Legal

Data Processing Addendum

Effective date: September 2026

This addendum forms part of our Terms of Service and applies where you use HackwithClaude to process personal data subject to data protection law such as the GDPR or UK GDPR.

1. Roles

You are the controller of any personal data contained in requests you send. We act as your processor for that content and as an independent controller for account and billing data we need to run the business.

2. Scope and duration of processing

  • Subject matter: routing your API requests to model providers and metering usage.
  • Duration: for request content, the lifetime of the request only. For account data, as long as your account exists.
  • Data subjects: whoever you choose to include in your prompts, plus your own account users.
  • Categories: free-text content you submit, plus email address, auth identifiers and usage counters.

3. Zero retention of content

Prompts and completions stream through the gateway and are discarded when the response finishes. They are not written to disk, not logged and not used for training. The only per-request records we keep are the model name, token counts and a timestamp, used to calculate usage.

4. Your instructions

We process content only to deliver the service and to comply with law. If we believe an instruction breaches data protection law, we will tell you.

5. Confidentiality and security

  • Access to production systems is limited to personnel who need it.
  • API keys are stored encrypted; row-level security isolates account data.
  • All traffic is encrypted in transit with TLS.
  • Administrative actions require server-side authorisation.

6. Subprocessors

We use the subprocessors listed on our Subprocessors page, each bound to equivalent data protection obligations. That page is updated before a new subprocessor begins processing.

7. International transfers

Requests may be served by infrastructure outside your country, primarily in the United States. Where required, transfers rely on the EU Standard Contractual Clauses or the UK Addendum, together with the safeguards operated by AWS and the upstream providers.

8. Assistance, incidents and audits

  • We will help you respond to data subject requests. Because we hold no request content, most requests concern account data only.
  • We will notify you without undue delay after becoming aware of a personal data breach affecting your account data.
  • We will provide reasonable information to support your compliance reviews on request.

9. Deletion and return

Request content is never stored, so there is nothing to return. When you delete your account, account and usage records are removed except where we must keep billing records for tax and accounting purposes.

10. Signing this DPA

Need a countersigned copy for procurement? Contact @hackwithclaude on Telegram and we will arrange it.