Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Customer", the data controller) and Begonia Holdings LLC, a Wyoming limited liability company with its registered office at 30 N Gould St, Ste R, Sheridan, Wyoming 82801, USA, operating HopToDesk ("HopToDesk", the data processor), governing HopToDesk's processing of personal data on the Customer's behalf in connection with the HopToDesk Dashboard Pro service (the "Service"). It reflects the parties' obligations under the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent laws.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings given in the GDPR. "Sub-processor" means any third party engaged by HopToDesk to process personal data. "Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission for transfers of personal data to third countries (Commission Implementing Decision (EU) 2021/914). "UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the SCCs.

2. Roles and scope

The Customer is the controller and HopToDesk is the processor of the personal data described in Annex A. HopToDesk processes personal data only to provide the Service and only as described in this DPA and the Customer's documented instructions.

3. Processing on documented instructions

HopToDesk will process personal data only on the Customer's documented instructions, including the agreement and this DPA, unless required by law, in which case HopToDesk will inform the Customer first unless that law prohibits it. HopToDesk will immediately inform the Customer if it considers that an instruction infringes data protection law (GDPR Article 28(3), final paragraph).

4. Confidentiality

HopToDesk ensures that personnel and contractors authorized to process the personal data are bound by appropriate confidentiality obligations and are informed of the confidential nature of the data. These confidentiality obligations survive termination of the agreement.

5. Security

HopToDesk implements appropriate technical and organizational measures to protect personal data, as described in Annex C, taking into account the state of the art, costs, and the nature and risks of the processing (GDPR Article 32).

6. Sub-processors

The Customer provides general authorization for HopToDesk to engage the sub-processors listed in Annex B. HopToDesk will impose data protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance.

HopToDesk will give the Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor. If the Customer objects on reasonable data protection grounds within that period, HopToDesk will use commercially reasonable efforts to make available a change to the Service, or to recommend a commercially reasonable alternative, that avoids processing by the objected-to sub-processor. If HopToDesk is unable to do so within a reasonable time, the Customer may, as its sole and exclusive remedy, terminate the portion of the Service that cannot be provided without the objected-to sub-processor.

7. International transfers

Where HopToDesk processes personal data outside the European Economic Area, the United Kingdom, or Switzerland (including in the United States, where the primary database is currently located), the parties agree to the following transfer mechanism:

  • The Standard Contractual Clauses are incorporated by reference, with Module Two (controller to processor) applying. For the purposes of the SCCs, the Customer is the data exporter and HopToDesk is the data importer. The optional docking clause applies; the Clause 9 option is General Authorization with a 30-day notice period (consistent with Section 6); the Clause 11 independent-dispute-resolution option does not apply; the governing law and forum for the SCCs are those of Ireland unless the parties agree otherwise; and Annexes I, II, and III to the SCCs are completed by reference to Annexes A, B, and C of this DPA.
  • For transfers subject to the UK GDPR, the UK Addendum is incorporated and completed by reference to the SCC information above.
  • For transfers subject to Swiss law, the SCCs apply with the adaptations described in guidance from the Swiss Federal Data Protection and Information Commissioner, or, alternatively, Switzerland is out of scope of this DPA where the parties so agree.
  • HopToDesk has performed, and will make available to the Customer on reasonable request, a transfer impact assessment, and will adopt supplementary measures where required by applicable law (consistent with Schrems II).
  • Where a US sub-processor is certified under the EU-US Data Privacy Framework (and the UK Extension and Swiss-US framework as applicable), that framework may also serve as a transfer mechanism for transfers to that sub-processor.

8. Assistance to the Customer

Taking into account the nature of the processing, HopToDesk will:

  • assist the Customer, by appropriate technical and organizational measures, in responding to data subject requests (access, rectification, erasure, restriction, portability, objection); and
  • assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation (GDPR Articles 32 to 36).

Such assistance is provided at no additional charge to the extent reasonable. HopToDesk may charge reasonable fees, notified in advance, for assistance that is disproportionate or unusually burdensome relative to the Service.

9. Personal data breach

HopToDesk will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Customer's personal data. The notification will include the information reasonably available to HopToDesk to help the Customer meet its own notification obligations, and HopToDesk will provide further information as it becomes available.

10. Audits

HopToDesk will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Where HopToDesk holds current third-party audit reports or certifications (for example a SOC 2 report or ISO/IEC 27001 certificate, whether of HopToDesk or of its sub-processors), the Customer will first accept those reports as evidence of compliance.

Where those reports are insufficient to address a specific, reasonable concern, the Customer (or an independent auditor it mandates that is not a competitor of HopToDesk and that has signed a non-disclosure agreement acceptable to HopToDesk) may conduct an audit, subject to: reasonable prior written notice of at least 30 days; no more than once per 12-month period except following a personal data breach or where required by a supervisory authority; conduct during business hours in a manner that does not unreasonably disrupt the Service; no access to the data or systems of HopToDesk's other customers or to HopToDesk's confidential or proprietary information; and the Customer bearing its own costs and HopToDesk's reasonable costs of cooperation.

11. Deletion or return

On termination of the Service, HopToDesk will, at the Customer's choice, delete or return the personal data and delete existing copies from production systems within 30 days, unless retention is required by law. Personal data residing in routine backups will be deleted or overwritten in the ordinary course of HopToDesk's backup retention cycle (currently 30 days: platform point-in-time recovery covers 30 days, and nightly encrypted export archives are pruned after 7 days), during which such data will be isolated and not restored to production or used for any other purpose except disaster recovery.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement, including its aggregate liability cap. Claims relating to data protection are not carved out of that cap and do not attract a separate or higher one.

Nothing in this Section limits or affects either party's liability to a data subject under GDPR Article 82, or to a supervisory authority. Article 82 liability runs directly to the individual and cannot be allocated by agreement between the parties; this Section governs only claims between HopToDesk and the Customer.

13. Data protection contact

Questions or requests relating to this DPA or HopToDesk's processing of personal data may be directed to contact@hoptodesk.com.

HopToDesk has not appointed a data protection officer. Article 37(1) requires one where processing is carried out by a public authority, where core activities consist of regular and systematic monitoring of data subjects on a large scale, or where core activities involve large-scale processing of special-category data. Assessed against HopToDesk's own processing as controller, which is account, billing, and support data for its account holders, none of those applies. The monitoring of end users that the Service makes possible is carried out by the Customer as controller and is assessed against the Customer, not against HopToDesk as processor. This position is reviewed as the service grows, in particular if the account base or the categories of data processed change materially.

14. Governing law

This DPA is governed by the law that governs the main agreement, which is the law of the State of Wyoming, USA, except where applicable data protection law or the SCCs require otherwise.

The Standard Contractual Clauses are an exception by their own terms. Clause 17 requires them to be governed by the law of an EU member state, and Section 7 sets that as the law of Ireland. So the SCC obligations, including the rights they confer on data subjects as third-party beneficiaries, are governed by Irish law regardless of the governing law of the rest of this DPA.

Where a Customer established in the EU asks that this DPA as a whole be governed by the law of its own establishment, that is a negotiated term rather than a standard one. It is available on a signed agreement and is not offered on self-serve plans.

15. Term and survival

This DPA takes effect when both parties sign and continues for as long as HopToDesk processes personal data on the Customer's behalf. The confidentiality, audit-record, deletion, and liability provisions survive termination to the extent necessary to give them effect.

---

Annex A: Details of processing

  • Subject matter: provision of the HopToDesk Dashboard Pro remote-support and device-management service.
  • Duration: the term of the agreement, plus the retention and deletion periods described in Section 11.
  • Nature and purpose: hosting, managing, and brokering remote access to the Customer's managed devices, plus related account, ticketing, and reporting features.
  • Types of personal data: account holder and team member identifiers (name, email address); device and end-user identifiers (device name, computer name, operating system, IP address, MAC address); connection and session records, including who connected to which device and when, file-transfer and unattended-access logs; support ticket contents and any personal data the Customer or its end users place in them; contact records the Customer creates; and billing identifiers. The Service transports remote-session content end to end and does not retain screen content, keystrokes, or transferred file contents.
  • Categories of data subjects: the Customer's personnel, the Customer's own clients and their personnel whose devices are managed, and support contacts.
  • Retention periods by category, verified against the running service on 2026-08-10: login attempt and team-invite attempt logs 90 days, enforced by a daily job; email delivery logs 180 days, same job; checkout intent records and avatar fetch logs 30 days; resolved alerts 90 days; customer audit logs for the term of the agreement, configurable 7 to 3650 days on the custom tier and enforced per account; support tickets for the term of the agreement; encrypted database backups 7 days in cloud object storage, plus encrypted copies held on company-controlled hardware; account data for the term of the agreement, hard-deleted on account deletion (devices, tickets, team members, API keys, subscriptions and the account records are removed, not flagged).

Annex B: Approved sub-processors

The current list of approved sub-processors, with the purpose, processing location and transfer basis for each, is published at https://www.hoptodesk.com/security and forms part of this DPA. That page is the authoritative list.

Payments made through the website checkout are handled by Link, LLC (formerly Lemon Squeezy LLC), trading as Lemon Squeezy, as merchant of record. For those the sale is legally between the Customer and Link, LLC, so for the payment transaction they act as an independent controller rather than as a sub-processor engaged by HopToDesk, and their own terms apply to it. Customers on invoiced agreements are billed directly by Begonia Holdings LLC and pay by bank transfer; there the sale is with HopToDesk, which holds the Customer's billing details as controller of its own commercial records, and the banks that move the funds act as independent controllers under their own legal obligations. Neither route places a sub-processor between HopToDesk and the Customer's personal data.

HopToDesk also engages Anthropic, PBC in two ways that fall outside this DPA because HopToDesk acts as controller for its own purposes rather than as the Customer's processor: automated fraud screening at checkout, and moderation of images uploaded to the custom client builder. These are described in the privacy notice.

Annex C: Technical and organizational measures

  • Encryption of data in transit (TLS) and at rest at the platform level (infrastructure provider).
  • End-to-end encryption of remote control sessions.
  • Salted password hashing; optional two-factor authentication, enforceable across a customer's team; single sign-on via OpenID Connect (for example Microsoft Entra) with SCIM user provisioning; role-based access control; device-group and tenant scoping of what a given user may see; scoped, revocable API keys that can be bound to a single tenant.
  • Admin activity audit logging with export.
  • Use of certified infrastructure providers (the dashboard cloud provider maintains ISO/IEC 27001 and SOC 2 Type II at the platform level; the signal and relay datacenter provider maintains ISO/IEC 27001).

This annex describes technical and organizational measures for GDPR Article 32. It is not a HIPAA Security Rule safeguards description, which is handled separately in the BAA. Each measure above was checked against the running service rather than aspirational; re-check it whenever authentication, scoping, or encryption behaviour changes.

English Français Español Português Deutsch Nederlands Polski Čeština Norsk Svenska Русский Türkçe עברית العربية Bahasa Tiếng Việt 简体中文 正體字 日本語 한국어 ภาษาไทย Italiano Български Ελληνικά