law requires a further audit, Customer may conduct one audit in any twelve-month period on at least 30 days’ written notice, during normal hours, through an independent qualified auditor bound by confidentiality, and without accessing another person’s data, source code, vulnerabilities, personal devices, or legally privileged material.

Customer bears its audit costs and HAFYCH’s reasonable out-of-scope assistance costs unless the audit identifies a material breach by HAFYCH. An urgent regulator-required or breach-related audit may occur on shorter notice where legally necessary and proportionate.

11. Personal Data Breaches

A notice from HAFYCH will describe, to the extent known and legally permitted, the nature of the incident, affected data, likely consequences, measures taken or proposed, and a contact point. Notice is not an admission of fault or liability. Customer is responsible for determining whether to notify a supervisory authority, Data Subject, customer, employee, or other person, except where law directly imposes that obligation on HAFYCH.

12. Deletion, Return, and Survival

At the end of processor services, HAFYCH will delete or return Customer Personal Data that HAFYCH controls, at Customer’s choice and where technically practicable. HAFYCH may retain data required for legal claims, security, fraud prevention, tax, accounting, platform, or legal obligations, with access restricted to those purposes. Local data, user-selected cloud data, app-store data, and provider records outside HAFYCH’s control must be deleted through the relevant device or provider.

Confidentiality, security, deletion, audit, transfer, liability, and other provisions intended to survive continue for retained Customer Personal Data.

13. Liability and Indemnity

The liability allocation, exclusions, caps, and Business User indemnity in the Terms apply to this DPA, except to the extent Applicable Data Protection Law prohibits that result. There is no double recovery for the same loss. Customer remains responsible for unlawful instructions, missing notices or legal bases, and data or use cases it introduces without HAFYCH’s written approval.