This Data Processing Agreement (“DPA”) supplements the BeHooked Terms of Service and applies to enterprise customers and organizations processing personal data subject to European Union (GDPR), UK GDPR, or similar data protection legislation.
1. Scope & Roles
- Customer as Data Controller: Customer determines the purposes and means of processing personal data contained within input prompts, media files, and account metadata.
- BeHooked as Data Processor: BeHooked processes personal data solely on documented instructions from Customer to deliver the services described in the Terms of Service.
2. Data Protection Obligations
BeHooked agrees to:
- Process personal data strictly in accordance with Customer instructions and relevant data protection laws.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (including encryption at rest and in transit).
- Ensure that personnel authorized to process personal data have committed themselves to confidentiality obligations.
- Assist Customer in responding to requests from data subjects exercising their legal privacy rights.
3. Sub-Processors
Customer grants general authorization for BeHooked to engage sub-processors for cloud hosting, infrastructure execution, and payment handling.
- Upstream AI model execution providers operate under strict processing contracts prohibiting model training on customer data.
- BeHooked maintains an up-to-date list of active sub-processors and provides 14 days’ advance notice to Enterprise customers before engaging new sub-processors.
4. Data Transfers & Security Controls
- Data transfers outside the EEA or UK are governed by standard contractual clauses (SCCs) approved by the European Commission.
- BeHooked conducts regular vulnerability scans and maintains strict access control logging across all production infrastructure.
Executing a Signed Copy
Enterprise customers requiring a countersigned copy of this DPA with custom annexes can contact [email protected].