Data Processing Addendum

Last updated: June 2026

This Data Processing Addendum ("DPA") forms part of the Honeyjar Terms of Service ("Terms") between The Honeyjar AI, Inc. ("Honeyjar", "Processor") and the customer accepting the Terms ("Customer", "Controller").

This DPA applies when Honeyjar processes Personal Data on behalf of Customer in connection with the Services.

1. Definitions

"Applicable Data Protection Laws" means applicable laws governing the processing of Personal Data, including the UK GDPR, EU GDPR, and related implementing legislation.

"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" shall have the meanings given to them under Applicable Data Protection Laws.

2. Scope and Roles

Customer acts as the Controller of Personal Data processed through the Services.

Honeyjar acts as a Processor and will process Personal Data solely as necessary to provide the Services, in accordance with the Terms, this DPA, and Customer's use of the Services.

3. Nature and Purpose of Processing

Honeyjar provides AI-powered communications, public relations, content creation, media discovery, workflow management, research, and related software services.

Processing activities may include collection, storage, organization, retrieval, analysis, transmission, and deletion of Personal Data as necessary to provide and improve the Services.

4. Categories of Data and Data Subjects

Data Subjects

May include:

  • Customer employees and contractors

  • Customer representatives

  • Journalists and media contacts

  • Business contacts

  • Event participants

  • Individuals whose information is included within Customer Content

Categories of Personal Data

May include:

  • Names

  • Email addresses

  • Job titles

  • Company affiliations

  • Contact information

  • User account information

  • Communications and correspondence

  • Customer-generated content

  • Usage and activity information

Customer agrees not to submit sensitive categories of personal data, protected health information, payment card information, government identification numbers, or other regulated data types through the Services.

5. Honeyjar Obligations

Honeyjar will:

  • Process Personal Data only as necessary to provide the Services

  • Use commercially reasonable measures designed to protect Personal Data from unauthorized access, disclosure, alteration, or destruction

  • Limit access to Personal Data to personnel, contractors, and service providers with a legitimate business need for such access

  • Notify Customer without undue delay after becoming aware of a confirmed unauthorized access event affecting Customer Personal Data, where notification is required by applicable law

  • Cooperate in good faith with reasonable requests relating to Customer's compliance obligations under applicable data protection laws

6. Security Measures

Honeyjar maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data.

Such measures may include:

  • Encryption in transit

  • Encryption at rest

  • Access controls and authentication measures

  • Logging and monitoring

  • Workspace-level permissions

  • Security review and incident response procedures

Honeyjar may modify its security practices from time to time provided that the overall level of protection is not materially reduced.

7. Subprocessors

Customer acknowledges that Honeyjar may use third-party service providers and subprocessors in connection with providing the Services.

Honeyjar will use commercially reasonable efforts to select service providers that are appropriate for the nature of the services being performed.

Honeyjar remains responsible for the processing activities it delegates to such providers in connection with the Services.

Information regarding Honeyjar's subprocessors may be provided upon request.

8. International Data Transfers

Customer acknowledges that Personal Data may be processed in the United States and other countries where Honeyjar or its service providers operate.

Where required by applicable law, Honeyjar will cooperate in good faith regarding appropriate mechanisms for international data transfers.

9. Data Subject Requests

If Honeyjar receives a request from a Data Subject relating to Personal Data processed on behalf of Customer, Honeyjar may direct the Data Subject to Customer or notify Customer of the request where appropriate and legally permitted.

10. Return and Deletion of Data

Upon termination or expiration of the Services, Honeyjar may retain Personal Data for a reasonable period consistent with backup, security, legal, and operational requirements.

Thereafter, Honeyjar will take commercially reasonable steps to delete or anonymize Personal Data in accordance with its standard retention practices.

11. Liability

The liability of each party arising under this DPA shall be subject to the limitations and exclusions of liability contained in the Terms.

12. Order of Precedence

If there is a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA shall control solely with respect to such processing.

13. Contact Information

Questions regarding this DPA may be directed to: Info@honeyjar.ai. 

Data Processing Addendum

Last updated: June 2026

This Data Processing Addendum ("DPA") forms part of the Honeyjar Terms of Service ("Terms") between The Honeyjar AI, Inc. ("Honeyjar", "Processor") and the customer accepting the Terms ("Customer", "Controller").

This DPA applies when Honeyjar processes Personal Data on behalf of Customer in connection with the Services.

1. Definitions

"Applicable Data Protection Laws" means applicable laws governing the processing of Personal Data, including the UK GDPR, EU GDPR, and related implementing legislation.

"Controller", "Processor", "Data Subject", "Personal Data", and "Processing" shall have the meanings given to them under Applicable Data Protection Laws.

2. Scope and Roles

Customer acts as the Controller of Personal Data processed through the Services.

Honeyjar acts as a Processor and will process Personal Data solely as necessary to provide the Services, in accordance with the Terms, this DPA, and Customer's use of the Services.

3. Nature and Purpose of Processing

Honeyjar provides AI-powered communications, public relations, content creation, media discovery, workflow management, research, and related software services.

Processing activities may include collection, storage, organization, retrieval, analysis, transmission, and deletion of Personal Data as necessary to provide and improve the Services.

4. Categories of Data and Data Subjects

Data Subjects

May include:

  • Customer employees and contractors

  • Customer representatives

  • Journalists and media contacts

  • Business contacts

  • Event participants

  • Individuals whose information is included within Customer Content

Categories of Personal Data

May include:

  • Names

  • Email addresses

  • Job titles

  • Company affiliations

  • Contact information

  • User account information

  • Communications and correspondence

  • Customer-generated content

  • Usage and activity information

Customer agrees not to submit sensitive categories of personal data, protected health information, payment card information, government identification numbers, or other regulated data types through the Services.

5. Honeyjar Obligations

Honeyjar will:

  • Process Personal Data only as necessary to provide the Services

  • Use commercially reasonable measures designed to protect Personal Data from unauthorized access, disclosure, alteration, or destruction

  • Limit access to Personal Data to personnel, contractors, and service providers with a legitimate business need for such access

  • Notify Customer without undue delay after becoming aware of a confirmed unauthorized access event affecting Customer Personal Data, where notification is required by applicable law

  • Cooperate in good faith with reasonable requests relating to Customer's compliance obligations under applicable data protection laws

6. Security Measures

Honeyjar maintains commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data.

Such measures may include:

  • Encryption in transit

  • Encryption at rest

  • Access controls and authentication measures

  • Logging and monitoring

  • Workspace-level permissions

  • Security review and incident response procedures

Honeyjar may modify its security practices from time to time provided that the overall level of protection is not materially reduced.

7. Subprocessors

Customer acknowledges that Honeyjar may use third-party service providers and subprocessors in connection with providing the Services.

Honeyjar will use commercially reasonable efforts to select service providers that are appropriate for the nature of the services being performed.

Honeyjar remains responsible for the processing activities it delegates to such providers in connection with the Services.

Information regarding Honeyjar's subprocessors may be provided upon request.

8. International Data Transfers

Customer acknowledges that Personal Data may be processed in the United States and other countries where Honeyjar or its service providers operate.

Where required by applicable law, Honeyjar will cooperate in good faith regarding appropriate mechanisms for international data transfers.

9. Data Subject Requests

If Honeyjar receives a request from a Data Subject relating to Personal Data processed on behalf of Customer, Honeyjar may direct the Data Subject to Customer or notify Customer of the request where appropriate and legally permitted.

10. Return and Deletion of Data

Upon termination or expiration of the Services, Honeyjar may retain Personal Data for a reasonable period consistent with backup, security, legal, and operational requirements.

Thereafter, Honeyjar will take commercially reasonable steps to delete or anonymize Personal Data in accordance with its standard retention practices.

11. Liability

The liability of each party arising under this DPA shall be subject to the limitations and exclusions of liability contained in the Terms.

12. Order of Precedence

If there is a conflict between this DPA and the Terms with respect to the processing of Personal Data, this DPA shall control solely with respect to such processing.

13. Contact Information

Questions regarding this DPA may be directed to: Info@honeyjar.ai.