Time management
No two workdays are the same, and it’s helpful to have an overview of what you’re working on each day. We’ve created a time tracking template you can customize and use however you like. Download it for free here.
No two workdays are the same, and it’s helpful to have an overview of what you’re working on each day. We’ve created a time tracking template you can customize and use however you like. Download it for free here.
Last updated September 30th 2026 (previous version of DPA).
This Huma Data Processing Agreement ("DPA") accompanies the parties' agreement, including the Huma Subscription Terms of Service (the "Agreement") entered into between you ("Customer") and Huma.
The DPA regulates the processing of personal data by the Processor on behalf of the Controller, as stated in this DPA.
All terms defined elsewhere in the Agreement apply to the DPA as well, but particularly pertinent terms are repeated here for clarity. Terms defined in the GDPR and used in this DPA shall have the same meaning as in the GDPR.
“Data Controller” refers to Customer
“Data Processor” refers to Huma
"GDPR" is the EU General Data Protection Regulation (EU regulation no. 2016/679)
“Personal data” shall have the same meaning as defined in the GDPR Article 4 (1):
"any information relating to an identified or identifiable natural person(‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person"
"Sensitive Personal Information" means any personal data deemed to be in a "special category" as defined in the GDPR Article 9 (1):
“personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation”
and as defined in Article 10
“Processing of personal data relating to criminal convictions and offenses or related security measures”
"Services" means Huma’s proprietary software-as-a-service solution(s), as described on https://humahr.com/plans.
“user” customer, or a person given access to the services by the customer, who makes use of the services, whether through the web client, mobile applications, or otherwise.
The types of personal data in actuality processed under this DPA depend on the Data Controller’s choices in what functionality to make use of, and how.
2.3 Types of processing
Any personal data processed by the Data Processor on behalf of the Data Controller shall be processed in accordance with the specified purposes and limitations of this DPA. The Data Processor shall process no such data beyond what is required for the purposes defined in this DPA without written agreement with the Data Controller.
The Data Processor shall facilitate the Data Controller’s compliance with GDPR by
The Data Controller confirms that:
The Data Controller shall ensure that personal data is processed in accordance with the GDPR, respond to inquiries from the Data Subjects and ensure that adequate technical and organizational measures are implemented to secure the Personal Data being processed, cf. GDPR Article 32.
The Data Controller is obliged to report data breach to the relevant supervisory authorities and, if applicable, to the Data Subject without undue delay in accordance with applicable legislation.
The Data Controller is responsible for ensuring that custom data fields in their own right, or by their content do not violate any applicable laws and regulations, including regarding personal data. The same applies to the use of combinations of data fields in, for example, reports, etc.
Where the system contains texts, data or other information, etc., which is owned/disposed by the Data Controller, the Data Controller warrants having full ownership or disposal rights for such texts, data, information, etc. and that neither storage nor the actual use of this material implies an infringement of third party rights or violates any law, regulation or other legal rules.
The Data Controller is subject to confidentiality regarding Data Processor's documentation and data that he/she has access to in accordance with this DPA. This provision also applies after the termination of the DPA.
Access to the system is administered by the administrator at the Data Controller. The Data Controller is obliged to ensure that credentials for such access are stored and handled in such a way that they are available only to persons authorized by the Data Controller and entitled to use the Services under the Agreement. The Data Controller is responsible for the use of personal data in the system by the users it has granted access.
The Data Controller handles and processes inquiries from the Data Subjects regarding access, rectification and deletion, etc.
In the case that subcontractors are added or replaced, the Data Controller shall be notified of the upcoming change at least 30 calendar days before the new subcontractor starts processing personal data and may within the 30 calendar days oppose the change. If the Data Controller opposes the change, the Data Processor will consider the objection. If the Data Controller cannot reasonably satisfy the objection, the Data Controller may terminate the Agreement with immediate effect. Notification of termination must be given by the end of the notification period. If the Data Controller does not terminate the Agreement, the new subcontractor is deemed to be accepted.
In the case that a subcontractor is removed from the Sub-processors list, Data Processor must ensure the former subcontractor has deleted all personal data the subcontractor processed on behalf of Data Processor from its systems.
The Data Processor may only transfer personal data to a country outside the EU/EEA on documented instructions by the Controller. The Controller agrees to transfers to approved Sub-processors as specified in the list of data processors. The Data Processor shall ensure that all transfers have a valid basis in accordance with Chapter V of the GDPR.
On the request of the Data Controller, the Data Processor is required to provide the Data Controller with information on the legal basis for the transfer, including, if relevant, a copy of the signed Standard Contractual Clauses.
Notwithstanding the paragraph above, Personal Data may in exceptional cases be transferred if necessary, to fulfill obligations under EU law or the national law of an EU or EEA country. In such a case, the Data Processor shall inform the Data Controller of that legal requirement before the transfer, unless that law prohibits such information.
The Data Processor shall have the capacity to provide documentation of such security measures, and shall make it available at the Data Controller's request.
The Data Processor shall implement processes to detect and follow up on threats to data security ("Deviation"), and shall without undue delay notify the Data Controller of any such Deviation that affects or identifies a risk to Data Controller’s data. If a Deviation is caused by the Data Controller, the Data Processor may invoice the Data Controller for reasonable and substantiated costs incurred by the follow-up.
The Data Controller is responsible for reporting data breaches to the relevant authorities in accordance with applicable law. The Data Processor shall as set out in clause 3.1.IV above provide necessary information for the Data Controller to comply with such requirements.
The Data Processor provides regular data backups.
The Data Processor maintains an information security management system certified to ISO/IEC 27001.
The Data Processor strongly recommends any personal data transmitted from the Data Controller to the Data Processor outside the Services happen only in encrypted form.
The Data Processor ensures that an independent third party performs a systematic audit of the system on a regular basis. The Data Processor primarily fulfils the Data Controller's audit right under GDPR art. 28 (3) (h) by making available its ISO/IEC 27001 certificate and the conclusions of the independent third-party audit. Where this is not sufficient to demonstrate compliance, or where required by a supervisory authority, the Data Controller may conduct an audit itself or through an independent auditor bound by confidentiality, with at least 30 days' written notice and at the Data Controller's own cost.
Claims from a party as a result of the other party's failure to comply with the DPA shall be subject to the same liability regulations and limitations of liability as provided by the Agreement.
The Data Controller is expected to use the Services to export personal data as necessary prior to termination. If this is not reasonably achievable, the Data Processor shall, upon request from the Data Controller, provide an export of such data, given that the request is made prior to the Data Processor fulfilling its obligations of deletion as described in section 9 of this DPA.