Skip to main content
Huntertech LogoHuntertech.io
Sign InStart free

Loading...

Legal

Data Processing Agreement

Effective date:July 05, 202671 days ago

About Huntertech.ioHome

Summary (Plain-English)

This Data Processing Agreement ("DPA") is between the customer entity that accepts it ("Customer") and Jonathan R. Hunter, an individual doing business as Huntertech.io ("Processor"). It applies when the Processor handles personal data on the Customer's behalf in connection with the Huntertech.io Services.

This DPA supplements the Huntertech.io Terms of Service and Privacy Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.

Execution. By referencing this DPA in an order form, enterprise agreement, or written acceptance, the Customer agrees to these terms. The Processor may provide a countersigned PDF on request using the signature block in Section 16. For procurement questions, .

1. Parties and definitions

Processor. Jonathan R. Hunter, an individual doing business as Huntertech.io ("Processor," "Huntertech," or "we" in this DPA).

Customer. The business entity or organization that accepts this DPA by order form, enterprise agreement, or written acceptance ("Customer" or "you").

Huntertech.io is operated by Jonathan R. Hunter, an individual doing business as Huntertech.io. In our agreements and policies, references to "Huntertech.io," "Huntertech," "we", "us", or "our", or similar terms mean the Service Provider, unless the context requires otherwise. The Service Provider is currently a sole proprietor and is not yet incorporated as a corporation or LLC. We plan to form a U.S. business entity and will offer enterprise customers a reasonable opportunity to assign or novate agreements to that entity when it is formed.

For vendor security questionnaires and enterprise procurement: Huntertech is operated today by a solo founder (Jonathan R. Hunter, d/b/a Huntertech.io), not a registered corporation. Subprocessors, security controls, and the published DPA reflect current operations. We disclose this status proactively and document our plan to migrate contracts when a formal entity is formed.

2. Roles and scope

Customer as controller. For personal data that the customer submits, uploads, or causes to be processed through the Services (including account profile fields, notification preferences, API configuration, and support content), the customer is the data controller and the Processor is the data processor.

Processor as controller. For the Processor's own account administration, billing, website analytics (where consented), and service operations, the Processor is the controller. Those activities are described in the Privacy Policy and Enterprise Trust Center, not this DPA.

Public vendor data. Huntertech ingests publicly published vendor status, incident, maintenance, advisory, and security data. That content is not customer confidential data and is not processed under this DPA as customer personal data unless the customer separately identifies it as such in writing.

3. Processing details

  • Subject matter: provision of vendor intelligence monitoring, notifications, API access, dashboards, and related account administration.
  • Duration: for the term of the customer's subscription or other Services agreement, plus any post-termination period described in Section 10.
  • Nature and purpose: storage, retrieval, transformation, display, alerting, and API delivery solely to provide the subscribed Services.
  • Categories of data subjects: customer personnel and authorized users whose data the customer submits to the Services.
  • Types of personal data: names, business contact details, account credentials metadata, notification configuration, API key metadata, usage metrics, and support communications the customer provides.

4. Customer instructions

The Processor will process Customer personal data only on documented instructions from the Customer, including as necessary to provide the Services, maintain security, comply with applicable law, or as otherwise set out in this DPA and the Terms of Service.

The customer is responsible for the lawfulness of its instructions and for providing any required notices and obtaining any required consents from data subjects.

5. Confidentiality

The Processor ensures that personnel authorized to process Customer personal data are bound by confidentiality obligations appropriate to the nature of the Services.

6. Security measures

The Processor implements commercially reasonable technical and organizational measures designed to protect Customer personal data. Measures vary by feature surface; not every control applies to every data category processed under this DPA.

Platform and API

  • encryption in transit (TLS) for data exchanged with the Services;
  • access controls limiting administrative access to production systems;
  • account authentication through our managed identity provider, plus scoped API keys for programmatic access;
  • SHA-256 hashing of API key secrets at rest (only a non-secret key prefix is retained for display);
  • rate limiting and usage monitoring intended to reduce abuse of the API and web application;
  • CSRF protections on mutating browser requests that use authenticated sessions;
  • self-service permanent account deletion from Subscription settings, which removes associated application data where applicable.

Community, coordination, and messaging

Huntertech.io includes optional member community features (groups, incident watch rooms, and Connect-gated direct messages). These surfaces apply additional access controls on top of the platform measures above:

  • Private incident watch rooms. Team-scoped rooms for a specific vendor incident are tied to a private group. Only group members can read or post; access is granted through group membership and revocable invite links, not public watchlist visibility alone.
  • Public incident watch rooms. Public coordination rooms remain server-readable so the Processor can enforce watchlist rules, archive read-only state, and apply moderation. They are separate from private team rooms.
  • Connect-gated direct messages. One-to-one member messaging is limited to mutually accepted connections and is subject to send-rate limits and reporting flows.
  • End-to-end encrypted direct messages. When encryption is enabled for a deployment, Connect-gated direct messages use client-side Signal Protocol via our browser implementation (PQXDH (Post-Quantum Extended Diffie-Hellman) for initial session setup, then Double Ratchet with authenticated encryption for message payloads derived from the combined PQXDH shared secret). For each enrolled member, the Processor registers and relays public key material only:
    • long-term identity key (Curve25519 / X25519)
    • signed prekey (Curve25519 / X25519, signed by the identity key)
    • one-time prekeys (Curve25519 / X25519)
    • Kyber1024 (CRYSTALS-Kyber-1024) prekey for post-quantum key encapsulation

    Kyber1024 adds a post-quantum key encapsulation layer to session setup. PQXDH derives message keys only when both the classical X25519 agreement and the Kyber1024 encapsulation succeed, which helps mitigate harvest-now-decrypt-later risk if large-scale quantum adversaries later weaken elliptic-curve assumptions.

    Private keys, session state, and decrypted plaintext stay on member devices (browser IndexedDB). The Processor stores and relays public prekey bundles and ciphertext blobs only; it cannot decrypt enrolled direct message bodies.

  • Private watch room message encryption (roadmap). Private incident watch room user messages are planned to reuse the same member encryption identities, with per-room keys distributed as ciphertext wrapped through pairwise PQXDH sessions. Until that capability is generally available, user messages in private team rooms may be stored in a form the Processor can read to deliver the service, while room access remains restricted to group members as described above.

Additional security documentation may be shared under NDA as part of enterprise procurement. No security measure guarantees absolute protection. See the Privacy Policy for related disclaimers.

7. Subprocessors

The Customer authorizes the Processor to engage subprocessors to support the Services. Current subprocessors that may process personal data are listed on the Enterprise Trust Center, including:

  • Supabase: Authentication, account identity, and managed Postgres for application data
  • Stripe: Subscription billing and payment processing
  • Cloudflare: CDN, DDoS protection, and edge delivery for the public site and API
  • Mailjet (Sinch Email): Transactional email for account and notification delivery
  • Google Analytics: Aggregated website usage measurement when cookies are accepted

The Processor will update the Enterprise Trust Center when subprocessors change. For Customers with an executed copy of this DPA, the Processor will provide reasonable advance notice before engaging a new subprocessor that processes Customer personal data, and will offer an objection process consistent with applicable data protection law and the executed agreement.

8. Data subject requests

Where legally required, the Processor will assist the Customer in responding to data subject requests to access, correct, delete, or restrict processing of Customer personal data processed on the Customer's behalf, taking into account the nature of the processing and information available to the Processor. The Customer should route verified requests through Huntertech support channels or the customer's designated enterprise contact. End users may also delete their own accounts through Subscription settings where applicable.

9. Personal data breach

The Processor will notify the Customer without undue delay after confirming a personal data breach affecting Customer personal data processed under this DPA, and will provide information reasonably available to help the Customer meet its regulatory obligations. Notification may be delayed where required by law enforcement or where the Processor reasonably determines notification would increase risk to affected systems.

10. Deletion and return

Upon termination or expiry of the Services, the Processor will delete or return Customer personal data processed on the Customer's behalf within a reasonable period, unless retention is required by applicable law or the Customer requests an export window in writing before deletion.

Account deletion initiated by an authorized user removes associated application records, API keys, and authentication identity as described in the Enterprise Trust Center.

11. Audits

Upon reasonable written request and subject to confidentiality, the Processor will make available information necessary to demonstrate compliance with this DPA, which may include responses to security questionnaires or summary audit materials under NDA. Onsite audits are available only by mutual written agreement and may be subject to reasonable fees and scheduling constraints.

12. International transfers

Customer personal data may be processed in the United States and in other countries where the Processor or its subprocessors operate. Where required by applicable law, the Processor will make appropriate transfer mechanisms available as part of the executed enterprise agreement.

13. Liability and order of precedence

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the Terms of Service regarding processing of customer personal data, this DPA controls. If there is a conflict between this DPA and a separately executed enterprise order form signed by both parties, the signed order form controls.

14. Governing law

This DPA is governed by the same governing law and dispute resolution provisions as the Terms of Service, unless a signed enterprise order form specifies otherwise.

15. Successor entity

If the Processor forms a corporation, LLC, or other business entity and assigns this DPA to that entity, the Processor will notify the Customer in writing and offer a reasonable opportunity to review updated contracting-party information. Continued use of the Services after notice, or execution of an assignment or novation document, constitutes acceptance of the successor entity as Processor unless the parties agree otherwise in writing.

16. Execution and signatures

Countersigned copies of this DPA use the signature blocks below. The Processor signs as an individual doing business as Huntertech.io, not as a corporation.

SERVICE PROVIDER (Processor):

Jonathan R. Hunter, d/b/a Huntertech.io

By: _________________________________
Name: Jonathan R. Hunter
Title: Sole proprietor / Founder
Date: _________________________________
CUSTOMER:

Entity name: _________________________________

By: _________________________________
Name: _________________________________
Title: _________________________________
Date: _________________________________

Related documents

  • Enterprise Trust Center (subprocessors, retention, operational controls)
  • This DPA (canonical URL for procurement references)
  • (countersigned DPA and security exhibits)
Review our legal documents: Terms of Service, Privacy Policy, Cookie Policy, Disclaimer, Security Policy, Community Guidelines, Enterprise Trust. Back to home.
Huntertech Logo
© 2026 Huntertech.io. All rights reserved.

Unified vendor incidents, maintenance, updates, and security intelligence for infrastructure teams.

Follow on LinkedInRate us on G2Powered by Huntertech

Product

  • Use Cases
  • Supply Chain
  • Pricing
  • Compare
  • Vendors
  • News
  • Developer
  • Status

Vendor Intelligence

  • Vendor Catalog
  • Security Vendors
  • Cloud Providers
  • Status Pages
  • Achievements

Tools

  • All Tools
  • Security Tools
  • Network Tools
  • Vulnerability Leaderboard

Account

  • Sign Up
  • Sign In
  • Dashboard
  • Account
  • Subscription
  • Share feedback

Legal

  • Disclaimer
  • Terms of Service
  • Privacy Policy
  • Enterprise Trust
  • Cookie Policy