Skip to main content
Haulbi

Legal information

Data Processing Summary

Last updated: 2 September 2026

Where Haulbi processes personal data on behalf of a Customer, the parties enter into a Data Processing Agreement (Auftragsverarbeitungsvertrag) in accordance with Art. 28 GDPR. This page is a non-binding public summary. The legally binding version is the signed DPA, available on request.
Draft for review. A signed DPA must be in place before any personal data is exchanged. This page summarises how we approach data processing and lists our current sub-processors.

1. Roles

Controller (Verantwortlicher)
The Customer (you), for Customer Data
Processor (Auftragsverarbeiter)
[Insert full legal name including legal form, e.g. Haulbi GmbH]
Sub-processors
See section 6 below

2. Subject matter and duration

The subject matter of the processing is the provision of the Haulbi Service to the Customer. Processing begins when the Customer submits personal data to the Service and continues for the term of the agreement. After termination, personal data is deleted or returned in accordance with the agreed retention rules.

3. Nature and purpose of processing

The processing is limited to what is necessary to provide the Haulbi Service to the Customer, including hosting, storing, transmitting, displaying, backing up, securing, and supporting Customer Data at the documented instruction of the Customer.

4. Categories of data and data subjects

Data categoryTypical examples
Customer account dataName, business email, role, login credentials (hashed)
Contact dataBuyer/supplier names, business emails, phone numbers
Operational dataInventory, orders, fulfilment status, account terms
Support dataSupport tickets, screenshots, attached files
Usage dataPseudonymous interaction logs within the Service

The typical categories of data subjects are the Customer's employees, contractors, and the Customer's business contacts (buyers, suppliers, carriers, customer-service representatives).

5. Technical and organisational measures (TOMs)

Haulbi implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The full list of TOMs is appended to the signed DPA and includes:

  • Encryption in transit (TLS 1.2+ for all client connections)
  • Encryption at rest for production databases and object storage
  • Role-based access control with least-privilege defaults
  • Multi-factor authentication for administrative access
  • Documented change management and release process
  • Centralised logging and audit trail
  • Regular vulnerability scanning and periodic third-party penetration tests
  • Backups with defined recovery objectives
  • Business-continuity and incident-response procedures
  • Sub-processor due diligence and onboarding review
  • Confidentiality commitments in employee and contractor agreements
  • Documented data-breach notification within statutory timeframes

6. Sub-processors

Haulbi uses the following categories of sub-processors. The current authoritative list is published at this URL and updated before any new sub-processor is engaged. Subscribed Customers are notified of changes in accordance with the DPA.

Sub-processors and processing locations

Sub-processorPurposeProcessing locationTransfer safeguard
[Insert hosting provider, e.g. Vercel Inc.]Application hosting and content deliveryEU and/or USASCCs / EU-US DPF
[Insert database provider, e.g. Neon / Supabase / AWS RDS]Managed database hostingEU and/or USASCCs / EU-US DPF
[Insert object storage, e.g. AWS S3 / Cloudflare R2]File storage and backupsEU and/or USASCCs / EU-US DPF
Cal.com, Inc.Scheduling (user-initiated)USA / EUSCCs
[Insert transactional email provider, e.g. Postmark / Resend]Transactional emailUSA / EUSCCs / EU-US DPF
[Insert error monitoring, e.g. Sentry]Error and performance monitoringUSA / EUSCCs / EU-US DPF
Replace the placeholders with the actual sub-processors in use at launch. A signed DPA requires an accurate and complete list.

7. International data transfers

Where personal data is transferred to a country outside the EEA without an adequacy decision, Haulbi relies on the EU Standard Contractual Clauses (SCC) and supplementary technical and organisational measures. Where applicable, the EU-US Data Privacy Framework (DPF) is also relied upon for certified US providers.

8. Data subject requests

Haulbi assists the Customer, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests for exercising data subjects' rights. Where Haulbi receives a request directly from a data subject relating to the Customer's use of the Service, Haulbi forwards the request to the Customer without undue delay.

9. Personal data breaches

Haulbi notifies the Customer without undue delay, and in any event within the timeframe required by applicable law, after becoming aware of a personal-data breach affecting the Customer's data. The notification includes the information required by Art. 33(3) GDPR to the extent then available, with subsequent updates as the investigation progresses.

10. Return and deletion at the end of the agreement

At the end of the agreement, Haulbi returns Customer Data to the Customer in a commonly used, machine-readable format, or deletes it, at the Customer's choice, unless retention is required by mandatory law.

11. Requesting the full DPA

To request the full, signed-ready Data Processing Agreement, contact our privacy team. We will provide the DPA for review and signature under NDA.

Privacy email
privacy@haulbi.com
Legal email
legal@haulbi.com
Postal
[Insert full legal name including legal form, e.g. Haulbi GmbH], [Insert street and house number], [Insert postal code] [Insert city], [Insert country, e.g. Germany]