Data Processing Addendum (DPA)
This DPA forms part of the Hooshi Terms of Service between the customer (“Controller”) and Intelligent Energy Solutions LLC (“Processor”, “Hooshi”) and governs the processing of personal data carried out by Hooshi on the Controller’s behalf under Article 28 GDPR. Where the Controller acts as a processor for its own end users, this DPA applies on a back-to-back basis.
1. Subject matter and duration
Hooshi processes personal data only to provide the voice-dictation service: capturing audio you dictate, transcribing it, cleaning up the text, and returning it to your device, plus operating accounts, subscriptions, and support. Processing lasts for the term of your subscription and any limited retention described below.
2. Nature and purpose of processing
Speech-to-text transcription, text punctuation/formatting (“polish”), account authentication, subscription and payment status, usage statistics, and customer support.
3. Categories of data subjects and personal data
Data subjects: the Controller’s users of the app. Personal data: account email, authentication tokens, subscription/payment status (card details are handled solely by the payment provider, never stored by Hooshi), dictation audio transiently processed for transcription, resulting transcribed text, usage metrics (dictation counts, minutes, character counts), and support messages.
4. Audio and transcript retention
Dictation audio is processed transiently for transcription and is not retained for long-term storage. Transcribed text is returned to the user’s device and not stored server-side beyond what is technically necessary to complete the request. Usage metrics are aggregate counters attributed to an account.
5. Controller instructions
Hooshi processes personal data only on documented instructions from the Controller, including this DPA and use of the product’s features, unless required by applicable law (in which case Hooshi will inform the Controller unless legally prohibited).
6. Confidentiality
Personnel authorised to process personal data are bound by confidentiality.
7. Security measures (Article 32)
TLS in transit, bearer-token authentication and server-side entitlement checks, per-token/IP rate limiting, least-privilege hardened services, encrypted off-site backups of the account database, secret hygiene controls, and access limited to named operators.
8. Sub-processors
The Controller authorises Hooshi to engage the sub-processors listed at hooshi.tech/subprocessors. Hooshi imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance. Hooshi will give notice of intended changes and allow objection.
9. International transfers
Where personal data is transferred outside the EEA/UK, Hooshi relies on an adequacy decision or the EU Standard Contractual Clauses (and UK Addendum) with appropriate supplementary measures.
10. Data subject rights and assistance
Taking into account the nature of processing, Hooshi assists the Controller with appropriate measures to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection) and with obligations under Articles 32–36.
11. Personal data breach
Hooshi notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, with information reasonably available.
12. Deletion or return
On termination, Hooshi deletes or returns personal data at the Controller’s choice, save where storage is required by law.
13. Audits
Hooshi makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, on reasonable notice and subject to confidentiality.
Contact
Data-protection contact: support@hooshi.tech, in-app Support, or Intelligent Energy Solutions LLC, Batumi, Georgia.