Data Processing Addendum

For customers who need a written processing agreement with Hive.

Effective date: August 25, 2026. This page is the reference copy; an executed copy fixes the contracting entities and transfer details, and prevails over it. See how to execute this DPA.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Hive Intelligence ("Hive") and the customer that accepts those terms ("Customer"). It applies where Hive processes personal data on Customer's behalf.

1. Definitions

"Data Protection Law" means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended (CCPA/CPRA), and any other privacy law applicable to the processing under this DPA. "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data that Hive processes on Customer's behalf under the Terms of Service.

2. Roles of the Parties

For Customer Personal Data, Customer is the controller (or a processor acting for its own controller) and Hive is the processor (or subprocessor). Hive acts as an independent controller for the limited data it processes for its own purposes (account administration, billing, security, and service telemetry), as described in the Privacy Policy. Under the CCPA, Hive is a service provider: it does not sell or share Customer Personal Data, and does not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the services.

3. Scope and Instructions

Hive processes Customer Personal Data only on Customer's documented instructions, which comprise the Terms of Service, this DPA, and Customer's configuration and use of the service, including the content of the queries Customer's agents send. Hive will tell Customer if an instruction appears to infringe Data Protection Law, and may suspend the affected processing until the instruction is corrected. Hive will not process Customer Personal Data for its own purposes, and will not use it to train machine-learning models.

4. Confidentiality

Hive restricts access to Customer Personal Data to personnel who need it to deliver the service, and binds them to written confidentiality obligations that survive the end of their engagement.

5. Security Measures

Hive maintains the technical and organizational measures set out in Annex II. Hive may update them, provided the level of protection is not reduced.

6. Subprocessors

Customer gives Hive general authorization to engage the subprocessors listed at /subprocessors. Hive will update that page before a new subprocessor begins processing Customer Personal Data, and will notify Customer by email if Customer has asked to be on the notification list. Customer may object on reasonable data-protection grounds within 30 days of notice; if the objection cannot be resolved, Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused term. Hive remains liable for its subprocessors' performance of these obligations.

7. International Transfers

Where a transfer of Customer Personal Data out of the EEA, the UK, or Switzerland requires a transfer mechanism, the European Commission's Standard Contractual Clauses (Decision 2021/914) are incorporated into this DPA (Module Two where Customer is a controller, Module Three where Customer is itself a processor), together with the UK International Data Transfer Addendum. The docking clause is deemed accepted and the optional clause on independent audit is not selected. The governing law and forum for the clauses, and the completed Annexes, are fixed in the executed copy of this DPA; Annex I is prepared from section 3 and Annex I below, and Annex II from Annex II below.

8. Assistance with Data Subject Rights

Hive will, taking into account the nature of the processing, provide reasonable assistance so Customer can respond to data subject requests for access, correction, deletion, restriction, portability, or objection. If a data subject contacts Hive directly about Customer Personal Data, Hive will refer them to Customer rather than respond substantively, unless legally required to do otherwise.

9. Assistance with Assessments

Hive will provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, to the extent they relate to Hive's processing and Customer cannot reasonably obtain the information elsewhere.

10. Personal Data Breach

Hive will notify Customer without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of records affected so far as known, the likely consequences, and the measures taken or proposed. Hive will provide further information as the investigation progresses. Notification is not an admission of fault.

11. Audit

On request, and no more than once in any twelve-month period unless a supervisory authority requires otherwise, Hive will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a security questionnaire. Where that is not sufficient for Customer to meet an obligation under Data Protection Law, the parties will agree the scope, timing, and cost of an on-site or remote audit conducted under confidentiality and without disrupting the service. Hive does not currently hold a SOC 2 or ISO 27001 certification.

12. Return and Deletion

On termination, Hive will delete Customer Personal Data within 90 days, except where retention is required by law, including the billing records described in section 6 of the Privacy Policy. Backups are deleted on their own rotation schedule. Hive cannot delete a payment recorded on a public blockchain.

13. Liability

Each party's liability under this DPA is subject to the limitation of liability in the Terms of Service, except where Data Protection Law does not permit that limit.

14. Order of Precedence

Where this DPA conflicts with the Terms of Service, this DPA controls for the processing of Customer Personal Data. Where the Standard Contractual Clauses conflict with this DPA, the clauses control.

Annex I: Details of Processing

  • Subject matter: provision of the Hive Intelligence MCP server, CLI, and agent skills.
  • Duration: the term of the Terms of Service, plus the retention periods in the Privacy Policy.
  • Nature and purpose: account administration, authentication, delivery of query results from upstream data providers, plan entitlement enforcement, security monitoring, and support.
  • Categories of data subject:Customer's personnel who hold Hive accounts or API keys, and any individual whose personal data Customer includes in a query.
  • Categories of personal data: account email address, account and key identifiers, plan and billing state, IP address, request metadata, and the content of queries. Query content typically contains blockchain identifiers such as wallet addresses, which may be personal data where the individual behind them is identifiable.
  • Special category data: none. Customer must not submit special category data, and the service is not designed to process it.
  • Frequency: continuous, for as long as Customer uses the service.
  • Subprocessors: as listed at /subprocessors.

Annex II: Technical and Organizational Measures

  • Encryption: all traffic to Hive surfaces is served over TLS. Data at rest is encrypted by the managed platforms listed on the subprocessor page.
  • Access control: sign-in is by GitHub or Google OAuth or a one-time emailed code, so no password is stored. API keys are issued through a key-management provider, which stores no recoverable copy; a key is shown in full once, at creation, and can be revoked immediately from the dashboard.
  • Least privilege: production secrets are held in a managed secret store and bound by service identity rather than distributed to individuals.
  • Data minimization in telemetry: tool arguments, response payloads, wallet addresses, and API key values are not written to service telemetry. The calling principal is recorded as a keyed hash.
  • Isolation: customer records are separated by account identifier with row-level access policies on the managed database.
  • Availability: the service runs on managed platforms with automated deployment gates, health checks, and automatic rollback on a failed verification.
  • Vulnerability management: a published disclosure policy with stated response targets at /security, and dependency vulnerability scanning in the release pipeline, which fails the deploy on a high-severity advisory, plus automated dependency updates.
  • Penetration testing: Hive does not currently commission an annual third-party penetration test and does not claim one; vulnerability handling runs through the disclosure policy and pipeline scanning above.

How to execute this DPA

To request an executed copy, email support@hiveintelligence.xyz with the legal name and registered address of the contracting entity, the name and title of the signatory, and any transfer mechanism you require. The executed copy fixes the contracting entities and Annexes and prevails over this page.