Legal
Data Processing Agreement
Last updated: 22 June 2026
Effective: 22 June 2026
Status: Template draft. A counter-signed copy is required for production B2B engagements — contact legal@hhsholding.com to execute.
1. Parties
This Data Processing Agreement supplements the agreement between HHS Holding B.V. (Chamber of Commerce — pending registration), trading as Ecombase (Processor, Ecombase, we), and the customer entity using Ecombase under the relevant subscription terms (Controller, Customer, you), in respect of any personal data the Processor handles on behalf of the Controller (the Processed Data).
2. Subject matter and duration
Ecombase processes Personal Data on behalf of the Controller for the sole purpose of delivering the subscribed services (ecommerce operations dashboard, support inbox, AI-assisted marketing tooling). Processing continues for the duration of the subscription, and for a wind-down period of up to 30 days following termination during which data is exported and permanently deleted.
3. Nature and purpose of processing
- Operational dashboards: storing order, ad-spend, P&L and product metadata fetched on behalf of the Customer from connected platforms (Shopify, Meta Ads, Google Ads, Pinterest, TikTok, Windsor.ai).
- Customer support inbox: ingesting emails sent to the connected Customer mailbox (Gmail / Microsoft 365), storing ticket history, generating AI-assisted reply drafts.
- Team collaboration: tasks, notes, mentions, notifications.
4. Categories of data and data subjects
Data subjects: (a) Customer authorised users, (b) end customers of Customer stores.
Categories of personal data:
- For authorised users: name, email address, IP address, user-agent, OAuth identity claims, session activity log.
- For end customers of Customer stores: name, email address, order history, shipping address, phone number, customer-supplied checkout notes, support message bodies.
No special-category data (Art. 9 GDPR) is intentionally processed. The Controller is responsible for ensuring its end customers do not submit special-category data through support channels.
5. Security measures (Art. 32)
- Encryption in transit (TLS 1.2+) for all customer and end-customer interactions.
- Encryption at rest at the database layer (Neon Postgres) plus application-layer AES-256-GCM encryption for OAuth tokens, API keys, and Shopify access tokens.
- Strict tenant isolation: workspace-scoped data is queried only via team-aware access helpers; no cross-tenant read paths exist.
- Authentication via Google OAuth with mandatory token rotation.
- Audit log (180-day retention) of every administrative action, login, ticket-touch and product-status change.
- Rate limiting on AI endpoints prevents resource exhaustion.
6. Sub-processors
Current sub-processors are listed on the Privacy Policy and updated as the service evolves. The Controller is notified of material changes at least 14 days before activation, and may object in writing — in which case Ecombase will provide alternative routing or accept termination of the affected service line.
7. Assistance with data-subject rights
Ecombase provides self-service tooling for the Controller to fulfil GDPR Articles 15, 16, 17 and 20 requests directly through the dashboard (data export, account deletion, audit log viewer). For complex requests, support is available via privacy@hhsholding.com within 5 business days.
8. Breach notification
Ecombase will notify the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting the Controller data, providing the information required under Art. 33(3) GDPR.
9. Audit rights
Once per calendar year, with at least 30 days of written notice, the Controller may request a written report on Ecombase processing practices. On-site audits require mutual agreement and reasonable rate reimbursement.
10. International data transfers
Personal Data is processed primarily within the EU (Neon Frankfurt, Vercel EU regions where available). Where sub-processors operate outside the EU (e.g. Anthropic US, Vercel global edge), Standard Contractual Clauses (Module 2 — Controller-to-Processor and Module 3 — Processor-to-Processor) apply.
11. Termination and return
Upon termination, all Processed Data is either returned in machine-readable form (JSON export) or permanently deleted within 30 days, at the Controller option. Anonymised billing and audit records may be retained for legal obligations (e.g. Dutch tax law — 7-year retention).
12. Liability
Liability is capped per the master subscription agreement. This DPA does not modify the cap.
Signing
To execute this DPA for your organisation, email legal@hhsholding.com with your company name, registration number, and the email address of the person authorised to sign. We countersign and return a PDF within 5 business days.