Legal information
Data Processing Summary
Last updated: 2 September 2026
1. Roles
- Controller (Verantwortlicher)
- The Customer (you), for Customer Data
- Processor (Auftragsverarbeiter)
- [Insert full legal name including legal form, e.g. Haulbi GmbH]
- Sub-processors
- See section 6 below
2. Subject matter and duration
The subject matter of the processing is the provision of the Haulbi Service to the Customer. Processing begins when the Customer submits personal data to the Service and continues for the term of the agreement. After termination, personal data is deleted or returned in accordance with the agreed retention rules.
3. Nature and purpose of processing
The processing is limited to what is necessary to provide the Haulbi Service to the Customer, including hosting, storing, transmitting, displaying, backing up, securing, and supporting Customer Data at the documented instruction of the Customer.
4. Categories of data and data subjects
| Data category | Typical examples |
|---|---|
| Customer account data | Name, business email, role, login credentials (hashed) |
| Contact data | Buyer/supplier names, business emails, phone numbers |
| Operational data | Inventory, orders, fulfilment status, account terms |
| Support data | Support tickets, screenshots, attached files |
| Usage data | Pseudonymous interaction logs within the Service |
The typical categories of data subjects are the Customer's employees, contractors, and the Customer's business contacts (buyers, suppliers, carriers, customer-service representatives).
5. Technical and organisational measures (TOMs)
Haulbi implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The full list of TOMs is appended to the signed DPA and includes:
- Encryption in transit (TLS 1.2+ for all client connections)
- Encryption at rest for production databases and object storage
- Role-based access control with least-privilege defaults
- Multi-factor authentication for administrative access
- Documented change management and release process
- Centralised logging and audit trail
- Regular vulnerability scanning and periodic third-party penetration tests
- Backups with defined recovery objectives
- Business-continuity and incident-response procedures
- Sub-processor due diligence and onboarding review
- Confidentiality commitments in employee and contractor agreements
- Documented data-breach notification within statutory timeframes
6. Sub-processors
Haulbi uses the following categories of sub-processors. The current authoritative list is published at this URL and updated before any new sub-processor is engaged. Subscribed Customers are notified of changes in accordance with the DPA.
Sub-processors and processing locations
| Sub-processor | Purpose | Processing location | Transfer safeguard |
|---|---|---|---|
| [Insert hosting provider, e.g. Vercel Inc.] | Application hosting and content delivery | EU and/or USA | SCCs / EU-US DPF |
| [Insert database provider, e.g. Neon / Supabase / AWS RDS] | Managed database hosting | EU and/or USA | SCCs / EU-US DPF |
| [Insert object storage, e.g. AWS S3 / Cloudflare R2] | File storage and backups | EU and/or USA | SCCs / EU-US DPF |
| Cal.com, Inc. | Scheduling (user-initiated) | USA / EU | SCCs |
| [Insert transactional email provider, e.g. Postmark / Resend] | Transactional email | USA / EU | SCCs / EU-US DPF |
| [Insert error monitoring, e.g. Sentry] | Error and performance monitoring | USA / EU | SCCs / EU-US DPF |
7. International data transfers
Where personal data is transferred to a country outside the EEA without an adequacy decision, Haulbi relies on the EU Standard Contractual Clauses (SCC) and supplementary technical and organisational measures. Where applicable, the EU-US Data Privacy Framework (DPF) is also relied upon for certified US providers.
8. Data subject requests
Haulbi assists the Customer, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests for exercising data subjects' rights. Where Haulbi receives a request directly from a data subject relating to the Customer's use of the Service, Haulbi forwards the request to the Customer without undue delay.
9. Personal data breaches
Haulbi notifies the Customer without undue delay, and in any event within the timeframe required by applicable law, after becoming aware of a personal-data breach affecting the Customer's data. The notification includes the information required by Art. 33(3) GDPR to the extent then available, with subsequent updates as the investigation progresses.
10. Return and deletion at the end of the agreement
At the end of the agreement, Haulbi returns Customer Data to the Customer in a commonly used, machine-readable format, or deletes it, at the Customer's choice, unless retention is required by mandatory law.
11. Requesting the full DPA
To request the full, signed-ready Data Processing Agreement, contact our privacy team. We will provide the DPA for review and signature under NDA.
- Privacy email
- privacy@haulbi.com
- Legal email
- legal@haulbi.com
- Postal
- [Insert full legal name including legal form, e.g. Haulbi GmbH], [Insert street and house number], [Insert postal code] [Insert city], [Insert country, e.g. Germany]