Data Processing Agreement
In effect from 8 July 2026. This agreement is part of the Terms of Service and applies automatically to every customer. You do not need to sign a separate copy. If your organisation needs a counter-signed version, contact support@hoodik.io.
In short. For the files and data you store on your Instance, you are the data controller and we are your processor. This agreement, required by Article 28 of the GDPR, sets out how we handle that data on your behalf. Because the data is end-to-end encrypted, we hold it as encrypted data we cannot read.
1. Roles
This agreement is between you (the "Controller") and Hudik d.o.o. (the "Processor", "we", "us"), for the personal data we process on your behalf when you use Hoodik Cloud. For our own account, billing and operational data, we are a controller in our own right, as described in the Privacy Policy, and that data is outside this agreement.
2. What we process, and why
- Subject matter and purpose: processing the data on your Instance solely to provide the Service to you under the Terms.
- Duration: for as long as your subscription is active, plus the grace and backup periods described in the Terms, after which the data is deleted.
- Nature of processing: storage, hosting, backup, transmission and deletion of encrypted data, and the technical operations needed to run the application.
- Types of personal data: your files and their contents (held as encrypted data we cannot read); and, in your Instance's database, the email addresses of the users you invite, their password verifiers, their public keys and password-protected private keys, and file metadata such as sizes, timestamps and folder structure, plus a search index of hashed tokens.
- Categories of data subjects: you, the users you invite to your Instance, and the recipients of any share links you create.
3. Our obligations
We will:
- Process only on your instructions. We process the data on your Instance only to provide the Service and as documented in the Terms and this agreement, unless the law requires otherwise, in which case we will tell you, unless the law prohibits it. Using the Service is your instruction to us; if you want us to process differently, ask, and if we cannot, we will tell you.
- Keep it confidential. Everyone we authorise to process the data is bound by confidentiality.
- Keep it secure. We apply appropriate technical and organisational measures (see section 4).
- Use sub-processors only as set out in section 5.
- Help you meet your obligations to data subjects and to regulators (see section 6).
- Delete or return the data at the end of the Service (see section 7).
- Give you the information needed to show compliance, and allow audits, as set out in section 8.
4. Security
The core protection is the end-to-end encryption built into Hoodik: your files are encrypted on your devices with keys we never receive, so we store only encrypted data and cannot read your Content. In addition, each customer's Instance is isolated from every other; data is encrypted in transit; access to our systems is restricted and controlled; and we keep backups of encrypted data. We consider these measures appropriate to the risk, taking into account that we hold no keys to your Content.
5. Sub-processors
You authorise us to use the sub-processors below to provide the Service. Each processes only what it needs to. Any sub-processor that stores your Content only ever receives and stores ciphertext; none of them receive decryption keys.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner | Servers and compute | EU or US (your choice) |
| Cloudflare | Encrypted object storage, DNS and network edge | EU or US (your choice) |
| Paddle | Payment processing (Merchant of Record) | EU / UK / US |
| Scaleway | Transactional email | EU (France) |
If we intend to add or replace a sub-processor, we will give you reasonable prior notice and a chance to object on reasonable data-protection grounds. Every sub-processor is bound by data-protection obligations equivalent to those in this agreement.
6. Helping you meet your obligations
Taking into account the nature of the processing, we will help you respond to requests from data subjects exercising their rights, and help you with your obligations around security, breach notification, data protection impact assessments and prior consultation. In practice, much of this is built into the Service. For example, your one-click encrypted export covers data portability directly, and you control the user accounts on your Instance.
7. Personal data breaches
If we become aware of a personal data breach affecting the data we process for you, we will notify you without undue delay and give you the information you need to meet your own notification duties. Because your file content is encrypted with keys we do not hold, exposure of that content alone would leave it unreadable; we will still tell you, and we assess any incident that could affect data that is not fully unreadable.
8. Return and deletion; audits
At any time, you can export all of your data yourself as an encrypted export. When the Service ends, we delete the data after the grace and backup periods described in the Terms, except where the law requires us to keep specific data. On reasonable request, we will make available the information needed to demonstrate our compliance with this agreement, and allow and contribute to audits, which may be satisfied through documentation, given the encrypted nature of the data.
9. International transfers
We keep your data in the region you choose (EU or US). Where a transfer outside the EEA occurs, appropriate safeguards apply, including Standard Contractual Clauses where required. In all cases the transferred data consists solely of encrypted Content that the recipient cannot read.
10. Precedence
If there is a conflict between this agreement and the rest of the Terms on the processing of personal data on your Instance, this agreement prevails. Everything else in the Terms continues to apply.
11. Contact
support@hoodik.io · Hudik d.o.o., Kapelska 6, 31000 Osijek, Croatia.