Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Hey Happy, LLC ("Hey Happy", "we", "us") and the customer that uses the Service ("Customer", "you"). It applies where we process personal data on your behalf. If you need a signed copy, email chris@heyhappy.io.

Effective Date: September 17, 2026

1. Roles and Scope

For personal data about your end customers and contacts that you submit to the Service, or that we collect on your behalf, you are the controller (or business) and we are the processor (or service provider). For personal data about your own account administrators, we act as a controller and our Privacy Policy applies.

In this DPA, "Data Protection Laws" means all privacy and data protection laws that apply to the processing, including the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, and other United States state privacy laws. "Personal Data" means personal data or personal information within Customer Data.

2. Your Responsibilities

You are responsible for the accuracy and lawfulness of the Personal Data you send us and for the instructions you give us. You represent that you have a lawful basis for the processing, that you have given any required notices to your end customers, that you have obtained any consents required to contact them, and that your instructions will not cause us to violate Data Protection Laws.

You are responsible for configuring the Service appropriately, including who receives surveys, how often, and what the messages say.

3. Our Obligations

We will:

  • process Personal Data only to provide, secure, support, and improve the Service, and only on your documented instructions, which include your configuration of the Service and these agreements;
  • not sell Personal Data, not share it for cross-context behavioral advertising, and not retain, use, or disclose it for any purpose other than performing the Service, except as permitted by Data Protection Laws;
  • not combine Personal Data with data from other sources except as needed to provide the Service to you or as permitted by Data Protection Laws;
  • ensure personnel with access to Personal Data are bound by confidentiality obligations and receive appropriate training, and limit access to those who need it;
  • tell you if, in our opinion, an instruction of yours infringes Data Protection Laws; and
  • notify you if we become legally required to disclose Personal Data, unless prohibited from doing so, and where possible give you the chance to object.

4. Subprocessors

You authorize us to engage subprocessors to help provide the Service. Our current subprocessors are the service providers listed in Section 5 of our Privacy Policy, which we keep current and which forms the authorized subprocessor list for this DPA.

We impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and we remain responsible for their performance.

We will give you at least 30 days' notice before adding or replacing a subprocessor that processes Personal Data, by email to your account administrators or by updating the list and notifying you. If you reasonably object on data protection grounds, tell us within that period and we will work with you in good faith on an alternative. If we cannot provide one, you may terminate the affected part of the Service and receive a pro-rated refund of prepaid fees.

5. Security

We maintain the technical and organizational measures described in Annex B, and we will not materially reduce their overall protection during the term.

6. Personal Data Breaches

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data. Our notice will describe what we know, the categories and approximate number of records affected if known, the likely consequences, and the steps we are taking. We will provide reasonable assistance so you can meet your own notification obligations. Our notice is not an acknowledgment of fault.

7. Assistance With Individual Rights

The Service provides tools you can use to access, correct, export, and delete Personal Data yourself. If an individual contacts us directly with a request about your Personal Data, we will not respond substantively, other than to direct them to you, and we will forward the request to you without undue delay. If you cannot fulfill a request using the Service, we will provide reasonable assistance, and we may charge for assistance that requires significant effort.

8. Data Protection Impact Assessments and Audits

On request, we will provide information reasonably necessary for you to complete a data protection impact assessment or to demonstrate compliance, including responses to a reasonable security questionnaire. You may audit our compliance with this DPA no more than once every 12 months, on at least 30 days' notice, during business hours, without unreasonably interfering with our operations, and subject to confidentiality. If we hold a current third-party audit report or certification, providing it satisfies this obligation. You bear the cost of an audit unless it uncovers a material breach of this DPA.

9. International Transfers

We process Personal Data in the United States. Where you transfer Personal Data from the EEA, the UK, or Switzerland to us, the European Commission Standard Contractual Clauses apply, with Module Two (controller to processor) incorporated into this DPA by reference, and:

  • the data exporter is Customer and the data importer is Hey Happy, LLC;
  • the optional docking clause applies;
  • for Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 4 of this DPA;
  • for Clause 11, the optional independent dispute resolution language does not apply;
  • for Clause 17, the governing law is the law of Ireland, and for Clause 18(b) the forum is the courts of Ireland;
  • Annex I is completed by Annex A of this DPA, and Annex II by Annex B; and
  • for UK transfers, the UK International Data Transfer Addendum applies to the Standard Contractual Clauses, with the courts and law of England and Wales, and for Swiss transfers, references to the GDPR are read as references to the Swiss FADP and the supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

10. Return and Deletion

You may export Personal Data at any time using the Service. On termination we retain, then delete or de-identify Personal Data on the schedule in our Terms of Service and Privacy Policy, unless law requires us to keep it. Backups are purged on our standard schedule.

11. Liability and Precedence

Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service. If this DPA conflicts with the Terms of Service on the processing of Personal Data, this DPA controls. If this DPA conflicts with the Standard Contractual Clauses, the Clauses control.

Annex A — Details of Processing

Subject matter. Provision of the HeyHappy customer satisfaction service.

Duration. The term of the Customer's subscription, plus the retention period described in Section 10. Nature and purpose. Collecting, storing, transmitting, analyzing, and displaying Personal Data in order to send customer satisfaction surveys and review requests on the Customer's instruction, record and report on responses, generate summaries and insights, and support the Customer.

Categories of data subjects. The Customer's end customers and contacts who are surveyed or whose records are synced; the Customer's own personnel who use the Service, including technicians and agents named on tickets or jobs.

Categories of Personal Data. Names; business or personal email addresses; telephone numbers; employer or company name; job or ticket records including titles, descriptions, assigned personnel, status, and dates; survey ratings and free-text comments; imported public review content and ratings; email engagement events such as delivery, open, and response; and IP address and technical metadata associated with responses.

Special categories. None requested or required. The Service is not intended for special category data, and the Customer should not submit it. Free-text comments written by end customers may occasionally contain unsolicited sensitive statements, which are processed only as part of the comment.

Frequency. Continuous, as tickets and jobs close and responses are received.

Recipients. The Customer and its Authorized Users, and the subprocessors identified under Section 4.

Annex B — Security Measures

Access control. Role-based access within the application, with team-scoped data isolation. Administrative access to production systems is limited to personnel who require it, uses individual credentials, and requires multi-factor authentication where supported.

Encryption. Personal Data is encrypted in transit using TLS, and encrypted at rest in our databases, object storage, and backups.

Authentication. Passwords are stored only as salted cryptographic hashes. Session cookies are signed, scoped, and expire.

Network and infrastructure. Production runs on managed cloud infrastructure with provider-level physical security, network isolation, and firewalling. Databases are not exposed to the public internet.

Secrets. Credentials and integration tokens are stored outside source control and encrypted. Logging and monitoring. Application and access logs are retained for a limited period and reviewed when investigating incidents. Errors are monitored and alerted on.

Patching. Operating systems, runtimes, and application dependencies are updated on a regular schedule and promptly for known high-severity vulnerabilities.

Backups and resilience. Databases are backed up on an automated schedule, backups are encrypted, and restoration is tested periodically.

Deletion. Data is deleted or de-identified on the schedule described in Section 10 and in the Terms of Service.

Personnel. Personnel with access are bound by confidentiality obligations and receive security guidance appropriate to their role. Incident response. We maintain a process for identifying, escalating, investigating, and remediating security incidents, and for notifying affected customers as described in Section 6.

Last updated: September 17, 2026