Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") supplements the Terms of Use and Privacy Policy between HYPERSTRUCK PTY LTD (ABN 18 697 361 738) ("Hyperstruck") and the customer entity agreeing to or using Hyperstruck ("Customer").

Last updated: 15 July 2026

Agreement and precedence

This DPA applies where Hyperstruck processes Customer Personal Data on Customer's behalf to provide the Hyperstruck product and related services. It is incorporated by reference into the Terms of Use and forms part of the agreement between the parties from the date Customer accepts those terms, executes an order form, or otherwise begins using Hyperstruck for business purposes.

If Customer has executed a separate written agreement with Hyperstruck that addresses data processing, that agreement prevails to the extent of a conflict. Otherwise, where this DPA conflicts with the Terms of Use or Privacy Policy regarding the processing of Customer Personal Data, this DPA governs.

Roles

For Customer Personal Data processed through the Hyperstruck product, Customer acts as the controller (or processor on behalf of its controller) and Hyperstruck acts as the processor. Hyperstruck will process Customer Personal Data only on documented instructions from Customer, consisting of this DPA, the Terms of Use, product configuration, and Customer's use of the service within documented functionality.

Processing details

Hyperstruck processes Customer Personal Data to provide, secure, maintain, and support the service, including authentication, storage, model inference, workflow execution, logging, and customer support. Categories of data may include account and contact details, user identity information, customer content, agent configuration, learnings, credentials metadata, workflow metadata, and operational logs, depending on Customer's use of Hyperstruck.

Processing continues for the term of the agreement and for the periods needed to perform post-termination obligations described in this DPA, including deletion or return of Customer Personal Data.

Security

Hyperstruck implements administrative, technical, and organizational measures appropriate to the risk, as described on the Security page, including encryption in transit (TLS 1.3+), encryption at rest (AES-256 where supported by underlying infrastructure), tenant isolation, and access controls.

Subprocessors

Customer provides general authorisation for Hyperstruck to engage the subprocessors listed on the Trust page as of the effective date of this DPA. Hyperstruck imposes data protection obligations on subprocessors that are no less protective than Hyperstruck's obligations to Customer under this DPA.

Hyperstruck will publish material additions or replacements to the Trust subprocessor list at least 30 days before a new subprocessor begins processing Customer Personal Data, except where urgent replacement is required for security or service continuity. Customer may object on reasonable data protection grounds within 30 days of notice. The parties will work in good faith to resolve the objection. If unresolved within 30 days, Customer may terminate the affected services without penalty for the portion that cannot be provided without that subprocessor.

Hyperstruck remains responsible to Customer for subprocessor acts and omissions to the same extent Hyperstruck would be responsible if performing those acts itself, subject to liability limits in the Terms of Use.

Standard vendor data processing terms apply on Hyperstruck's paid plans. Links to each subprocessor's vendor DPA are published on the Trust page.

International transfers

Customer Personal Data may be processed outside Australia or across global infrastructure where required to provide the service. Hyperstruck relies on subprocessors' standard contractual safeguards, including Standard Contractual Clauses, UK addenda, and other transfer mechanisms in the vendor DPAs linked on the Trust page.

Where Hyperstruck configures production workloads in a specific region supported by a vendor, processing is performed in that region except where reasonably necessary for support, security, legal compliance, or features initiated by Customer.

Retention and deletion

Hyperstruck treats up to 30 days as the conservative maximum for subprocessor operational retention of Customer Personal Data in normal operation. Shorter periods may apply, including zero-retention configurations for AI inference where enabled. Longer periods may apply for legal retention obligations, isolated backup copies pending deletion, or security and abuse monitoring where zero-retention is not enabled.

On termination or expiry of the agreement, Hyperstruck will delete or return Customer Personal Data within timeframes reasonably required to complete deletion across production systems and vendor subprocessors, subject to applicable law and vendor deletion schedules. Some subprocessors may retain isolated backup copies for longer periods (for example, up to 180 days post-termination) before secure deletion.

AI processing and customer-managed keys

AI subprocessors engaged by Hyperstruck do not use Customer Personal Data to train or improve foundation models unless Customer explicitly enables a feature that requires such use.

Where Customer connects its own LLM API keys or third-party AI services, processing by that provider is governed by the provider's agreement with Customer. Hyperstruck processes connection metadata and routing data only as needed to provide the integration.

Assistance, incidents, and audits

Hyperstruck will assist Customer with data subject requests relating to Customer Personal Data processed through Hyperstruck, to the extent Hyperstruck can do so and the request cannot be fulfilled through product functionality.

Hyperstruck will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and will provide information reasonably required for Customer's regulatory notifications.

On reasonable written request, Hyperstruck will make available security documentation and third-party assurance reports sufficient to demonstrate compliance with this DPA. Customer may request one audit per 12-month period on 30 days' notice, subject to confidentiality and scope limits, unless applicable law requires otherwise or following a confirmed breach.

Contact and changes

Data protection questions may be sent to hello@hyperstruck.com. Security incidents may be reported to security@hyperstruck.com.

Hyperstruck may update this DPA to reflect changes to the service, subprocessors, or legal requirements. Material updates will be posted on this page. Continued use of Hyperstruck after an update constitutes acceptance unless Customer terminates under the objection rights above.