Data Processing Addendum
Version 2026-08-28 · Effective August 28, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Hardroad, Inc. (“Hardroad”) and the organisation using the Service (“Customer”). It applies where Customer uses Hardroad to process personal data of its own people — employees, members, or contacts — and Customer is the controller of that data.
If you use Hardroad as an individual for your own planning, this DPA does not apply to you. Hardroad is the controller of your data and our Privacy Policy governs it.
1. Roles and scope
Customer is the controller and Hardroad is the processor of Customer Personal Data. Hardroad processes it only on Customer's documented instructions, which are the Terms of Service, this DPA, and Customer's use of the Service's features. Hardroad will tell Customer if it believes an instruction infringes applicable data protection law.
2. Nature of the processing
- Subject matter: provision of the Hardroad planning, scheduling, habit and collaboration service.
- Duration: for the term of the agreement, plus the deletion period in section 8.
- Categories of data subject: Customer's users, and the contacts and collaborators they add.
- Categories of personal data: names, email addresses, phone numbers, profile information, and the content users create — tasks, projects, goals, habits, journals, calendar entries and planner data.
- Special categories: Hardroad does not require special category data. Customer should not use free-text fields to record it. Where a user voluntarily records health or wellbeing information about themselves, Hardroad processes it only to provide the features that user turned on.
3. Confidentiality
Hardroad ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, and limits access to those who need it to provide or support the Service.
4. Security
Hardroad implements appropriate technical and organisational measures under Article 32 GDPR, including encryption of data in transit (TLS) and at rest, access control with authentication and least privilege, logical separation of customer data, audit logging of administrative access, regular backups, and dependency and vulnerability monitoring.
5. Subprocessors
Customer gives general authorisation for Hardroad to engage subprocessors. The current list is published at hardroad.app/subprocessors and is updated before a new subprocessor begins processing. Customer may subscribe to change notices by emailing privacy@hardroad.app, and may object on reasonable data-protection grounds within 30 days of notice; if the objection cannot be resolved, Customer may terminate the affected part of the Service. Hardroad remains liable for its subprocessors' performance and imposes data protection terms on them no less protective than this DPA.
6. Assistance to Customer
Taking into account the nature of the processing, Hardroad will assist Customer with: responding to data subject requests for access, correction, deletion, restriction, objection and portability, using the Service's own features where possible; data protection impact assessments and prior consultation; and the security obligations in Articles 32 to 36 GDPR. Requests reach us at privacy@hardroad.app. If a data subject contacts Hardroad directly about Customer Personal Data, Hardroad will refer them to Customer rather than responding substantively.
7. Personal data breach
Hardroad will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information Customer reasonably needs to meet its own notification obligations.
8. Return and deletion
On termination, Customer may export its data through the Service. Hardroad deletes Customer Personal Data within 30 days of termination or of a written deletion request, except where retention is required by law. Residual copies in encrypted backups age out within 90 days. See Data Deletion & Retention.
9. International transfers
Hardroad processes data in the United States. Where Customer Personal Data originates in the European Economic Area, the United Kingdom or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies. Hardroad carries out transfer impact assessments and applies supplementary measures where needed.
10. Audit
Hardroad will make available the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits by Customer or an auditor it mandates, no more than once per year unless required by a supervisory authority, on reasonable notice and subject to confidentiality.
11. Google user data
Where a user connects a Google account, Hardroad's handling of the resulting data is additionally governed by the Google User Data section of our Privacy Policy and by the Google API Services User Data Policy, including the Limited Use requirements. Those restrictions apply in addition to this DPA, and where they are stricter, they prevail.
12. Signing this DPA
This DPA applies automatically to Customers processing personal data through the Service. If your organisation needs a countersigned copy, email privacy@hardroad.app with your legal entity name and address, and we will return an executed version.