Data Processing Addendum
Effective October 6, 2026. Last updated October 6, 2026.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Quill Hound ("Processor", "we") and the customer ("Customer", "you") and applies when we process personal data on your behalf to provide Portal Hound. If anything here conflicts with the Terms, this DPA wins for personal data.
Need a signed copy? Email hello@portalhound.com with your company's legal name and the signer's name and title, and we'll send this DPA for countersignature. Healthcare customers can ask for our Business Associate Agreement the same way.
1. Roles
You are the controller (or "business") of the personal data in your Portal Hound deployment, and we are your processor (or "service provider"). We process it only on your documented instructions, which are these terms, your configuration of Portal Hound and your administrators' actions in it. If we think an instruction breaks the law, we'll tell you.
2. What we process
- People: your administrators and workers.
- Data: names, work emails, roles and status; device details (computer name, operating system and app version, connection public key, approval and check-in times); connection test results; the gateway access log (time, worker ID, tunnel address, destination site name and port, allowed or blocked, response size); the administrator activity record; approved portals. No page contents, form data or portal passwords: the gateway never decrypts traffic.
- Purpose: to run the gateway and control plane, sign users in, enforce your approved-portal list, keep the access record you review, and support you.
- Duration: for the term of your service, then until deletion under section 8.
We don't sell or share this data, use it for our own purposes, combine it with other data, or use it to train AI models. Where the CCPA applies, we're your service provider and comply with its restrictions.
3. Confidentiality
Only people who need access to provide or support the service have it, and they're bound to keep it confidential.
4. Security measures
- A dedicated gateway, sign-in pool and data store for each customer; nothing shared between customers.
- Encryption in transit (TLS and WireGuard) and encryption at rest for the AWS data stores.
- The gateway only reaches destinations you approve, can't route general traffic, and never decrypts.
- Individual credentials per worker, tied to one computer; administrator approval of every computer; instant revocation and emergency lockdown.
- Least-privilege access between components; secrets held in AWS Secrets Manager; administrator actions recorded.
- Point-in-time recovery for the control-plane database; documented recovery runbooks.
5. Subprocessors
You authorize the subprocessors on our subprocessor list. We have written terms with each that protect the data at least as well as this DPA, and we're responsible for their work. We'll update the list and email your account contact at least 30 days before adding or replacing a subprocessor; you can object on reasonable data-protection grounds, and if we can't resolve it you may end the affected service and get a refund of prepaid fees for the unused period.
6. Helping you
We'll help you answer requests from your workers to see, correct, delete or export their data, and with security reviews, data protection impact assessments and consultations with regulators, as reasonably needed. If a worker asks us directly, we'll pass the request to you.
7. Personal data breaches
We'll notify you without undue delay, and in any case within 72 hours, after we become aware of a breach affecting your personal data, with what we know about it, and we'll keep you updated and take reasonable steps to contain it.
8. Deletion and return
When your service ends, you can ask for an export of your data for 30 days. After that, or sooner if you ask (for example by deleting your account), we delete your deployment and the personal data in it within 30 days, except where the law requires us to keep something. Backups expire on their normal cycle.
9. Audits
We'll give you the information reasonably needed to show we meet this DPA, including answers to security questionnaires. If that isn't enough, or a regulator requires it, you may audit our compliance once a year on 30 days' notice, during business hours, at your cost, under confidentiality terms. We don't currently hold third-party certifications such as SOC 2 or ISO 27001.
10. Location and transfers
We host Portal Hound in the United States. If you transfer personal data to us from the EU, EEA, UK or Switzerland, the Standard Contractual Clauses adopted by the European Commission (Module 2, controller to processor, or Module 3 where you are a processor), with the UK Addendum or Swiss amendments where they apply, are incorporated by reference, with this DPA supplying the required details. Texas law governs this DPA except where the clauses require otherwise.
11. Your own AWS account
If Portal Hound runs in an AWS account you control, the data stays in your account, AWS is your provider rather than our subprocessor, and we process the data only when you give us access to support or update the deployment.
12. Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service.