H
Harbr Change

Data Processing Agreement

Last updated: 03 August 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Harbr Change Ltd ("Processor", "we", "us") and the customer organisation using Harbr Change ("Controller", "you"), and applies whenever we process personal data on your behalf in connection with the Harbr Change platform. It supplements our Terms of Service and should be read alongside our Privacy Policy. Where this DPA conflicts with the Terms of Service on data processing matters, this DPA prevails.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Sub-processor" have the meanings given in UK GDPR. "Customer Data" means personal data you or your users submit to Harbr Change (e.g. stakeholder names, contact details, and other programme information entered into the platform).

2. Subject Matter and Duration

We process Customer Data solely to provide the Harbr Change platform to you, for the duration of your subscription and any period afterwards during which we retain Customer Data in accordance with Clause 9 (Deletion on Termination).

3. Nature and Purpose of Processing

3.1 We process Customer Data to: create and maintain your account; store and organise programme, stakeholder, and change-management data you enter; generate AI-assisted artefacts based on that data; provide readiness tracking and institutional knowledge features; and provide customer support.

3.2 We process Customer Data only on your documented instructions, which include the instructions given by your use of the platform's features, unless we are required to do otherwise by UK law.

3.3 We will not use Customer Data for any purpose other than providing and improving the service, and will not use it to train our own machine-learning models.

3.4 AI sub-processing (Anthropic). Where you use the platform's AI-generation features, Customer Data you submit for that purpose is sent to Anthropic, PBC ("Anthropic") for processing via its commercial API, as a sub-processor under Clause 5 and Annex 3. Anthropic does not train its models on data submitted through its commercial API (Anthropic Commercial Terms, Section C; Anthropic Data Processing Addendum, Section B.3.b). Anthropic retains this data only for the duration of our agreement with Anthropic and deletes it within 30 days of that agreement's termination or expiration, except where retention is required to comply with law, resolve disputes, or address violations of Anthropic's usage policies (Anthropic Data Processing Addendum, Section H.1.b). Anthropic's own current sub-processors are listed at trust.anthropic.com/subprocessors.

4. Our Obligations

We will: ensure personnel authorised to process Customer Data are subject to confidentiality obligations; implement appropriate technical and organisational security measures (Annex 2); assist you, at your reasonable request, in responding to Data Subject rights requests and in meeting your UK GDPR obligations relating to security, breach notification, and data protection impact assessments; and make available the information reasonably necessary to demonstrate compliance with this DPA.

5. Sub-processors

5.1 You provide general authorisation for us to engage the sub-processors listed in Annex 3 to this DPA.

5.2 We will impose data protection terms on any sub-processor that are no less protective than those in this DPA, and remain liable to you for a sub-processor's performance of its data protection obligations.

5.3 We will give you reasonable notice (by updating Annex 3 and, where practical, emailing account administrators) before appointing a new sub-processor, so you may object on reasonable data-protection grounds.

6. Data Subject Rights

If we receive a request from a Data Subject relating to Customer Data, we will promptly forward it to you and will not respond to it ourselves except on your instructions or as required by law. We will provide reasonable assistance to help you respond to such requests within the timeframes required by UK GDPR.

7. Personal Data Breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to us to help you meet any notification obligations you have under UK GDPR.

8. Audit

On reasonable written request, and no more than once per year (unless following a personal data breach), we will make available the information reasonably necessary to demonstrate compliance with this DPA, including by providing summaries of relevant security documentation or responding to a reasonable written questionnaire, in lieu of an on-site audit unless required by a regulator.

9. International Transfers

Where Customer Data is transferred outside the United Kingdom to a sub-processor listed in Annex 3, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or an equivalent lawful transfer mechanism offered by that sub-processor) to safeguard the transfer.

10. Deletion on Termination

On termination of your subscription, we will delete or, at your written request made within 30 days of termination, return Customer Data, except to the extent we are required to retain copies by law or for the establishment, exercise, or defence of legal claims. Sub-processor deletion timelines are as stated in Annex 3; where a sub-processor's own deletion commitment (e.g. Anthropic's, described in Clause 3.4) differs from ours, the sub-processor's own terms govern data held by that sub-processor.

11. Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations of liability in our Terms of Service.

12. Governing Law

This DPA is governed by the laws of England and Wales, consistent with our Terms of Service.

Annex 1 — Details of Processing

Categories of Data Subjects: your employees, contractors, and other individuals whose information you or your users enter into the platform (e.g. stakeholders, change contacts).

Categories of Personal Data: names, job titles, email addresses, organisational/business unit information, and programme-related notes about individuals (e.g. influence, sentiment, engagement notes) that you choose to enter. We do not knowingly process special category data; see Section 3 of our Privacy Policy.

Nature of Processing: collection, storage, organisation, AI-assisted analysis and content generation, and display within the platform.

Duration: for the term of your subscription, plus the retention period described in Clause 10.

Annex 2 — Technical and Organisational Security Measures

  • Encryption of data in transit (HTTPS/TLS) and at rest (via our database provider, Supabase)
  • Row-level security policies restricting data access by organisation
  • Multi-factor authentication available for user accounts
  • Access to production systems restricted to authorised personnel
  • Regular review of application security practices

Annex 3 — Sub-processors

Sub-processorPurposeProcessing locationData deletion on termination
Supabase, Inc.Database, authentication, file storageUnited Kingdom (region eu-west-2, London) — confirmed via Supabase dashboard, Settings → GeneralPer our instruction on account deletion
Vercel Inc.Application hosting and deliveryUnited States (Washington, D.C.). No EU/UK hosting region is currently configured for this project.Per our instruction on account deletion
Anthropic, PBCAI-assisted artefact generation (Claude API)United StatesWithin 30 days of termination of our agreement with Anthropic (see Clause 3.4)
Resend, Inc.Transactional email delivery (account and notification emails)United StatesPer Resend's standard retention terms

We will update this Annex whenever a sub-processor is added, removed, or changed, in line with Clause 5.3.

Contact

Harbr Change Ltd
Company number: 17377475
Registered office: [pending]
phil@harbrchange.com
United Kingdom