When this applies. For your own account data, we are the controller and the Privacy Policy governs. This Addendum applies where you use the Service to process personal data about other people — overwhelmingly, the businesses and individuals you contact through the outreach add-on. There, you are the controller and we are your processor.

This Addendum is incorporated into the Terms of Service and takes effect automatically when you accept them. No signature is required. If your organisation needs a countersigned copy, write to contact@hanuxai.com.

1. Parties and roles

This Addendum is between you (the "Customer", acting as controller) and Hanu AI Solutions LLC (LLC), of 1191 Clearwater Dr Frisco TX ("we", "us", acting as processor).

"Customer Personal Data" means personal data we process on your behalf under the Terms. "Data Protection Law" means the UK GDPR, the EU GDPR, and any other privacy or data protection law applicable to that processing. Terms such as controller, processor, data subject, processing and personal data breach carry their meanings under Data Protection Law.

You determine the purposes and means of processing Customer Personal Data. We process it only on your documented instructions. Where we determine the purposes and means ourselves — running and securing our own business — we act as a controller, and the Privacy Policy applies instead.

2. Scope of processing

ItemDetail
Subject matterProviding the Service, including finding, storing and contacting business prospects on the Customer's behalf
DurationFor as long as the Customer's account is active, plus our retention periods
Nature and purposeCollection from public sources, storage, organisation, enrichment, scoring, composition of messages, transmission by email, and recording of delivery, opens, clicks, replies, bounces and unsubscribes
Categories of data subjectBusiness contacts at prospect organisations; recipients of the Customer's outreach; individuals named in content the Customer uploads
Categories of personal dataBusiness name, business email address, telephone number, website, postal location, publicly available business description and social profile links, message content sent to them, and engagement and unsubscribe records
Special category dataNone requested or required. Do not put special category data into the Service

3. Your obligations as controller

You warrant and undertake that:

The obligations in the Acceptable Use Policy form part of your instructions to us.

4. Our obligations as processor

We will:

We will tell you if we consider an instruction to infringe Data Protection Law. We are not obliged to give you legal advice, and telling you does not make us responsible for your compliance.

5. Sub-processors

You give us general authorisation to engage sub-processors. The current list is published at /legal/subprocessors/ and is incorporated here.

6. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, we maintain technical and organisational measures including:

A limitation we state rather than gloss. Third-party credentials you supply — in particular the email sending credentials for the outreach add-on — are held in our database under access control and the platform's encryption at rest, but are not additionally encrypted by us at the application layer. Use a dedicated, least-privilege sending account, and rotate its credentials if you stop using the Service.

We may update these measures as the Service evolves, provided security is not materially reduced.

7. International transfers

Our sub-processors operate internationally, including in the United States. Where Customer Personal Data is transferred out of the UK or EEA to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor) or Module Two as applicable, and — for UK transfers — the UK International Data Transfer Addendum to those Clauses. By accepting this Addendum, both parties are deemed to have entered into those Clauses, with:

8. Deletion and return

On termination, or on your written request, we will delete Customer Personal Data within 30 days, except:

Where you need an export before deletion, request it at contact@hanuxai.com before your access ends.

9. Data subject requests and audits

If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it substantively ourselves. We will forward it to you without undue delay and assist you in responding. One exception: where someone asks to be removed from outreach mail, we will suppress their address immediately as well as forwarding the request — suppression is a protective act and we will not delay it.

We will provide information reasonably necessary to demonstrate compliance with this Addendum on request. Where that is insufficient, you may audit once in any twelve-month period, on 30 days' written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost — unless the audit reveals material non-compliance, in which case we bear the reasonable cost.

10. Liability and precedence

Each party's liability under this Addendum is subject to the limitations and exclusions in section 12 of the Terms of Service.

If this Addendum conflicts with the Terms of Service, this Addendum prevails on data protection matters. If it conflicts with the Standard Contractual Clauses, the Clauses prevail. This Addendum is version 1.0, effective 2026-07-27, and is governed by the law stated in section 15 of the Terms of Service.