Legal · Data processing agreement

Data processing agreement.

Last updated · July 2026

This Data Processing Agreement (“DPA”) forms part of the CoreDesk Terms of Service between HC Core Tech, the operator of CoreDesk (“Processor”), and the User (“Controller”) in respect of the personal data that the Controller enters into or generates within a CoreDesk workspace. It sets out the rights and obligations of the parties for the purposes of Article 28 of the EU General Data Protection Regulation (GDPR).

This DPA applies to the CoreDesk platform at hccoredesk.com only. A separate DPA applies to consulting engagements under HC Core Tech at hccoretech.com.
01

Definitions

Terms used in this DPA have the meaning given to them in GDPR Article 4, including “personal data”, “processing”, “controller”, “processor”, “sub-processor”, and “data subject”. “Applicable Data Protection Law” means GDPR together with the Dutch Uitvoeringswet AVG and any successor or supplementing legislation.

02

Subject matter and duration

The subject matter of processing is the operation of the CoreDesk platform on behalf of the Controller in accordance with the Terms of Service. The duration of processing is the term of the Controller's CoreDesk subscription plus the post-termination retention period defined in Section 10.

03

Nature and purpose of processing

Processing is performed to provide the CoreDesk platform: email triage, CRM, meeting logging, finance management, content drafting, AI-assisted operations, and the governance layer that monitors and documents these operations. Processing is carried out only on documented instructions from the Controller, including through the Controller's ordinary use of the platform.

04

Categories of personal data

Depending on how the Controller uses CoreDesk, processed personal data may include: names, business email addresses, phone numbers, mailing addresses, roles, meeting notes, communications content, financial records (invoices, quotes, payment references), scheduling data, and any other personal data the Controller chooses to enter into the workspace.

05

Categories of data subjects

Data subjects may include: the Controller's own personnel, the Controller's clients or patients, the Controller's contractors and suppliers, individuals contacted or invoiced through the CoreDesk platform, and prospects whose data the Controller has entered.

06

Processor obligations

The Processor undertakes to:

  • Process personal data only on documented instructions from the Controller, unless required to do otherwise by EU or member-state law (in which case the Processor will inform the Controller of that requirement before processing, unless the law prohibits such notice).
  • Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement the technical and organisational measures set out in the Annex below (Security Measures) in accordance with GDPR Article 32.
  • Assist the Controller, taking into account the nature of processing, in fulfilling the Controller's obligations to respond to data-subject rights requests.
  • Assist the Controller in ensuring compliance with GDPR Articles 32 to 36 (security, breach notification, data protection impact assessments).
  • At the Controller's choice, delete or return all personal data to the Controller at the end of the provision of CoreDesk services, and delete existing copies unless retention is required by law (see Section 10).
07

Sub-processors

The Controller provides general written authorisation to the Processor to engage the sub-processors listed below, all of which support the operation of CoreDesk. The Processor will notify the Controller at least thirty (30) days before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds.

Sub-processorPurposeLocation
Hetzner Online GmbHInfrastructure hosting, workspace databases, backupsGermany / Finland (EU)
Anthropic PBCAI-assisted drafting, triage, and summarisationUnited States
OpenAI L.L.C.AI-assisted operations (where enabled by Controller)United States
Microsoft Ireland Ops Ltd.Email / calendar integration (where connected)Ireland (EU)
Google Ireland LimitedGoogle Meet integration (where connected)Ireland (EU)
Stripe Payments EuropePayment processing for CoreDesk subscription feesIreland (EU)
Vercel Inc.Public marketing surface hosting (hccoredesk.com)United States / EU

The Processor imposes on each sub-processor, by way of a contract or other legal act, obligations equivalent to those set out in this DPA in accordance with GDPR Article 28(4).

08

International transfers

Where sub-processors are located outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, together with the supplementary technical measures set out in the Annex, and, where the recipient participates, the EU-US Data Privacy Framework.

09

Personal data breach notification

The Processor will notify the Controller of any personal data breach affecting the Controller's data within twenty-four (24) hours of becoming aware of it, in accordance with GDPR Article 33(2).

Such notification will describe, to the extent then known: the nature of the breach, the categories and approximate number of data subjects concerned, the categories and approximate number of personal data records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects. Further information will be provided in phases as the investigation progresses.

10

Return and deletion of data

Upon termination of the CoreDesk subscription, the Processor will, at the Controller's choice: (a) return all personal data in a structured, commonly-used, machine-readable format, or (b) delete all personal data. In either case, workspace data is preserved for ninety (90) days as a safety buffer to protect against inadvertent termination, after which deletion is completed.

The Processor may retain personal data to the extent required by EU or member-state law (for example, invoice records retained for seven years under the Dutch Fiscal Code); such retained data continues to be protected in accordance with this DPA.

11

Audit rights

The Processor makes available to the Controller information reasonably necessary to demonstrate compliance with this DPA, including summaries of security controls, sub-processor agreements, and audit logs relevant to the Controller's workspace. On-site audits may be requested by the Controller with thirty (30) days' prior written notice, no more than once per year, at the Controller's cost, unless a breach is confirmed during the audit in which case reasonable audit costs are borne by the Processor.

12

Liability

The liability of each party under this DPA is subject to the limitations of liability set out in the CoreDesk Terms of Service. This DPA does not enlarge or reduce statutory liability arising under GDPR Article 82.

13

Governing law

This DPA is governed by the laws of the Netherlands and subject to the exclusive jurisdiction of the competent Dutch courts, without prejudice to the rights of data subjects under GDPR Article 79.

0A

Annex — Security measures

The following technical and organisational measures are implemented in the operation of CoreDesk in accordance with GDPR Article 32:

  • Encryption at rest — workspace databases and backups are stored on encrypted volumes.
  • Encryption in transit — all connections use TLS 1.2 or higher; older protocols are disabled.
  • Workspace isolation — each active Controller has a dedicated database instance; there is no shared multi-tenant table structure for workspace content.
  • Access control — production access is limited to the Processor (HC Core Tech), enforced via strong authentication and audit logging.
  • Audit logging — the governance layer records every AI action and administrative operation. Logs are retained for up to twelve (12) months for security review.
  • Backups — automated daily backups within the EU with retention appropriate to workspace continuity.
  • Vulnerability management — timely patching of underlying infrastructure and dependencies.
  • Approval-first AI operations — nothing sends, publishes, or acts across the workspace without explicit Controller approval, reducing the risk of unauthorised outbound processing.
0B

Contact

Questions or requests relating to this DPA may be sent to hello@hccoredesk.com, with hc@hccoretech.com as a backup.

Terms of servicePrivacy policyData processing