Data Processing Agreement
Last updated 2026-10-04
This Data Processing Agreement ("DPA") forms part of the ClassifierHub Terms of service between the customer ("Controller") and [ENTIDADE], tax number [NIF], [MORADA] ("Processor"), and applies when the Processor processes personal data on the Controller's behalf under Article 28 GDPR. Need a signed copy? Email hello@classifierhub.com.
1. Subject matter and duration
Processing of personal data contained in decision inputs, batch items and stored executions, for the duration of the subscription plus the deletion period below.
2. Nature and purpose
Classifying, scoring and routing inputs submitted through the API, MCP, dashboard and integrations, and returning results. Inputs are forwarded to the model provider solely to compute results and are never used to train models.
3. Categories of data and data subjects
Determined by the Controller: typically contact details and message contents of the Controller's customers, leads or users. The Controller must not submit special category data without a lawful basis.
4. Processor obligations
- Process personal data only on documented instructions from the Controller (these terms, the API calls and workspace settings).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational measures: encryption in transit and at rest, per-workspace access control with row-level security, hashed API keys, least-privilege service credentials, input storage off by default with configurable retention, logging without decision contents.
- Assist the Controller with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing.
- Notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach.
- Make available the information needed to demonstrate compliance and allow audits by the Controller or an appointed auditor, with reasonable notice, at most once a year.
5. Subprocessors
The Controller authorizes the subprocessors below. The Processor will give at least 30 days' notice of new subprocessors by email or in the dashboard; the Controller may object on reasonable grounds and terminate if no solution is found. Subprocessors are bound by data protection terms no less protective than this DPA.
| Subprocessor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, CDN, DNS and request logs | Global edge network (US company) | EU SCCs / EU-US Data Privacy Framework |
| Supabase, Inc. | Database and authentication | EU (Frankfurt, eu-central-1) | Data stored in the EU; SCCs for support access |
| OpenRouter, Inc. | Routes decision inputs to the model provider | United States | EU SCCs |
| TypeSafe (Jev model, via OpenRouter) | Runs the decision model on your inputs | United States | EU SCCs |
| Stripe Payments Europe, Ltd. | Payments, invoicing and tax | EU (Ireland), with US processing | EU SCCs / EU-US Data Privacy Framework |
| Resend, Inc. | Transactional email | United States | EU SCCs |
| PostHog, Inc. | Product analytics (only with consent) | EU (Frankfurt) | Data stored in the EU |
| Functional Software, Inc. (Sentry) | Error monitoring | EU (Frankfurt) | Data stored in the EU; SCCs for support access |
6. International transfers
Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses (Module 3, processor to processor) or an adequacy decision such as the EU-US Data Privacy Framework.
7. Deletion and return
On termination, the Controller can export its data from the dashboard. The Processor deletes personal data within 30 days, and from backups within a further 30 days, unless law requires retention.
8. Liability and precedence
Liability follows the Terms of service. If this DPA conflicts with the Terms on data protection, this DPA prevails.