harbor
How it worksYour agentsYou decideWhat it provesPricing
Get started →
How it worksYour agentsYou decideWhat it provesPricingGet started →
Home/Legal

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Refund Policy

Legal

Data Processing Agreement

Published: September 1, 2026 · Effective: September 15, 2026

This Data Processing Agreement forms part of the Terms of Service between [LEGAL NAME PENDING], a sole trader registered in Israel, trading as Harbor (“Harbor”, the “Processor”), and the customer that agreed them (“you”, the “Controller”). Harbor is a trading name and not a separate company: the Processor is the person named here, who contracts and is accountable personally. It applies wherever Harbor processes Personal Data on your behalf within the meaning of the EU General Data Protection Regulation, the UK GDPR, or an equivalent law. Where it conflicts with the Terms of Service on the subject of data protection, this DPA prevails.

It takes effect when you accept the Terms of Service. No signature is required. If your process needs a counter-signed copy, write to privacy@gethrbr.com and we will execute one on these terms.

1. Definitions

Controller, Processor, Sub-processor, Personal Data, Processing, Data Subject and Personal Data Breach have the meanings given in Article 4 of the GDPR. “Controller Content” means the content Harbor reads from the sources you connect, and the statements Harbor derives from it.

2. Roles of the Parties

For Controller Content, you are the Controller and Harbor is the Processor. For the account, billing, analytics and crash data described in our Privacy Policy, Harbor is a Controller in its own right, and this DPA does not apply to it. Paddle acts as merchant of record and as an independent controller for payment and tax data. The AI providers named in Annex 2 process Controller Content as our sub-processors, under terms we pass through to them.

3. Scope, Purpose and Instructions

Harbor processes Personal Data only to provide the Service as described in the Terms of Service and the Privacy Policy, and only on your documented instructions. This DPA, the Terms, the Privacy Policy and your configuration of the Service together constitute those instructions. We will not process Personal Data for any other purpose without your prior written consent, unless law requires it, in which case we will tell you first unless that law forbids it. We will tell you if, in our opinion, an instruction infringes data protection law.

We do not use Controller Content to train AI models, and we have not granted any sub-processor the right to use it for that purpose.

4. Your Obligations as Controller

You decide which sources Harbor may read, and that decision carries the duties that come with it. You warrant that:

  • You have a lawful basis for the processing you instruct, and the authority to connect each source you connect.
  • You have given the notices and obtained the consents that your own law requires of you, to your personnel and to anyone else whose Personal Data may be present in the content you connect. This includes people who have never used Harbor: correspondents in a connected mailbox, participants in a connected meeting, and members of a connected channel.
  • You will not connect a source whose content you are not entitled to bring into a workspace-visible system, having read section 6 of the Privacy Policy and Annex 4 below.
  • You will not use the Service to process special categories of Personal Data, data concerning criminal convictions, or data subject to sector-specific regimes such as HIPAA or PCI DSS, as Harbor is not built for them and no clause here should be read as accepting them.
  • Your instructions to us will comply with applicable law, and you will keep your own record of processing as your law requires.

5. Our Obligations as Processor

Harbor shall:

  • Process Personal Data only on your documented instructions.
  • Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations.
  • Implement and maintain the technical and organisational measures set out in Annex 3, as required by Article 32.
  • Assist you in responding to Data Subject requests. Erasure is available at workspace granularity through the product. Access, rectification and portability requests are answered by hand, and we will respond within 30 days of your written request.
  • Assist you with security, breach notification, breach communication and data protection impact assessments, as required by Articles 32 to 36, taking into account the nature of processing and the information available to us.
  • Make available the information necessary to demonstrate compliance with this DPA, including the annexes below and the design-partner security pack.
  • Notify you before engaging a new Sub-processor, as set out in section 6.

6. Sub-processors

You give Harbor general authorisation to engage the Sub-processors listed in Annex 2. We will give you at least 14 days' notice, by email to your workspace administrators and by updating Annex 2, before we add or replace one. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro-rata refund of fees paid for the unused remainder of your term, which is your exclusive remedy.

We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.

7. Security

Harbor maintains the measures set out in Annex 3, and will not materially reduce them during the term. You are responsible for your own configuration, for the credentials you issue, for who you admit to a workspace, and for the security of the devices on which the desktop app caches data.

8. Personal Data Breach

Harbor will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Controller Content. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. We will give you the information you reasonably need to meet your own notification obligations. Our notification is not an admission of fault or liability.

9. Audit

On request, and no more than once in any 12-month period, Harbor will complete a written security questionnaire and provide the design-partner security pack. Where that is not sufficient to demonstrate compliance with Article 28, you may audit us, or appoint an independent auditor who is not our competitor and who signs a confidentiality undertaking, on at least 30 days' written notice, during business hours, without unreasonable disruption, and at your cost unless the audit finds a material breach of this DPA.

We do not hold a SOC 2 report or an equivalent third-party attestation today, so none is offered in place of an audit. See Annex 4.

10. International Transfers

Harbor is in Israel, which the European Commission has recognised as providing an adequate level of data protection, so transfers from the EEA to us require no additional mechanism. Where Personal Data is transferred onward to a Sub-processor outside the EEA or the UK, we rely on the Standard Contractual Clauses approved by the European Commission, with the UK International Data Transfer Addendum where applicable, on the EU-US Data Privacy Framework where the recipient is certified, or on another lawful transfer mechanism. Where the Clauses apply, module two governs controller-to-processor transfers and module three governs our onward transfers, and this DPA and its annexes populate their appendices.

11. Term, Deletion and Return

This DPA lasts as long as Harbor processes Personal Data on your behalf. On termination, Harbor will delete Controller Content in accordance with Annex 3, and workspace deletion is available to you at any time through the product.

Return is a person, not a feature, and we would rather say so than write a clause we cannot perform. Article 28(3)(g) contemplates deletion or return at your choice. Harbor has no structured workspace export. If you elect return, ask in writing before termination and we will produce a machine-readable copy of your statements and metadata by hand within 30 days. We will not describe that as a self-service export, because it is not one, and if a clean exit with your data in hand is a requirement for you, raise it before you sign.

Backups are overwritten on their ordinary cycle. We will delete or return Personal Data unless law requires us to keep it, in which case we will keep it only for as long as that law requires and continue to protect it under this DPA.

12. California and Other US State Privacy Laws

To the extent the California Consumer Privacy Act applies, Harbor is a “service provider” and you are the “business”. Harbor does not sell or share Personal Information, does not retain, use or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, does not combine it with Personal Information from other sources except as the CCPA permits, and will notify you if it determines it can no longer meet those obligations. The equivalent terms apply where Virginia, Colorado, Connecticut, Texas, Oregon or another US state privacy law governs, and Harbor acts as a “processor” under them.

13. Liability

Each party's liability under this DPA is subject to the exclusions and the aggregate cap in the Terms of Service, and the cap is a single aggregate cap across the Terms and this DPA rather than one for each. Nothing in this section limits either party's liability to a Data Subject, or any liability that cannot be limited under applicable law.

Annex 1: Details of the Processing

Subject matter
Provision of the Harbor service: reading content from the systems the Controller connects, deriving short written statements from that content, and serving those statements back to the Controller’s users and their AI assistants.
Duration
The term of the Terms of Service, plus the retention windows in Annex 3.
Nature and purpose
Ingestion, automated extraction and summarisation using third-party AI models, vector embedding, storage, retrieval, ranking, display, and measurement of which statements were served and cited.
Categories of Data Subject
The Controller’s personnel, being workspace members; and any individual whose Personal Data appears in the content the Controller connects, which may include the Controller’s customers, suppliers and correspondents.
Categories of Personal Data
Identity and contact data, being name, email address and organisation membership; content data, being the text of messages, issues, documents, meeting transcripts and mail drawn from connected sources, and the statements derived from it; usage and telemetry data; and billing identity.
Special category data
Not intentionally processed. Harbor does not solicit it and does not filter for it. Content drawn from a Controller’s chat or mail may contain it incidentally, and the Controller decides which sources are connected.
Frequency
Continuous, on the sync schedule the Controller configures.
Transfers
To the Sub-processors in Annex 2, in the locations stated there.

Annex 2: Sub-processors

Ten, split by the distinction that decides most reviews. Five receive Controller Content:

  • OpenAI. Extraction, classification, embeddings, and the default assistant model. Receives text read from connected sources, the derived statements, the embeddings, and assistant conversation turns. United States.
  • Anthropic. Question answering over stored knowledge, and longer multi-step assistant runs. United States.
  • Google (Gemini). Optional assistant model, and failover. Receives content only where selected as the provider or on failover. United States.
  • Amazon Web Services (S3). Storage of statement bodies and the workspace index. United States, us-east-1. Retained until the statement is deleted.
  • Amazon Web Services (managed database). Primary datastore operated by Harbor: statements, metadata, sessions, retrieval records, and encrypted connector tokens. United States, us-east-1. Retention per Annex 3.

Five receive identity, billing or telemetry only:

  • Clerk. Authentication. Name, email address, organisation membership.
  • Paddle. Payment processing and subscription management, as merchant of record and independent controller. Billing identity, plan, subscription events.
  • Amazon Web Services (SES). Transactional email. Email addresses and message bodies.
  • PostHog. Product analytics and feature flags. Product events, pageviews, a pseudonymous identifier, and the workspace name and slug. United States.
  • Sentry. Crash reporting, desktop application only. Crash reports, redacted before transmission.

We do not yet hold written zero retention and no training terms from the three AI providers. We have asked all three, and we will state the position here once we hold it in contract rather than on a vendor marketing page. Ask us again. A vendor who tells you today that its AI sub-processors retain nothing is, in most cases, repeating something it has not been given in contract form, and you should ask them for the artefact too.

Annex 3: Technical and Organisational Measures

Encryption
TLS in transit. Encryption at rest. Connector tokens encrypted with AES-256-GCM, with the key derived using scrypt and the authenticated data bound to the identity of the record, so a ciphertext moved between records fails the tag check rather than decrypting into the wrong account.
Secrets and logging
Credentials are stripped before anything is written to a log, by one shared pattern catalogue rather than per-call-site handling.
Access control
Role-based access, restricted to personnel who need it. Tenancy is enforced in code at the workspace boundary; nothing crosses a workspace. Within a workspace, see Annex 4 L3.
Telemetry
No third-party analytics in the backend. No session replay and no autocapture in the web or desktop app. Do Not Track is respected and product analytics are disabled outside production builds.
AI processing
Content is sent to the providers in Annex 2 for extraction, embedding and answering. It is not used to train models, and no provider is granted the right to use it for that purpose.
Retention: statements
Plan-driven. Free 30 days, Pro 365 days, Premium and Enterprise no expiry. Not Controller-configurable. See Annex 4 L2.
Retention: raw payloads
Raw payloads fetched from connected sources are purged automatically after 7 days.
Retention: statement bodies
Deleted from object storage with the statement they belong to.
Deletion
Workspace deletion removes the workspace and its data, and is available to the Controller at any time.

Annex 4: Known Limitations

Disclosed here rather than discovered later. Each of these bears on your own compliance assessment, so you should read them before you rely on Harbor for a regulated workload.

  • L1. No self-service export. Deletion works. A structured return of everything Harbor holds is not built, and is produced by hand under section 11.
  • L2. Retention follows your billing plan, not your policy. There is no Controller-settable retention ceiling today. If your posture requires one, we do not have it.
  • L3. Per-member access control within a workspace is not built. Every member of a workspace can recall every statement in it, whatever the permissions on the source it came from. Space-scoped statements are the only narrowing that exists. This is material, and it is the reason section 4 asks you to warrant what you connect.
  • L4. No application-level audit log. There is no per-record record of who accessed what and when that we can make available to you.
  • L5. No SOC 2 report and no third-party penetration test. We will begin that work when a customer needs it. Until then no report is offered in place of the audit right in section 9.

Contact

To ask a question about this DPA, to object to a Sub-processor, or to have a counter-signed copy executed, email privacy@gethrbr.com, or write to [LEGAL NAME PENDING], [BUSINESS ADDRESS PENDING], Tel Aviv, Israel.

harbor

One shared brain for every agent your team runs. Built from work you already do, kept only while it is still true.

Product

  • How it works
  • The gate
  • Your agents
  • What it proves
  • Pricing

Developers

  • Environments
  • MCP server
  • Measurement
  • Served and cited

Company

  • Get started
  • Contact
  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Refund Policy
© 2026 harborFigures shown are sample data
harborharbor