Data processing agreement
How Hebno processes personal data on your organisation's behalf as a processor under the GDPR.
Last updated 16 August 2026
This is Hebno's standard data processing agreement. Acceptance of the terms of service incorporates it for business use. Enterprise customers may request a signed version with custom annexes.
1. Parties, roles, and incorporation
This data processing agreement ("DPA") forms part of the agreement between Hebno("Hebno", "Processor") and the subscribing organisation ("Customer", "Controller"). It applies whenever Processor processes personal data on Customer's behalf in the Service. It is intended to meet Article 28 of the GDPR and the equivalent UK GDPR provisions.
- Controller- Customer decides why and how personal data of its users and, where it submits such data, its clients' personnel is processed in the Service.
- Processor - Hebno processes that data only on documented instructions, to run the platform.
Where Hebno acts as controller (website, sales, billing for Customer's account with us), the privacy policy applies instead of this DPA.
2. Definitions
"Customer Personal Data" means personal data that Customer or its users submit to the Service, or that Processor generates on Customer's behalf while providing the Service (including prompts, attachments, model outputs, membership data, and usage records tied to named users).
"Service" means the Hebno platform described in the terms of service. Capitalised terms not defined here have the meaning in those Terms. "GDPR" includes, where it applies, the UK GDPR.
3. Subject matter, duration, nature, and purpose
Processor provides the Service for the term of the main agreement: source-backed research and drafting from approved sources and firm knowledge, with review in the product, direct connections to enabled model providers, usage and cost visibility, role-based access, and platform hosting in the EU or the US as Customer selected when the workspace was created.
Processing includes collection, storage, organisation, retrieval, transmission, restriction, and deletion of Customer Personal Data as needed to perform the Service. Processor will not use Customer Personal Data to train AI models, and will not permit a subprocessor to do so except as that provider's own terms require for the models Customer has switched on (Customer remains responsible for those provider terms).
4. Categories of data subjects and data
Data subjects
Customer's employees, contractors, and authorised users; and, where Customer submits such data, individuals related to Customer's clients (for example names or contact details in a brief or attached file).
Categories of personal data
- Identification and contact data (name, email, role).
- Account, authentication, and organisation membership data.
- Prompts, uploaded files, material retrieved from a connected source, and model outputs.
- Usage metadata, credit and cost records, and budget assignments.
- Sign-in events, administrative changes, and usage records.
- Encrypted provider API keys Customer supplies for direct inference.
- Credentials if a user connects a third-party or custom connector.
Customer is responsible for a lawful basis, transparency to data subjects, and the accuracy of instructions. Customer must not submit special category data or data relating to children unless it has a lawful basis and has instructed Processor in writing to process it. The Service is not designed for that processing as a default.
5. Customer instructions
Processor processes Customer Personal Data only on documented instructions: configuration of the Service, the Terms, this DPA, and any order form, unless EU, Danish, or other applicable law requires processing. If law requires processing and notice is not prohibited, Processor will tell Customer before complying where reasonably possible.
Instructions include: the EU or US hosting choice recorded at workspace creation; which models are enabled; whether Customer uses its own provider API keys; roles, teams, and budgets; connecting third-party or custom connectors; searching or attaching material from those sources; and uploading files.
Processor will inform Customer without undue delay if, in Processor's opinion, an instruction infringes the GDPR. Processor may pause the affected processing until Customer confirms or amends the instruction.
6. Direct model provider connections
When Customer enables a model, Processor transmits the prompt (and any retrieved or attached content used in that turn) over a direct API connection to that provider and returns the response. Each enabled provider is a separate subprocessor. Data is not sent to other model providers except as required to deliver the feature Customer selected (for example Auto routing among models Customer has allowed).
If Customer supplies its own API keys, Customer remains party to its agreement with that provider. Processor uses the keys only to route requests and to record usage as configured. Keys are encrypted at rest.
7. Connectors and uploads
Customer may connect third-party systems and custom connectors. Processor searches and retrieves material a user or the Service is permitted to use, under the permissions that account already has. Retrieved material used in a conversation is stored in the organisation's private storage so the conversation remains usable. Custom connectors that call Customer's own systems remain under Customer's control.
Files dragged into chat go to the same private storage, encrypted at rest. They stay on the conversation unless Customer deletes them or the workspace data is deleted under Section 16.
8. Confidentiality and personnel
Processor ensures persons authorised to process Customer Personal Data are bound by confidentiality and trained on data protection and security appropriate to their role. Access for support is limited to what is needed to fix a problem, is not used to browse customer work as a matter of course, and is subject to confidentiality.
9. Security measures
Processor maintains measures appropriate to the risk, including:
- Platform hosting and primary storage in the EU or the US, as Customer selected when the workspace was created.
- No use of Customer Personal Data to train models by Hebno.
- AES-256 encryption at rest; TLS 1.2 or higher in transit.
- Owner, admin, and member roles. Connected sources keep the permissions those accounts already have.
- Records of sign-in, administrative changes, and usage. This is not a complete log of every action in the product.
- Encryption of Customer API keys at rest.
- Incident response and periodic review of privileged access.
A public overview is at hebno.com/security. That page does not replace this DPA.
10. Subprocessors
Customer grants general authorisation for the subprocessors listed below. Processor will tell Customer of intended additions or replacements at least 30 days in advance, by email to the administrator on file or by notice in the product, and will allow objection on reasonable data-protection grounds. If the parties cannot resolve an objection, Customer may terminate the affected part of the Service without a penalty attributable to that component.
Processor will impose data-protection obligations on subprocessors that are no less protective than this DPA, so far as they apply to the subcontracted processing. Processor remains liable to Customer for subprocessor performance as required by applicable law.
Platform infrastructure
These providers host and operate the Hebno application. They receive Customer Personal Data as needed to run the platform (for example the database, encrypted file storage, authentication, email, and billing). They do not run model inference.
Optional connectors
Customer may connect third-party systems and custom connectors. Those providers are used only when that source is connected. Hebno searches and retrieves material the user or the Service is permitted to use, under the permissions that account already has. Material used in a conversation is stored in the organisation's private storage. Custom connectors that call Customer's own systems remain under Customer's control.
AI model providers (direct connection)
When you enable a model, inference requests are sent directly to that provider's API. Each enabled provider is a separate subprocessor and only receives data for the models you have turned on. Models are off by default.
OpenAI, Anthropic, and xAI process inference in the United States. Google may process in the US, the EU, or other regions it operates. Mistral can process in the EU. DeepSeek processes in China. Enabling a provider is your instruction to send prompts, retrieved or attached content used in that turn, and responses to that provider's locations. You can keep inference in the EU by enabling only EU-resident providers.
11. International transfers
Platform data for a workspace is hosted in the region Customer selected at creation (EU or US). Choosing US hosting is Customer's instruction to store and process that workspace's platform data in the United States.
Inference runs where the enabled provider runs. OpenAI, Anthropic, and xAI process in the United States. Google may process in the US, the EU, or other regions it operates. Mistral can process in the EU. DeepSeek processes in China. Enabling a provider is Customer's instruction to transfer prompt, retrieved or attached content used in that turn, and response data to that provider's locations. Customer can keep inference in the EU by enabling only EU-resident providers.
Ancillary services (including edge delivery, email, and payments) may process limited data outside the selected hosting region, as listed under subprocessors.
For transfers Processor arranges from the EEA, Processor will use appropriate safeguards, including the European Commission's standard contractual clauses where required. For transfers from the UK, Processor will use the UK International Data Transfer Addendum to those clauses, or another mechanism approved by the UK Information Commissioner. Processor will make information reasonably available for Customer's transfer assessments on request.
DeepSeek processes in the People's Republic of China. That jurisdiction does not have an EU adequacy decision. If Customer enables DeepSeek, Customer accepts that prompt and response data will be processed there under that provider's terms, and that equivalent protection cannot be guaranteed. Do not enable DeepSeek if that transfer is not acceptable for the work.
12. Data subject rights
Taking into account the nature of processing, Processor will assist Customer with technical and organisational measures to respond to requests from data subjects under applicable law. Customer should use in-product tools (including user administration and conversation deletion) before asking Processor for help.
13. Personal data breaches
Processor will notify Customer without undue delay after confirming a personal data breach that affects Customer Personal Data, and within 72 hours where feasible, with information reasonably available to help Customer meet its own notification duties. Processor will cooperate on containment, mitigation, and documentation.
Report suspected incidents to support@hebno.com.
14. Impact assessments and prior consultation
Processor will provide reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities where the GDPR requires it, given the information available to Processor. Customer will bear Processor's reasonable costs where the assistance is disproportionate to the Service fees.
15. Records and information
Processor will keep the records of processing required of a processor and will make available information reasonably necessary to demonstrate compliance with this DPA.
16. Deletion and return
During the term, Customer may delete conversations and related files using product features. On termination or at Customer's written request, Customer may export data using product features. Processor will delete Customer Personal Data from production systems within 30 days after termination, unless law requires retention or Customer requests earlier deletion subject to technical limits. Backup copies may persist for up to 90 days before they are overwritten.
Processor is not required to deliver a bespoke extract beyond product export features, except as required by law or a signed annex.
17. Audits
Customer may audit Processor's compliance with this DPA no more than once in any twelve months, on 30 days' written notice, during ordinary business hours, under confidentiality, and with minimal disruption. Processor may instead provide a current third-party audit report or equivalent independent evidence where available. Additional audits are allowed if Customer has a documented reason to believe a personal data breach or material non-compliance has occurred.
18. Liability
Each party's liability under this DPA is subject to the limitations in the Terms, except that nothing in those Terms limits liability that cannot be limited under the GDPR or other mandatory law. Administrative fines imposed on a party by Datatilsynetor another authority remain that party's responsibility.
19. Governing law
This DPA is governed by the laws of Denmark, without regard to conflict-of-law rules, which is consistent with Processor operating from Denmark. Mandatory data-protection rules of the EEA or the UK still apply to the processing they cover.
20. Signed DPA and contact
Acceptance of the terms of service incorporates this DPA for business use. For a signed version or custom annexes, write to support@hebno.com.
21. Order of precedence
A signed DPA or order form prevails over this DPA for that Customer. Otherwise, on data-protection matters this DPA prevails over conflicting provisions of the Terms. The privacy policy describes Hebno's controller processing and does not reduce Processor obligations in this DPA.