LEGAL
Data Processing Addendum
Last updated: September 3, 2025
Scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement between the customer ("Customer") and Human Behavior, Inc. ("Human Behavior") governing use of the Human Behavior services (the "Agreement"). It applies whenever Human Behavior processes personal data within Customer Data on Customer's behalf ("Customer Personal Data"). Capitalized terms not defined here have the meaning in the Agreement. If this DPA conflicts with the Agreement, this DPA controls for data protection matters.
"Data Protection Laws" means the privacy and data protection laws applicable to the Customer Personal Data, which may include the GDPR, UK GDPR, Swiss FADP, ePrivacy rules, and the CCPA. For that data, Customer is the controller and Human Behavior is a processor (or, under the CCPA, a service provider).
Processing of Customer Personal Data
Human Behavior processes Customer Personal Data only to provide the services in accordance with the Agreement, this DPA, and Customer's documented instructions, unless required otherwise by law (in which case Human Behavior will inform Customer unless legally prohibited). The categories of data processed include account information, authentication information, usage logs, screen recordings, mouse movements, clicks and scrolls, page metadata (URL, referrer, device information, IP address), and custom events sent via the client API; data subjects include Customer personnel and Customer's end users. Processing continues for the duration of the Agreement.
Anyone Human Behavior authorizes to process Customer Personal Data is bound by confidentiality obligations.
Subprocessors
Customer authorizes Human Behavior to engage subprocessors to help provide the services. Every subprocessor that processes personal data on our behalf is listed on the Subprocessors page, with what it is used for and what data it handles. Human Behavior imposes data protection obligations on subprocessors consistent with this DPA and remains responsible for their performance. Where required by Data Protection Laws, we will notify Customer by email before engaging a new subprocessor and allow ten (10) days to object; if Customer has a legitimate objection, the parties will work in good faith to resolve it.
Security and incidents
Human Behavior implements and maintains reasonable administrative, technical, and physical safeguards designed to protect Customer Personal Data, as described on our Security page. If Human Behavior becomes aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, it will notify Customer without undue delay and within the time frame required by Data Protection Laws, with the details available at the time to support Customer's own notification obligations.
Assistance
Taking into account the nature of the processing, Human Behavior will provide reasonable assistance with requests from individuals exercising their rights under Data Protection Laws, and with data protection impact assessments and consultations with supervisory authorities where required. Requests reaching Human Behavior directly for data collected on a Customer's site will be referred to that Customer.
California (CCPA)
To the extent the CCPA applies, Customer discloses Customer Personal Data to Human Behavior only for the limited and specific purpose of providing the services. Human Behavior will not sell or share Customer Personal Data; will not retain, use, or disclose it for any purpose other than providing the services or as otherwise permitted by the CCPA; will not use it outside the direct business relationship with Customer; will provide the same level of privacy protection as the CCPA requires; and will notify Customer if it can no longer meet its CCPA obligations.
Aggregated and de-identified data
Where permitted by Data Protection Laws, Human Behavior may compile aggregated and/or de-identified information that cannot reasonably be used to identify Customer or any data subject, and may use it to provide, maintain, and improve the services, detect security incidents, and protect against fraudulent or illegal activity.
In addition, for Customers on the Get Started plan only, Human Behavior may use and share redacted, de-identified data derived from Customer's use of the services — with personal identifiers and identifying content removed — to improve and develop its products. This does not apply to any other plan, and it does not apply during any free trial on any plan. See the De-identified data section of the Privacy Policy.
International transfers
Customer authorizes Human Behavior and its subprocessors to transfer Customer Personal Data across international borders, including from the European Economic Area, Switzerland, and the United Kingdom to the United States. Where such transfers are made to a country not recognized as providing an adequate level of protection, the parties rely on the EU Standard Contractual Clauses (Module Two, controller-to-processor), as supplemented for Swiss transfers and by the UK International Data Transfer Addendum for UK transfers, which are incorporated into this DPA by reference.
Audits
Where Data Protection Laws give Customer an audit right, Human Behavior will provide information reasonably necessary to demonstrate compliance with this DPA, and Customer (or its appointed representative) may conduct an audit no more than once per year, during business hours, with reasonable advance notice, under reasonable confidentiality procedures, and in a manner that does not unreasonably disrupt Human Behavior's operations.
Deletion
On expiry or termination of the Agreement, Human Behavior deletes Customer Personal Data in accordance with the Retention section of the Privacy Policy, except for backup or archival copies that expire on their own rotation schedule and data Human Behavior is legally required to retain, which is isolated and protected from further processing.
Customer obligations
Customer is responsible for complying with Data Protection Laws for the Customer Personal Data it collects through the services, including providing end users with an accurate privacy notice and establishing a lawful basis (and, where required, consent) for the recording and analytics it configures. Customer agrees not to provide Human Behavior with sensitive data requiring heightened protection (such as government identifiers, financial account or payment card numbers, health information, or data of children under 13) and to use the available masking and privacy controls to prevent its capture.
Contact
The designated contact for urgent privacy and security issues:
Human Behavior, Inc.
1395 22nd St, San Francisco, CA
Email: founders@humanbehavior.co