Data processing agreement
Effective 4 October 2026.
This agreement is part of the Terms of service for every organization on Hookspot, and needs no signature. It covers the personal data in the webhooks your organization receives and in the answers your local app sends back.
Who this covers
Your organization is the controller of that data, and Hookspot is its processor. Bohdan Yuriiovych Hryshchenko, an individual entrepreneur registered in Ukraine, at 36 Laherna Street, apartment 31, Kyiv 03113, Ukraine, runs Hookspot.
Hookspot writes to your organization’s owners by email. Your organization writes to support@hookspot.dev.
How Hookspot processes the data
Hookspot processes the data only on your organization’s instructions: this agreement, what its members do in the app and the CLI, and what its owners ask for in writing. If a law requires other processing, Hookspot tells your organization first, unless that law forbids it. If Hookspot thinks an instruction breaks data protection law, it tells your organization. Hookspot processes the data for as long as your organization uses Hookspot.
Hookspot also:
- keeps the data confidential: besides the subprocessors, only the person who runs Hookspot can reach it
- protects it with the measures under Security
- deletes it when the retention period ends, or when an owner deletes its project or organization, and keeps deleted data in the encrypted backups for up to 7 days
- deletes it when your organization stops using Hookspot, or first returns it if an owner asks in writing
- deletes, within 30 days, the webhooks an owner names in writing, for example to answer someone the data is about
- helps your organization answer requests from the people the data is about, and helps with its security and data protection assessments, as far as the data in Hookspot allows
- tells your organization’s owners of a breach of the data without undue delay after learning of it, with what it knows
- answers your organization’s written questions about how it meets this agreement, and allows the audits that the clauses under International transfers provide for
Subprocessors
Hookspot uses these subprocessors for the data:
- netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany, reached at
mail@netcup.de, hosts Hookspot’s servers and all the data on them. - Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, reached at
legal@cloudflare.com, carries all traffic to Hookspot, the webhooks and your local app’s answers included, and stores the encrypted nightly backups in the European Union.
Your organization authorizes them, and the ones Hookspot adds under this section. Hookspot binds each one to data protection duties as strict as this agreement’s. Hookspot emails your organization’s owners at least 30 days before it adds or replaces one. Your organization can object in writing before then, or stop using Hookspot.
Security
Hookspot protects the data with these measures:
- Senders (the services that send the webhooks) reach Cloudflare over TLS, and Cloudflare reaches Hookspot’s servers over TLS with an origin certificate.
- Hookspot’s servers talk to each other over Tailscale, which encrypts the traffic between them.
- The database servers cannot be reached from the internet. Only the person who runs Hookspot reaches the servers, with SSH keys over Tailscale.
- Every night, Hookspot deletes the webhooks older than their organization’s retention period, and makes an encrypted backup it keeps in the European Union for 7 days.
The database disks are not encrypted at rest.
International transfers
Hookspot is run from Ukraine. When the GDPR applies to your organization’s processing, the standard contractual clauses for transfers from controllers to processors (Module Two) in the European Commission’s Implementing Decision (EU) 2021/914 are part of this agreement. Your organization is the data exporter, and Hookspot is the data importer. In those clauses:
- Clause 7 applies.
- Under Clause 9(a), Option 2 applies, with 30 days’ notice.
- The option in Clause 11(a) does not apply.
- Under Clause 17, Option 2 applies: the clauses follow the law of the EU Member State where your organization is established. If your organization is not established in the EU, or that law does not allow third-party beneficiary rights, they follow the law of Ireland.
- Under Clause 18(b), disputes go to the courts of the Member State whose law the clauses follow.
- Annex I is Details of the processing, Annex II is Security and Annex III is Subprocessors.
When the UK GDPR applies, the International Data Transfer Addendum to those clauses, issued by the UK Information Commissioner (version B1.0), is part of this agreement too. Its tables take their details from this agreement, and neither party may end it under its Section 19.
When the Swiss Federal Act on Data Protection applies, the clauses apply with the Federal Data Protection and Information Commissioner as the supervisory authority, and references to the GDPR in them mean that Act. People in Switzerland can enforce their rights in Switzerland.
If anything on this page conflicts with the clauses, the clauses prevail.
Details of the processing
- The data exporter is your organization, through its owners. The data importer is Hookspot, at support@hookspot.dev.
- The data is about the people your organization’s webhooks describe, usually its own customers and users.
- The data is whatever personal data senders put in those webhooks and your local app puts in its answers. Hookspot asks for no special categories of data, and the Terms of service bar health information that needs a HIPAA business associate agreement.
- The transfer is continuous, as webhooks arrive.
- Hookspot receives, stores, shows and forwards the webhooks to your local app through the CLI, to run the service for your organization.
- Hookspot keeps each webhook for the organization’s retention period: 14 days on the Free plan and 60 days on Pro. When Pro ends, the retention period stays 60 days for 7 more days.
- The competent supervisory authority is that of the EU Member State where your organization is established, or where its EU representative is. If your organization has neither, it is the authority of a Member State where the people the data is about live, as Clause 13(a) provides.