Data Processing Addendum (DPA)

Status: DRAFT — pending legal review. Counsel must finalize this before it is relied on for a regulated workload; the entity name will be completed on formation. Changes are recorded in the legal changelog.

Last updated: 2026-07-02 (draft) · version history: legal changelog

This DPA forms part of the Terms of Service between the customer ("Customer") and [ENTITY — to be completed on formation] ("Hosaka"). It applies automatically — no signature required — whenever Hosaka processes personal data subject to the GDPR, UK GDPR, or Swiss FADP on the Customer's behalf in providing crate-api. Customers who need a countersigned copy for their records can email legal@hosaka.fm.

1. Roles + scope

For personal data the Customer submits or that is generated by the Customer's use of crate-api, the Customer is the controller and Hosaka is the processor. Hosaka processes such data only to provide the service and only on the Customer's documented instructions (the Terms, this DPA, and the Customer's use of the API being those instructions).

Dual role: Hosaka acts as an independent controller — not the Customer's processor — for the personal data it must process to run its own business: billing records, service telemetry, security logs, and aggregate demand statistics derived from usage. That processing is described in the Privacy Policy.

Customer obligations: the Customer is responsible for the lawfulness of the personal data it submits and of its instructions, for providing any required notices to (and obtaining any required permissions from) its own data subjects, and must not submit special-category data to the service.

2. Details of processing (Annex I)

  • Subject matter / duration: provision of the crate-api for the term of the agreement.
  • Nature + purpose: hosting, authentication, usage metering, billing, security, and — only if the Customer uses the opt-in AI features — natural-language query interpretation via a sub-processor.
  • Types of personal data: account contact (email, name), billing metadata, technical identifiers (API key id, IP, usage logs), and — for AI features only — the query text the Customer submits (PII-redacted before transmission; not persisted; a one-way fingerprint only in telemetry).
  • Categories of data subjects: the Customer's authorized users / administrators.
  • Sensitive data: none intended; the Customer must not submit special-category data.
  • Frequency: continuous, for the duration of the subscription.

3. Processor obligations

Hosaka will: (a) process personal data only on documented instructions, including with regard to international transfers; (b) ensure persons authorized to process it are bound by confidentiality; (c) implement the technical + organizational measures in Annex II (§8); (d) assist the Customer, taking into account the nature of processing, with data-subject requests and with DPIAs/consultations (assistance beyond providing our standard documentation may be charged at reasonable rates); (e) notify the Customer of a personal-data breach affecting Customer personal data without undue delay, and in any case within 72 hours of becoming aware, with the information Art. 33(3) GDPR requires (supplemented as it becomes available); and (f) on termination, delete Customer personal data within 30 days (or return it on request made within that window), except what law requires us to retain (retained data stays protected by this DPA and is deleted when the obligation ends).

4. Sub-processors

The Customer generally authorizes the sub-processors listed at /legal/subprocessors. Hosaka will post intended additions or replacements there at least 30 days in advance (subscribe to change notices via privacy@hosaka.fm). If the Customer reasonably objects on data-protection grounds and Hosaka cannot offer an alternative, the Customer may terminate the affected subscription with a pro-rata refund of prepaid fees — that termination right is the exclusive remedy for a sub-processor change. Hosaka imposes data-protection terms on each sub-processor consistent with this DPA and remains liable for their performance. Anthropic is engaged only for the opt-in AI features; a Customer that does not invoke them can ensure its data is never sent to that sub-processor by not using them.

5. International transfers

Where personal data protected by EEA, UK, or Swiss law is transferred to Hosaka in the United States (or onward to a sub-processor outside an adequate jurisdiction), the parties rely on:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller → processor), which are incorporated into this DPA by reference and completed as follows: Annex I = §2 of this DPA (exporter: the Customer; importer: Hosaka); Annex II = §8 of this DPA; Clause 9(a): general authorization with the notice period in §4; Clause 17: Irish law; Clause 18: Irish courts; the optional docking clause and redress-body options are not used;
  • for UK transfers, the UK International Data Transfer Addendum to the EU SCCs (ICO, version B1.0), with the tables completed by the same information; and
  • for Swiss transfers, the SCCs adapted as the FDPIC requires (references to the GDPR read as the FADP; supervisory authority: the FDPIC).

If Hosaka certifies under the EU-U.S. Data Privacy Framework in the future, that certification may serve as the transfer mechanism for the data it covers; the SCCs remain the fallback.

6. Audit

Hosaka will make available information reasonably necessary to demonstrate compliance with this DPA (including Annex II documentation and summaries of any third-party assessments), and will allow for and contribute to audits — satisfied first through written responses and documentation; an on-site or remote inspection may occur at most once per 12 months, on 30 days' notice, during business hours, at the Customer's cost, under confidentiality.

7. CCPA / US state privacy

Where the CCPA/CPRA (or a similar US state law) applies to Customer personal data, Hosaka acts as the Customer's service provider/processor: it will not sell or share that data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than providing the service (or as the law permits), will comply with the CCPA's obligations, and certifies that it understands these restrictions. Hosaka will notify the Customer if it can no longer meet them.

8. Technical + organizational measures (Annex II)

  • TLS for all data in transit; encryption at rest for databases, object storage, and backups.
  • API keys stored only as salted hashes — plaintext shown once at creation, never persisted.
  • Least-privilege access: separated database roles per function (public catalogue reads vs. billing/admin reads vs. writes), each with its own credentials; secrets held in a managed secrets store, never in code.
  • Raw per-request logs pruned after ~30 days; only aggregate statistics persist.
  • Infrastructure in AWS us-east-1 behind a CDN/WAF; audit trails on privileged mutations; deployment via reviewed, versioned pipelines.
  • Personnel: access limited to those who need it to operate the service, under confidentiality obligations.
  • PII redaction + injection filtering applied to AI-feature query text before any transmission to the AI sub-processor.

9. Precedence, liability + duration

In case of conflict, this DPA (and the SCCs, which prevail over everything for the transfers they govern) prevails over the Terms with respect to processing of personal data. Each party's liability under this DPA is subject to the limitations in the Terms, except where the SCCs or applicable data-protection law do not permit that limitation. This DPA lasts as long as Hosaka processes Customer personal data.


Questions or a countersigned copy: legal@hosaka.fm.