HyveFlow

Data Processing Agreement

Last updated: July 2026

This DPA describes how HyveFlow processes personal data on behalf of a Shop. It applies to any Shop that uses HyveFlow and supplements our Terms of Service and Privacy Policy. Where a Shop's customers are in the EU/UK or California, it also serves as the Shop's data-processing agreement. It is not legal advice — have counsel review it against your obligations.

1. Roles

For personal data a Shop stores in HyveFlow about the Shop's own customers ("Shop Personal Data"), the Shop is the controller and HyveFlow is the processor. HyveFlow processes Shop Personal Data only on the Shop's documented instructions — which include the Shop's configuration and use of the service — except where law requires otherwise (in which case we notify the Shop unless the law prohibits it).

2. Subject matter, duration, nature & purpose

We process Shop Personal Data to provide HyveFlow's order-management service — intake, deposits, proofs, rosters, invoicing, transactional email, and the integrations a Shop enables — for as long as the Shop's account is active, and thereafter as described in Section 8.

3. Categories of data & data subjects

4. HyveFlow's obligations

5. Subprocessors

The Shop authorizes HyveFlow to engage the subprocessors below to provide the service. We impose data-protection obligations on each that are no less protective than this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended new subprocessor so the Shop can object.

SubprocessorPurpose
SupabaseDatabase & storage of Shop data
RenderApplication hosting (API)
NetlifyWeb hosting (admin & portal)
Cloudflare R2File storage (proofs, certificates, design files)
ResendTransactional email delivery
ClerkAuthentication / login
AnthropicAI features (order intake, drafting)
Intuit / QuickBooksInvoicing & payment tracking (when the Shop connects it)
GoogleDrive/Sheets sync (when the Shop connects it)

6. Security measures

We maintain measures appropriate to the risk, including: encryption in transit; encryption of integration tokens at rest; tenant isolation so one Shop cannot access another Shop's data; private file storage served only via short-lived signed links; role-based access controls; row-level security on the database; and rate limiting and logging to detect abuse. We review these measures as the service evolves.

7. Personal data breaches

We will notify the Shop without undue delay after becoming aware of a personal-data breach affecting Shop Personal Data, with the information reasonably available to help the Shop meet its own notification obligations, and we will take reasonable steps to mitigate.

8. Return & deletion

On request during the term, and on termination, the Shop may obtain a full export of Shop Personal Data (self-serve on request via the platform). At the Shop's choice we will delete or return Shop Personal Data and delete existing copies within a reasonable period, except where law requires retention.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once a year (or as a supervisory authority requires), allow the Shop or its mandated auditor to review that information, subject to confidentiality and without disrupting the service or other Shops' data.

10. International transfers

Where processing involves transferring personal data across borders (for example to a subprocessor), we rely on a lawful transfer mechanism, such as the EU Standard Contractual Clauses or an adequacy decision, where applicable.

11. Term & precedence

This DPA is effective while the Shop uses HyveFlow and, for Shop Personal Data, survives until deletion or return. If this DPA conflicts with the Terms of Service on the processing of Shop Personal Data, this DPA controls for that data.

12. Contact

Requests under this DPA — including subprocessor objections, data-subject assistance, or a countersigned copy — go to support@hyveflow.io.