HAIL.SOAll legal docs

Data Processing Agreement

Last updated: 2026-07-07

Where Standard Contractual Clauses (Module 2: Controller to Processor, Commission Implementing Decision (EU) 2021/914) are required for a cross-border transfer, they are incorporated by reference with Annexes I–III populated as set out in this DPA. See Section 6 and Annexes I–II below.

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Use (or other written or electronic agreement) between Hail HQ, reachable at hi@hail.so ("we", "us"), and the customer entity identified in that agreement ("Developer", "you"), governing Hail HQ's provision of the Hail platform (the "Service").

This DPA applies only to Hail HQ's hosted cloud version of the Service. It does not apply to self-hosted deployments of Hail's AGPLv3-licensed software: a party self-hosting Hail is an independent data controller/operator of its own instance, and Hail HQ has no processor or controller relationship with, no visibility into, and no liability for such self-hosted deployments.

1. Definitions

  • "Developer" means Hail HQ's direct customer — the organization or account using the Service's API, MCP interface, or CLI to trigger communications.
  • "Recipient" means the individual who receives a call, SMS/text message, or email that a Developer triggers via the Service. Recipients are not Hail HQ's customers.
  • "Developer Personal Data" means personal data relating to Recipients (and any other personal data Developer submits to the Service) that Hail HQ processes on Developer's behalf in the course of providing the Service, as further described in Annex I.
  • "Data Protection Laws" means all applicable laws relating to the processing of personal data, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and, where applicable, its UK counterpart.
  • "Sub-processor" means any third party engaged by Hail HQ to process Developer Personal Data in connection with the Service.
  • Other capitalized terms not defined here have the meaning given in the Terms of Use.

For the purposes of Data Protection Laws: Developer is the controller of Developer Personal Data, and Hail HQ is the processor, acting only on Developer's instructions as set out in this DPA. (Separately, with respect to Developer's own account and billing data, Hail HQ acts as an independent controller under its Privacy Policy — that processing is outside the scope of this DPA.)

2. Scope and processing on instructions

2.1 Hail HQ will process Developer Personal Data only for the purpose of providing the Service — that is, only to deliver communications (voice calls, SMS/text messages, and email) that Developer triggers — and only in accordance with Developer's documented instructions, which consist of: (a) this DPA, (b) the Terms of Use, and (c) Developer's use of the Service's API, MCP interface, CLI, and account settings to configure and trigger communications.

2.2 Hail HQ will not process Developer Personal Data for any other purpose, including its own marketing purposes, and will not sell Developer Personal Data.

2.3 If Hail HQ believes an instruction from Developer infringes Data Protection Laws, Hail HQ will inform Developer without undue delay. This does not obligate Hail HQ to conduct legal review of every instruction.

2.4 Developer is solely responsible for ensuring it has a lawful basis and all necessary consent from Recipients to have Hail HQ process their personal data as instructed, per applicable law (including GDPR, ePrivacy/PECR, TCPA, and CAN-SPAM as applicable). This DPA does not shift that responsibility to Hail HQ.

3. Confidentiality of personnel

Hail HQ ensures that personnel authorized to process Developer Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory), and that access to Developer Personal Data is limited to personnel who need it to perform their duties in connection with the Service.

4. Security measures (Article 32)

4.1 Hail HQ will implement and maintain appropriate technical and organisational measures designed to protect Developer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, proportionate to the risk presented by the processing. These measures include, at minimum:

  • Encryption in transit — data transmitted between the Service, Developer, Recipients, and Sub-processors is encrypted using industry-standard transport encryption (e.g., TLS).
  • Encryption at rest — stored Developer Personal Data (including email content, SMS/text message content, and call transcripts) is encrypted at rest using industry-standard methods.
  • Access controls — access to production systems and Developer Personal Data is restricted to authorized personnel and enforced through authentication controls.
  • Least privilege — personnel and systems are granted only the minimum level of access needed to perform their function, with access reviewed periodically.
  • Audit logging — security-relevant access and administrative actions are logged in a manner designed to support detection of and investigation into unauthorized access. See Annex II for further detail.

4.2 Further detail on Hail HQ's technical and organisational measures is set out in Annex II. Hail HQ may update these measures from time to time provided the update does not materially decrease the overall level of protection.

5. Sub-processors

5.1 Developer generally authorizes Hail HQ to engage Sub-processors to process Developer Personal Data in connection with the Service. The current list of Sub-processors is published at /legal/subprocessors and is incorporated into this DPA by reference.

5.2 Hail HQ will impose data protection obligations on each Sub-processor that are substantially consistent with those set out in this DPA, through a written contract, and remains responsible for each Sub-processor's compliance with those obligations.

5.3 Hail HQ will notify Developer of any new Sub-processor added to the list at /legal/subprocessors before that Sub-processor begins processing Developer Personal Data. Developer may object to a new Sub-processor on reasonable data protection grounds by notifying Hail HQ in writing within a reasonable time (not less than 14 days) of the notice. If Developer objects, the parties will discuss in good faith a resolution; if none is reached, Developer's exclusive remedy is to terminate the affected portion of the Service.

6. International transfers

6.1 Hail HQ operates as a global service. Developer Personal Data may be transferred to, and processed in, countries other than Developer's own, including by Sub-processors located outside the EEA/UK.

6.2 Where a transfer of Developer Personal Data from the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of data protection requires a transfer mechanism under Data Protection Laws, the Standard Contractual Clauses (Module 2: Controller to Processor), as approved by Commission Implementing Decision (EU) 2021/914 ("SCCs"), are hereby incorporated into this DPA by reference and apply to such transfer, with:

  • Developer as "data exporter" and Hail HQ as "data importer";
  • Annex I to this DPA populating Annex I to the SCCs (description of processing, categories of data subjects and data, purposes, and duration);
  • Annex II to this DPA populating Annex II to the SCCs (technical and organisational measures); and
  • the Sub-processor list at /legal/subprocessors populating Annex III to the SCCs (authorized sub-processors).

This DPA does not reproduce the full SCC text; the SCCs as published by the European Commission govern in the event of any conflict with this summary.

7. Audit rights

7.1 On reasonable prior written notice (at least 30 days, unless a shorter period is required by a supervisory authority), and no more than once per 12-month period (except where required by a supervisory authority or following a Security Incident), Hail HQ will make available to Developer information reasonably necessary to demonstrate compliance with this DPA, which may include a summary of relevant audit reports, security certifications, or completed questionnaires, in lieu of an on-site audit.

7.2 If such information is insufficient, Developer may conduct an audit (including inspection) of Hail HQ's relevant processing activities, subject to reasonable scope, confidentiality, and scheduling conditions, and at Developer's expense. Audits must not unreasonably disrupt Hail HQ's business or compromise the confidentiality/security of other customers' data.

8. Breach notification

If Hail HQ becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Developer Personal Data ("Security Incident"), Hail HQ will notify Developer without undue delay, and in any case within 72 hours of becoming aware, to support Developer's own regulatory and Recipient notification obligations. The notification will include, to the extent then known, the nature of the Security Incident, the categories and approximate number of data subjects and records affected, and the measures taken or proposed to address it. Hail HQ will provide reasonable cooperation and updates as more information becomes available.

9. Assistance with data subject requests

Hail HQ will provide reasonable assistance to Developer, taking into account the nature of the processing, to enable Developer to respond to requests from Recipients exercising their rights under Data Protection Laws (including access, rectification, erasure, restriction, and portability requests). Where the Service provides Developer with tools to fulfill such requests directly, Hail HQ may direct Developer to use those tools in the first instance.

10. Deletion or return of data

10.1 Developer Personal Data (call transcripts, SMS/text message content, and stored email content) is retained by Hail HQ for the duration of Developer's account plus 12 months following account closure, consistent with Hail HQ's published retention policy.

10.2 On expiry of that retention period, or upon Developer's written request following termination of the Service (subject to the retention period above and any legal retention obligations on Hail HQ), Hail HQ will delete or, at Developer's request, return Developer Personal Data, except to the extent applicable law requires continued retention.

10.3 Audit-log data is retained separately from transcript/email content, for three (3) years from the date the log entry is created, for security and fraud-investigation purposes.

11. Sub-processor and personnel liability

Hail HQ remains liable to Developer for the acts and omissions of its Sub-processors to the same extent Hail HQ would be liable if performing the services of each Sub-processor directly under this DPA, subject to any limitations of liability set out in the Terms of Use.

12. Assignment

Hail HQ may assign this DPA, without requiring fresh consent from Developer, to a successor or affiliate entity — including any future corporate entity formed as part of a restructuring — provided the assignee assumes all of Hail HQ's obligations under this DPA.

13. Governing law

This DPA is governed by the laws of Sweden, and the parties submit to the exclusive jurisdiction of the courts of Sweden, consistent with the Terms of Use, unless otherwise required by mandatory Data Protection Laws.


Annex I — Description of Processing

Categories of data subjects Recipients — individuals who receive a voice call, SMS/text message, or email triggered by a Developer through the Service.

Categories of personal data

  • Call transcripts (text transcriptions of voice conversations between Hail's AI voice agent and Recipients; call audio itself is not recorded or retained)
  • SMS/text message content (Developer-triggered message body and delivery metadata)
  • Email content (raw MIME content of Developer-triggered emails, stored for delivery and audit purposes)
  • Contact identifiers (Recipient phone numbers, email addresses, and any other identifying information Developer includes when triggering a communication)

Special categories of data None knowingly processed by design. The Service is not intended to process special categories of personal data (Art. 9 GDPR), and Developer is responsible for not submitting such data via the Service absent a separate agreement.

Nature and purpose of processing Hail HQ processes Developer Personal Data to deliver Developer-triggered communications on Developer's behalf — receiving Developer's instructions via API, MCP, or CLI; placing voice calls and generating transcripts; sending SMS/text messages; sending emails; and storing the resulting content/transcripts for the duration of the retention period, for delivery, support, and audit purposes.

Duration of processing For the duration of Developer's account with Hail HQ, plus 12 months following account closure, as set out in Section 10 of this DPA.

Sub-processors See the list at /legal/subprocessors, incorporated by reference, covering (as of this writing): Supabase, Stripe, Twilio, LiveKit, AWS, Deepgram, Cartesia, ElevenLabs, OpenAI, Google, Anthropic, PostHog, Vercel, and Resend (the latter for Hail HQ's own auth/transactional email only, not Developer-triggered communications).

Annex II — Technical and Organisational Measures

Encryption

  • Data in transit between the Service, Developer, Recipients, and Sub-processors is encrypted using industry-standard transport encryption (e.g., TLS).
  • Developer Personal Data at rest (call transcripts, SMS/text message content, stored email content) is encrypted using industry-standard encryption methods.

Access control

  • Access to production systems and Developer Personal Data is restricted to authorized Hail HQ personnel, gated by authentication controls.
  • Access follows a least-privilege model: personnel and service accounts are granted only the access needed for their function, and access is reviewed periodically and revoked when no longer needed.

Audit logging

  • Security-relevant access and administrative actions affecting Developer Personal Data are logged in a manner designed to support detection of, and investigation into, unauthorized or anomalous access, independent of and in addition to the transcript/email content itself.
  • Audit-log records are retained on a separate schedule from transcript/email retention, per Section 10.3 of this DPA.

Organisational measures

  • Personnel with access to Developer Personal Data are bound by confidentiality obligations (Section 3).
  • Consent and lawful-basis obligations for contacting Recipients rest with Developer; Hail HQ applies compensating controls at the account level (e.g., signup email verification and account velocity caps on calls/SMS/email) as part of its overall risk posture, without representing that it verifies Recipient consent on Developer's behalf.
  • Carrier-required telephony compliance (e.g., brand/campaign registration, caller-ID attestation, and related know-your-customer requirements) is registered and maintained by Hail HQ on an ongoing basis.

Sub-processor oversight Hail HQ flows down substantially consistent data protection obligations to each Sub-processor per Section 5 of this DPA (see /legal/subprocessors for the current list).