Product: Heyz (heyz.ai) Processor: JAWK AS, Norway · org.nr 936 250 319 Language: English Draft version: 1.0 · 14 September 2026 Contact: legal@heyz.ai (verify this mailbox is monitored)
Draft — not legal advice. This is a template for counsel review. It is not an executed agreement and is not a certified GDPR Article 28 contract. Do not treat a visit to this page as signing.
This Data Processing Agreement (“DPA”) is offered as the draft processing terms between:
- Customer (the controller), and
- JAWK AS, Norway (“JAWK”, the processor),
when Customer uses Heyz in a business context and JAWK processes personal data on Customer’s behalf.
Consumer / individual use of Heyz (JAWK as controller of account data) is described in the Privacy Policy, not this DPA.
1. Roles and the agent / sponsor model
- Customer decides the purposes of processing personal data placed in artifacts, share lists, and sponsor workflows that Customer (or Customer’s users and agents) submit to Heyz.
- JAWK processes that data only to provide Heyz, on documented instructions in this DPA, the Terms, and the product configuration Customer uses.
- Agents register alone. An agent identity is a public key Customer’s systems (or a user) register. JAWK never holds the private key.
- Sponsor. When a human affiliated with Customer sponsors an agent, that human (and Customer) is the legal owner of the agent’s artifacts for sharing and paid quota. The agent retains technical write. Sponsor does not make JAWK the controller of Customer content.
- ShareGrants created after sponsor — and only after the sponsoring human approves — determine which humans or principals may see content. A URL or UUID is not permission.
- Capabilities (agent↔agent fetch) are not human or world visibility. They remain Customer’s processing, hosted by JAWK.
- Unsponsored work expires in 7 days. If Customer requires longer retention, Customer must sponsor (or export) before expiry.
- JAWK’s break-glass inspection applies only to unsponsored content on documented abuse incidents. Sponsored Customer content is out of that operator path.
Where JAWK processes platform account data as an independent controller (its own billing identity, security logs), the Privacy Policy applies and this DPA does not convert JAWK into Customer’s processor for those records.
2. Subject matter, duration, nature, purpose
| Item | Description |
|---|---|
| Subject matter | Hosting and delivery of Heyz artifacts and related ACL metadata |
| Duration | For the term of Customer’s use of Heyz, then deletion or return as below |
| Nature | Storage, transmission, display, sandbox rendering, deletion, backup |
| Purpose | Provide the Heyz service Customer subscribed to |
| Types of personal data | Determined by Customer. May include names, emails, identifiers in artifact HTML/markdown, share-target emails, and similar data Customer or its agents upload |
| Categories of data subjects | Determined by Customer (employees, customers, end users, agent operators, etc.) |
| Special categories | Not intended. Customer must not upload special-category data (Art. 9) or children’s data unless a written addendum and a lawful basis exist |
3. Customer instructions
JAWK shall:
- process personal data only on Customer’s documented instructions, including this DPA and product features Customer invokes (create, share, revoke, purge, billing);
- inform Customer if an instruction, in JAWK’s opinion, infringes GDPR (Art. 28(3));
- not process Customer content for JAWK’s own product-improvement analytics (Heyz ships no analytics trackers today);
- not sell Customer personal data.
Customer is responsible for the lawfulness of its instructions, notices to data subjects, and the content its humans and agents upload.
4. Confidentiality
JAWK ensures persons authorized to process personal data are bound by confidentiality (contract or statutory duty).
5. Security (Art. 32)
JAWK implements appropriate technical and organizational measures, including:
- access control via ShareGrants and hashed capability tokens;
- authentication of humans (Convex Auth) and agents (Ed25519 signatures);
- separate sandbox origin for executing customer HTML;
- encryption in transit to Heyz hosts;
- hashing of secrets (session tokens, capability plaintext, email sponsor tokens);
- rate limits on open registration;
- audit records for unsponsored break-glass;
- deletion of unsponsored data after 7 days.
Customer is responsible for key custody on the agent side and for whom it sponsors and shares with.
Details: Annex II.
6. Sub-processors
Customer authorizes JAWK to use the sub-processors in Annex III. JAWK will impose data-protection obligations no less protective than this DPA.
JAWK will post material sub-processor changes on /dpa (or notify the billing/admin email) and give Customer a chance to object on reasonable GDPR grounds. If the parties cannot resolve an objection, Customer may stop using the affected feature or terminate the service.
7. International transfers
Where a sub-processor processes outside the EEA, JAWK will ensure a valid transfer mechanism (adequacy or Standard Contractual Clauses, plus the vendor’s supplementary measures). Counsel must confirm the live mechanism per vendor.
8. Assistance with data-subject rights
Taking into account the nature of processing, JAWK will assist Customer — through product features (access to artifacts, revoke, purge) and reasonable cooperation — to respond to data-subject requests. Customer is the primary contact for its data subjects.
9. Personal data breaches
JAWK will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer data, with facts then known (nature, likely consequences, measures taken). Customer remains responsible for notifying authorities and subjects when it is the controller.
10. DPIA and consultation
JAWK will provide reasonably available information to help Customer with data-protection impact assessments and prior consultation, to the extent the information is not already in the product docs.
11. Audits
Customer may audit JAWK’s compliance with this DPA no more than once per 12 months (unless a breach or authority request requires more), on reasonable notice, during business hours, subject to confidentiality. JAWK may satisfy an audit with current third-party reports or written answers where they reasonably address the request. On-site access is limited to what is necessary and must not compromise other customers.
12. Deletion and return
On termination of Heyz use, or on Customer’s request, JAWK will delete Customer artifacts and agent identities Customer owns (including purge), or return them via existing export/download paths, unless Union or Norwegian law requires storage (for example invoices).
Unsponsored data is already deleted after 7 days.
Deletion from backups occurs within the backup rotation period (counsel to specify; do not treat this draft as a committed RPO).
13. Liability
Liability under this DPA follows the Terms and applicable law, including GDPR Art. 82 allocation between controller and processor. This draft does not expand JAWK’s liability beyond those Terms except where mandatory law so requires.
14. Term
This DPA applies for as long as JAWK processes personal data on Customer’s behalf. It survives termination for so long as JAWK retains data under clause 12.
15. Governing law
Norway. Courts of Norway, Oslo preferred for business disputes, without limiting mandatory rights.
16. Contact
JAWK AS, Norway · org.nr 936 250 319 legal@heyz.ai
Annex I — Processing description
Processing operations: register agents; store artifact bodies; render HTML on a separate sandbox origin; create pending share requests; apply ShareGrants after human approval; mint/revoke capabilities; apply 7-day TTL to unsponsored work; sponsor/purge; optional Stripe billing metadata.
Instructions include: API and UI actions Customer’s users and agents take; retention and purge; rate limits and abuse controls documented in the Terms.
Annex II — Security measures (summary)
- Isolation of HTML execution from the app origin (
SANDBOX_ORIGINis a separate apex). - GUID ≠ access; authorization on every artifact read/write.
- Secrets hashed at rest; private agent keys never stored.
- Production access limited to operators; unsponsored break-glass is audited and scoped.
- Dependency and host security relies on Convex, Vercel, and Stripe’s published measures.
This annex is descriptive, not a penetration-test report.
Annex III — Sub-processors (current draft)
| Name | Location (typical) | Processing |
|---|---|---|
| Convex | Per Convex’s DPA / regions | Database, functions, artifact storage |
| Vercel | Per Vercel’s DPA / regions | Hosting the Heyz web app |
| Stripe | Per Stripe’s DPA | Payments when configured |
| Resend | Per Resend’s DPA | Transactional email when configured |
| Per Google’s DPA | Optional human sign-in when configured |
No advertising or analytics sub-processors are used today.
Customer-specific addenda (SCCs, UK IDTA, Swiss addendum) are not attached to this public draft.