ClassifierHub
Pricing

Data Processing Agreement

Last updated 2026-10-04

This Data Processing Agreement ("DPA") forms part of the ClassifierHub Terms of service between the customer ("Controller") and [ENTIDADE], tax number [NIF], [MORADA] ("Processor"), and applies when the Processor processes personal data on the Controller's behalf under Article 28 GDPR. Need a signed copy? Email hello@classifierhub.com.

1. Subject matter and duration

Processing of personal data contained in decision inputs, batch items and stored executions, for the duration of the subscription plus the deletion period below.

2. Nature and purpose

Classifying, scoring and routing inputs submitted through the API, MCP, dashboard and integrations, and returning results. Inputs are forwarded to the model provider solely to compute results and are never used to train models.

3. Categories of data and data subjects

Determined by the Controller: typically contact details and message contents of the Controller's customers, leads or users. The Controller must not submit special category data without a lawful basis.

4. Processor obligations

  • Process personal data only on documented instructions from the Controller (these terms, the API calls and workspace settings).
  • Ensure persons authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational measures: encryption in transit and at rest, per-workspace access control with row-level security, hashed API keys, least-privilege service credentials, input storage off by default with configurable retention, logging without decision contents.
  • Assist the Controller with data subject requests, security, breach notification and impact assessments, taking into account the nature of the processing.
  • Notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach.
  • Make available the information needed to demonstrate compliance and allow audits by the Controller or an appointed auditor, with reasonable notice, at most once a year.

5. Subprocessors

The Controller authorizes the subprocessors below. The Processor will give at least 30 days' notice of new subprocessors by email or in the dashboard; the Controller may object on reasonable grounds and terminate if no solution is found. Subprocessors are bound by data protection terms no less protective than this DPA.

SubprocessorPurposeLocationTransfer safeguard
Cloudflare, Inc.Hosting, CDN, DNS and request logsGlobal edge network (US company)EU SCCs / EU-US Data Privacy Framework
Supabase, Inc.Database and authenticationEU (Frankfurt, eu-central-1)Data stored in the EU; SCCs for support access
OpenRouter, Inc.Routes decision inputs to the model providerUnited StatesEU SCCs
TypeSafe (Jev model, via OpenRouter)Runs the decision model on your inputsUnited StatesEU SCCs
Stripe Payments Europe, Ltd.Payments, invoicing and taxEU (Ireland), with US processingEU SCCs / EU-US Data Privacy Framework
Resend, Inc.Transactional emailUnited StatesEU SCCs
PostHog, Inc.Product analytics (only with consent)EU (Frankfurt)Data stored in the EU
Functional Software, Inc. (Sentry)Error monitoringEU (Frankfurt)Data stored in the EU; SCCs for support access

6. International transfers

Transfers outside the EEA rely on the European Commission's Standard Contractual Clauses (Module 3, processor to processor) or an adequacy decision such as the EU-US Data Privacy Framework.

7. Deletion and return

On termination, the Controller can export its data from the dashboard. The Processor deletes personal data within 30 days, and from backups within a further 30 days, unless law requires retention.

8. Liability and precedence

Liability follows the Terms of service. If this DPA conflicts with the Terms on data protection, this DPA prevails.