When this applies. For your own account data, we are the controller and the Privacy Policy governs. This Addendum applies where you use the Service to process personal data about other people — overwhelmingly, the businesses and individuals you contact through the outreach add-on. There, you are the controller and we are your processor.
This Addendum is incorporated into the Terms of Service and takes effect automatically when you accept them. No signature is required. If your organisation needs a countersigned copy, write to contact@hanuxai.com.
1. Parties and roles
This Addendum is between you (the "Customer", acting as controller) and Hanu AI Solutions LLC (LLC), of 1191 Clearwater Dr Frisco TX ("we", "us", acting as processor).
"Customer Personal Data" means personal data we process on your behalf under the Terms. "Data Protection Law" means the UK GDPR, the EU GDPR, and any other privacy or data protection law applicable to that processing. Terms such as controller, processor, data subject, processing and personal data breach carry their meanings under Data Protection Law.
You determine the purposes and means of processing Customer Personal Data. We process it only on your documented instructions. Where we determine the purposes and means ourselves — running and securing our own business — we act as a controller, and the Privacy Policy applies instead.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Providing the Service, including finding, storing and contacting business prospects on the Customer's behalf |
| Duration | For as long as the Customer's account is active, plus our retention periods |
| Nature and purpose | Collection from public sources, storage, organisation, enrichment, scoring, composition of messages, transmission by email, and recording of delivery, opens, clicks, replies, bounces and unsubscribes |
| Categories of data subject | Business contacts at prospect organisations; recipients of the Customer's outreach; individuals named in content the Customer uploads |
| Categories of personal data | Business name, business email address, telephone number, website, postal location, publicly available business description and social profile links, message content sent to them, and engagement and unsubscribe records |
| Special category data | None requested or required. Do not put special category data into the Service |
3. Your obligations as controller
You warrant and undertake that:
- you have a valid lawful basis for each instance of processing you instruct, including for contacting every recipient of an outreach campaign;
- you have completed any legitimate interests assessment your basis requires, and can produce it on request from a supervisory authority;
- your instructions to us will not cause us to breach Data Protection Law;
- you have provided any notices and obtained any consents required in the jurisdictions you target;
- you will not instruct us to process special category data or data about children;
- you are responsible for the accuracy, quality and legality of the targeting criteria and message content you supply.
The obligations in the Acceptable Use Policy form part of your instructions to us.
4. Our obligations as processor
We will:
- process Customer Personal Data only on your documented instructions — the Terms, this Addendum, and your configuration of the Service — unless required otherwise by law, in which case we will tell you first unless the law forbids it;
- ensure personnel with access are bound by confidentiality obligations;
- implement the security measures in section 6;
- respect the conditions in section 5 for engaging sub-processors;
- assist you, so far as reasonably possible and taking into account the nature of processing, with responding to data subject requests, with data protection impact assessments, and with consultations with supervisory authorities;
- notify you of a personal data breach without undue delay after becoming aware of it, with the information reasonably available to us;
- delete or return Customer Personal Data as set out in section 8;
- make available the information reasonably necessary to demonstrate compliance with this Addendum, and allow audits as set out in section 9.
We will tell you if we consider an instruction to infringe Data Protection Law. We are not obliged to give you legal advice, and telling you does not make us responsible for your compliance.
5. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at /legal/subprocessors/ and is incorporated here.
- Each sub-processor is bound by written terms imposing data protection obligations no less protective than this Addendum.
- We remain fully liable to you for their performance.
- We will update the published list before a new sub-processor begins processing. You may subscribe to changes by emailing contact@hanuxai.com.
- You may object on reasonable data protection grounds within 30 days of the list being updated. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the Service; fees already paid are not refunded.
6. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, we maintain technical and organisational measures including:
- encryption of all data in transit using TLS;
- encryption at rest provided by our managed infrastructure providers;
- role-based access control, with production data access limited to personnel who require it;
- tenant isolation so one customer's data is not accessible to another;
- logging of administrative actions;
- authentication handled by a specialist provider, so we never hold your password;
- automated deletion of generated media and content records on the retention schedule in the Privacy Policy;
- signed unsubscribe tokens and enforced suppression lists to prevent contact after opt-out.
A limitation we state rather than gloss. Third-party credentials you supply — in particular the email sending credentials for the outreach add-on — are held in our database under access control and the platform's encryption at rest, but are not additionally encrypted by us at the application layer. Use a dedicated, least-privilege sending account, and rotate its credentials if you stop using the Service.
We may update these measures as the Service evolves, provided security is not materially reduced.
7. International transfers
Our sub-processors operate internationally, including in the United States. Where Customer Personal Data is transferred out of the UK or EEA to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Three (processor to processor) or Module Two as applicable, and — for UK transfers — the UK International Data Transfer Addendum to those Clauses. By accepting this Addendum, both parties are deemed to have entered into those Clauses, with:
- the Customer as data exporter and us as data importer;
- Annex I populated by section 2 and the parties' details in section 1;
- Annex II populated by section 6;
- Annex III populated by the sub-processor list;
- the optional docking clause applying, and the supervisory authority and governing law being those of Texas, USA where the Clauses permit that choice.
8. Deletion and return
On termination, or on your written request, we will delete Customer Personal Data within 30 days, except:
- unsubscribe and suppression records, which we retain indefinitely — deleting them would allow the people who opted out to be contacted again;
- data we are required to retain by law;
- backups, which expire on their normal cycle.
Where you need an export before deletion, request it at contact@hanuxai.com before your access ends.
9. Data subject requests and audits
If we receive a request from a data subject relating to Customer Personal Data, we will not respond to it substantively ourselves. We will forward it to you without undue delay and assist you in responding. One exception: where someone asks to be removed from outreach mail, we will suppress their address immediately as well as forwarding the request — suppression is a protective act and we will not delay it.
We will provide information reasonably necessary to demonstrate compliance with this Addendum on request. Where that is insufficient, you may audit once in any twelve-month period, on 30 days' written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at your cost — unless the audit reveals material non-compliance, in which case we bear the reasonable cost.
10. Liability and precedence
Each party's liability under this Addendum is subject to the limitations and exclusions in section 12 of the Terms of Service.
If this Addendum conflicts with the Terms of Service, this Addendum prevails on data protection matters. If it conflicts with the Standard Contractual Clauses, the Clauses prevail. This Addendum is version 1.0, effective 2026-07-27, and is governed by the law stated in section 15 of the Terms of Service.