Data Processing Addendum (DPA)

Data Processing Addendum (DPA) | HireHop Equipment Rental Software

Effective Date: 30 September 2026

Applicable Frameworks: UK GDPR, EU GDPR (Regulation (EU) 2016/679), California CCPA/CPRA, ISO/IEC 27001:2022, SOC 2 Type II

This Data Processing Addendum (“DPA”) supplements and forms an integral part of the Master Services Agreement, Terms of Service, or Subscription Agreement (the “Agreement”) between HireHop Software Limited (Company No. 11241806, registered at London North Studios, The Ridgeway, London, NW7 1RP, United Kingdom) (“HireHop”, “Processor”, or “Service Provider”) and the customer entity subscribing to or utilising the HireHop rental management software (“Customer”, “Controller”, or “Business”).

01

Definitions

  • “Applicable Data Protection Law” means all worldwide privacy and data protection legislation applicable to the processing of Customer Data, including the UK Data Protection Act 2018, the UK GDPR, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), and the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”).
  • “Customer Data” means any personal data regarding the Customer’s clients, personnel, inventory, suppliers, or operations uploaded into or processed by the HireHop software platform on behalf of the Customer.
  • “Data Controller”, “Data Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” shall have the meanings given to them under Applicable Data Protection Law.
  • “Sub-processor” means any authorised third-party service provider engaged by HireHop to assist in processing Customer Data under this DPA.
02

Scope, Roles & Processing Instructions

2.1 Role of the Parties: The parties acknowledge and agree that with respect to Customer Data, the Customer acts as the Data Controller and HireHop acts solely as the Data Processor.

2.2 Documented Instructions: HireHop shall process Customer Data exclusively to deliver, maintain, support, and secure the HireHop software services, in accordance with the Customer’s documented instructions, the Agreement, this DPA, and Applicable Data Protection Law.

2.3 Details of Processing:

  • Subject Matter & Duration: Provision of cloud-based equipment rental and inventory software for the subscription term plus 6 months post-termination retention.
  • Categories of Data Subjects: Customer’s staff, crew, drivers, client contacts, and event personnel.
  • Categories of Personal Data: Names, business contact details (email, phone, billing address), job roles, transactional rental records, and audit logs. No special category (sensitive) personal data is processed.
03

Artificial Intelligence (AI) Restrictions & Customer-Initiated AI Tools

3.1 Prohibition on AI Model Training: HireHop explicitly warrants and represents that it does not use, ingest, or process Customer Data, confidential files, rental records, or tenant telemetry to train, retrain, fine-tune, or optimise any artificial intelligence (AI), machine learning (ML), or large language model (LLM) algorithms.

3.2 No Unauthorised Third-Party AI Ingestion: HireHop will never disclose or transmit Customer Data to third-party public foundation models or generative AI services without the Customer’s prior, express, written opt-in consent.

3.3 Customer-Initiated AI Plugins, Extensions & API Connectors: Where the Customer (or its authorised users) utilises, connects, or deploys third-party AI tools, AI-generated plugins, custom scripts, browser extensions, or automated LLM agents to query, extract, or interact with Customer Data via the HireHop API, the Customer acts strictly as the Data Controller directing such transfer. The Customer assumes sole responsibility for ensuring that any such third-party AI provider complies with Applicable Data Protection Law and maintains adequate security standards. HireHop disclaims all liability for the processing, retention, or disclosure of Customer Data once accessed or ingested by Customer-authorised external AI plugins or tools.

04

Technical & Organisational Security Measures (TOMs)

HireHop designs, implements, and maintains technical and organisational measures aligned with ISO/IEC 27001:2022 and SOC 2 Type II standards:

  • Encryption in Transit: Mandatory SSL/TLS (minimum TLS 1.2 / TLS 1.3) with strong ciphers across all web applications and APIs.
  • Encryption at Rest: All customer tenant databases, file stores, and backups are encrypted using industry-standard AES-256 managed via AWS Key Management Service (KMS).
  • Network & Server Isolation: Database and application clusters are isolated within private subnets of an Amazon Web Services (AWS) Virtual Private Cloud (VPC), protected behind stateful firewalls with zero direct public ingress.
  • Endpoint Fleet Security: All personnel workstations and laptops are centrally monitored via ManageEngine Mobile Device Manager Plus (MDM Plus) with enforced BitLocker/FileVault disk encryption, 5-minute screen locks, and real-time telemetry.
  • Personnel Confidentiality: All personnel authorised to process Customer Data are bound by strict contractual confidentiality agreements and regular information security awareness training.
05

Sub-Processors

5.1 Authorised Core Sub-Processors: The Customer grants general authorisation to HireHop to engage the following core Sub-processors:

Sub-ProcessorService ProvidedProcessing LocationCompliance & Transfer Safeguards
Amazon Web Services (AWS)Cloud infrastructure, hosting, RDS MySQL databases & storageSweden (EU / Stockholm) & United States (US)ISO 27001, SOC 2 Type II, Standard Contractual Clauses (SCCs), EU-US DPF
Stripe, Inc.Payment card processing & merchant subscription billingGlobal / United States (US)ISO 27001, SOC 2 Type II, Standard Contractual Clauses (SCCs), EU-US DPF

5.2 30-Day Advance Notification of Changes: If HireHop intends to appoint any new Sub-processor or replace an existing provider with access to Customer Data, HireHop will provide at least thirty (30) days’ advance written notice via email or software dashboard announcement.

5.3 Right to Object: The Customer has the contractual right to object to any new Sub-processor on legitimate data protection grounds within the 30-day notice period. If the parties cannot resolve the objection, the Customer may terminate the affected service without penalty.

06

International Data Transfers

6.1 Hosting Regions: Customer Data is hosted within AWS secure cloud regions located in Sweden (EU) and the United States (US).

6.2 Transfer Mechanisms: Where Customer Data originating from the UK, EEA, or Switzerland is transferred to US-based infrastructure, HireHop ensures appropriate safeguards:

  • Execution of the European Commission’s approved Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum.
  • Verification of third-party infrastructure certification under the EU-US Data Privacy Framework (DPF) and the UK Extension to the EU-US DPF.
  • Enforcement of technical measures including AES-256 encryption at rest and in transit.
07

7. Personal Data Breach Notification (72-Hour Commitment)

In the event of a confirmed Personal Data Breach impacting Customer Data, HireHop shall notify affected Customers and relevant supervisory authorities (such as the UK Information Commissioner’s Office – ICO) without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach. HireHop will provide timely details on the nature of the breach, affected records, containment measures, and remediation guidance.

08

Data Subject Rights & Customer-Directed Exports (CDC)

8.1 Assistance: Taking into account the nature of the processing, HireHop provides technical controls within the software to enable the Customer to respond to requests from Data Subjects exercising their statutory rights (access, rectification, erasure, restriction, and portability).

8.2 Customer-Directed Data Exports: If the Customer utilises Change Data Capture (CDC) or direct database export features, data is transmitted via SSL or directly to a customer-managed static IP address. Upon data successfully exiting the HireHop cloud infrastructure, the Customer (as Data Controller) assumes sole responsibility for its security, retention, and ongoing compliance.

09

Data Retention, Purging & Irreversible Destruction

9.1 Post-Termination Retention Grace Period (6 Months): Upon termination or expiry of the subscription, HireHop retains the Customer’s account and data in a dormant, read-only state for six (6) months. During this window, the Customer may request an export archive or reactivate the subscription.

9.2 Irreversible Purge & Cryptographic Destruction (Max 60 Days): Following the expiration of the 6-month retention period (or upon a valid early erasure request by the Customer), all Customer Data is irreversibly purged and overwritten from live production databases within thirty (30) days. Associated data within encrypted, isolated disaster recovery backup snapshots is permanently eliminated and cryptographically destroyed within a maximum timeframe of sixty (60) days.

9.3 Destruction Certification: HireHop will provide a formal Certificate of Data Destruction upon written request confirming the completion of live data purging.

10

Audit & Third-Party Assurance

To satisfy GDPR Article 28 verification without compromising multi-tenant security, HireHop makes available to Customers upon request:

  • Current ISO/IEC 27001:2022 Statement of Applicability (SoA) and certification documentation;
  • Executive summaries of annual external penetration tests; and
  • SOC 2 Type II compliance reports.
11

Compliance Contacts & EU Representative