Data Processing Agreement

Last updated: July 13, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Hummingdeck, MB, company code 308055336, with its registered office at Vilkpėdės g. 22, LT-03151 Vilnius, Lithuania (the "Processor"), and the customer that has subscribed to the HummingDeck service (the "Controller"). It applies whenever HummingDeck processes Personal Data on behalf of the Controller in connection with the service.

By using HummingDeck, the Controller accepts the terms of this DPA. A signed counterpart is available on request from hello@hummingdeck.com.

1. Definitions

Terms used in this DPA have the meanings given in the GDPR (Regulation (EU) 2016/679). Specifically:

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Controller — the customer who determines the purposes and means of processing.
  • Processor — HummingDeck, processing Personal Data on behalf of the Controller.
  • Sub-processor — any third party engaged by HummingDeck to process Personal Data, listed at hummingdeck.com/sub-processors.
  • Data Subject — the natural person to whom the Personal Data relates, including the Controller's employees, contacts, and the recipients who view documents shared via HummingDeck ("Document Viewers").

2. Scope and Roles

HummingDeck acts as a Processor on behalf of the Controller for all Personal Data processed in connection with the service, including:

  • Account holders and team members the Controller adds to a workspace.
  • Contacts and leads the Controller imports or creates.
  • Document Viewers who open links shared by the Controller.
  • Engagement events generated by Document Viewers (page views, time on page, return visits, location at country level, IP-derived signals).

The Controller remains responsible for the lawfulness of the processing, the choice of lawful basis under Article 6 GDPR, and the rights of Data Subjects.

3. Controller's Obligations

The Controller represents and warrants that:

  • It has a valid lawful basis under GDPR Article 6 for the processing it instructs HummingDeck to carry out.
  • It has provided all required notices to Data Subjects under GDPR Articles 13 and 14, including informing Document Viewers about the engagement tracking carried out via HummingDeck links. The Controller is solely responsible for this disclosure, whether via its own privacy policy, the email or message accompanying the share link, or any other appropriate channel.
  • It will not instruct HummingDeck to process Personal Data in violation of applicable data protection law.
  • Unless the parties agree otherwise in writing, it will not upload, share, or otherwise process through the service any special categories of personal data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR), or personal data of children below the applicable age of digital consent. The Controller is solely responsible if it does so.

To support the Controller in meeting its disclosure obligation, HummingDeck makes the following available:

  • A public privacy policy at hummingdeck.com/privacy describing what is collected from Document Viewers and on what basis.
  • Template language the Controller may adopt or adapt for its own privacy policy, available on request.
  • A public sub-processor list at hummingdeck.com/sub-processors.

4. HummingDeck's Obligations

As Processor, HummingDeck shall:

  • Process Personal Data only on documented instructions from the Controller, including those given through the use of the service itself.
  • Ensure persons authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures (Section 5).
  • Engage sub-processors only under written contracts that impose equivalent data-protection obligations, and notify the Controller of intended changes per Section 6.
  • Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to Data Subject requests under GDPR Chapter III.
  • Assist the Controller with security, breach notification, data protection impact assessments, and prior consultation obligations under GDPR Articles 32 to 36.
  • Notify the Controller without undue delay (and within 72 hours where feasible) after becoming aware of a Personal Data Breach affecting the Controller's data.
  • At the Controller's choice, delete or return all Personal Data after the end of the service, and delete existing copies unless retention is required by law.
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow audits or inspections by the Controller or an auditor mandated by the Controller (subject to Section 7).

5. Security Measures

HummingDeck implements and maintains appropriate technical and organizational measures, including:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest (Google Cloud Storage default encryption).
  • Access controls based on least-privilege principles, with logging of administrative access.
  • Authentication via Google Firebase with secure session handling.
  • Bot and abuse-detection systems to filter automated traffic from engagement analytics.
  • Backup and disaster-recovery procedures.
  • Regular review of security practices.

HummingDeck is not currently SOC 2 certified. Customers requiring formal certification should contact hello@hummingdeck.com for the current security questionnaire and timeline.

6. Sub-processors

The Controller authorizes HummingDeck to engage the sub-processors listed at hummingdeck.com/sub-processors. HummingDeck will provide at least 30 days' prior notice to the Controller before adding or replacing any sub-processor that processes Controller's Personal Data, by:

  • Updating the public sub-processor list, and
  • Notifying the workspace owner by email if the change materially affects the processing.

If the Controller objects in good faith to a new sub-processor on data-protection grounds within 30 days of notice, the parties will work in good faith to address the concern. If no resolution is reached, the Controller may terminate the affected portion of the service for convenience.

7. Audits

HummingDeck will make available, on reasonable notice and no more than once per 12-month period (or more often if required by a regulator):

  • Its current Records of Processing Activities (Article 30 documentation).
  • Information on its security measures and any third-party assessments.
  • The opportunity for a remote audit (questionnaire-based or video conference) at the Controller's expense.

On-site inspections are permitted only where required by applicable law or by binding regulator order, on reasonable notice and at the Controller's expense.

8. International Transfers

The Controller acknowledges that some sub-processors are located outside the European Economic Area, primarily in the United States. For such onward transfers from HummingDeck (as Processor) to a sub-processor (acting as a further processor), HummingDeck relies on the European Commission's Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914, Module Three (Processor-to-Processor), incorporated into its agreements with the relevant sub-processors, supplemented by the technical and organizational measures described in Section 5.

Where required, and to the extent the Controller itself transfers Personal Data to HummingDeck from outside the EEA, the parties agree that the relevant module of the Standard Contractual Clauses applies between them, with HummingDeck as data importer.

United Kingdom. For transfers subject to UK data protection law, the parties incorporate the UK International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner's Office (the "UK Addendum"). The EU SCCs apply as amended by the UK Addendum, and references to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018.

Switzerland. For transfers subject to Swiss data protection law, the EU SCCs apply with the following adjustments: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for transfers governed exclusively by Swiss law; references to the GDPR are understood as references to the Swiss Federal Act on Data Protection (FADP); and the SCCs also protect the data of legal entities until the entry into force of the revised FADP removes that requirement.

9. California Service-Provider Terms

This Section applies where HummingDeck processes personal information of California residents on behalf of the Controller and to which the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies. For that processing, HummingDeck acts as a service provider as defined by the CCPA, and the following terms apply:

  • HummingDeck will not sell or share (as those terms are defined in the CCPA) the personal information it processes on the Controller's behalf.
  • HummingDeck will not retain, use, or disclose that personal information for any purpose other than the specific purpose of performing the service, or as otherwise permitted by the CCPA, including retaining, using, or disclosing it for a commercial purpose other than providing the service.
  • HummingDeck will not combine that personal information with personal information it receives from, or on behalf of, other persons, except as permitted by the CCPA.
  • HummingDeck will not process that personal information outside the direct business relationship between the parties.
  • HummingDeck certifies that it understands and will comply with these restrictions.

The Controller may take reasonable and appropriate steps to help ensure that HummingDeck uses the personal information in a manner consistent with the Controller's obligations under the CCPA.

10. Deletion and Return

Upon termination of the service, the Controller may, within 30 days, request a structured export of its data via the application or via support. After 30 days, HummingDeck will delete all Controller Personal Data from production systems within a further 30 days, except where retention is required by law (e.g., billing records). Backup copies are retained according to standard backup-rotation schedules and overwritten in due course.

11. Liability

Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in HummingDeck's Terms of Service, including the aggregate liability cap. Any reference in this DPA to a limitation of liability in the underlying agreement is a reference to that cap. This applies to all claims in the aggregate under both the underlying agreement and this DPA.

12. Order of Precedence

In the event of a conflict between this DPA and the underlying agreement (including HummingDeck's Terms of Service), this DPA prevails to the extent of the conflict and only with respect to the processing of Personal Data.

13. Changes to this DPA

HummingDeck may update this DPA from time to time to reflect changes in applicable law or in our processing practices. Material changes will be communicated to the workspace owner by email at least 30 days before they take effect. Continued use of the service after the effective date constitutes acceptance.

14. Contact

Questions about this DPA, requests for a signed counterpart, or formal Data Subject requests should be sent to hello@hummingdeck.com.

Annexes

These Annexes form part of the DPA and supply the details required by the Standard Contractual Clauses referenced in Section 8.

Annex I — Description of Processing

A. Parties. The data exporter is the Controller (the customer subscribing to HummingDeck). The data importer is the Processor, Hummingdeck, MB, company code 308055336, with its registered office at Vilkpėdės g. 22, LT-03151 Vilnius, Lithuania.

B. Description of the transfer.

  • Categories of data subjects: the Controller's authorized users and team members; the Controller's contacts and leads; and Document Viewers who open documents shared by the Controller.
  • Categories of personal data: names, email addresses, and company or role information; account and profile information; the content of documents the Controller chooses to upload and share; engagement events (pages viewed, time spent per page, return visits, completion); and technical data (IP address, approximate location at country level, browser and device information, and a short-lived browser fingerprint).
  • Special categories of data: none are intended to be processed. The Controller must not include such data in shared documents (Section 3).
  • Frequency of the transfer: continuous, for the duration of the service.
  • Nature and purpose: hosting documents shared by the Controller and providing engagement analytics, deal rooms, and related features to the Controller.
  • Duration of processing: for the term of the Controller's subscription and until deletion in accordance with Section 10; identifiable Document Viewer data is anonymized after 12 months.

C. Competent supervisory authority. The Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, VDAI), or the Controller's lead supervisory authority where the transfer is governed by the Controller's establishment in another EEA state.

Annex II — Technical and Organizational Measures

HummingDeck implements the measures described in Section 5, summarized here for the purposes of the Standard Contractual Clauses:

  • Encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (Google Cloud Storage default encryption).
  • Access controls based on least-privilege principles, with logging of administrative access.
  • Authentication via Google Firebase with secure session handling.
  • Bot and abuse-detection systems that filter automated traffic from engagement analytics.
  • Pseudonymization and anonymization of identifiable Document Viewer data after the applicable retention period.
  • Backup and disaster-recovery procedures.
  • Engagement of sub-processors only under written contracts imposing equivalent data-protection and security obligations.
  • Regular review of security practices.

Annex III — Sub-processors

The Controller has authorized the sub-processors listed, and kept current, at hummingdeck.com/sub-processors. That list forms Annex III to the Standard Contractual Clauses and specifies each sub-processor's name, processing activity, and location. Changes are notified in accordance with Section 6.

Template language for Controllers

To help Controllers meet their obligation to inform Document Viewers about engagement tracking (Section 3), the following language may be adopted or adapted into the Controller's own privacy policy or the message accompanying a HummingDeck-shared link:

"When you open this document, [Controller name] uses HummingDeck (a third-party document-engagement platform) to record certain technical information for analytics and security purposes, including the date and time of access, the pages you view, time spent per page, return visits, your IP address, approximate location at country level, browser and device information, and a short-lived browser fingerprint. This data is processed on our behalf to help us understand engagement and is not sold or shared with anyone outside the service. For more information, see HummingDeck's privacy policy at hummingdeck.com/privacy."

Adapt as appropriate for your context. This template is provided for convenience and does not constitute legal advice.