Data Processing Addendum
This DPA applies where HoneyNotify processes personal data for a customer. The customer is controller and HoneyNotify is processor unless applicable law assigns different roles.
Instructions and purpose
HoneyNotify processes device tokens, identifiers, attributes, message content, delivery data, and engagement events only to provide and secure push-notification services, follow documented customer instructions, meet legal obligations, and maintain agreed support.
Security and confidentiality
HoneyNotify limits access by role, encrypts provider credentials at rest, uses private service networking, logs administrative actions, supports MFA, separates tenants, backs up encrypted data, and maintains incident, recovery, and vulnerability-management procedures. Personnel and subprocessors are bound by confidentiality.
Subprocessors and transfers
The customer authorises subprocessors listed by the production operator. HoneyNotify remains responsible for their data-protection obligations and provides notice of material changes. Restricted transfers use applicable adequacy decisions or standard contractual clauses.
Assistance
HoneyNotify provides self-service export and deletion workflows and reasonable assistance with data-subject requests, security assessments, breach notifications, impact assessments, and regulator enquiries. Customers remain responsible for lawful instructions and recipient notices.
Deletion and audit
At termination or instruction, HoneyNotify deletes or returns personal data after the safety period unless law requires retention. The operator provides information reasonably necessary to demonstrate compliance and supports proportionate audits under confidentiality.
The production operator and customer must complete party details, subject matter, duration, data categories, data subjects, subprocessors, transfer terms, and signatures before relying on this DPA.