Legal
Data Processing Agreement
Governs personal data that HAKKIU processes on behalf of its customers, under GDPR Article 28.
Last updated: 28 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and HAKKIU ("HAKKIU", "Processor") for use of the Service. It applies where HAKKIU processes personal data on the Controller's behalf. A countersigned copy is available on request from legal@hakkiu.com.
1. Roles
The Controller determines the purposes and means of processing Customer Data. HAKKIUacts as Processor and processes personal data only on the Controller's documented instructions, including as set out in the agreement and this DPA.
2. Subject matter, nature and purpose
The processing consists of hosting, monitoring, detection, AI analysis, evidence capture and takedown support provided through the Service, for the duration of the agreement.
3. Types of data and categories of data subjects
- Data subjects: the Controller's authorized users; and individuals appearing in monitored content (e.g. sellers or others associated with potentially infringing listings).
- Types of data: contact and account data; marketplace/listing data; and any personal data contained in content submitted to or retrieved by the Service.
4. Processor obligations (Art. 28(3))
- Instructions — process personal data only on the Controller's documented instructions, including for international transfers, unless required by law (in which case we notify the Controller where permitted).
- Confidentiality — ensure persons authorized to process the data are bound by confidentiality.
- Security — implement appropriate technical and organizational measures under Art. 32 (see our Trust & Security page).
- Sub-processing — the Controller grants general authorization to engage sub-processors listed on our Sub-processors page; we impose equivalent data-protection obligations on them, remain liable for their performance, and give notice of changes with an opportunity to object.
- Data-subject requests — assist the Controller, by appropriate measures, in responding to data-subject rights requests.
- Assistance — assist the Controller with security, breach notification, data-protection impact assessments and prior consultation (Art. 32–36).
- Breach notification — notify the Controller without undue delay after becoming aware of a personal-data breach.
- Deletion or return — at the Controller's choice, delete or return personal data at the end of the services, unless retention is required by law.
- Audits — make available information necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and security conditions.
5. International transfers
Where personal data is transferred outside the EEA, the transfer is protected by appropriate safeguards — the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, which are incorporated by reference where they apply.
6. Liability and precedence
Liability under this DPA is subject to the limitations in the agreement. In case of conflict between this DPA and the agreement on data-protection matters, this DPA prevails.
7. Annexes
- Annex A — Processing details: as described in sections 2–3 above.
- Annex B — Technical & organizational measures: see Trust & Security.
- Annex C — Sub-processors: see Sub-processors.
- Annex D — Standard Contractual Clauses: available on request where transfers require them.
8. Contact
To request a signed DPA or discuss data-processing terms, contact legal@hakkiu.com.