Legal
Data Processing Agreement
Published: September 1, 2026 · Effective: September 15, 2026
This Data Processing Agreement forms part of the Terms of Service between [LEGAL NAME PENDING], a sole trader registered in Israel, trading as Harbor (“Harbor”, the “Processor”), and the customer that agreed them (“you”, the “Controller”). Harbor is a trading name and not a separate company: the Processor is the person named here, who contracts and is accountable personally. It applies wherever Harbor processes Personal Data on your behalf within the meaning of the EU General Data Protection Regulation, the UK GDPR, or an equivalent law. Where it conflicts with the Terms of Service on the subject of data protection, this DPA prevails.
It takes effect when you accept the Terms of Service. No signature is required. If your process needs a counter-signed copy, write to privacy@gethrbr.com and we will execute one on these terms.
1. Definitions
Controller, Processor, Sub-processor, Personal Data, Processing, Data Subject and Personal Data Breach have the meanings given in Article 4 of the GDPR. “Controller Content” means the content Harbor reads from the sources you connect, and the statements Harbor derives from it.
2. Roles of the Parties
For Controller Content, you are the Controller and Harbor is the Processor. For the account, billing, analytics and crash data described in our Privacy Policy, Harbor is a Controller in its own right, and this DPA does not apply to it. Paddle acts as merchant of record and as an independent controller for payment and tax data. The AI providers named in Annex 2 process Controller Content as our sub-processors, under terms we pass through to them.
3. Scope, Purpose and Instructions
Harbor processes Personal Data only to provide the Service as described in the Terms of Service and the Privacy Policy, and only on your documented instructions. This DPA, the Terms, the Privacy Policy and your configuration of the Service together constitute those instructions. We will not process Personal Data for any other purpose without your prior written consent, unless law requires it, in which case we will tell you first unless that law forbids it. We will tell you if, in our opinion, an instruction infringes data protection law.
We do not use Controller Content to train AI models, and we have not granted any sub-processor the right to use it for that purpose.
4. Your Obligations as Controller
You decide which sources Harbor may read, and that decision carries the duties that come with it. You warrant that:
- You have a lawful basis for the processing you instruct, and the authority to connect each source you connect.
- You have given the notices and obtained the consents that your own law requires of you, to your personnel and to anyone else whose Personal Data may be present in the content you connect. This includes people who have never used Harbor: correspondents in a connected mailbox, participants in a connected meeting, and members of a connected channel.
- You will not connect a source whose content you are not entitled to bring into a workspace-visible system, having read section 6 of the Privacy Policy and Annex 4 below.
- You will not use the Service to process special categories of Personal Data, data concerning criminal convictions, or data subject to sector-specific regimes such as HIPAA or PCI DSS, as Harbor is not built for them and no clause here should be read as accepting them.
- Your instructions to us will comply with applicable law, and you will keep your own record of processing as your law requires.
5. Our Obligations as Processor
Harbor shall:
- Process Personal Data only on your documented instructions.
- Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations.
- Implement and maintain the technical and organisational measures set out in Annex 3, as required by Article 32.
- Assist you in responding to Data Subject requests. Erasure is available at workspace granularity through the product. Access, rectification and portability requests are answered by hand, and we will respond within 30 days of your written request.
- Assist you with security, breach notification, breach communication and data protection impact assessments, as required by Articles 32 to 36, taking into account the nature of processing and the information available to us.
- Make available the information necessary to demonstrate compliance with this DPA, including the annexes below and the design-partner security pack.
- Notify you before engaging a new Sub-processor, as set out in section 6.
6. Sub-processors
You give Harbor general authorisation to engage the Sub-processors listed in Annex 2. We will give you at least 14 days' notice, by email to your workspace administrators and by updating Annex 2, before we add or replace one. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of fees paid for the unused remainder of your term, which is your exclusive remedy.
We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.
7. Security
Harbor maintains the measures set out in Annex 3, and will not materially reduce them during the term. You are responsible for your own configuration, for the credentials you issue, for who you admit to a workspace, and for the security of the devices on which the desktop app caches data.
8. Personal Data Breach
Harbor will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Controller Content. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. We will give you the information you reasonably need to meet your own notification obligations. Our notification is not an admission of fault or liability.
9. Audit
On request, and no more than once in any 12-month period, Harbor will complete a written security questionnaire and provide the design-partner security pack. Where that is not sufficient to demonstrate compliance with Article 28, you may audit us, or appoint an independent auditor who is not our competitor and who signs a confidentiality undertaking, on at least 30 days' written notice, during business hours, without unreasonable disruption, and at your cost unless the audit finds a material breach of this DPA.
We do not hold a SOC 2 report or an equivalent third-party attestation today, so none is offered in place of an audit. See Annex 4.
10. International Transfers
Harbor is in Israel, which the European Commission has recognised as providing an adequate level of data protection, so transfers from the EEA to us require no additional mechanism. Where Personal Data is transferred onward to a Sub-processor outside the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Addendum where applicable, on the EU-US Data Privacy Framework where the recipient is certified, or on another lawful transfer mechanism. Where the Clauses apply, module two governs controller-to-processor transfers and module three governs our onward transfers, and this DPA and its annexes populate their appendices.
11. Term, Deletion and Return
This DPA lasts as long as Harbor processes Personal Data on your behalf. On termination, Harbor will delete Controller Content in accordance with Annex 3, and workspace deletion is available to you at any time through the product.
Backups are overwritten on their ordinary cycle. We will delete or return Personal Data unless law requires us to keep it, in which case we will keep it only for as long as that law requires and continue to protect it under this DPA.
12. California and Other US State Privacy Laws
To the extent the California Consumer Privacy Act applies, Harbor is a “service provider” and you are the “business”. Harbor does not sell or share Personal Information, does not retain, use or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, does not combine it with Personal Information from other sources except as the CCPA permits, and will notify you if it determines it can no longer meet those obligations. The equivalent terms apply where Virginia, Colorado, Connecticut, Texas, Oregon or another US state privacy law governs, and Harbor acts as a “processor” under them.
13. Liability
Each party's liability under this DPA is subject to the exclusions and the aggregate cap in the Terms of Service, and the cap is a single aggregate cap across the Terms and this DPA rather than one for each. Nothing in this section limits either party's liability to a Data Subject, or any liability that cannot be limited under applicable law.
Annex 1: Details of the Processing
- Subject matter
- Provision of the Harbor service: reading content from the systems the Controller connects, deriving short written statements from that content, and serving those statements back to the Controller’s users and their AI assistants.
- Duration
- The term of the Terms of Service, plus the retention windows in Annex 3.
- Nature and purpose
- Ingestion, automated extraction and summarisation using third-party AI models, vector embedding, storage, retrieval, ranking, display, and measurement of which statements were served and cited.
- Categories of Data Subject
- The Controller’s personnel, being workspace members; and any individual whose Personal Data appears in the content the Controller connects, which may include the Controller’s customers, suppliers and correspondents.
- Categories of Personal Data
- Identity and contact data, being name, email address and organisation membership; content data, being the text of messages, issues, documents, meeting transcripts and mail drawn from connected sources, and the statements derived from it; usage and telemetry data; and billing identity.
- Special category data
- Not intentionally processed. Harbor does not solicit it and does not filter for it. Content drawn from a Controller’s chat or mail may contain it incidentally, and the Controller decides which sources are connected.
- Frequency
- Continuous, on the sync schedule the Controller configures.
- Transfers
- To the Sub-processors in Annex 2, in the locations stated there.
Annex 2: Sub-processors
Ten, split by the distinction that decides most reviews. Five receive Controller Content:
- OpenAI. Extraction, classification, embeddings, and the default assistant model. Receives text read from connected sources, the derived statements, the embeddings, and assistant conversation turns. United States.
- Anthropic. Question answering over stored knowledge, and longer multi-step assistant runs. United States.
- Google (Gemini). Optional assistant model, and failover. Receives content only where selected as the provider or on failover. United States.
- Amazon Web Services (S3). Storage of statement bodies and the workspace index. United States, us-east-1. Retained until the statement is deleted.
- Amazon Web Services (managed database). Primary datastore operated by Harbor: statements, metadata, sessions, retrieval records, and encrypted connector tokens. United States, us-east-1. Retention per Annex 3.
Five receive identity, billing or telemetry only:
- Clerk. Authentication. Name, email address, organisation membership.
- Paddle. Payment processing and subscription management, as merchant of record and independent controller. Billing identity, plan, subscription events.
- Amazon Web Services (SES). Transactional email. Email addresses and message bodies.
- PostHog. Product analytics and feature flags. Product events, pageviews, a pseudonymous identifier, and the workspace name and slug. United States.
- Sentry. Crash reporting, desktop application only. Crash reports, redacted before transmission.
Annex 3: Technical and Organisational Measures
- Encryption
- TLS in transit. Encryption at rest. Connector tokens encrypted with AES-256-GCM, with the key derived using scrypt and the authenticated data bound to the identity of the record, so a ciphertext moved between records fails the tag check rather than decrypting into the wrong account.
- Secrets and logging
- Credentials are stripped before anything is written to a log, by one shared pattern catalogue rather than per-call-site handling.
- Access control
- Role-based access, restricted to personnel who need it. Tenancy is enforced in code at the workspace boundary; nothing crosses a workspace. Within a workspace, see Annex 4 L3.
- Telemetry
- No third-party analytics in the backend. No session replay and no autocapture in the web or desktop app. Do Not Track is respected and product analytics are disabled outside production builds.
- AI processing
- Content is sent to the providers in Annex 2 for extraction, embedding and answering. It is not used to train models, and no provider is granted the right to use it for that purpose.
- Retention: statements
- Plan-driven. Free 30 days, Pro 365 days, Premium and Enterprise no expiry. Not Controller-configurable. See Annex 4 L2.
- Retention: raw payloads
- Raw payloads fetched from connected sources are purged automatically after 7 days.
- Retention: statement bodies
- Deleted from object storage with the statement they belong to.
- Deletion
- Workspace deletion removes the workspace and its data, and is available to the Controller at any time.
Annex 4: Known Limitations
Disclosed here rather than discovered later. Each of these bears on your own compliance assessment, so you should read them before you rely on Harbor for a regulated workload.
- L1. No self-service export. Deletion works. A structured return of everything Harbor holds is not built, and is produced by hand under section 11.
- L2. Retention follows your billing plan, not your policy. There is no Controller-settable retention ceiling today. If your posture requires one, we do not have it.
- L3. Per-member access control within a workspace is not built. Every member of a workspace can recall every statement in it, whatever the permissions on the source it came from. Space-scoped statements are the only narrowing that exists. This is material, and it is the reason section 4 asks you to warrant what you connect.
- L4. No application-level audit log. There is no per-record record of who accessed what and when that we can make available to you.
- L5. No SOC 2 report and no third-party penetration test. We will begin that work when a customer needs it. Until then no report is offered in place of the audit right in section 9.
Contact
To ask a question about this DPA, to object to a Sub-processor, or to have a counter-signed copy executed, email privacy@gethrbr.com, or write to [LEGAL NAME PENDING], [BUSINESS ADDRESS PENDING], Tel Aviv, Israel.