This Data Processing Agreement ("DPA") is part of the Terms of Service between you ("Customer") and Hi5 Biz Solutions LLC ("Hi5"). It applies whenever Hi5 processes personal data on Customer's behalf through Hi5 Connect. By accepting the Terms, Customer accepts this DPA. If this DPA conflicts with the Terms, this DPA controls for personal data.
1. Definitions
- Customer Personal Data: personal data in Customer Data that Hi5 processes for Customer through the Platform.
- Data Protection Laws: all privacy and data protection laws that apply, including the GDPR, UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), the Texas Data Privacy and Security Act and other U.S. state privacy laws, PIPEDA and the Australian Privacy Act.
- Controller, Processor, Data Subject, Personal Data Breach, Processing: as defined in the GDPR. "Business," "Service Provider" and "Contractor" have the meanings in the CCPA.
- Subprocessor: a third party Hi5 engages to process Customer Personal Data.
2. Roles
Customer is the Controller (or "Business"), and Hi5 is the Processor (or "Service Provider"). Customer decides what personal data to collect and why. Customer is responsible for having a lawful basis and any consents needed, and for giving its contacts the privacy notices the law requires.
3. How Hi5 processes Customer Personal Data
Hi5 will:
- Process Customer Personal Data only on Customer's documented instructions (these Terms, this DPA and Customer's use of the Platform are Customer's instructions), unless the law requires otherwise
- Tell Customer if it believes an instruction violates Data Protection Laws
- Not sell or share Customer Personal Data, or use it for any purpose other than providing the Platform, including targeted advertising
- Not combine Customer Personal Data with other data except as the law allows
- Comply with the CCPA's obligations for service providers and give the same level of protection it requires
4. Confidentiality of personnel
Hi5 limits access to Customer Personal Data to personnel who need it to provide or support the Platform and who are bound by confidentiality obligations.
5. Security
Hi5 and its Subprocessors keep appropriate technical and organizational measures in place to protect Customer Personal Data, as described in Annex 2, including encryption in transit and at rest, access controls, two-factor authentication, backups, monitoring and regular security testing.
6. Subprocessors
- Customer authorizes Hi5 to use the Subprocessors listed in Annex 3.
- Hi5 puts written agreements in place with each Subprocessor that protect Customer Personal Data at least as well as this DPA, and remains responsible for their performance.
- Hi5 will update Annex 3 and notify Customer at least 14 days before adding or replacing a Subprocessor. Customer can object in writing on reasonable data protection grounds within that period. If we can't resolve the objection, Customer can cancel the affected service and receive a refund of prepaid fees for the unused period.
7. Data subject requests
Hi5 will promptly tell Customer about any request it receives from a Data Subject about Customer Personal Data, and won't respond except on Customer's instructions. The Platform gives Customer tools to access, correct, export and delete contact data. Hi5 will provide reasonable additional help where Customer can't handle a request with these tools.
8. Personal data breaches
Hi5 will notify Customer without undue delay, and within 72 hours after Hi5 becomes aware of a Personal Data Breach affecting Customer Personal Data. The notice will include what Hi5 knows about the nature of the breach, the data and people affected, likely consequences and the steps being taken, with updates as more information becomes available. Hi5 will reasonably help Customer meet its own breach notification obligations.
9. Assessments and consultations
Hi5 will provide reasonable information to help Customer complete data protection impact assessments and consult regulators where the law requires.
10. Deletion and return
Customer can export Customer Personal Data at any time while its account is active. After the account ends, Hi5 will delete Customer Personal Data within 90 days, except where the law requires it to be kept. Data in backups is deleted on the normal backup cycle and stays protected by this DPA until then.
11. Audits
Hi5 will make available the information reasonably needed to show compliance with this DPA, including summaries of its platform provider's independent security audits (such as SOC 2 Type II reports, under confidentiality). If the law requires more, Customer may request an audit with at least 30 days' notice, no more than once per year, during business hours and at Customer's expense.
12. International transfers
Customer Personal Data may be processed in the United States and other countries where Hi5 and its Subprocessors operate. For transfers of personal data from the EEA, UK or Switzerland to countries without an adequacy decision, the parties agree to the EU Standard Contractual Clauses (Module 2, Controller to Processor, or Module 3 where applicable) and the UK International Data Transfer Addendum, which are incorporated by reference, and Subprocessors rely on the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses.
13. Government requests
If a government authority asks Hi5 for Customer Personal Data, Hi5 will require a valid legal order, notify Customer first unless legally prohibited, and challenge requests that are overly broad or unlawful where reasonable. Hi5 has not built backdoors into the Platform and won't do so voluntarily.
14. Health information (HIPAA)
This DPA is not a Business Associate Agreement. Customer must not store protected health information in the Platform unless Hi5 and Customer have signed a separate Business Associate Agreement and the account is configured for it. Hi5 does not currently offer Business Associate Agreements.
15. Liability
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws don't allow those limitations.
16. Changes and term
Hi5 may update this DPA to reflect changes in law or its services, with at least 14 days' notice for material changes. This DPA lasts as long as Hi5 processes Customer Personal Data.
Annex 1: Details of processing
- Subject matter: providing the Hi5 Connect Platform
- Duration: the term of the Terms of Service, plus the deletion period in section 10
- Nature and purpose: hosting, storage, CRM, communications (calls, texts, email, voicemail drops, chat), websites and forms, calendars and booking, payments, reputation management, AI features, automations, reporting and support
- Data Subjects: Customer's leads, clients, contacts, website visitors, students and families, employees and users
- Categories of data: names, contact details (phone, email, address), business information, messages and call recordings, appointments, form and survey responses, transaction records (not full card numbers), files and documents, website usage data and any other data Customer chooses to upload
- Sensitive data: none intended. Customer must not upload special category data, government ID numbers or health information unless the parties agree in writing.
Annex 2: Security measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Hosting in Google Cloud Platform data centers with physical security controls
- Two-factor authentication, role-based permissions and activity logs
- Frequent automated backups and disaster recovery
- DDoS protection and web application firewall
- Third-party penetration testing and automated vulnerability scanning by our platform provider
- Independent SOC 2 Type II audits of platform infrastructure
- Personnel access limited by need, with confidentiality obligations
- Incident response procedures and breach notification (section 8)
- Vendor risk management for Subprocessors
Annex 3: Subprocessors
Hi5 uses subprocessors in these categories:
| Category | Purpose | Location |
|---|---|---|
| Core platform provider | Platform infrastructure, CRM, hosting and communications | United States |
| Cloud hosting | Data storage and hosting | United States |
| Telecommunications providers | Calls, texts and phone numbers | United States |
| Email delivery providers | Email sending | United States |
| AI model providers | AI features | United States |
| Payment processors | Payments and billing | United States |
| Support and productivity tools | Customer support and internal communications | United States |
The full list of named subprocessors is available on request. Email info@hi5connect.com with "Subprocessor list" in the subject line and we'll send it within 5 business days. Customers who want notice of changes can ask to be added to our subprocessor update list.