Data processing addendum

Hiya Labs, Inc., d/b/a Pardon my Language. Last updated: August 30, 2026.

This Data Processing Addendum (the "DPA") forms part of the agreement for the provision of language-learning services (the "Agreement", including our Terms of Service) between Hiya Labs, Inc., a Delaware corporation d/b/a Pardon my Language, with its principal U.S. address at 7901 4th St N, Ste 300, St. Petersburg, FL 33702 ("Provider"), and the business customer that has entered into the Agreement ("Customer"). It applies automatically, without signature, where and to the extent Provider processes Personal Data on behalf of Customer in connection with providing the services described in the Agreement (the "Services"). A countersigned copy is available on request at support@pardonmylanguage.com.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA").

"Personal Data" means any information relating to an identified or identifiable natural person that Provider processes on behalf of Customer under the Agreement, as described in Annex A.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.

The terms "controller," "processor," "data subject," "processing," "personal data breach," and "supervisory authority" have the meanings given in the GDPR. Under the CCPA, "controller" is read as "business," "processor" as "service provider," and "data subject" as "consumer."

2. Roles and scope

Customer is the controller and Provider is the processor of the Personal Data described in Annex A. Each party will comply with the Data Protection Laws applicable to it. For clarity: where an individual creates a personal account with Provider outside the Agreement, Provider acts as an independent controller of that account under its own Privacy Policy, and this DPA does not apply to that processing.

3. Processing on instructions

Provider will process Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do so by law to which Provider is subject; in that case Provider will inform Customer of the legal requirement before processing, unless the law prohibits it. The Agreement, this DPA, and Customer's configuration and use of the Services constitute Customer's complete documented instructions. Provider will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Confidentiality

Provider will ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process Personal Data only as needed to provide the Services.

5. Security

Provider will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The current measures are described in Annex B. Provider may update them from time to time provided the updates do not materially reduce the overall level of protection.

6. Subprocessors

Customer grants Provider general authorization to engage subprocessors to provide the Services. The subprocessors engaged as of the date of this DPA are listed in Annex C. Provider will: (a) impose data protection obligations on each subprocessor that are no less protective than those in this DPA; (b) remain liable for each subprocessor's performance; and (c) give Customer at least 30 days' prior written notice (email suffices) of any intended addition or replacement of a subprocessor. If Customer reasonably objects on data protection grounds within that period and the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.

7. Assistance with data subject rights

Taking into account the nature of the processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests from data subjects exercising their rights under Data Protection Laws. If a data subject contacts Provider directly regarding Personal Data processed under this DPA, Provider will promptly forward the request to Customer and will not respond except to direct the data subject to Customer, unless legally required.

8. Personal data breach

Provider will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Provider will cooperate with Customer and take reasonable steps to mitigate the effects of the breach.

9. Impact assessments and consultation

Taking into account the nature of the processing and the information available to it, Provider will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Data Protection Laws in relation to the Services.

10. International transfers

Provider stores and processes Personal Data in the locations identified in Annex C. Where the processing involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties agree that the SCCs (Module Two: controller to processor) are incorporated into this DPA by reference, with Customer as data exporter and Provider as data importer; Annexes A, B, and C of this DPA serve as Annexes I, II, and III of the SCCs; the optional docking clause applies; option 2 of clause 9(a) applies with the notice period in Section 6; the SCCs are governed by the law of Ireland and disputes under them are resolved before the courts of Ireland; and, for UK transfers, the SCCs are read together with the UK International Data Transfer Addendum.

11. U.S. state privacy laws

To the extent the CCPA or another U.S. state privacy law applies, Provider acts as Customer's service provider or processor. Provider will not sell or share Personal Data; will not retain, use, or disclose Personal Data for any purpose other than providing the Services or as otherwise permitted by such laws; will not combine Personal Data with personal information it receives from other sources except as permitted; and certifies that it understands and will comply with these restrictions. Provider will notify Customer if it determines it can no longer meet its obligations under such laws, and Customer may take reasonable steps to stop and remediate unauthorized use.

12. Audits

Provider will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and security documentation of its subprocessors, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, no more than once per year on at least 30 days' notice, during business hours, without disruption to Provider's operations, and subject to reasonable confidentiality obligations. Customer bears its own audit costs.

13. Return and deletion

Upon termination or expiry of the Agreement, Provider will, at Customer's choice, delete or return all Personal Data processed on Customer's behalf, and delete existing copies, within 90 days, unless applicable law requires longer storage. Deprovisioned learner accounts and their records are deleted or anonymized in accordance with this Section.

14. General

This DPA is effective as of the effective date of the Agreement and remains in force as long as Provider processes Personal Data on behalf of Customer. In case of conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Personal Data; where the SCCs apply, the SCCs prevail over this DPA. Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the law governing the Agreement, except where the SCCs require otherwise.

Annex A: Description of processing

Subject matter and duration: provision of the Pardon my Language language-learning platform and tutoring services to learners sponsored by Customer, for the term of the Agreement.

Nature and purpose: hosting learner accounts; scheduling and delivering lessons; assessing language level and tracking learning progress; processing payments made by Customer; communicating with learners about their lessons; product analytics; AI-assisted evaluation of lesson exercises and errors.

Categories of data subjects: Customer's employees and other individuals whose learning Customer sponsors; Customer's administrative contacts.

Categories of personal data: name, email address, time zone, language preferences and interests, learning level and assessment results, lesson attendance and scheduling data, recorded language errors and progress evidence, usage data, communications with tutors and support.

Special categories of data: none intended or required; learners are instructed not to submit special-category data.

Frequency: continuous, for the duration of the Agreement.

Annex B: Technical and organizational measures

  • Encryption of data in transit (TLS) for all traffic between browsers, the application, and the database.
  • Encryption at rest for the production database and backups.
  • Row-level security in the database so learner records are only readable by authorized roles.
  • Role-based access control in the application (learner, tutor, administrator); least-privilege service credentials.
  • Authentication via a managed identity provider with email verification; optional Google single sign-on; no plaintext password storage.
  • Production access restricted to authorized personnel; secrets held in managed environment configuration, never in source control.
  • Automated daily backups with point-in-time recovery on the managed database service.
  • Logging and monitoring of authentication and application errors.
  • Vendor due diligence: subprocessors are established providers operating under their own security programs and data processing terms.
  • Personnel confidentiality obligations in contractor and employment agreements.

Annex C: Subprocessors

The following subprocessors are engaged as of the date of this DPA:

SubprocessorPurposeLocation
Supabase, Inc.Database, authentication, and file storageUnited States / European Union
Vercel Inc.Application hosting and content deliveryUnited States
Stripe, Inc.Payment processing and billingUnited States
Google LLCSign-in (OAuth) and analyticsUnited States
PostHog, Inc.Product analyticsUnited States / European Union
Resend, Inc.Transactional and notification emailUnited States
Anthropic, PBCAI-assisted lesson evaluation and content featuresUnited States