Legal

Data Processing Agreement

Last updated: June 19, 2026

This Data Processing Agreement forms part of the agreement between Awesome System Design Sweden AB as processor and the customer as controller, unless the parties have signed a separate data processing agreement.

This DPA applies when Hai processes personal data on behalf of a customer in connection with the Services.

Subject matter and duration

Hai processes customer personal data to provide, secure, support, and improve the Services under the main agreement. The duration of processing is the duration of the main agreement, plus any period needed for deletion, return, backup expiry, legal compliance, or dispute handling.

Nature and purpose of processing

  • Hosting, storing, retrieving, and transmitting customer personal data.
  • Operating workspaces, integrations, agents, automations, tasks, and live artifacts.
  • Providing support, debugging, logging, security monitoring, and abuse prevention.
  • Processing customer instructions through connected systems and AI providers.
  • Deleting, exporting, or returning customer personal data as required by the agreement.

Categories of data subjects and personal data

Data subjects may include customer personnel, authorized users, customers, prospects, suppliers, job candidates, support contacts, and other individuals whose data is made available through the Services.

Personal data may include names, email addresses, account identifiers, workplace profile information, messages, files, prompts, outputs, credentials or tokens required for integrations, usage data, logs, and other customer-controlled content.

Special category data

Customers should not submit special category personal data unless the applicable agreement permits it and appropriate safeguards are in place. The Services are not intended to infer or process sensitive personal data unless configured by the customer.

Processor obligations

  • Process personal data only on documented customer instructions, including instructions reflected in the product configuration.
  • Ensure personnel with access to personal data are bound by confidentiality obligations.
  • Use appropriate technical and organizational measures to protect personal data.
  • Assist customers with data subject requests, security obligations, impact assessments, and regulator consultations where required and reasonably possible.
  • Notify customers without undue delay after becoming aware of a personal data breach affecting customer personal data.
  • Delete or return customer personal data at the end of the Services, subject to backups, legal requirements, and operational retention obligations.

Controller obligations

  • Provide lawful instructions and ensure a valid legal basis for processing.
  • Obtain all notices, consents, and permissions needed for customer personal data and integrations.
  • Configure user access, permissions, retention, and integration scopes appropriately.
  • Do not submit personal data that the Services are not designed or contracted to process.

Subprocessors

Customer authorizes Hai to use subprocessors to provide the Services, including providers for cloud hosting, databases, AI processing, analytics, email delivery, payment processing, observability, support, and security.

Hai will impose data protection obligations on subprocessors that are materially consistent with this DPA. A subprocessor list is available on request.

International transfers

Where customer personal data is transferred outside the EEA, United Kingdom, or Switzerland, Hai will use appropriate transfer safeguards such as Standard Contractual Clauses or equivalent mechanisms where required.

Security measures

  • Access controls and least-privilege operational practices.
  • Encryption in transit and appropriate protection for stored data.
  • Logging, monitoring, and vulnerability management practices.
  • Separation of customer workspaces and permission-scoped integrations.
  • Incident response, backup, and business continuity practices appropriate to the Services.

Audit and compliance

Hai will make information reasonably necessary to demonstrate compliance with this DPA available to customers, subject to confidentiality, security, and commercial limitations. Formal audit rights may be handled through a separate enterprise agreement.

Appendix: processing details

  • Subject matter: customer personal data processed in Hai workspaces, integrations, agents, automations, and support channels.
  • Purpose: providing, securing, supporting, and improving Hai according to customer instructions.
  • Frequency: continuous while the customer uses the Services.
  • Retention: for the term of the main agreement and any applicable backup, legal, security, or operational retention period.

Contact

Contact us at privacy@usehai.ai or Norrtullsgatan 25D, 113 27 Stockholm, Sweden.