Data Processing Agreement
Version 1.0 · August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the applicable order, registration or subscription ("Customer") and Danai Data UK Ltd, a company registered in England and Wales, trading as HermanWa ("HermanWa"), for the provision of the HermanWa platform and related services (the "Services") (together, the "Agreement"). It applies to the extent HermanWa processes Personal Data on the Customer's behalf in providing the Services.
In plain terms: for the content you put into HermanWa — tenant records, compliance evidence, registers, findings — you are the controller and we are your processor (in Singapore: your data intermediary). We process it only on your instructions, protect it as described in Annex 2, use only the sub-processors in Annex 3, tell you within 72 hours if we confirm a breach affecting your data, and delete it when you leave. For a countersigned copy of this DPA, email hi@hermanwa.com.
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including as applicable: the UK GDPR and the Data Protection Act 2018 (the "UK Regime"); Regulation (EU) 2016/679 ("EU GDPR"); the Singapore Personal Data Protection Act 2012 ("PDPA"); and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL").
- "Personal Data" means any information relating to an identified or identifiable natural person that HermanWa processes on the Customer's behalf in providing the Services ("Customer Personal Data").
- "Sub-processor" means a third party engaged by HermanWa to process Customer Personal Data.
- "controller", "processor", "data subject", "processing" and "personal data breach" have the meanings given in the UK Regime; under the PDPA, "controller" is read as the "organisation" and "processor" as the "data intermediary".
2. Roles and scope
- As between the parties, the Customer is the controller and HermanWa is the processor of Customer Personal Data. Under the PDPA, HermanWa processes Customer Personal Data as the Customer's data intermediary pursuant to a contract evidenced in writing, namely this DPA.
- The subject matter, duration, nature and purpose of processing, and the categories of data subjects and Personal Data, are set out in Annex 1.
- This DPA does not apply to Personal Data for which HermanWa is itself the controller (Customer account and billing contacts, marketing-site visitors), which is described in the Privacy Policy.
3. HermanWa's obligations
HermanWa shall:
- Instructions. Process Customer Personal Data only on the Customer's documented instructions — including this DPA, the Agreement, and the Customer's configuration and use of the Services — unless required to do otherwise by law to which HermanWa is subject, in which case HermanWa shall inform the Customer of that legal requirement before processing unless the law prohibits it. HermanWa shall immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
- Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality.
- Security. Implement and maintain the technical and organisational measures set out in Annex 2, and not materially reduce the overall protection they provide during the term of the Agreement.
- Sub-processing. Engage Sub-processors only as permitted by section 5.
- Data subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subject requests (access, correction, erasure, restriction, portability and objection) under Data Protection Laws. If a data subject contacts HermanWa directly about Customer Personal Data, HermanWa will refer the request to the Customer without undue delay and will not respond substantively except on the Customer's instruction or where legally required.
- Assistance. Taking into account the nature of the processing and the information available to it, assist the Customer in ensuring compliance with its obligations regarding security of processing, breach notification, data protection impact assessments and prior consultation with supervisory authorities.
- Deletion and return. Comply with section 7 on expiry or termination of the Agreement.
- Audits. Comply with section 8.
4. Personal data breach
- HermanWa shall notify the Customer without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting Customer Personal Data.
- The notification shall, to the extent then known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and a contact point; information may be provided in phases as it becomes available.
- HermanWa shall provide reasonable assistance with the Customer's own notification obligations to supervisory authorities (including the ICO, the PDPC and the UAE Data Office) and to data subjects, and shall document the breach and remediation.
- HermanWa's notification of, or response to, a breach is not an acknowledgement of fault or liability.
5. Sub-processors
- The Customer provides a general authorisation for HermanWa to engage the Sub-processors listed in Annex 3, which is kept current on the Trust & Security page.
- HermanWa shall give the Customer at least 30 days' prior notice of the addition or replacement of a Sub-processor (by updating the Trust & Security page and emailing the Customer's account contact). If the Customer reasonably objects on data protection grounds within that period and the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the unexpired period.
- HermanWa shall impose on each Sub-processor, by written contract, data protection obligations that provide at least the level of protection required by this DPA, and shall remain fully liable to the Customer for the Sub-processor's performance.
6. International transfers
- Customer Personal Data is hosted in the United Kingdom (Manchester), as described on the Trust & Security page.
- HermanWa shall not transfer Customer Personal Data outside the UK except to the Sub-processors in Annex 3 or on the Customer's instructions, and any such transfer shall be made only under a lawful transfer mechanism under the UK Regime — UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework where the recipient is certified, or the ICO's International Data Transfer Agreement / Addendum with any required supplementary measures.
- Singapore (PDPA s.26). Where the Customer's use of the Services transfers personal data outside Singapore, HermanWa contractually undertakes to provide the transferred personal data a standard of protection comparable to that under the PDPA while it is in HermanWa's possession or under its control. This DPA constitutes the legally enforceable obligation for the purposes of the transfer limitation obligation.
- UAE (PDPL). HermanWa shall provide reasonable information and assistance for the Customer's assessment of cross-border transfer requirements under the PDPL and its Executive Regulations once issued.
7. Deletion and return
- During the term, the Customer can access and export its data through the Services; HermanWa will provide reasonable export assistance on request.
- On expiry or termination of the Agreement, or earlier on the Customer's written request, HermanWa shall delete Customer Personal Data from the production environment within 30 days (or return it and then delete it, at the Customer's choice), unless retention is required by law — in which case HermanWa shall protect it as under this DPA and process it for no other purpose.
- Backup archives containing deleted data age out automatically within the 14-day backup retention window described in Annex 2 and are not restored except as necessary for disaster recovery, in which case deletion is re-applied.
- Under the PDPA, HermanWa shall cease to retain documents containing personal data, or anonymise them, as soon as retention is no longer necessary for the purposes of this DPA.
8. Audit and information
- HermanWa shall make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA — starting with the Trust & Security page, security documentation, and written responses to security and procurement questionnaires.
- Where that information is insufficient, HermanWa shall allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer (not a competitor of HermanWa), no more than once in any 12-month period except following a personal data breach or at a supervisory authority's direction, on at least 30 days' notice, during business hours, without disrupting the Services, subject to reasonable confidentiality undertakings, and at the Customer's cost.
9. Liability, term and general
- Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement. If the Agreement contains no such limitation, each party's aggregate liability under this DPA is limited to the fees paid or payable by the Customer for the Services in the 12 months preceding the event giving rise to the claim — except for liability that cannot be limited by law.
- This DPA takes effect when the Customer first uses the Services (or on countersignature, if earlier) and continues for as long as HermanWa processes Customer Personal Data, surviving termination of the Agreement to that extent.
- If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA prevails. If any provision is held unenforceable, the remainder continues in effect.
- This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except that the PDPA module in sections 2.1, 6.3 and 7.4 is to be interpreted consistently with the PDPA for personal data transferred from Singapore.
Annex 1 — Details of processing
| Subject matter | Provision of the HermanWa building-compliance, self-audit, energy and operations platform. |
| Duration | The term of the Agreement, plus the deletion periods in section 7. |
| Nature and purpose | Hosting, storage, retrieval, display, analysis, report generation, notification and backup of data the Customer records in the Services; AI-assisted answers to Customer queries (Annex 3, OpenAI). |
| Categories of data subjects | Customer's staff and authorised users; tenants and residents; contractors and their staff; building visitors and correspondents whose details appear in records the Customer uploads. |
| Categories of Personal Data | Names, contact details, roles; tenancy and unit records; work orders, complaints and correspondence; compliance and audit records, findings and evidence (photos, invoices, certificates) which may incidentally contain Personal Data; usage and audit logs. |
| Special category data | The Services are not designed for special category / sensitive personal data, and the Customer agrees not to submit it except where unavoidable within evidence records; any such data is protected under the same measures. |
Annex 2 — Technical and organisational measures
- Hosting: single production environment on a dedicated virtual server in Manchester, United Kingdom (Hostinger International Ltd); no multi-region replication.
- Transport encryption: HTTPS/TLS on all connections, with HTTP Strict Transport Security across the domain and subdomains.
- Credentials: passwords stored as bcrypt hashes; TOTP two-factor authentication on administrative access, enabled by default.
- Sessions and application security: Secure/HttpOnly/SameSite=Strict session cookies with 4-hour expiry; CSRF tokens on state-changing requests; input sanitisation; login and registration rate-limiting; Content-Security-Policy restricting scripts to known origins.
- Access control: role-scoped portals (administrator, client, tenant, contractor), each authenticating independently and limited to its own scope.
- Monitoring: security event log with automated alerting on suspicious activity.
- Payments: payment card data is processed by PayPal on its own infrastructure and never touches HermanWa's servers.
- Backups: automated daily compressed backups of the application and databases, stored off-site (Annex 3, Dropbox), 14-day retention; supervised processes with automatic restart.
- Organisational: access to production systems is limited to authorised personnel bound by confidentiality; sub-processors are bound by written data protection terms (section 5.3).
Annex 3 — Authorised Sub-processors
The current list, maintained on the Trust & Security page:
| Sub-processor | Purpose | Customer Personal Data involved | Location |
|---|---|---|---|
| Hostinger International Ltd | Production hosting; transactional email | All Customer Personal Data (hosted); notification email content | Hosting in Manchester, UK |
| Dropbox, Inc. | Off-site backup storage | Compressed backup archives | United States |
| PayPal | Subscription billing | Billing contact and payment data (controller-to-controller for payment processing) | Global (US-headquartered) |
| OpenAI | Herman AI assistant | Chat messages and the building/facility data extracts needed to answer them | United States |
DeepSeek (internal marketing-site analytics), Google (marketing-site analytics/advertising) and the weather APIs listed on the Trust & Security page do not process Customer Personal Data and are therefore not Sub-processors under this DPA.
Need a countersigned copy, or your own DPA template reviewed against ours? Email hi@hermanwa.com. This page prints cleanly to PDF for your vendor file.