This Data Processing Agreement (“DPA”) forms part of the CoreDesk Terms of Service between HC Core Tech, the operator of CoreDesk (“Processor”), and the User (“Controller”) in respect of the personal data that the Controller enters into or generates within a CoreDesk workspace. It sets out the rights and obligations of the parties for the purposes of Article 28 of the EU General Data Protection Regulation (GDPR).
Definitions
Terms used in this DPA have the meaning given to them in GDPR Article 4, including “personal data”, “processing”, “controller”, “processor”, “sub-processor”, and “data subject”. “Applicable Data Protection Law” means GDPR together with the Dutch Uitvoeringswet AVG and any successor or supplementing legislation.
Subject matter and duration
The subject matter of processing is the operation of the CoreDesk platform on behalf of the Controller in accordance with the Terms of Service. The duration of processing is the term of the Controller's CoreDesk subscription plus the post-termination retention period defined in Section 10.
Nature and purpose of processing
Processing is performed to provide the CoreDesk platform: email triage, CRM, meeting logging, finance management, content drafting, AI-assisted operations, and the governance layer that monitors and documents these operations. Processing is carried out only on documented instructions from the Controller, including through the Controller's ordinary use of the platform.
Categories of personal data
Depending on how the Controller uses CoreDesk, processed personal data may include: names, business email addresses, phone numbers, mailing addresses, roles, meeting notes, communications content, financial records (invoices, quotes, payment references), scheduling data, and any other personal data the Controller chooses to enter into the workspace.
Categories of data subjects
Data subjects may include: the Controller's own personnel, the Controller's clients or patients, the Controller's contractors and suppliers, individuals contacted or invoiced through the CoreDesk platform, and prospects whose data the Controller has entered.
Processor obligations
The Processor undertakes to:
- Process personal data only on documented instructions from the Controller, unless required to do otherwise by EU or member-state law (in which case the Processor will inform the Controller of that requirement before processing, unless the law prohibits such notice).
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement the technical and organisational measures set out in the Annex below (Security Measures) in accordance with GDPR Article 32.
- Assist the Controller, taking into account the nature of processing, in fulfilling the Controller's obligations to respond to data-subject rights requests.
- Assist the Controller in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments).
- At the Controller's choice, delete or return all personal data to the Controller at the end of the provision of CoreDesk services, and delete existing copies unless retention is required by law (see Section 10).
Sub-processors
The Controller provides general written authorisation to the Processor to engage the sub-processors listed below, all of which support the operation of CoreDesk. The Processor will notify the Controller at least thirty (30) days before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure hosting, workspace databases, backups | Germany / Finland (EU) |
| Anthropic PBC | AI-assisted drafting, triage, and summarisation | United States |
| OpenAI L.L.C. | AI-assisted operations (where enabled by Controller) | United States |
| Microsoft Ireland Ops Ltd. | Email / calendar integration (where connected) | Ireland (EU) |
| Google Ireland Limited | Google Meet integration (where connected) | Ireland (EU) |
| Stripe Payments Europe | Payment processing for CoreDesk subscription fees | Ireland (EU) |
| Vercel Inc. | Public marketing surface hosting (hccoredesk.com) | United States / EU |
The Processor imposes on each sub-processor, by way of a contract or other legal act, obligations equivalent to those set out in this DPA in accordance with GDPR Article 28(4).
International transfers
Where sub-processors are located outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, together with the supplementary technical measures set out in the Annex, and, where the recipient participates, the EU-US Data Privacy Framework.
Personal data breach notification
Such notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of personal data records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects. Further information will be provided in phases as the investigation progresses.
Return and deletion of data
Upon termination of the CoreDesk subscription, the Processor will, at the Controller's choice: (a) return all personal data in a structured, commonly-used, machine-readable format, or (b) delete all personal data. In either case, workspace data is preserved for ninety (90) days as a safety buffer to protect against inadvertent termination, after which deletion is completed.
The Processor may retain personal data to the extent required by EU or member-state law (for example, invoice records retained for seven years under the Dutch Fiscal Code); such retained data continues to be protected in accordance with this DPA.
Audit rights
The Processor makes available to the Controller information reasonably necessary to demonstrate compliance with this DPA, including summaries of security controls, sub-processor agreements, and audit logs relevant to the Controller's workspace. On-site audits may be requested by the Controller with thirty (30) days' prior written notice, no more than once per year, at the Controller's cost, unless a breach is confirmed during the audit in which case reasonable audit costs are borne by the Processor.
Liability
The liability of each party under this DPA is subject to the limitations of liability set out in the CoreDesk Terms of Service. This DPA does not enlarge or reduce statutory liability arising under GDPR Article 82.
Governing law
This DPA is governed by the laws of the Netherlands and subject to the exclusive jurisdiction of the competent Dutch courts, without prejudice to the rights of data subjects under GDPR Article 79.
Annex — Security measures
The following technical and organisational measures are implemented in the operation of CoreDesk in accordance with GDPR Article 32:
- Encryption at rest — workspace databases and backups are stored on encrypted volumes.
- Encryption in transit — all connections use TLS 1.2 or higher; older protocols are disabled.
- Workspace isolation — each active Controller has a dedicated database instance; there is no shared multi-tenant table structure for workspace content.
- Access control — production access is limited to the Processor (HC Core Tech), enforced via strong authentication and audit logging.
- Audit logging — the governance layer records every AI action and administrative operation. Logs are retained for up to twelve (12) months for security review.
- Backups — automated daily backups within the EU with retention appropriate to workspace continuity.
- Vulnerability management — timely patching of underlying infrastructure and dependencies.
- Approval-first AI operations — nothing sends, publishes, or acts across the workspace without explicit Controller approval, reducing the risk of unauthorised outbound processing.
Contact
Questions or requests relating to this DPA may be sent to hello@hccoredesk.com, with hc@hccoretech.com as a backup.