Hivanced
Join the beta
HivancedHivanced

The sovereign AI assistant, grounded on your data.

Part of the Humari ecosystem.

Open source - repository coming soon

Company

  • Pricing
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Legal Notice
  • Cookie Policy

© 2026 Hivanced. All rights reserved.

Hosted in the EUGDPR Compliant

    Data Processing Agreement

    Last updated: June 17, 2026

    This Data Processing Agreement (DPA) describes how Hivanced processes personal data on behalf of its business customers, as a processor under Article 28 GDPR. It applies in addition to the Terms of Service. For business customers who require a signed DPA, this document forms the basis of that agreement, to be finalised together with the publishing entity details.

    1. Roles of the parties

    For personal data that a customer uploads, connects or generates through the platform, the customer acts as the data controller and Hivanced acts as the data processor, processing that data only on the customer's documented instructions. For the data Hivanced processes for its own purposes (account management, billing, security), Hivanced acts as the controller, as described in the Privacy Policy.

    2. Subject matter and duration

    The subject matter of the processing is the provision of the Hivanced AI assistant and related features. The processing lasts for the duration of the customer's contract. On termination, Hivanced deletes or returns the personal data as set out below, subject to legal retention obligations.

    3. Nature, purpose and categories of data

    Nature and purpose: storing, organising, retrieving and processing the customer's content and connected-source data to deliver AI-assistant answers grounded on that data, and the other features the customer enables.

    Categories of data subjects: the customer's employees, contacts, and any individuals referenced in the customer's content or connected sources.

    Categories of personal data: as determined by the customer; typically professional identification and contact data, and any personal data contained in the customer's documents, messages and records.

    4. Obligations of Hivanced as processor

    Hivanced undertakes to:

    • process personal data only on the customer's documented instructions, including for transfers, unless required by law;
    • ensure that persons authorised to process the data are bound by confidentiality;
    • implement appropriate technical and organisational security measures (Article 32 GDPR);
    • assist the customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting its security, breach-notification and data-protection-impact-assessment obligations;
    • notify the customer without undue delay after becoming aware of a personal-data breach;
    • at the customer's choice, delete or return the personal data at the end of the service, and delete existing copies unless retention is legally required;
    • make available the information necessary to demonstrate compliance with Article 28 and allow for audits within reasonable terms.

    5. Subprocessors

    The customer authorises Hivanced to engage the subprocessors needed to deliver the service. Current subprocessors include:

    • Scaleway (France, fr-par): hosting and infrastructure.
    • Mistral AI (European Union): default AI model provider.
    • PostHog Cloud EU (Frankfurt, Germany): product analytics, where enabled.

    The connectors a customer authorises (Google Drive, Microsoft 365, Notion, Slack, HubSpot) are accessed read-only on the customer's instruction as grounding sources. Hivanced imposes data-protection obligations on its subprocessors equivalent to those in this DPA, and informs customers of intended changes to its subprocessors so they may object.

    6. International transfers

    By default, processing takes place within the European Union and personal data does not leave the European perimeter. The European subprocessors above are not US companies and are not subject to the US CLOUD Act. Where a customer enables a non-European AI provider, the related transfer is carried out only on the customer's explicit instruction and under the safeguards required by Chapter V GDPR (such as Standard Contractual Clauses).

    7. Security measures

    Hivanced applies, among others: encryption in transit and of sensitive data at rest; multi-tenant isolation segregating each customer's data; a permission system governing access within an organisation; access controls and logging; and operational measures to maintain the confidentiality, integrity, availability and resilience of the systems.

    8. Data-subject requests and assistance

    Hivanced provides functionality within the platform that helps the customer respond to data-subject requests (including access and erasure). Where a data subject contacts Hivanced directly regarding the customer's data, Hivanced forwards the request to the customer and does not respond on the customer's behalf unless instructed.

    9. Audit

    Hivanced makes available the information reasonably necessary to demonstrate compliance with its obligations as a processor and contributes to audits, including inspections, conducted by the customer or a mandated auditor, on reasonable notice and under appropriate confidentiality.

    10. Contact

    For any question about this DPA or to request a signed copy, contact contact@hivanced.eu.