Data processing
Data processing agreement.
v0.1 (draft) · last updated 2026-05-24
Pending legal review.
This page reflects our intended policy and serves as a placeholder so links don't 404. The final, legally-binding version lands before public launch after Legal's formal review. For customer-facing contracts in the interim, contact [email protected].
1. Roles
Customer is the controller of personal data uploaded into Ligarbo. HexxLock Inc. is the processor, acting only on Customer's documented instructions per GDPR Art. 28.
2. Subject matter + duration
HexxLock Inc. processes contact-level personal data (email, phone, name, job title, custom attributes, behavioural events) for the duration of the subscription plus the 30-day grace period after cancellation.
3. Sub-processors
The list of approved sub-processors is maintained at /security. Customer is notified 30 days in advance of any addition, and may object in writing. Sub-processors are bound by DPA terms at least as protective as these.
4. Security
HexxLock Inc. maintains the tier-1 security stack documented at /security — including TLS 1.3 in transit, AES-256 at rest, RLS-based tenant isolation, and 7-year WORM audit retention. Annual third-party penetration test. No SOC 2 or ISO 27001 report exists yet; both are on our roadmap.
5. International transfers
HexxLock Inc. runs on self-hosted infrastructure without a region guarantee. A formal, contractual data-residency or cross-border-transfer commitment is not yet published — contact us if this is a requirement for your organization.
6. Data subject rights
HexxLock Inc. assists Customer in fulfilling access, correction, deletion, portability, and objection requests within 14 working days.
7. Breach notification
HexxLock Inc. notifies Customer without undue delay (and in any event within 72 hours of becoming aware) of a personal-data breach affecting Customer data.
8. Audit + return / deletion
On reasonable notice, Customer may audit HexxLock Inc.'s compliance with this DPA. On termination, Customer may export all customer data within 30 days; after that, data is deleted per the retention policy.