Data processing addendum
Data Processing Addendum
- Version:
- Oct 8, 2026
- Effective:
Canonical URL: /legal/dpa/2026-10-08
1. When this addendum applies
This Data Processing Addendum (DPA) is part of the agreement between Boondoggle Studio, LLC, a North Carolina limited liability company doing business as Hemingway Editor App, with mailing and legal-notice address PO Box 72, Durham, NC 27702, United States (Hemingway, we, or us), and the customer identified in the applicable Hemingway account, purchase, and acceptance records or agreed Order Form, together with any agreed customer-specific supplement (Customer or you). The agreement is your accepted version of the Terms of Use, together with any agreed Order Form or addendum. This applies whether you purchase online or pay by invoice. Capitalized terms not defined here have the meanings given in that agreement.
This DPA applies when we process personal information on your behalf to provide the service. It is incorporated automatically when you accept the applicable agreement and covered processing begins. You do not need to request or separately sign a copy for it to apply. We will provide a signature copy on request. Each party's electronic acceptance binds it to this DPA and its applicable transfer terms. The acceptance record identifies the parties, accepted version, date, and person accepting for the Customer.
This DPA covers the Hemingway web app, Microsoft Word add-in, and sign-in services, including configured organization single sign-on (SSO).
This DPA applies to covered processing for both free and paid accounts. Section 6 explains when return and deletion duties begin. Information controlled by an organization does not become an individual user's personal-account information when a paid plan ends.
Personal information means information protected as personal data or personal information by an applicable privacy law. Covered Data means personal information we process on your behalf, as described in Schedule A. Privacy Law means a privacy or data-protection law that applies to a party's processing under this DPA, including the EU GDPR, UK GDPR and Data Protection Act 2018, and applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended (CCPA). These references do not make a law apply where it otherwise would not.
You act as a controller when you decide why personal information is processed and as a processor when you process it for another controller. We act as your processor or subprocessor for Covered Data. A subprocessor is another provider we use to process Covered Data on your behalf.
Our role depends on how we use information. For example, a document you attach to a support request remains Covered Data when we use it to help you. Our separate billing, tax, and business-administration uses follow the Privacy Policy. Labeling a record as account, analytics, security, or support information does not remove it from this DPA or give us broader rights to use it.
2. Your instructions and our permitted uses
We will process Covered Data only on your documented instructions. These include this DPA, the agreed service settings, and authorized users' requests for features and support. Schedule A describes the authorized activities and their limits. Entering text does not authorize unrelated processing or reuse.
You are responsible for having a lawful basis and giving required notices for the personal information you submit. You must obtain any consent that applicable law requires. These duties are separate from instructing us to process the information. If you act for another controller, you must have authority to appoint us, approve our subprocessors, and give these instructions.
We will immediately inform you if we believe an instruction violates Privacy Law and pause the affected processing while the issue is resolved. We may process Covered Data as binding law requires; unless that law prohibits notice, we will tell you about the legal requirement before processing it. We will not carry out an instruction we know is unlawful.
The service supports ordinary business personal information, subject to the unsupported-information restrictions in section 8 of your accepted Terms of Use. Those restrictions do not remove our duties for Covered Data that we actually receive. Schedule A addresses any additional safeguards needed for sensitive information.
Content and confidentiality safeguards
We will use Covered Data only for the activities in Schedule A, binding legal requirements, and the permitted return or deletion process. The content-use, no-training, confidentiality, and limited-human-access safeguards in section 6 of your accepted Terms of Use also apply here. They cover your documents, prompts, instructions, outputs, and support attachments, including material supplied incidentally. These references are to the version that governs your service, not a later posted version.
All Covered Data remains confidential, including personal information that is not Customer Data under the agreement. Anyone accessing it must need that access for an authorized purpose and be bound by confidentiality duties. Our subprocessors are subject to the same limits on content use, including the prohibition on training, fine-tuning, or improving AI models and voluntary provider sharing for those uses.
Usage records and sign-in information
We may record account-linked usage and error information for the purposes in Schedule A. Usage and error records must not contain your writing or AI-generated content. Records linked to a person remain personal information, not anonymous data. Schedule B sets out additional safeguards for usage and error records.
We use sign-in and SSO information to verify users and enforce their authorized access. Signing in does not grant access beyond the permissions you have authorized.
3. Security and incidents
Security measures
We will maintain technical and organizational measures appropriate to the processing and its risks, including the measures in Schedule B. We will consider the nature, scope, context, and purposes of processing, the likelihood and seriousness of harm, available technology, and implementation costs.
Schedule B and the incident duties in this section also protect Customer Data under your accepted agreement, including content that is not personal information. These security commitments do not make that content subject to the DPA's other personal-information processing rules. They continue while we or our providers handle or retain the protected information, including during free service and the return or deletion process.
We may update those measures as technology and risks change, provided we do not materially reduce their overall protection during your committed term. A change may not reduce a measure required by Privacy Law or the transfer clauses. We will assist with your security obligations to the extent required by Privacy Law, considering the processing and information available to us.
Security incidents and personal-data breaches
A Personal-Data Breach is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Covered Data. Unsuccessful attempts that do not compromise Covered Data are not Personal-Data Breaches.
A Security Incident is a breach with those effects on Customer Data, whether or not it contains personal information, or a Personal-Data Breach. Unsuccessful attacks that do not compromise either Customer Data or Covered Data are not Security Incidents.
We will notify your designated incident contact without undue delay after becoming aware of a Security Incident and in any event within 72 hours after awareness, or sooner where applicable law requires. We will not wait for a completed investigation before sending the initial notice. The 72-hour maximum does not permit a delay that would otherwise be undue.
As information becomes available, we will describe the nature of the breach; affected data and people, including approximate numbers where known; likely consequences; measures taken or proposed to contain and address it; and a contact for further information. We will provide material updates when we cannot provide everything at once. We will take reasonable steps to contain, investigate, and remedy the breach and preserve relevant evidence. We will cooperate with your legally required notices and other response duties. You decide whether to notify people or authorities on your own behalf; we will not speak for you without authorization unless the law requires it. Giving notice is not an admission of fault.
4. Providers that process information for us
By accepting this DPA, you give general written authorization for the entries identified as subprocessors for covered processing in Service Providers and Subprocessors, version 2026-10-08, including the listed AI providers. Only those entries and their stated covered functions, data categories, and processing-location disclosures form part of this DPA. Listing a provider for another purpose in that directory or the Privacy Policy does not authorize it to receive Covered Data.
Before a subprocessor receives Covered Data, we will assess its ability to protect it and enter a written agreement requiring protections consistent with this DPA and Privacy Law. We remain responsible to you for its performance of the applicable data-protection obligations. We will provide information about those obligations as required by Privacy Law and the transfer clauses, with permitted redactions that do not prevent you from assessing compliance.
We will email your designated privacy contact at least 30 calendar days before a new or replacement subprocessor outside your authorized list first receives your Covered Data. The email will identify the provider, work, data, locations, safeguards, and proposed start date, with enough information to assess the change. This applies to existing customers whose authorized list does not include that provider. Updating the public list alone is neither notice nor authorization. You do not need to approve each change separately: we may proceed after the notice period if you have not raised a timely objection.
We will follow the same notice and objection process before an existing subprocessor begins materially different processing outside its authorized purposes, data categories, or disclosed locations.
You may object on reasonable data-protection grounds within 15 calendar days after receiving the notice. We will discuss the grounds and seek a solution during the remainder of the notice period. We do not promise customer-specific provider routing, a separate technical setup, or that a particular alternative will be available. We will not send your Covered Data to the disputed provider while a timely objection remains unresolved.
If we have not agreed on a solution by the proposed start date, either party may end the affected service. We will refund its unused prepaid fees. If it cannot be separated from the subscription, either party may end the subscription with the same refund. We must stop the affected processing before the disputed provider receives your Covered Data; a downgrade to free service is not enough if that processing would continue. These remedies do not limit rights under Privacy Law or the transfer clauses.
Existing authorized providers may continue their authorized work while we consider an objection.
These requirements also apply to Covered Data used in beta or experimental features.
5. Privacy requests, assessments, and audits
Requests, assessments, and government demands
Taking account of the nature of processing, we will help you respond to requests to access, correct, delete, restrict, or receive Covered Data and other rights under Privacy Law. We will use appropriate technical and organizational measures and provide available information promptly enough to support the applicable deadline. Send instructions to support@hemingwayapp.com. We will reasonably verify your authority and protect information about other customers and people.
If someone sends us a request about Covered Data, we will promptly direct it to you where we can identify you and will not independently decide your response, unless you authorize us or law requires otherwise. We remain responsible for requests about our separate controller processing.
We will provide required assistance with data-protection impact assessments, transfer assessments, consultations with authorities, and applicable U.S. risk assessments and cybersecurity audits, considering the information available to us. Any separately agreed charges for extraordinary assistance must be lawful and must not prevent or delay assistance required by Privacy Law or the transfer clauses.
Where legally permitted, we will direct government requests to you, notify you before disclosure, and disclose only what a binding demand requires. We will assess the demand's legal validity and exercise the review, challenge, documentation, and notification duties required by applicable transfer clauses. A commercial confidentiality clause does not prevent disclosures required to an authority.
Compliance information and audits
We will provide the information needed to demonstrate compliance with this DPA. We will normally start with written answers, relevant policies, control summaries, and other available evidence. If these adequately address the request, a further inspection may be unnecessary. This initial review will not prevent or delay an audit or inspection required by Privacy Law or applicable transfer clauses.
We will allow and contribute to required audits and inspections by you or an independent auditor you appoint. The review will focus on our processing of your Covered Data and the systems and controls relevant to it, rather than unrelated business activities.
We will coordinate the scope, timing, confidentiality, and safe access arrangements with you. Where practical, reviews will take place on reasonable advance notice and during normal business hours, with reasonable steps to minimize disruption and protect other customers' information and service security. We will adjust these arrangements for incidents, suspected noncompliance, regulator requests, or legal deadlines. They must not block required access, restrict an authority's powers, or impose a frequency or fee barrier inconsistent with Privacy Law or the transfer clauses.
We will promptly tell you if we can no longer comply with this DPA and work with you to stop and remedy unauthorized processing. You may take reasonable and appropriate steps to verify compliance and require us to stop and remedy unauthorized use, including receiving evidence that a required deletion was completed.
6. Returning and deleting information
When processing ends
When the relevant work we do on your behalf ends, we will return or delete its Covered Data, at your choice, and delete remaining copies unless applicable law requires retention. Account closure is one example. A paid-to-free downgrade does not end processing needed for the free service. Records used only for a discontinued feature must still follow their purpose and deletion limits.
We also carry out valid deletion instructions during the service. The Retention Schedule, version 2026-10-08, governs the different record categories and copies, subject to the duties below.
Live service records and return requests
For eligible live account, organization, membership, usage, subscription-service, and saved-instruction records:
- Deletion: within 30 calendar days of a valid deletion request or the end of the relevant covered processing. No separate request is needed when that processing ends.
- Ordinary return requests: request eligible stored service records from Hemingway-controlled systems within 14 calendar days after the relevant processing ends. We will supply them within 14 calendar days of receiving your request. We will preserve them through the request window and fulfill a timely request before deleting them within the 30-day deadline.
- Sign-in credentials: we will revoke them promptly when the relevant connection ends or the account is deleted. We will delete eligible live token copies within one calendar day, including coordinating the applicable identity-provider cleanup. We will not export raw tokens or other secrets.
An instruction to delete sooner or a shorter legal deadline takes priority. The ordinary return window does not limit statutory rights or required DPA assistance, and does not require us to recreate lawfully deleted records. We will reasonably assist with available Covered Data actually held by us or our subprocessors, including eligible account, membership, usage, support, and saved-instruction records, as this DPA and applicable law require.
Provider copies and business records
We will submit eligible, exactly scoped provider return or deletion requests within the applicable period. A provider's accepted request or job reference confirms submission, not completed deletion. Provider processing may continue afterward, but we remain responsible for our applicable obligations; possession by a provider does not excuse required deletion.
Independent business records follow the Privacy Policy and Retention Schedule, rather than automatic deletion at account closure. Correspondence may include text or attachments you send us for support. We retain these as part of the correspondence record, subject to applicable privacy requirements and this DPA's obligations. They remain protected content, and treating them as correspondence does not exempt Covered Data from required deletion. We may keep limited evidence of a completed privacy request, not the deleted information itself. Applicable necessity limits and mandatory deletion duties still apply.
Backups and required retention
Where law permits delayed deletion from isolated backups, those copies follow the backup cycles in the Retention Schedule. We will protect those copies, keep them out of ordinary use, and reapply deletions if they are restored. Backups may not be used to avoid required deletion.
Covered Data retained because the law requires it remains protected by this DPA. We will use it only for the required retention purpose and delete it when that requirement ends.
On request, we will report our deletion actions, provider submissions, and any lawful remaining categories, their basis, and retention period where disclosure is permitted. We will distinguish completed deletion from a provider's acceptance of a request and provide any legally required confirmation. This DPA continues to protect Covered Data for as long as we or our subprocessors retain it.
Documents you control
Our return and deletion obligations cover information held by us or our subprocessors, not copies you keep in your own systems or with providers under your separate arrangements. We do not provide a hosted document library to export.
7. Additional U.S. privacy requirements
For Covered Data governed by the CCPA, you disclose it only for the limited business purposes in Schedule A, and we act as your service provider or contractor, as applicable. We certify that we understand and will comply with the restrictions in this DPA. We will provide the level of protection the CCPA requires and comply with its applicable provisions and regulations.
We will not sell or share Covered Data, use it for cross-context behavioral advertising, or retain, use, or disclose it outside our direct business relationship or the specified business purposes, except where the CCPA expressly permits and this DPA authorizes the processing. We will not combine it with personal information from another customer, another source, or our own interactions with a consumer except as expressly permitted by the CCPA and consistent with this DPA. Statutory permissions do not expand the content-use rights in section 2. We will assist with applicable consumer rights and required audit, risk-assessment, and automated-decisionmaking compliance obligations; the service does not authorize prohibited high-impact decisionmaking.
For other applicable U.S. state privacy laws, we will follow your instructions as processor, provide required assistance and compliance information, allow required assessments, impose appropriate written duties on subprocessors, and return or delete Covered Data as the law requires. The applicable statutory meanings govern any state-specific term. Each party remains responsible for the duties that law assigns to its role.
8. International processing and which terms control
Hemingway's application and database hosting takes place in the United States. Authorized providers may process or access information in other countries as disclosed in Service Providers and Subprocessors, including for support and abuse monitoring.
We will use a valid transfer mechanism for each restricted international transfer and will not make a transfer that lacks required safeguards. Schedule C applies to eligible EEA transfers and Schedule D applies to UK transfers. The parties will provide information reasonably needed for the required transfer assessment, implement necessary additional safeguards, and suspend affected transfers if lawful protection cannot be maintained.
Mandatory law and the priority rules of the EU Standard Contractual Clauses (SCCs) and UK Addendum prevail over conflicting terms. No liability cap, exclusive remedy, arbitration clause, Order Form, or other commercial term may contradict those instruments, reduce their protections, or limit rights that law does not allow the parties to waive. Subject to those requirements, the agreement's express document hierarchy applies. An amendment affecting processing must continue to satisfy this DPA and all applicable mandatory requirements.
Schedule A — Processing particulars and parties
A1. Parties and contacts (also SCC Annex I.A)
For this Schedule, the Customer's records are the applicable Hemingway account records, purchase records, including Stripe records where used, agreement acceptance records, and any agreed Order Form or customer-specific supplement. These records identify the legal party contracting with Hemingway; a different billing payer does not replace that party. The records and any agreed supplement provide the particulars below. Required particulars must be completed before a restricted transfer that requires them. To agree a supplement or update designated contacts, contact support@hemingwayapp.com.
| Field | Customer / exporter | Hemingway / importer |
|---|---|---|
| Legal name, trading name, registered address and registration number if applicable | The Customer's legal name, trading name, registered address, and registration number, if applicable, as identified in the Customer's records and any agreed supplement. | Boondoggle Studio, LLC, doing business as Hemingway Editor App; 216 West Geer Street, Unit A, Durham, NC 27701, United States; North Carolina registration number 1375050 |
| Mailing and DPA notice address | The Customer's mailing and DPA notice address as identified in the Customer's records or agreed supplement. | PO Box 72, Durham, NC 27702, United States |
| Activities | Using writing assistance for its own work or providing authorized services to its controller | Providing writing assistance and the specific supporting activities below |
| Role | Controller where the Customer determines the purposes and means of the covered processing; processor where it acts for an underlying controller identified in the Customer's records or agreed supplement. Module 3 requires the controller's authority and the applicable conditions in Schedule C. | Processor, or subprocessor where Customer is a processor |
| Privacy contact and job title | The privacy contact, job title, and email designated by the Customer in the Customer's records or agreed supplement. The person accepting the agreement is the privacy contact only if the Customer designates that person for this purpose. | Adam Long, privacy requests owner; support@hemingwayapp.com |
| Incident contact | The incident contact and email designated by the Customer in the Customer's records or agreed supplement. The person accepting the agreement is the incident contact only if the Customer designates that person for this purpose. | Adam Long, security incident owner; support@hemingwayapp.com |
| Acceptance / signature and date | The Customer's recorded agreement acceptance, including the accepted version, acceptance date, and person accepting for the Customer, or the signature and date in an agreed Order Form or signed DPA. | Hemingway offers this DPA and its applicable transfer terms as part of the agreement under section 1. The Customer's agreement acceptance record identifies the version of that offer accepted and the acceptance date. Where the parties sign an Order Form or DPA, Hemingway's signature and date are recorded there. |
A2. Scope (also SCC Annex I.B)
Subject and nature: Writing assistance in the web app and Word add-in, related account administration and sign-in (including configured organization SSO), authorized AI processing, customer-directed support, and security. Activities include receiving, transmitting, organizing, analyzing for the authorized task, returning, storing only the specified records, and deleting information.
Duration and frequency: During the relevant covered service, including continuing free service, and the return/deletion period in section 6. Transfers recur as authorized users use the features and supporting functions. DPA protections continue while we or our subprocessors retain Covered Data; this does not extend any retention period.
People concerned: Your authorized users, administrators, personnel, contractors, and other individuals whose ordinary business personal information you lawfully include in writing or support requests, such as your customers, suppliers, and business contacts.
| Authorized activity and specific purpose | Covered categories and handling |
|---|---|
| Provide automatic writing assistance and user-invoked AI tools, including generation, analysis, scoring, and classification needed for those features; return results | Personal information in the necessary passage, surrounding context or entire document, user prompts, style instructions and output; transmitted to an authorized AI provider. Automatic processing may run as you type, paste, or import text, without a separate button click. Other AI tools run when you choose them. |
| Read and analyze Word document content and apply accepted edits | Document text and related formatting or structural information needed to provide the editing features you use, including automatic analysis. Processing may include selected passages, surrounding context, or the full document text. Access is limited to the document you use with Hemingway, not unrelated files. |
| Manage customer-directed access and team membership, including configured required SSO and Word authentication | Name, email, account and organization identifiers, organization name, membership/role, sign-in attributes, SSO connection details, linked-login and session records, and required credentials or tokens; stored to verify users, enforce organization access rules, manage sessions, and synchronize identity |
| Allocate paid AI entitlement and show permitted usage information | User/workspace identifiers, credit usage, token counts and entitlement status; stored for service delivery and reconciliation |
| Diagnose reliability, protect service and assist users with feature operation | Identifiers, feature/event names, sequence, timing, duration, token counts, status, and necessary technical metadata; no Customer Data content in analytics or diagnostic payloads |
| Provide requested support | Requester/contact details and support correspondence, including text and attachments you send us; access limited to that support purpose and required security/legal handling. Content protections continue to apply, and retention follows section 6. This is not routine storage of documents entered into the editor |
| Store style guidance or reusable instructions you save for editing | Your saved guidance or instructions, protected as content and returned or deleted under section 6. We do not analyze them to create style-preference statistics or collect separate style-preference settings for that analysis |
Our own billing administration, marketing, and product and subscription analytics follow the Privacy Policy when we determine their independent purposes, rather than process information on your behalf. This does not expand our permitted uses of Customer Data or exclude customer-directed service diagnostics from this DPA.
Sensitive information: The service is not designed for the prohibited categories in section 2. Other sensitive personal information is not an agreed routine category. Before intentionally processing a sensitive category that requires additional safeguards, the parties must record the category, authority, need, and safeguards in an agreed customer-specific processing supplement. Contact support@hemingwayapp.com to discuss that supplement. Unexpected receipt remains protected and is addressed through restricted access and appropriate deletion or lawful instructions.
Retention: Section 6 and the completed Retention Schedule specify each record category's period or permitted legal criterion. No retention permission is implied by an incomplete field.
Subprocessor transfers: The incorporated subprocessor entries in Service Providers and Subprocessors specify each authorized provider's covered function, categories and location disclosures. Applicable retention follows the Retention Schedule; authorizations last only while necessary for the stated function and permitted deletion period. Those entries are incorporated as supporting information for Annex I.B and, where applicable, Annex III. Under general authorization, that cross-reference does not convert the election into specific authorization.
A3. Supervisory authority (SCC Annex I.C)
For an EEA transfer governed by Schedule C, the competent supervisory authority is determined under SCC Clause 13 by the Customer's relevant establishment, representative, or affected individuals, as applicable. The parties will identify that authority in the Customer's records or an agreed supplement before a transfer that requires it. The choice of Irish law and courts in Schedule C does not by itself identify the supervisory authority. For UK restricted transfers, the competent authority is the ICO under the UK Addendum.
Schedule B — Security particulars (SCC Annex II)
We will apply these measures to our systems and personnel and require appropriate safeguards from providers handling information under our instructions. They protect Covered Data and Customer Data as described in section 3. Stored instructions and content supplied for support receive the same content protections; their use and retention follow the applicable agreement and Retention Schedule.
| Processing risk / safeguard | Applicable measure |
|---|---|
| Confidentiality in transit and storage | Encrypt Customer Data and Covered Data in transit across public networks, and stored service records and managed backups at rest. Authorized systems and providers may process readable information as needed for permitted functions. Restrict database network access to necessary sources and review privileged infrastructure access. Keep production secrets in restricted configuration or secret storage, and do not intentionally expose them in source code or diagnostic output. |
| Separation between customers | Use logical access controls to separate customer records on shared infrastructure. Enforce user, organization, and role permissions on protected service paths, test those authorization controls, and address identified failures. |
| Staff and administrative access | Limit staff and contractor access to authorized business needs, require confidentiality commitments, review access periodically, and remove access when no longer needed. Restrict privileged credentials to authorized operators and protect them against disclosure. Use multifactor authentication for administrative systems where supported; document compensating controls for exceptions. |
| Authentication and sessions | Enforce configured required organization SSO and prevent alternative sign-in methods from bypassing it. Enforce applicable organization and plan-access checks on protected paths. Protect authenticated sessions and provide ways to sign out. |
| Analytics and error reporting | Keep writing, prompts, saved instructions, AI output, excerpts, and errors containing that material out of analytics and diagnostic records. Exclude document names, paths, markup, sign-in tokens, and secret access codes from recorded events, errors, activity trails, and captured URLs. Restrict access to monitoring records. Limit error reports to the technical information needed to diagnose problems, and use the local account identifier rather than an email address for user context. |
| Email records | Disable email open and click tracking. Do not create a permanent email-delivery archive, event ledger, or bulk export. Retain delivery evidence for an active support or billing dispute only as permitted by the Retention Schedule: minimal message type, provider message/event identifier, timestamp, and outcome, excluding message bodies, sign-in links, tokens, IP addresses, and raw payloads. Keep preference and suppression evidence separate. |
| Development and security weaknesses | Use a documented process to review, test, and deploy material application changes. Assess reported security issues and address them according to risk. Review privacy and security when changes affect recipients, purposes, storage, or access to protected information. |
| Backups and deletion | Maintain encrypted, access-controlled backups of stored service records and periodically test restoration. Apply the expiry and deletion rules in section 6 and the Retention Schedule. Before restored data returns to ordinary use, reapply relevant deletion instructions and ensure revoked sign-in connections cannot become active again. Prompt revocation, live-token deletion within one calendar day, and applicable authentication-provider cleanup follow section 6. |
| Incident response | Maintain assigned responsibilities, escalation contacts, investigation procedures, evidence preservation, and customer communications. Follow section 3's initial notification, updates, containment, and response-assistance duties. |
| Evidence and control assessment | Maintain the authorization, change, and restoration testing described above. Provide compliance information and audit assistance under section 5, with appropriate confidentiality and security safeguards. Other security questionnaires and procurement reviews are discretionary unless required by law or applicable transfer clauses, or separately agreed. Providing documents does not prevent or delay required audits or inspections. |
Account and operational records can identify users. We protect them by limiting the information collected and access to it; we do not promise that all Covered Data is anonymous or pseudonymized.
For request assistance, Hemingway will use its support channel and authorized administrator procedures to identify responsive service records, verify the instructing customer, coordinate vendor requests, and record completion or a lawful exception. Data-breach assistance follows section 3. Impact-assessment and compliance assistance follows section 5. These procedures must protect other customers' records and exclude raw authentication secrets from returned copies.
Any additional processing-specific security measures required for the applicable processing will be recorded in an agreed customer-specific supplement before that processing begins. Contact support@hemingwayapp.com to discuss the supplement. A supplement does not reduce the measures in this Schedule or any safeguard required by Privacy Law or the applicable transfer terms.
Schedule C — EEA transfer clauses
Where an EEA transfer to Hemingway requires an Article 46 safeguard and falls within their permitted scope, the SCCs in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated without alteration except the permitted elections and completed appendix information below. The official text is available from EUR-Lex. The parties agree to be bound by that text, including its third-party beneficiary rights. This DPA's plain-language provisions do not replace the SCCs.
| SCC field | Election / completion |
|---|---|
| Module | Module 2 for Customer as controller to Hemingway as processor; Module 3 for Customer as processor to Hemingway as subprocessor, only for processing satisfying that module's conditions |
| Clause 7, optional docking | Does not apply; another legal entity joins only through a separately completed binding agreement |
| Clause 9(a) | Option 2, general written authorization; advance notice period is 30 calendar days, matching section 4 |
| Clause 11 optional independent dispute-resolution body | Not selected; mandatory complaint and redress rights remain |
| Clause 17 governing law | Option 1: the law of Ireland |
| Clause 18(b) courts | The courts of Ireland; Clause 18's other mandatory rights remain, including a data subject's right to bring proceedings in the courts of the Member State where they habitually reside |
| Annex I.A / I.B / I.C | Completed Schedule A |
| Annex II | Completed Schedule B |
| Annex III, where needed | Incorporated authorized subprocessor entries in Service Providers and Subprocessors, with completed provider and processing details |
Module 3 applies only to processing for which you have the controller's authority and can meet that module's duties, including passing the relevant instructions and information between the controller and Hemingway. The parties will identify the underlying controller and relevant processing before the transfer.
These SCCs are not asserted to be a valid transfer mechanism for processing outside Decision 2021/914's permitted scope, including where the importer's relevant processing is already subject to the GDPR and that prevents use of these clauses as the required safeguard. Before such a transfer, the parties must document another applicable, valid mechanism. No transfer may proceed merely because this DPA contains a link to SCCs. The parties will comply with the applicable transfer-assessment, government-access, suspension, and termination duties in the incorporated SCCs.
Schedule D — UK international transfer addendum
For a UK restricted transfer that requires this safeguard, the parties enter the ICO International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 in force 21 March 2022, with its required updates. Its mandatory provisions and permitted UK adaptations govern the Approved EU SCCs identified below. The official instrument is available from the ICO.
Table 1 — Parties. Start date: the applicable DPA acceptance date identified by the records in Schedule A1. Exporter and importer: the parties, addresses, registration numbers, and key contacts identified in Schedule A1 through the Customer's records and any agreed supplement, together with Hemingway's stated particulars. The parties enter the UK Addendum through the agreement acceptance described in section 1 or a signed agreement, using a method that makes it legally binding on both parties and allows data subjects to enforce their rights. Required party and transfer particulars must be completed before a UK restricted transfer relying on this Addendum.
Table 2 — Approved EU SCCs. The Approved EU SCCs are Decision 2021/914 identified in Schedule C, with the appendix information in this DPA. Module 2 applies to controller-to-processor transfers and Module 3 to processor-to-processor transfers as applicable. Clause 7 is not selected. Clause 11's optional body is not selected. Clause 9(a) uses general authorization with 30 calendar days' notice. The Module 4 combining-data field is not applicable. These elections also identify the EU SCCs used for a UK-only transfer; a parallel EEA transfer is not required.
Table 3 — Appendix information. Annex I.A is Schedule A1; Annex I.B is Schedule A2; Annex II is completed Schedule B; Annex III information is the incorporated subprocessor entries in Service Providers and Subprocessors. UK authority, governing-law and court substitutions follow the mandatory Addendum. The default law and courts of England and Wales apply, with all alternative rights preserved by the Addendum; no commercial U.S. venue overrides them.
Table 4 — Ending the Addendum after an approved change. Both the exporter and the importer may end the Addendum under its Section 19, only when that section's conditions are met. This is the limited right arising from an ICO-approved update under Section 18, not a general right to cancel whenever a party wishes. All of Section 19's requirements concerning a demonstrable substantial and disproportionate increase in direct costs of performing Addendum obligations or risk under the Addendum, reasonable mitigation and written notice remain unchanged. Ending the Addendum does not authorize transfers without another valid safeguard or remove a duty to suspend an unlawful transfer.
Part 2 — Mandatory clauses incorporated without alteration:
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
The parties accept the prescribed priority, governing-law, court, and update provisions of that instrument. The incorporation language above is prescribed text; the surrounding explanation does not amend it.