1. Why this page exists
Organizations subject to the GDPR routinely need a written agreement under Article 28 with vendors that handle personal data on their behalf, and equivalent instruments exist under UK GDPR and several US state privacy laws. Procurement, security review and DPIA processes usually ask for one by name. Hilo does not publish a click-through agreement here, because the operative text — including how each party's role is characterised and which transfer mechanism applies — is a legal judgment our counsel makes, not one an engineering page should improvise.
2. What such an agreement can cover
It can only cover data we actually handle. That is a deliberately short list, and it is the same list the Privacy Policy publishes rather than a second copy that would drift away from it:
- The service records we durably store — account, organization and membership, connection and routing records, sessions and push tokens, billing and plan state, the agent-runtime waitlist, and short-lived operational metadata. Section 2 of the Privacy Policy is the authoritative list.
- What transits the gateway when you use the hosted workspace. TLS terminates at our gateway, so your requests and your node's responses are readable there for that instant. We do not store or content-log them. Section 3 of the Privacy Policy describes this.
- Notification payloads relayed in transit, described in Section 4 of the Privacy Policy.
It cannot cover your fleet's content at rest, because that content is never in our possession: it is on the machine you run, in your own storage, under your own backups. For that data you are the controller and there is no processor for us to be. The same is true of your model provider — your node calls it directly under your own keys and your own agreement with it, so that provider is your vendor and not our subprocessor.
3. Subprocessors
The current list of infrastructure providers, and what each one receives, is published in Section 7 of the Privacy Policy. It is maintained in that one place on purpose — a subprocessor list that appears twice is a list that will eventually disagree with itself. Where an executed agreement requires advance notice of a new subprocessor, the notice period and the notification address are set in that agreement.
4. How to request one
Write to contact@hilo.team with the subject "DPA request" and include:
- the full legal entity name and registered address of the contracting party;
- the name, role and email address of the person who will sign;
- the Hilo organization the agreement should cover;
- whether you require your own paper rather than ours, and if so, attach it;
- any transfer, audit or retention requirement your review process has already identified, so counsel can address it in one pass rather than three.
We will acknowledge the request and reply with the agreement and the execution route. Requests are handled by a small team; if a procurement deadline applies, say so in the first message.
5. Execution
The agreement is countersigned by Finis Ventures LLC. The signing mechanics, whether customer paper is accepted, and the transfer mechanism used for international transfers are settled with counsel at the time of the request rather than asserted here, because publishing a commitment we have not reviewed would be worse than publishing none. Nothing on this page varies the Terms of Service or the Privacy Policy; where an executed agreement and those documents differ on the handling of personal data, the executed agreement governs.
6. Contact
Finis Ventures LLC
30 N Gould St, Ste R, Sheridan, WY 82801, USA
contact@hilo.team