Last updated · 2026-04-30
Data Processing Agreement
This DPA forms part of the Hurrah Terms of Service. It applies whenever Hurrah(“the Processor”) processes personal data on behalf of a customer (“the Controller”) in connection with the Service.
1. Roles
For contact data uploaded by the Controller (the workspace owner) and sent to message recipients, the Controller is the data controller andHurrah is the data processor. For account data submitted directly to us (login, billing), Hurrah is the controller — see the Privacy Policy.
2. Subject matter + duration
Subject matter: storage, transmission, and rendering of contact data for the purpose of sending review requests and capturing replies. Duration: the term of the Controller’s subscription, plus 30 days for deletion.
3. Sub-processors
The Controller authorises Hurrah to engage the following sub-processors. We will notify the Controller of any addition or replacement at least 30 days in advance via email and an update to this page; the Controller may object on reasonable grounds.
| Sub-processor | Purpose | Region | DPA |
|---|---|---|---|
| Supabase | Application database (PostgreSQL) + auth + file storage | United States (AWS) | view |
| Resend | Transactional + marketing email delivery and webhooks | United States | view |
| Stripe | Payment processing + subscription billing | United States | view |
| Anthropic | AI review-assist drafts (only when workspace owner enables it) | United States | view |
| Vercel / Render | Application hosting + edge delivery | United States | view |
4. Cross-border transfers
Personal data processed under this DPA is stored in the United States. We rely on (a) Standard Contractual Clauses with each US-based sub-processor, (b) the EU-US Data Privacy Framework where applicable, and (c) the model contract clauses published by the New Zealand Office of the Privacy Commissioner (OPC) for cross-border disclosures from NZ controllers.
5. Security
We implement appropriate technical and organisational measures: TLS 1.2+ for data in transit, encryption at rest at the disk and database level, Row-Level Security policies enforcing per-workspace isolation, principle-of-least-privilege access for staff, and audit logging on sensitive operations.
6. Breach notification
We will notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any actual or suspected breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data processed on the Controller’s behalf.
7. Data subject rights
We will assist the Controller in responding to data-subject requests (access, rectification, erasure, portability, objection) within the timelines set by applicable law — typically 20 working days under NZ Privacy Act 2020, 30 days under AU APP 12, and 45 days under CCPA/CPRA.
8. Audits
We will, on request, provide the Controller with summaries of the latest sub-processor SOC 2 reports + our own most recent security assessment. Direct on-site audits are available on request for Enterprise plans subject to confidentiality and reasonable advance notice.
9. Return + deletion
Within 30 days of subscription termination, the Controller’s contact data and message history are deleted from production. Backups roll off within an additional 90 days. The suppression list (recipient unsubscribes, bounces, and complaints) is retained indefinitely as required to honour opt-outs across future signups by the same Controller or other Controllers.
10. Liability
Liability for breaches of this DPA is governed by the limitations in the Terms of Service §6.