Back to Terms and Privacy · Writer Studio product page
PART IV
Standing addendum; applies automatically only where the conditions below are met
This DPA applies only between HAFYCH and a Business Customer, and only to the extent HAFYCH processes Customer Personal Data on documented instructions as a processor. It does not apply to Consumers, local data HAFYCH never receives, or independent processing by an app store or user-selected cloud provider.
This Data Processing Addendum (“DPA”) is between Nazarii Hafych, acting under the HAFYCH brand (“HAFYCH” or “Processor”), and the Business User that is a controller or processor and that obtains an App or submits Customer Personal Data for processing (“Customer”). It forms part of the Terms or applicable signed agreement.
If there is a conflict concerning Processor obligations for Customer Personal Data, this DPA controls over the general Terms. A separately signed data-processing amendment controls over this standing DPA to the extent of an express conflict.
“Applicable Data Protection Law” means law governing the relevant processing, including the GDPR or UK GDPR where applicable. “Customer Personal Data” means personal data processed by HAFYCH on Customer’s documented instructions in connection with an App. “Process,” “Controller,” “Processor,” “Subprocessor,” “Personal Data Breach,” and “Data Subject” have the meanings given by Applicable Data Protection Law.
Customer is controller of Customer Personal Data, or a processor authorized by its controller. HAFYCH is a processor only for processing that Customer instructs and HAFYCH accepts. HAFYCH remains an independent controller for its own support administration, security, legal claims, sanctions compliance, tax, business records, and platform relationship where it determines the purposes and means.
Customer instructs HAFYCH to process Customer Personal Data only as necessary to: provide and support the applicable App or entitlement; respond to Customer requests; protect security and prevent abuse; comply with documented lawful instructions; and perform the agreement. The agreement, App settings, support requests, and written instructions constitute Customer’s documented instructions.
HAFYCH will inform Customer if, in HAFYCH’s reasonable opinion, an instruction infringes Applicable Data Protection Law, unless law prohibits notice. HAFYCH may suspend the affected processing until the parties resolve the issue and may terminate the affected service if an unlawful instruction is not withdrawn.
| Required detail | Standing description |
|---|---|
| Subject matter | Limited processing necessary for subscription or entitlement administration, support, security, legal compliance, and any App feature through which Customer expressly sends personal data to HAFYCH. |
| Duration | For the agreement term and the retention periods in the Privacy Policy, unless Customer lawfully instructs earlier deletion or law requires longer retention. |
| Nature of processing | Receiving, accessing, organizing, reviewing, transmitting to approved Subprocessors, troubleshooting, securing, restricting, deleting, and returning data as necessary for the stated purposes. |
| Purpose | Provide, support, secure, administer, and enforce the App and Customer relationship. |
| Data subjects | Customer personnel, administrators, contractors, end users, customers, or other persons whose data Customer lawfully supplies. |
| Personal-data categories | Contact details, organization details, purchase and entitlement data, App User IDs, technical and diagnostic information, support correspondence and attachments, and data Customer expressly provides for support. |
| Special categories | Not intentionally requested or approved. Customer must not provide special-category, criminal-offence, child, medical, payment-card, classified, or similarly high-risk data unless HAFYCH expressly agrees in writing and the parties document lawful safeguards. |
Customer represents and warrants that it:
has authority to give instructions and has provided all required notices;
has a valid legal basis for collection, disclosure, and processing;
will not instruct HAFYCH to violate law, a platform rule, or another person’s rights;
will minimize data and avoid sending unnecessary sensitive information;
will maintain appropriate security, access control, device management, and backups;
will respond to Data Subjects and regulators as controller and provide HAFYCH with accurate information needed for assistance; and
will compensate HAFYCH for reasonable out-of-scope assistance or unlawful instructions, subject to the agreement and mandatory law.
HAFYCH will, to the extent required by Applicable Data Protection Law and proportionate to the processing:
process Customer Personal Data only on documented instructions, unless law requires processing and permits notice;
ensure that any person authorized to process Customer Personal Data is bound by confidentiality;
implement technical and organizational measures appropriate to risk and the limited architecture;
engage Subprocessors under written data-protection obligations materially protective of the relevant data;
provide reasonable assistance with Data Subject requests, security, breach response, impact assessments, and regulator consultations, taking account of the nature of processing and information available;
notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data processed by HAFYCH as processor;
delete or return Customer Personal Data at the end of processing at Customer’s choice where technically possible, unless law requires retention; and
make information reasonably necessary to demonstrate compliance available through documentation, questionnaires, or an audit under Section 10.
The parties acknowledge the current architecture: HAFYCH has no ordinary User Content backend and no employees or contractors. Measures applicable to processing HAFYCH controls include:
minimizing receipt of Customer Personal Data and encouraging redaction of unnecessary content;
limiting access to Nazarii Hafych and protecting developer, email, store, source-code, and RevenueCat accounts with available account-security controls;
using provider-supported encrypted transport where data is transmitted to RevenueCat, Google, Apple, GitHub, or email infrastructure;
maintaining platform and dependency updates reasonably appropriate to the App;
separating local User Content from HAFYCH systems by not operating a HAFYCH content-storage backend;
reviewing suspected security incidents and preserving information needed for response and legal compliance;
deleting support data when no longer required under the Privacy Policy; and
reviewing Subprocessor and platform terms relevant to the service.
These measures are not a certification, penetration-test result, service level, or guarantee of absolute security. Customer remains responsible for its devices, cloud providers, users, credentials, and configuration.
Customer generally authorizes the Subprocessors below for the limited functions stated. HAFYCH may replace or add a Subprocessor where reasonably necessary. Where required by law and reasonably practicable, HAFYCH will provide notice through the Website, App, or Customer contact before a material new Subprocessor begins processing Customer Personal Data. Customer’s sole remedy for a reasonable unresolved objection is to stop the affected feature or terminate the affected paid service, subject to mandatory law and accrued payment obligations.
| Provider | Service and data | Role under this DPA |
|---|---|---|
| RevenueCat, Inc. | Subscription management, App User IDs, purchase history, transaction and entitlement status, subscription analytics | Subprocessor / service provider where processing is on HAFYCH’s behalf |
| Google LLC and relevant affiliates | Email infrastructure used for support and legal communications; limited message and attachment data | Subprocessor / service provider for HAFYCH-controlled email processing |
Google Play, Google Drive, Apple file services, GitHub Pages, device manufacturers, and operating systems may act as independent controllers, user-selected providers, or separate service providers rather than HAFYCH Subprocessors for particular processing. This DPA does not make HAFYCH responsible for processing independently determined by those providers.
Where Customer Personal Data is transferred from the EEA, United Kingdom, or another restricted jurisdiction to a country without an adequacy decision and HAFYCH is responsible for the transfer, the parties will rely on applicable standard contractual clauses, a United Kingdom addendum, provider data-processing terms, or another lawful mechanism. The relevant controller-to-processor module applies where the GDPR Standard Contractual Clauses are required. This DPA incorporates the applicable mechanism by reference only to the extent legally valid and necessary.
Customer authorizes HAFYCH to enter into transfer terms with Subprocessors on Customer’s behalf where permitted. Customer will provide information reasonably necessary for a transfer assessment and will not instruct an unlawful transfer.
HAFYCH may satisfy audit obligations first through current documentation, provider certifications, questionnaires, and written responses. If Applicable Data Protection Law requires a further audit, Customer may conduct one audit in any twelve-month period on at least 30 days’ written notice, during normal hours, through an independent qualified auditor bound by confidentiality, and without accessing another person’s data, source code, vulnerabilities, personal devices, or legally privileged material.
Customer bears its audit costs and HAFYCH’s reasonable out-of-scope assistance costs unless the audit identifies a material breach by HAFYCH. An urgent regulator-required or breach-related audit may occur on shorter notice where legally necessary and proportionate.
A notice from HAFYCH will describe, to the extent known and legally permitted, the nature of the incident, affected data, likely consequences, measures taken or proposed, and a contact point. Notice is not an admission of fault or liability. Customer is responsible for determining whether to notify a supervisory authority, Data Subject, customer, employee, or other person, except where law directly imposes that obligation on HAFYCH.
At the end of processor services, HAFYCH will delete or return Customer Personal Data that HAFYCH controls, at Customer’s choice and where technically practicable. HAFYCH may retain data required for legal claims, security, fraud prevention, tax, accounting, platform, or legal obligations, with access restricted to those purposes. Local data, user-selected cloud data, app-store data, and provider records outside HAFYCH’s control must be deleted through the relevant device or provider.
Confidentiality, security, deletion, audit, transfer, liability, and other provisions intended to survive continue for retained Customer Personal Data.
The liability allocation, exclusions, caps, and Business User indemnity in the Terms apply to this DPA, except to the extent Applicable Data Protection Law prohibits that result. There is no double recovery for the same loss. Customer remains responsible for unlawful instructions, missing notices or legal bases, and data or use cases it introduces without HAFYCH’s written approval.