Data Processing Agreement
Last updated: September 1, 2026
This Data Processing Agreement describes how WarmHawk (“we,” “Processor”), the operator of warmhawk.com and its billing/checkout flow, processes personal data as a processor on behalf of a customer (“Customer,” “Controller”), for organizations whose procurement process requires a standalone DPA. It is linked from the checkout flow for exactly that reason.
1. Why this DPA is short
A typical SaaS DPA is long because the vendor stores and processes the customer’s end-user data on the vendor’s own infrastructure. WarmHawk’s architecture is the opposite: the product is fully self-hosted, running on Customer’s own server, own Postgres database, and own containers. As a direct consequence, WarmHawk itself never touches Customer’s lead, prospect, or campaign data at rest, in transit through WarmHawk’s systems, or in any backup WarmHawk holds. This DPA is intentionally short relative to a typical SaaS DPA — it covers only the narrow slice of personal data that does reach WarmHawk’s systems: billing and checkout data processed through Stripe.
2. Definitions
Terms used in this DPA — “controller,” “processor,” “data subject,” “personal data,” “processing,” and “sub-processor” — have the meanings given in Article 4 of the GDPR. In summary: Customer is the controller of its own lead and campaign data, deciding why and how that data is processed; WarmHawk is the processor only for the narrow billing-contact data described in Section 5, processing it solely on Customer’s instructions to deliver the subscription Customer purchased.
3. Subject matter and duration
The subject matter of processing under this DPA is the billing-contact personal data submitted through the warmhawk.com checkout flow. Processing continues for the duration of Customer’s active subscription and for any retention period required afterward by tax, accounting, or other applicable law, consistent with the Privacy Policy.
4. Nature and purpose of processing
The marketing site’s billing/checkout flow processes payment and contact data (name, email, billing address, payment method) via Stripe as a sub-processor, solely to complete Customer’s purchase, issue a license key, and administer the subscription. This DPA does not cover, and does not need to cover, Customer’s lead lists, mailbox contents, or campaign data — that data is generated, stored, and processed entirely within Customer’s own self-hosted instance and never reaches any system WarmHawk operates.
5. Categories of data subjects and data
The only data subjects in scope of this DPA are Customer’s billing contacts — typically the individual who completes checkout on Customer’s behalf. The only categories of data in scope are ordinary billing-contact details: name, business email address, billing address, and payment-method metadata handled by Stripe. No special categories of data (GDPR Art. 9) are knowingly processed under this DPA.
6. Sub-processors
WarmHawk engages Stripe, Inc. as its sole sub-processor for the processing described in this DPA, to handle payment processing and subscription billing. We will provide reasonable advance notice before adding or replacing a sub-processor for this billing-contact data.
7. Security measures
All traffic between Customer, warmhawk.com, and Stripe is encrypted in transit via TLS. Because Customer’s lead and campaign data is never transmitted to or stored by WarmHawk, the largest data-security risk present in a typical SaaS deployment — a vendor-side breach of end-user data — does not apply to this architecture; that data exists only on infrastructure Customer itself controls and secures.
8. International transfers
Where Stripe processes billing-contact data outside the EU/EEA or UK, such transfers are made subject to appropriate safeguards under Stripe’s own data processing terms — including the EU Standard Contractual Clauses and, where applicable, a Data Privacy Framework certification — as published and kept current in Stripe’s own DPA documentation. Because WarmHawk has no visibility into which specific mechanism Stripe applies to a given transfer at a given time, Customer should consult Stripe’s own current DPA for the mechanism in effect.
9. Data subject rights assistance
WarmHawk will provide Customer with reasonable assistance to respond to a data subject access, correction, deletion, or portability request concerning billing-contact data processed under this DPA. Requests can be directed to support@warmhawk.com. WarmHawk has no ability to fulfill a request concerning Customer’s lead or campaign data, since that data never reaches WarmHawk’s systems; such requests must be handled by Customer directly on its own self-hosted instance.
10. Audit rights
On reasonable written request, no more than once per 12-month period, WarmHawk will make available information reasonably necessary to demonstrate compliance with this DPA with respect to the billing-contact processing described above, which may include a summary of Stripe’s own compliance documentation in lieu of an on-site audit.
11. Term and termination
This DPA takes effect when Customer accepts it (or, if not separately executed, upon Customer’s acceptance of the Terms of Service) and remains in effect for as long as the Terms of Service remain in effect, terminating automatically alongside them. This DPA is governed by the laws of the State of Texas, without regard to its conflict-of-laws principles — the same governing law as the Terms of Service.
12. Contact
Questions about this DPA can be sent to support@warmhawk.com.