Last updated 12 September 2026
Data processing agreement
This agreement is required by Article 28 of the GDPR and forms part of the terms of service. It applies whenever we process personal data on your behalf — which is to say, whenever you use HutAssets.
Which of us is which
You are the controller. You decide what is kept in HutAssets about your customers, their people and their equipment, why it is kept, and for how long. You are responsible for having a lawful basis for it and for telling those people what you hold.
We are the processor: SC HUT IT SOLUTIONS SRL, Strada Sfântul Apostol Andrei 117, Oradea 410333, Bihor, Romania; trade register J05/767/2022; tax identification number RO45848567 (“Hut IT Solutions”, “we”). We hold and protect that data, act only on your documented instructions, and use it for nothing else.
This is the reverse of the public website, where we are the controller of our own visitor data. The privacy notice describes that half.
What is processed, and about whom
Subject matter: providing the HutAssets service. Duration: as long as your account is open, plus the deletion periods below. Nature and purpose: storing, organising, retrieving, exporting and deleting the records you create.
Categories of data subject:
- Your own staff, who have accounts and sign in.
- Your customers' staff, where you record them as contacts, custodians of equipment, or people on an attendance register.
- Anybody named in a ticket, a note, a document you upload, or an audit entry.
Categories of personal data:
- Identity and contact details: name, work e-mail, telephone and extension, mobile, Teams number, job title, department, location, employee number, domain username.
- Employment facts you choose to record: hire and termination dates, attendance and leave entries, time recorded against work.
- Activity: sign-in times, what was created, changed, read or deleted and by whom, including every reveal of a stored secret.
- Anything free-form you put in notes, tickets or uploaded documents, whose content is your choice and not ours.
Special-category data under Article 9 is outside the scope of this agreement. The application is not built for it and must not be used to hold it.
Our instructions come from you
We process your data only on your documented instructions, which are: these terms, this agreement, the configuration you choose in the application, and anything you ask us in writing. We will tell you if we think an instruction breaks data-protection law, and we may decline it.
Where the law requires us to process your data for some other reason, we will tell you before doing so unless that same law forbids telling you.
Who else touches it
You give general authorisation for the sub-processors below. We will give you at least 30 days' notice before adding or replacing one. If you object on reasonable data-protection grounds within those 30 days, we will discuss it, and if it cannot be resolved you may end the agreement without penalty for the remainder of the period.
| Sub-processor | What they do | Where | Transfer basis |
|---|---|---|---|
| Hetzner Online GmbH | The server. All application data and uploaded documents live here. | Germany | Inside the EEA; no transfer. |
| Resend (Plus Five Five, Inc.) | Sends notification and account e-mail on our behalf. Receives the recipient's address and the content of the message. | United States | Standard Contractual Clauses, plus the EU–US Data Privacy Framework where the recipient is certified. |
We impose the same obligations on each sub-processor as this agreement imposes on us, and we remain fully liable to you for what they do.
No analytics of any kind runs inside the application. Google Analytics exists only on the public website, where nothing of yours is present.
How it is protected
The measures required by Article 32, as actually implemented:
- In transit: TLS everywhere, with certificates renewed automatically. Session tokens are held in cookies the browser's own scripts cannot read.
- At rest: stored secrets — passwords, keys, Wi-Fi codes, PINs — are encrypted with AES-256-GCM, each one bound cryptographically to the record it belongs to, so a value copied to another record or another business will not open. Passwords are hashed with bcrypt and are not recoverable by anyone, us included.
- Between businesses: every table carrying tenant data is fenced by PostgreSQL row-level security, enforced by the database rather than only by the application, and the application connects as a role that those policies apply to.
- Access: roles and per-field access profiles decide what each person sees. A second factor can be required of everybody or of the privileged roles. Sign-in is rate-limited per account and per address; reading stored secrets is rate-limited per person, capped per day, and the business's owners are notified while an unusual number is being read.
- Accountability: an append-only audit trail records who read or changed what, including every reveal of a stored secret. The role used for backups can read everything and write nothing, so a compromise of the application cannot erase that trail.
- Recoverability: nightly backup of the database and uploaded documents, with a copy held away from the server, kept 14 days, and a weekly automated rehearsal that restores the newest backup and verifies what came back.
- Deletion: records deleted in the application are recoverable for a retention period you set — 30 days unless you change it — and are then purged.
Two limitations we would rather you heard from us. The service runs on a single server, so a hardware failure means downtime and a restore rather than a transparent failover. And the key that encrypts stored secrets currently lives on the same machine as the data it protects; moving it to separate custody is planned and is not done.
If something goes wrong
We will tell you without undue delay, and in any event within 48 hours of becoming aware of a personal-data breach affecting your data. We will tell you what happened, which categories of data and roughly how many people are affected, what the likely consequences are, what we are doing, and what we do not yet know — rather than waiting until the picture is complete.
Notifying a supervisory authority, and the people affected, is yours to do as controller. We will give you everything you need to do it, and we will help.
When somebody exercises their rights
Most of it you can do yourself: the application lets you find, correct, export and delete a person's records without us. Where you need more, we will help you meet a request for access, correction, erasure, restriction, portability or objection within the time the GDPR gives you, at no extra charge.
If such a request reaches us directly, we will not answer it ourselves. We will pass it to you, because you are the controller and only you know the context.
People, audits and records
- Everybody with access to your data is bound by confidentiality that survives their leaving, and access is given on need rather than by default.
- We keep the records of processing Article 30(2) requires and will make them available to you on request.
- We will give you the information you need to show compliance, and allow an audit or inspection by you or an auditor you appoint, once a year and on reasonable notice — or more often after a breach.
At the end
When the service ends, you choose: we return your data or we delete it. Unless you tell us otherwise, it stays available for you to export for 30 days, and is then deleted from the live system. It leaves the backups as those age out, within 14 days. We will confirm deletion in writing when you ask.
The exception is anything the law requires us to keep, which we will name if it ever applies.
Signing it, and asking about it
This agreement applies from the moment you start using HutAssets, whether or not a copy has been signed. If your procurement needs a signed counterpart — and public-sector buyers generally do — write to support@hutassets.com and we will send one, including as a countersigned copy of your own template where you have one.