Last updated: August 3, 2026
This Data Processing Addendum ("DPA") supplements the Hivewave Terms of Service or another agreement between Hivewave Inc. ("Hivewave") and the customer identified in that agreement ("Customer"). It applies when Hivewave processes personal data on Customer's behalf in connection with Hivewave AI.
This DPA is incorporated into the agreement without a separate signature when Customer uses a feature that submits Customer Personal Data to Hivewave. If the parties sign a different DPA, the signed version controls.
Definitions and roles
"Customer Personal Data" means personal data contained in Customer Data that Hivewave processes on Customer's behalf. "Data Protection Laws" means privacy and data-protection laws applicable to that processing, including the GDPR, UK GDPR, and applicable US state privacy laws.
Customer is the controller or business and Hivewave is the processor or service provider for Customer Personal Data, except where law requires a different role. Each party is independently responsible for personal data it processes as its own controller.
Customer instructions
Hivewave will process Customer Personal Data only to provide, secure, support, and maintain the service; comply with the agreement and this DPA; follow Customer's documented product settings and instructions; and comply with law. The agreement, Customer's configuration, authorized support requests, and use of service features are documented instructions.
Hivewave will notify Customer if it reasonably believes an instruction violates Data Protection Laws, unless law prohibits notice. Customer is responsible for lawful instructions, notices, permissions, legal bases, targeting decisions, and use of service outputs.
Processing details
- Subject matter and purpose.Providing AI-assisted brand knowledge, store connections, contact import and enrichment, partner discovery, outreach drafting and sending, reply processing, attribution, billing support, security, and related services selected by Customer.
- Duration.For the term of the agreement and afterward only as described in this DPA, the Privacy Policy, Customer instructions, and applicable retention obligations.
- Data subjects.Customer users and team members; Customer's buyers and contacts; uploaded contacts; prospective business partners and their personnel; communication recipients; and other people whose information Customer submits or directs Hivewave to process.
- Data categories.Identity and business contact details; account and role information; store, customer, purchase-summary and consent data; brand and product content; uploaded files; prospect and enrichment data; outreach and mailbox message content; social connection and attribution data; suppression choices; usage, device, support, and billing-related information.
- Sensitive data.OAuth credentials and authentication data are treated as sensitive operational data. The service is not designed for health, biometric, government identifier, precise geolocation, children's, or other special-category data unless expressly agreed in writing.
Confidentiality and access
Hivewave will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their responsibilities. Hivewave will maintain access controls and review access appropriate to the risk.
Security measures
Hivewave will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, alteration, or disclosure.
- Encryption of supported connector credentials at rest and encrypted transport for service communications.
- Tenant and organization scoping, authentication, authorization, least-privilege access, and secret management.
- Logging controls and redaction intended to reduce exposure of tokens, email addresses, prompts, and raw payloads.
- Backup, recovery, vulnerability, change-management, incident-response, and vendor-review practices appropriate to the service.
- Data minimization and mailbox capture filters intended to retain only messages relevant to Customer's Hivewave outreach workflows.
Subprocessors
Customer gives general authorization for Hivewave to use subprocessors to provide the service. Hivewave will require subprocessors to protect Customer Personal Data under terms appropriate to their role. Contact contact@hivewave.ai for the current provider list applicable to your account.
Hivewave will notify Customer of a material new subprocessor before or when it begins processing, using an available notice mechanism as the service matures. Customer may object on reasonable data-protection grounds by contacting contact@hivewave.ai within 15 days after notice. The parties will work in good faith on a commercially reasonable solution; if none is available, Customer may stop the affected feature.
International transfers
Where Customer Personal Data is transferred from the EEA, Switzerland, or the United Kingdom to a country without an applicable adequacy decision, the parties incorporate the then-current European Commission Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.
For controller-to-processor transfers, Module Two applies; for processor-to-processor transfers, Module Three applies. Customer is data exporter and Hivewave is data importer. The optional docking clause applies, subprocessor authorization is general, the objection period is 15 days, and the competent supervisory authority and governing-law selections are those permitted for Customer's establishment or otherwise required by the clauses. The processing description and safeguards in this DPA form the relevant annexes.
Data-subject requests
Taking into account the nature of processing, Hivewave will provide reasonable assistance for Customer to respond to access, correction, deletion, restriction, portability, objection, and opt-out requests. If Hivewave receives a request relating to Customer Personal Data, it will ordinarily direct the requester to Customer and notify Customer where legally permitted. Customer remains responsible for the response.
Security incidents
Hivewave will notify Customer without undue delay after confirming a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Notice will include available information reasonably needed for Customer's obligations. Notification is not an admission of fault. Customer is responsible for notices to regulators and individuals unless law assigns that duty to Hivewave.
Assistance and assessments
Considering the nature of processing and information available to Hivewave, Hivewave will provide reasonable assistance with security obligations, data-protection impact assessments, and regulator consultations. On reasonable request, Hivewave will provide information needed to demonstrate compliance with this DPA.
Any audit must be no more than once annually unless required by a regulator or following a confirmed incident, use an independent qualified auditor, protect confidentiality, avoid disrupting the service, and be at Customer's expense unless the audit identifies a material Hivewave breach.
Return and deletion
At the end of the service or on a valid instruction, Hivewave will delete or return Customer Personal Data within a commercially reasonable period, subject to technical feasibility, backup rotation, suppression obligations, security records, legal holds, and legal retention requirements. Where data must be retained, Hivewave will isolate it from further service processing except for the required purpose.
Connector removal and Shopify privacy webhooks may trigger more specific deletion behavior described in the Privacy Policy. Customer should export needed information before termination where an export feature is available.
US service-provider commitments
Where US state privacy law applies, Hivewave acts as Customer's service provider or contractor for Customer Personal Data. Hivewave will not sell or share it for cross-context behavioral advertising; retain, use, or disclose it outside the business purposes specified in the agreement except as permitted by law; or combine it with personal information from unrelated sources except as legally permitted to provide the service. Customer may take reasonable steps to verify compliance and require remediation of unauthorized use.
Order of precedence and contact
This DPA controls over conflicting data-processing terms in the agreement, while the Standard Contractual Clauses control over both where applicable. Other liability terms in the agreement apply to this DPA unless prohibited by Data Protection Laws.
Questions, objections, and requests concerning this DPA may be sent to contact@hivewave.ai.