Data Processing Agreement (DPA)
This agreement governs the processing of personal data that we carry out on your behalf when you use HYWOS. It forms an integral part of our Terms of Service and is concluded when you accept it during registration.
PURSUANT TO ART. 28 GDPR
Version 2026-07-30 · last updated: 30 July 2026
Parties
- Controller — You — the natural or legal person who uses HYWOS in a professional or business capacity and thereby has personal data stored with us (“Controller”, “you”).
- Processor — TROLUT UG (haftungsbeschränkt), Rosa-Luxemburg-Ring 10 B, 34253 Lohfelden, Germany, operator of HYWOS (“Processor”, “we”).
This agreement covers only the processing we carry out on your behalf, on your instructions and for no purpose of our own. Everything we decide the purposes and means of ourselves — your account, licence, device and billing data, the security of the service, and the improvement of our product — is processing for which we are the controller. It is not governed by this agreement but by our Privacy Policy. Section 2 states exactly which is which.
If you use HYWOS purely privately, you are a consumer and not a controller: Art. 28 GDPR does not apply to you, this agreement has no subject matter, and we are the controller of your data under the Privacy Policy. Accepting it at registration is therefore without prejudice to your rights as a data subject.
1. Subject matter, nature and purpose
This agreement governs two things, and only these two. First: on the free plan, HYWOS stores the chat history and activity records created by your use of the software so that they are available in your account. Second: for company deployments, the installation, backup, recovery, support and training work we perform on your systems. To the extent that personal data for which you are the controller is involved, we process it solely to perform these tasks for you — for no purpose of our own. Its nature, scope and purpose, the types of personal data and the categories of data subjects are set out in Annex 1.
2. Scope depends on your plan
What we process, and in which role, depends entirely on the plan you use. This distinction is a deliberate part of the product, not a configuration detail. Note that not everything listed under the free plan is processed on your behalf — the table “Which role we act in” below draws that line precisely:
The application and this website record: your chat history (your prompts and the assistant's replies), records of the actions you perform in the software (e.g. imports, generated documents, searches), which functions you use and when, the pages you visit here, and technical event and error data. This is transmitted to our servers in the EU and stored there. Your documents themselves are never uploaded — they stay on your computer; only the chat text, which may contain excerpts you or the assistant quoted from them, leaves your machine.
The application sends us no chat history, no activity records, no usage data and no document content. Processing takes place exclusively on your own computer and the AI model runs locally as well; after activation the software can be used fully offline until the next licence check. The only thing it transmits is that licence check itself, with the device and licence identifiers described in the Privacy Policy — that is our own controller processing, not processing on your behalf.
Where we install HYWOS on your server, set up backup and recovery, or access your systems for support or training, we necessarily come into contact with personal data of yours. That is processing on your behalf and is governed by this agreement in full. Each such access is agreed with you in advance, limited to what the task requires, and logged. If your organisation requires an individually negotiated agreement instead of this one, we will conclude it — this agreement then applies until it is replaced.
Which role we act in
- We act as processor for you — for the storage, provision and deletion of the free-plan chat history and activity records described above, and — in company deployments — for the installation, backup, support and training work we perform on your systems. This is the processing governed by this agreement, and nothing beyond it.
- We act as controller ourselves — for your account, licence, device and billing data; for the security and abuse prevention of the service; and for the improvement of HYWOS. We name this openly because a processor may not pursue purposes of its own: for these purposes we are answerable under Art. 6 GDPR, and the legal bases are set out in our Privacy Policy. Improvement is carried out exclusively on aggregated or anonymised data. We do not evaluate identifiable chat content for our own purposes — not even with your permission, because an instruction cannot turn a purpose of ours into processing on your behalf.
- We never do either of these — we do not use your chat history, your activity records or your content to train or fine-tune any AI model — neither our own HYWOS Cortex nor any third-party model — and we do not pass this data to any AI provider.
If you move from the free plan to a paid plan, the transmission ends with the plan change. Data already collected is then, at your choice, handed over to you or deleted in accordance with section 9.
3. Processing on documented instructions
We process personal data only on your documented instructions, including with regard to transfers to a third country or an international organisation, unless we are required to do so by Union or Member State law to which we are subject; in such a case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. Your initial instructions are laid down in this agreement and in the settings you configure in the product. You may supplement, amend or revoke them at any time; individual instructions beyond this agreement are to be issued in text form to {email}, and we will confirm them.
4. Confidentiality
We ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they are familiar with the applicable data-protection provisions. Access is limited to those employees who need it to perform their duties (need-to-know principle). This obligation continues after the end of their activity.
5. Technical and organisational measures (Art. 32 GDPR)
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in force at the time of conclusion of this agreement are set out in Annex 2. We may adapt them in line with technical developments, provided the agreed level of protection is not fallen below.
6. Sub-processors
You grant us general authorisation to engage sub-processors. The sub-processors engaged at the time of conclusion of this agreement are listed in Annex 3 and are hereby approved. We will inform you of any intended addition or replacement of a sub-processor at least 30 days in advance and you may object on reasonable data-protection grounds within that period; if we cannot accommodate your objection, you may terminate the affected services with immediate effect. We impose on every sub-processor, by contract, data-protection obligations that are no less protective than those set out in this agreement, and we remain fully liable to you for their performance.
7. Assisting you with data subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests for exercising the data subject's rights under Chapter III GDPR (in particular access, rectification, erasure, restriction, data portability and objection). If a data subject contacts us directly in relation to processing carried out on your behalf, we will forward the request to you without undue delay and will not respond to it ourselves unless you instruct us to.
8. Assisting you with security, breaches and impact assessments
Taking into account the nature of processing and the information available to us, we assist you in ensuring compliance with the obligations under Art. 32 to 36 GDPR. We will notify you without undue delay — and in any event within 48 hours — after becoming aware of a personal data breach affecting data processed on your behalf, providing the information you need for your own notification obligations under Art. 33 and 34 GDPR, and we will take reasonable remedial measures without delay.
9. Deletion and return of data
Independently of the end of the contract, data processed on your behalf is erased no later than 12 months after it arises; this storage limitation is binding and we may not extend it unilaterally. After the end of the provision of services relating to processing — and equally upon a change from the free plan to a paid plan, which ends the collection — we will, at your choice, delete or hand over to you all personal data processed on your behalf and delete existing copies, unless Union or Member State law requires storage. You have 30 days from the end of the contract or from the plan change to request the handover; if you do not, we delete the data. You may request erasure earlier at any time. Backups are deleted within the ordinary backup cycle, which does not exceed 90 days.
10. Evidence and audits
We make available to you all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by you or another auditor mandated by you. Evidence may be provided by way of self-assessments, current certificates or audit reports. On-site inspections are carried out during business hours, after reasonable notice (as a rule 14 days), without disrupting operations, and subject to confidentiality. Where we object to a specific auditor because it is a competitor of ours, we must state the reason in writing and accept in its place an independent auditor bound by professional secrecy or by a confidentiality agreement; your audit right may not be defeated by such an objection.
11. Notification of unlawful instructions
We will inform you immediately if, in our opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions. We are entitled to suspend the execution of the instruction concerned until it is confirmed or amended by you.
12. Place of processing and international transfers
The data processed on your behalf is stored on servers within the European Union. Where a sub-processor is established outside the EU/EEA, administrative or support access from a third country cannot be ruled out; such access is itself a transfer. For every such case the transfer is safeguarded by the EU Standard Contractual Clauses or another legal mechanism under Chapter V GDPR, together with the additional measures required after a transfer impact assessment. We do not carry out any transfer that goes beyond this without your instruction.
13. Liability and rights of the controller
You are responsible for assessing the lawfulness of the processing and for safeguarding the rights of data subjects. You retain the right to issue instructions concerning the type, scope and method of processing at any time; where an instruction means we can no longer provide the service as agreed, we will tell you so and you may terminate. Liability between the parties is governed by Art. 82 GDPR. The limitations of liability in our Terms of Service do not apply to claims under this agreement, and in particular do not limit our full liability for our sub-processors under section 6.
14. Term and termination
This agreement takes effect when you accept it during registration and runs for as long as we process personal data on your behalf — as a rule for the term of the underlying contract. It ends automatically with that contract; the obligations under sections 4, 9 and 10 survive its termination. It may be terminated separately for good cause, in particular in the event of a serious breach of data-protection provisions.
15. Final provisions
Should individual provisions of this agreement be or become invalid, the validity of the remainder is unaffected. In the event of contradictions, the provisions of this agreement take precedence over those of the Terms of Service in respect of data protection. German law applies. Changes to this agreement require your agreement: we will notify you of any intended change at least 30 days in advance, stating the reason; if you object within that period we will continue on the existing terms or, if that is not possible, you may terminate the affected services with immediate effect. Changes that merely reflect a mandatory legal requirement take effect on the date the requirement applies. The current version is always available on this page.
Annex 1 — Details of the processing
- Subject matter and duration — Storage and provision of the chat history and activity records created on the free plan, for the term of the free plan and no longer than the storage limitation in section 9. In addition, for company deployments: installation, backup and recovery, support and training access to your systems, for the duration of the respective task. On a paid plan used solely on your own machine, none of this arises.
- Nature and purpose — Storing, retrieving, making available and deleting the data listed below, so that your chat history and activity records are available in your account; for company deployments additionally the installation, backup, recovery, support and training activities agreed with you. No purpose of our own, no evaluation of identifiable content for our own purposes, no use for model training.
- Types of personal data
- Chat history: your prompts and the assistant's replies, including any personal data contained in text you or the assistant quoted from your documents.
- Activity records: the actions performed in the software (e.g. imports, generated documents, searches) with the associated timestamps and the user account they belong to.
- Company deployments only: whatever personal data is contained in the systems, project data or backups we are given access to in order to install, restore, support or train — limited in each case to what the agreed task requires.
- Categories of data subjects — The persons you authorise to use HYWOS (e.g. your employees), and persons whose personal data appears in the chat content they enter or quote (e.g. named contacts from project documents).
- Expressly not part of this processing — Your documents themselves — they are never uploaded. Likewise account, licence, device and billing data, and technical event, error and website usage data: we process these as controller for our own purposes (operation, security, billing, product improvement), which is why they are governed by the Privacy Policy and not by this agreement.
- Erasure — In accordance with section 9 of this agreement — at the latest 12 months after the data arises.
Annex 2 — Technical and organisational measures (Art. 32 GDPR)
The following measures are in force at the time this agreement is concluded and are reviewed regularly:
- Data minimisation by design — on paid plans no content or usage data leaves your computer at all, and your documents are never uploaded on any plan — the most effective protective measure is that the data is never transmitted.
- Pseudonymisation and aggregation — analyses for operating and improving the service are carried out on aggregated or anonymised data; where a record has to be retained for evaluation, direct identifiers are separated from the content and stored apart (Art. 32(1)(a) GDPR).
- Encryption — transport encryption (TLS) for all connections between the application, the website and our servers; encryption of data at rest on our servers; passwords stored only as salted hashes.
- Access control — individual accounts with strong authentication for administrative access, role-based authorisation, need-to-know principle, and logging of administrative activity.
- Separation — logical separation of customer data; separation of production, test and development environments; no use of production data for development.
- Availability and resilience — regular backups, monitoring, protection against loss due to hardware failure, and restore procedures that are tested.
- Integrity — protection against unauthorised modification, versioned deployments and the ability to trace changes.
- Physical security — processing takes place in the data centres of our hosting provider, which are certified to recognised standards (physical access control, fire protection, redundant power supply).
- Review and evaluation — regular review of the effectiveness of the measures, security updates without undue delay, and an incident-response procedure with defined notification paths.
Annex 3 — Approved sub-processors
Only the following sub-processor is engaged for the processing on your behalf under this agreement:
| Sub-processor | Purpose | Place of processing |
|---|---|---|
| Railway Corporation | Hosting of the database in which the chat history and activity records are stored | EU (data centre region EU-West); EU Standard Contractual Clauses for support access from the USA |
We engage no AI, analytics, advertising or tracking service as a sub-processor. Your content is not passed to any external AI provider and is not used to train or fine-tune any model, ours or a third party's. Stripe Payments Europe, Ltd. is deliberately absent from this table: payment processing serves our own billing purposes, for which we are the controller and not your processor — it is described in the Privacy Policy.
Contact
Questions about this agreement, requests for the return of data, or instructions under section 3: {email}.