Skip to document
HTO Labs
Your work, connectedYour dataPagesWorkroom
Apps, pages, and documentsExplore examples
Who it’s forPricing
Log inExplore HTO Labs
Home
Your work, connectedYour dataPagesWorkroom
Apps, pages, and documentsExplore examples
Who it’s forPricingRequest an invitationLog in
info@htobeyond.com
HTO Labs

Data Processing Agreement

Last updated 24 September 2026.

On this page

  • 1. Definitions
  • 2. Roles
  • 3. Instructions
  • 4. Confidentiality and access
  • 5. Security
  • 6. Sub-processors
  • 7. Transfers outside the EU and EEA
  • 8. Helping the customer
  • 9. Personal data breaches
  • 10. Deletion and return
  • 11. Information and audits
  • 12. Duration, liability and precedence
  • Annex 1: Description of the processing
  • Annex 2: Security measures
  • Annex 3: Sub-processors
On this page
  • 1. Definitions
  • 2. Roles
  • 3. Instructions
  • 4. Confidentiality and access
  • 5. Security
  • 6. Sub-processors
  • 7. Transfers outside the EU and EEA
  • 8. Helping the customer
  • 9. Personal data breaches
  • 10. Deletion and return
  • 11. Information and audits
  • 12. Duration, liability and precedence
  • Annex 1: Description of the processing
  • Annex 2: Security measures
  • Annex 3: Sub-processors

This agreement applies when a company or other organisation (“the customer”) uses HTO Labs for its team, and personal data is kept in its workspaces. It is made between the customer and HTO & Beyond ApS, CVR DK46108043, Ålekistevej 184, 2720 Vanløse, Denmark (“we”, “us”), and it forms part of our Terms of Service. It takes effect when the customer accepts those terms. If the customer needs a signed copy, write to info@htobeyond.com.

1. Definitions

“Data protection law” means the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Danish Data Protection Act. “Personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the GDPR. “Customer personal data” means personal data in the customer's workspaces that we process on the customer's behalf. A “sub-processor” is another processor we engage to process customer personal data.

2. Roles

The customer is the controller of customer personal data and we are its processor. Annex 1 describes the processing. We are the controller for the accounts people use to sign in and for the technical data we collect to run and protect HTO Labs. Our Privacy Policy covers that data, and this agreement does not.

The customer is responsible for having a lawful basis for the personal data its members put into HTO Labs and for the instructions it gives us.

3. Instructions

We process customer personal data only on the customer's documented instructions, including for transfers outside the EU or EEA. The Terms of Service, this agreement, and the customer's use and settings of HTO Labs are the customer's instructions. If EU or Danish law requires us to process customer personal data in another way, we tell the customer before we do, unless that law forbids it. We tell the customer at once if we believe an instruction breaks data protection law.

4. Confidentiality and access

Everyone we authorise to process customer personal data is bound by confidentiality. Our people access customer content only at the customer's request, when it is necessary to keep HTO Labs secure or to investigate misuse, or when the law requires it. Access is limited to the people who need it for that task, and we keep a record of each such access. We do not use customer personal data to train AI models, and we do not sell it or use it for advertising.

5. Security

We take the technical and organisational measures that Article 32 of the GDPR requires. Annex 2 describes them. We may improve them over time, but we will not reduce the overall level of protection.

6. Sub-processors

The customer gives us general authorisation to use the sub-processors listed in Annex 3. We tell the customer at least 30 days before we add or replace a sub-processor, by updating Annex 3 and emailing the team's owners. The customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, the customer may stop using the affected part of HTO Labs or end its use of HTO Labs.

We bind each sub-processor by contract to data protection obligations that give at least the protection this agreement gives. We remain responsible to the customer for our sub-processors.

7. Transfers outside the EU and EEA

We transfer customer personal data outside the EU or EEA only where an adequacy decision of the European Commission covers the transfer, or where the EU Standard Contractual Clauses or another safeguard under Chapter V of the GDPR is in place. Annex 3 shows where each sub-processor processes data.

8. Helping the customer

If a data subject asks us directly to exercise their rights over customer personal data, we pass the request to the customer and do not answer it ourselves unless the customer asks us to. We help the customer respond to such requests, as far as the nature of the processing allows.

Taking into account the nature of the processing and the information available to us, we also help the customer meet its obligations on security, personal data breaches, data protection impact assessments and prior consultation with a supervisory authority under Articles 32 to 36 of the GDPR.

9. Personal data breaches

We tell the customer without undue delay after we become aware of a personal data breach affecting customer personal data. We give the information the customer needs to meet its own obligations, as far as we have it: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and what we have done or propose to do. We add to it as we learn more.

10. Deletion and return

When the customer's use of HTO Labs ends, or a workspace is deleted, we delete the customer personal data concerned within 30 days. Before that, at the customer's request, we return a copy in a commonly used format. We may keep data longer only where EU or Danish law requires it, and we continue to protect it under this agreement while we do.

11. Information and audits

We make available to the customer the information it needs to show that this agreement and Article 28 of the GDPR are being met. We allow and contribute to audits, including inspections, by the customer or an auditor it appoints who is bound by confidentiality. The customer gives us at least 30 days' notice, and we first try to answer its questions in writing. Audits take place during business hours, no more than once a year unless a personal data breach or a supervisory authority requires it, and at the customer's cost.

12. Duration, liability and precedence

This agreement lasts as long as we process customer personal data. Each party's liability under it is subject to the limits in the Terms of Service, except where data protection law does not allow a limit. If this agreement and the Terms of Service differ on the processing of personal data, this agreement prevails. Where the Standard Contractual Clauses apply, they prevail over both. If the customer has signed a separate data processing agreement with us, that agreement applies instead of this one.

Danish law governs this agreement, and the courts of Denmark decide any dispute about it.

Annex 1: Description of the processing

  • Subject matter: providing HTO Labs to the customer.
  • Duration: while the customer uses HTO Labs, and up to 30 days afterwards for deletion.
  • Nature and purpose: storing, organising, showing and sharing the customer's workspace content; sending invitations to join the customer's team; and support and security related to the customer's workspaces.
  • Data subjects: the customer's team members and the people it invites, and anyone whose personal data the customer's members put into its workspaces, such as the customer's employees, clients and contacts.
  • Types of personal data: names, email addresses, team roles and membership; the pages, chats, messages, tasks and files in the workspaces; content brought in from services the customer connects, such as Meta or GitHub; and technical data about the use of the workspaces.
  • Special categories: HTO Labs is not designed for special categories of personal data or data about criminal convictions. The customer decides whether its members put such data into HTO Labs, and if they do, it is responsible for the legal basis.
  • Frequency: continuous, while the customer uses HTO Labs.

Annex 2: Security measures

  • Everything sent between the customer's members and HTO Labs is encrypted in transit.
  • Our database is encrypted at rest.
  • Our database runs in Frankfurt, Germany.
  • The web app's signed-in pages check each account with our sign-in provider.
  • Row-level security is switched on for every table in our database.
  • Administrative access to the systems that hold customer personal data is limited to named people who run HTO Labs. We record each access to customer content.
  • Everyone with access is bound by confidentiality.
  • Deleted data is removed within 30 days, as section 10 describes.

Annex 3: Sub-processors

  • Supabase, Inc.: sign-in and our database. Frankfurt, Germany.
  • Vercel Inc.: hosts the website and the sign-in and team pages. United States, under the Standard Contractual Clauses.

Services the customer chooses to connect, such as Meta or GitHub, and the providers its members use to sign in, such as Google, Microsoft or Apple, are not our sub-processors. The customer's own agreement with each of them applies.

HTO Labs

HTO Labs. Work seamlessly with AI.

HTO Labs

  • Overview
  • Your data
  • Pages
  • Workroom

Explore

  • What you can create
  • Who it’s for
  • Pricing
  • FAQ
  • Request an invitation
  • Log in

Contact

  • Get in touch
  • Book a demo

Legal & company

  • Privacy
  • Terms
  • Data processing
  • HTO & Beyond

© 2026 HTO & Beyond