Data Processing Agreement
Baseline controller-processor terms for an eligible contracted SqueHub service, including security, subprocessors, rights assistance, deletion, audits, and transfers.
- Published
- 2026-10-08
- Last updated
- 2026-10-08
1. Status and incorporation
This Data Processing Agreement (DPA) is a public baseline for a SqueHub-operated service under which SqueHub processes personal data on behalf of an organizational customer. It becomes binding only when it is incorporated into an executed order form, service agreement, or other written agreement accepted by both parties (Agreement).
Publishing this page does not by itself create a customer relationship, appoint SqueHub as a processor, or bind either party. Contact hello@squehub.com before relying on this DPA for a regulated deployment. The parties must identify the covered service and complete the processing and subprocessor details appropriate to that service.
The open-source SqueHub framework is software the user installs and operates. SqueHub is not a processor merely because a customer uses the framework in its own environment. A processor relationship arises only for personal data SqueHub actually processes on the customer's behalf through a covered contracted service.
If this DPA conflicts with the Agreement, this DPA controls for protection of Covered Data unless the conflicting term provides greater protection or mandatory law requires otherwise. A signed service-specific DPA, order form, or approved standard contractual clause controls over this public baseline for its subject.
2. Definitions
- Applicable Data Protection Law means laws governing the processing of Covered Data that apply to a party in the relevant context, including applicable controller-processor, security, breach-notification, and international-transfer duties.
- Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given by Applicable Data Protection Law.
- Customer means the organization that enters the Agreement and determines the purposes and means of processing Covered Data.
- Covered Data means Personal Data processed by SqueHub on Customer's behalf through the covered service. It excludes data for which SqueHub independently determines purposes and means, which is governed by the Privacy Policy.
- SqueHub means the SqueHub contracting party identified in the Agreement.
- Subprocessor means a third party appointed by SqueHub to process Covered Data on Customer's behalf.
- Services means the SqueHub-operated services identified in the Agreement or applicable order form.
3. Roles and scope
Customer is the Controller and SqueHub is the Processor for Covered Data, except where Customer acts as a Processor for another Controller, in which case SqueHub is Customer's Subprocessor. Each party will comply with the duties that apply to its role.
Customer determines the purposes and essential means of processing, chooses the Services and configuration, identifies authorized users, and is responsible for the lawfulness of its instructions and Covered Data. SqueHub processes Covered Data only to provide, secure, support, and improve the operational delivery of the Services under documented instructions.
The subject matter, duration, nature, purpose, categories of Data Subjects, and types of Covered Data are described in Schedule 1 and the Agreement. Processing continues for the term of the Services and the bounded deletion or return period, unless law requires longer retention.
4. Documented instructions
Customer's documented instructions consist of the Agreement, this DPA, applicable order forms, the service configuration Customer selects, and lawful written instructions consistent with the Services.
SqueHub will:
- process Covered Data only on those instructions;
- process data as required by law only after informing Customer, unless law prohibits notice;
- inform Customer if, in SqueHub's reasonable view, an instruction infringes Applicable Data Protection Law; and
- suspend the affected instruction where necessary to avoid unlawful processing while the parties seek a lawful alternative.
Instructions that require material functionality, risk, or cost beyond the Services may require a written change, additional fees, and a feasibility or security review. SqueHub is not required to build an unlawful or insecure processing method.
5. Customer responsibilities
Customer represents that it has a lawful basis for the collection and processing of Covered Data and authority to instruct SqueHub. Customer is responsible for:
- providing legally required notices and honoring Data Subject rights;
- obtaining consents where consent is the chosen basis;
- limiting Covered Data to what is necessary for the Services;
- ensuring instructions, configurations, retention settings, and user access are lawful;
- the accuracy and quality of Covered Data;
- securing Customer-controlled accounts, credentials, devices, integrations, and environments;
- determining whether the Services are suitable for regulated or special-category data; and
- notifying SqueHub before submitting data subject to additional legal or industry requirements.
Customer must not submit special-category data, criminal-offence data, payment-card data, government identifiers, health records, children's data, or other highly regulated information unless the Agreement expressly permits it and the parties document appropriate safeguards.
6. Confidentiality and personnel
SqueHub will ensure that people authorized to process Covered Data are bound by confidentiality obligations or an appropriate statutory duty and receive access only as necessary for their role. Access may be withdrawn when no longer required.
SqueHub will provide appropriate privacy and security awareness for personnel with access to Covered Data. Customer confidential information remains subject to the confidentiality provisions of the Agreement.
7. Security measures
Taking into account the state of the art, implementation cost, scope, context, purposes, and risk, SqueHub will maintain technical and organizational measures designed to protect Covered Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures for the covered service are described in Schedule 2 and may include:
- identity, authentication, session, and least-privilege access controls;
- separation of production, development, and administrative responsibilities;
- encryption in transit and suitable protection at rest where supported;
- secure configuration, secret management, dependency review, and change control;
- input validation, CSRF protection, authorization, rate limiting, and abuse prevention;
- logging, monitoring, diagnostics, and incident-response procedures;
- backup, restoration, availability, and business-continuity controls;
- vulnerability assessment, remediation, and responsible disclosure processes;
- subprocessor due diligence and contractual security duties; and
- secure deletion or de-identification at the end of the applicable period.
Security measures can evolve to address risks and technology. SqueHub will not materially reduce the overall protection of the covered service during the term without a lawful and documented basis. No control guarantees absolute security, and Customer remains responsible for Customer-controlled parts of the environment.
8. Subprocessors
Customer authorizes SqueHub to use Subprocessors necessary to provide the Services, subject to this section. The current approved Subprocessors, locations, and functions must be identified in Schedule 3, the order form, or a maintained service-specific list made available to Customer.
SqueHub will:
- conduct proportionate due diligence before appointing a Subprocessor;
- enter written terms requiring data-protection obligations no less protective in substance than those applicable to the relevant processing;
- remain responsible to Customer for performance of the Subprocessor's obligations to the extent required by law and the Agreement; and
- provide notice of a new Subprocessor where Applicable Data Protection Law or the Agreement requires it.
Customer may object to a new Subprocessor on reasonable, documented data-protection grounds within the notice period specified in the Agreement. The parties will work in good faith on a commercially reasonable alternative. If no reasonable alternative is available, the Agreement governs termination of the affected Service. An objection does not require SqueHub to provide a service that is technically infeasible or materially different without an agreed change.
9. Data Subject requests
Taking into account the nature of processing, SqueHub will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests for access, correction, deletion, restriction, objection, portability, or another applicable right.
If SqueHub receives a request relating to Covered Data, it will ordinarily direct the requester to Customer and will not independently fulfill the request except on Customer's instruction or as required by law. SqueHub may authenticate requests and must not disclose information that would compromise another person, tenant, or service.
Customer is responsible for determining whether a request is valid and for communicating with the Data Subject or authority. Assistance beyond standard service functionality may be subject to reasonable fees where permitted and disclosed in advance.
10. Security incidents and Personal Data Breaches
SqueHub will maintain a process to identify, investigate, contain, remediate, and document security incidents affecting Covered Data. SqueHub will notify Customer without undue delay after confirming a Personal Data Breach for which notice is required under Applicable Data Protection Law.
The notice will provide information reasonably available to SqueHub, which may include:
- the nature of the breach and affected systems;
- categories and approximate number of affected Data Subjects and records, where known;
- likely consequences;
- measures taken or proposed to contain and remediate it; and
- a contact for follow-up.
Information may be provided in stages as the investigation develops. Notification is not an admission of fault or liability. Customer is responsible for determining and making notices to Data Subjects, regulators, customers, or others, unless the Agreement assigns a specific notice to SqueHub.
Customer will notify SqueHub promptly of incidents arising from Customer-controlled credentials, integrations, configurations, or environments that may affect the Services or Covered Data.
11. Compliance assistance
Considering the processing and information available, SqueHub will provide reasonable assistance with Customer's obligations concerning security, breach notification, data-protection impact assessments, and prior consultation with a Supervisory Authority.
Customer should first use available documentation, configuration, exports, security summaries, and contractual information. Requests must be specific and must not require SqueHub to disclose another customer's data, compromise security, waive privilege, or violate law.
12. Demonstrating compliance and audits
SqueHub will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations. The parties should first use current third-party reports, certifications, summaries, questionnaires, and remote review where suitable.
If those materials are insufficient and law requires further review, Customer may request an audit subject to the Agreement and these safeguards:
- reasonable advance written notice and a defined scope;
- no more than once in a 12-month period unless a confirmed breach, regulator, or material noncompliance reasonably requires another audit;
- use of an independent, qualified auditor bound by confidentiality;
- avoidance of disruption, source-code disclosure, security compromise, and access to another customer's information;
- audits during normal business hours and in compliance with site and security rules; and
- Customer bearing reasonable costs unless material noncompliance is established or law requires otherwise.
SqueHub may provide responsive evidence directly to a regulator where appropriate. Audit findings are confidential and used only for compliance, risk remediation, and legal obligations.
13. Return and deletion
During the term, Customer may use available export functions described for the Services. On termination or expiry, and on Customer's documented choice where required by law, SqueHub will return or delete Covered Data within the period stated in the Agreement, unless law requires retention.
Deletion may occur through ordinary system and backup lifecycles. Until backup rotation completes, retained backup data remains protected, isolated from ordinary use, and restored only for legitimate recovery. SqueHub may retain minimal records for security, billing, dispute resolution, or legal compliance, subject to purpose and access restrictions.
Customer is responsible for exporting needed data before the service or agreed recovery window ends. The open-source framework's project bundles do not automatically include every live database record, persistent upload, external service, or secret.
14. International transfers
If SqueHub or a Subprocessor transfers Covered Data across a border and Applicable Data Protection Law requires a transfer mechanism, the parties will use a valid mechanism appropriate to the transfer. This may include an adequacy decision, approved standard contractual clauses, binding corporate rules, certification, or another lawful safeguard.
Where the European Commission's Standard Contractual Clauses are selected, the Agreement must identify the applicable module, options, parties, competent authority, governing law, forum, transfer description, security measures, and Subprocessors. The parties will also complete any transfer assessment and supplementary safeguards required by law.
SqueHub will provide information reasonably necessary for Customer to assess an applicable transfer. If a transfer mechanism is invalidated or materially changed, the parties will work in good faith to implement a lawful replacement. If none is reasonably available, either party may suspend the affected transfer or terminate the affected Service as the Agreement permits.
15. Government and third-party demands
Unless prohibited by law, SqueHub will notify Customer before disclosing Covered Data in response to a binding government or third-party demand. SqueHub may review the demand's validity, seek clarification, object to overbroad requests, or pursue available protective measures where reasonable.
SqueHub will disclose only information reasonably required by the valid demand and will document the response as appropriate. Nothing in this section requires SqueHub to violate law or disclose confidential legal advice.
16. Liability, duration, and termination
This DPA remains in effect while SqueHub processes Covered Data under the Agreement. Rights and duties that by their nature survive—such as confidentiality, deletion, audit records, and international-transfer protections—continue for as long as relevant Covered Data is retained.
Liability, indemnity, exclusions, limitations, dispute resolution, governing law, and termination rights are governed by the Agreement, subject to mandatory Applicable Data Protection Law. This DPA does not reduce non-waivable rights of Data Subjects or powers of a Supervisory Authority.
17. Precedence and updates
The order of precedence for data-protection terms is: mandatory law; executed transfer clauses for their regulated transfer; a signed service-specific DPA; the applicable order form; this incorporated baseline; and general service terms, unless an executed document expressly states another lawful order.
SqueHub may update the public baseline for future agreements. A change does not silently amend an executed DPA unless the Agreement provides a valid update mechanism. Material reductions in protection require the process specified in the Agreement and Applicable Data Protection Law.
Schedule 1 — Details of processing
The parties must complete or incorporate the following details for the covered Service:
| Item | Service-specific detail |
|---|---|
| Subject matter | Hosting, support, processing, or other functions of the Services identified in the order form. |
| Duration | The service term plus the agreed return, deletion, backup, and legal-retention period. |
| Nature and purpose | Collection, recording, organization, storage, retrieval, transmission, support, security, deletion, and other operations required to provide the configured Services. |
| Frequency | Continuous, intermittent, or one-time as identified in the order form and Customer's use. |
| Data Subjects | Customer users, workforce, applicants, customers, end users, contacts, suppliers, or other categories identified by Customer. |
| Personal Data | Account, contact, authentication, usage, content, support, technical, transaction, and other categories expressly identified in the order form. |
| Sensitive data | None unless expressly approved and documented with additional safeguards. |
| Customer instructions | Agreement, order form, configuration, and lawful written instructions accepted under this DPA. |
| Retention | Customer-selected settings and the periods stated in the order form, followed by bounded deletion and backup rotation. |
Customer must ensure the completed schedule accurately reflects its use before submitting Covered Data.
Schedule 2 — Technical and organizational measures
Service-specific measures should address, as applicable:
- Governance: assigned responsibilities, policies, training, risk review, vendor management, and incident procedures.
- Access control: unique identities, least privilege, strong authentication, role review, timely revocation, and protected administrative access.
- Application security: authorization, validation, session security, CSRF defenses, rate limits, secure defaults, dependency maintenance, and reviewable changes.
- Infrastructure security: hardened configuration, network controls, patching, malware and abuse defenses, and separation of environments.
- Cryptography: secure transport and appropriate protection of secrets, credentials, backups, and stored data.
- Logging and detection: bounded security logs, monitoring, alerting, time synchronization, and protected audit records.
- Availability: backup, restoration tests, capacity planning, redundancy where contracted, and documented recovery objectives.
- Data lifecycle: minimization, classification, retention controls, export, secure deletion, and protection during support.
- Testing: vulnerability assessment, change testing, incident exercises, and remediation based on risk.
- Physical and personnel controls: provider facility protections, confidentiality, access approval, and offboarding.
The executed service schedule should identify the actual measures rather than treating this list as a representation that every optional control applies to every Service.
Schedule 3 — Subprocessors and transfer details
The executed Agreement or service-specific list must identify each approved Subprocessor's:
- legal name;
- service and processing purpose;
- processing location or transfer region;
- categories of Covered Data involved; and
- applicable transfer safeguard where required.
No Subprocessor or transfer is created merely by appearing as an example in public documentation.
18. Contact and execution
To request an executable DPA, email hello@squehub.com with the subject DPA request and provide the organization name, requested Service, jurisdictions, expected data categories, Data Subject categories, sensitive-data requirements, transfer locations, and desired signing contact.
Do not attach production datasets, credentials, or confidential security material to the initial request. SqueHub will identify the contracting party, service scope, security schedule, Subprocessors, transfers, and execution method before the DPA becomes binding.

