Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between Rad Soft, Inc. ("Harkly", "we") and the customer identified in the order or the account ("Customer", "you") for the Harkly service (the "Agreement"). It applies where Harkly processes personal data on your behalf and the GDPR, the UK GDPR, or a similar law requires a written processing contract.

Self-hosted installs: you run the software on your own infrastructure and Harkly processes no personal data on your behalf, so this DPA does not apply unless you use Harkly Cloud.

1. Roles

You are the controller (or a processor acting for your own customers) of the personal data you send to Harkly. Harkly is your processor. Where Harkly processes your admins' account data to run the service — sign-in email, name, audit trail — it does so as an independent controller under its privacy policy.

2. What is processed

  • Data subjects: your end users (the people who send feedback, open conversations, answer surveys) and your admins.
  • Categories: identifiers you pass through identify (a user id, email, name, company), the content of feedback, conversations and survey answers, product events you choose to track, push tokens, and technical data (IP address, user agent) kept for security and rate limiting.
  • Special categories: none intended. Do not send them.
  • Duration: for the life of your account, then per §8.

3. Instructions

Harkly processes personal data only to provide the service as described in the documentation, as configured by you in the dashboard and the API, and as required by law. If Harkly believes an instruction breaks the law, it will tell you and may pause that instruction.

4. Confidentiality

Every person Harkly authorizes to process your data is bound by confidentiality. Access to production is limited to the engineers who operate it, requires two-factor authentication, and is logged.

5. Security

Harkly maintains the measures described in security.md: encryption in transit and at rest, per-tenant isolation enforced in the application layer, an append-only audit log, secrets kept out of source and logs, review gates on every deploy, and daily backups. Harkly may improve these measures over time and will not reduce their overall level.

6. Sub-processors

Harkly uses the sub-processors listed in subprocessors.md. Harkly gives 30 days' notice of a new sub-processor by email to the workspace owners. You may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected service and receive a pro-rated refund.

7. Data subject rights and assistance

The dashboard and the API let you export or delete any end user yourself (GET /customers/:id/export, DELETE /customers/:id). Where a data subject contacts Harkly directly, Harkly will forward the request to you and not respond on its own except to confirm it was passed on. Harkly assists you with impact assessments and consultations with authorities where the information is only available to Harkly, at cost for anything beyond a reasonable effort.

8. Deletion and return

You can export everything at any time. On termination, Harkly deletes your data within 30 days of the account closing, and from backups within a further 30 days, unless a law requires retention. Deletion is logged.

9. Personal-data breach

Harkly notifies the workspace owners without undue delay, and in any case within 48 hours of confirming a breach affecting your data, with what is known at the time and updates as the investigation proceeds.

10. Audits

Harkly provides its security documentation and answers to a reasonable security questionnaire once a year on request. If those are not enough to meet a legal requirement, you may audit at your cost with 30 days' notice, during business hours, under confidentiality, no more than once a year.

11. International transfers

Harkly Cloud is hosted in the region you choose when creating the workspace (see regions.md). Where your data is transferred outside the EEA, the UK or Switzerland — including to sub-processors in the United States — the transfer relies on the EU Standard Contractual Clauses (module two, controller to processor, or module three where you are a processor), the UK International Data Transfer Addendum, and the Swiss FDPIC amendments, which are incorporated by reference. The parties' details in the annexes are those of the Agreement; the description of processing is §2; the security measures are §5.

12. Liability and order of precedence

Liability under this DPA is subject to the limits in the Agreement. Where this DPA and the Agreement conflict on data protection, this DPA governs.

13. Term

This DPA lasts as long as Harkly processes personal data for you.


Signed electronically by accepting the Agreement. A countersigned copy is available on request from privacy@harkly.app.