Trust Center

Data Processing Agreement

Effective Date: June 2026 · Version 1.0

This Data Processing Agreement ("DPA") forms part of the RequirementsHub Terms of Service (available at requirementshub.ai/terms) and applies where RequirementsHub processes Personal Data on behalf of a Customer in connection with the RequirementsHub platform ("Services"). By using the Services, Customer agrees to this DPA.

1. Definitions

"Controller" means the entity that determines the purposes and means of processing Personal Data. In the context of this DPA, Customer is the Controller.

"Processor" means the entity that processes Personal Data on behalf of the Controller. In the context of this DPA, RequirementsHub is the Processor.

"Personal Data" means any information relating to an identified or identifiable natural person that is submitted to the Services by or on behalf of Customer.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.

"Subprocessor" means any third-party processor engaged by RequirementsHub to process Personal Data in connection with the Services. The current Subprocessor List is maintained at requirementshub.ai/trust/subprocessors.

"Data Protection Laws" means all applicable data protection and privacy legislation, including the EU General Data Protection Regulation (GDPR) (Regulation 2016/679), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and any other applicable national or state privacy laws.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Decision 2021/914.

"Restricted Transfer" means a transfer of Personal Data from the European Economic Area or United Kingdom to a country not recognized as providing an adequate level of data protection.

2. Roles and Relationship

2.1 The parties acknowledge that with respect to Personal Data processed through the Services:

  • Customer is the Controller of Personal Data relating to Customer's end users, workspace members, and project content.
  • RequirementsHub is the Processor, processing such Personal Data only on Customer's behalf and in accordance with Customer's instructions as expressed through use of the Services and this DPA.

2.2 Each party shall comply with its respective obligations under applicable Data Protection Laws in performing its role under this DPA.

2.3 RequirementsHub also processes certain Personal Data as a Controller in its own right (e.g., account registration data, billing records, support communications). Such processing is governed by the RequirementsHub Privacy Policy at requirementshub.ai/trust/privacy.

3. Processing Details

3.1 Subject matter: The provision of the RequirementsHub collaborative requirements workspace platform, including requirements analysis, intelligence scoring, collaboration features, and artifact generation.

3.2 Duration: For the term of Customer's subscription and for as long as RequirementsHub retains Personal Data in accordance with its data retention obligations under this DPA.

3.3 Nature and purpose of processing: Storage, retrieval, analysis (including AI-assisted analysis), display, and deletion of Customer project content and workspace member data as directed by Customer through use of the Services.

3.4 Categories of data subjects: Customer's workspace members, invited collaborators, and any individuals whose data is contained in project content uploaded by Customer.

3.5 Categories of Personal Data:

  • Identity and contact data: name, email address, job title (workspace members)
  • Account data: workspace configuration, role assignments, activity logs
  • Project content: requirements, documents, decisions, stakeholder information, and any other content submitted by Customer — which may incidentally contain personal data at Customer's discretion
  • Usage data: feature usage, timestamps, session metadata

3.6 Sensitive data: The Services are not designed or intended for the processing of special categories of personal data (GDPR Article 9), protected health information (HIPAA), or payment card data. Customer shall not submit such data to the Services.

4. Customer Instructions

4.1 RequirementsHub shall process Personal Data only on documented instructions from Customer, including as set out in this DPA and the Terms of Service, or as required by applicable law.

4.2 Customer's use of the Services — including configuration of workspaces, inviting members, submitting project content, and initiating AI analysis — constitutes Customer's primary documented instruction for processing.

4.3 If RequirementsHub is required by applicable law to process Personal Data other than as instructed by Customer, RequirementsHub shall notify Customer before such processing unless prohibited by law.

4.4 If RequirementsHub reasonably believes an instruction from Customer violates applicable Data Protection Laws, RequirementsHub shall promptly inform Customer.

5. Subprocessors

5.1 Authorization: Customer provides general authorization for RequirementsHub to engage Subprocessors to assist in providing the Services, subject to the conditions in this Section 5.

5.2 Current Subprocessors: The current list of Subprocessors is maintained and publicly available at requirementshub.ai/trust/subprocessors.

5.3 Change notice: RequirementsHub shall provide at least 30 days' prior notice before engaging a new Subprocessor or making material changes to an existing Subprocessor's role, by updating the Subprocessor List page and notifying workspace owners of active Pro and Enterprise subscriptions by email. Customers who subscribe to subprocessor change notifications at security@requirementshub.ai will receive direct email notice.

5.4 Objection: If Customer has a reasonable, documented objection to a new or changed Subprocessor on data protection grounds, Customer shall notify RequirementsHub in writing within 14 days of the change notice. The parties will work in good faith to resolve the objection. If the parties cannot reach a resolution, Customer may terminate the affected Services on written notice, without penalty, before the new Subprocessor begins processing Customer Data.

5.5 Subprocessor obligations: RequirementsHub shall impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and shall remain liable to Customer for the performance of Subprocessors' obligations.

6. Security Measures

6.1 RequirementsHub shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, or damage, including:

MeasureImplementation
Encryption in transitTLS 1.3 for all data in transit between client and platform
Encryption at restAES-256 encryption at the database and storage layer, managed by Supabase (AWS infrastructure)
Access controlRole-based access control within workspaces (owner, editor, viewer); row-level security enforced at the database layer; principle of least privilege for internal staff access
AuthenticationPasswordless authentication via magic link (email-verified); password-based authentication and MFA are on the development roadmap
IsolationLogical tenant isolation via row-level security; workspace data is not accessible across tenant boundaries
Subprocessor securityAI processing subprocessors (Anthropic, OpenAI, Google via Lovable AI Gateway) operate under API terms prohibiting use of submitted data for model training
Incident responseDefined incident response process with customer notification commitments — see requirementshub.ai/trust/incident-response

6.2 RequirementsHub will review and update its security measures periodically and, in any case, in response to material changes to the threat environment.

6.3 RequirementsHub does not guarantee that its security measures will be breach-proof. Customer is responsible for implementing appropriate security measures on its own systems and for ensuring that workspace members use the Services in accordance with the Acceptable Use Policy at requirementshub.ai/trust/acceptable-use.

7. Data Subject Rights

7.1 RequirementsHub shall provide Customer with reasonable assistance, through the technical features of the Services, to enable Customer to fulfill its obligations to respond to data subject rights requests under applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).

7.2 Self-service data controls available to workspace owners at requirementshub.ai/account/data include: full data export (JSON) and account deletion.

7.3 If RequirementsHub receives a data subject rights request directly relating to Customer's data, RequirementsHub shall promptly forward the request to Customer and shall not respond to the data subject directly without Customer's instruction, except as required by law.

8. Incident Notification

8.1 RequirementsHub shall notify Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach that is likely to result in a risk to the rights and freedoms of natural persons.

8.2 Notification shall be made to the email address associated with the workspace owner account and, where applicable, posted to the status page at status.requirementshub.ai.

8.3 The initial notification will include, to the extent then known: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach.

8.4 RequirementsHub acknowledges that Customer, as Controller, may have independent notification obligations to supervisory authorities and data subjects. RequirementsHub shall cooperate with Customer and provide supplementary information necessary for Customer to meet those obligations.

9. Data Transfers

9.1 Personal Data is stored at rest on Supabase infrastructure in the United States (AWS us-east-1). Processing may also occur in the United States through RequirementsHub's AI and infrastructure Subprocessors.

9.2 For customers located in the European Economic Area (EEA) or United Kingdom, such transfers to the United States constitute Restricted Transfers and are governed by the Standard Contractual Clauses set out in Annex A to this DPA.

9.3 RequirementsHub will not transfer Personal Data to any country or territory that does not provide an adequate level of data protection, except in accordance with a lawful transfer mechanism.

9.4 RequirementsHub relies on its Subprocessors' own transfer mechanisms for onward transfers. Details are available in each Subprocessor's documentation as linked in the Subprocessor List.

10. Audit and Cooperation

10.1 RequirementsHub shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including this DPA, the Subprocessor List, and any relevant security certifications.

10.2 RequirementsHub shall permit Customer (or a qualified third-party auditor appointed by Customer and subject to reasonable confidentiality obligations) to conduct audits or inspections of RequirementsHub's data processing activities under this DPA, subject to the following conditions:

  • Customer shall provide at least 30 days' written notice
  • Audits shall be conducted during normal business hours, no more than once per calendar year (except where a confirmed breach requires otherwise), and in a manner that minimizes disruption to RequirementsHub's operations
  • Customer shall bear the cost of any third-party auditor
  • Audit reports are confidential and subject to mutual NDA

10.3 RequirementsHub may satisfy audit requests, in whole or in part, by providing relevant third-party audit reports (e.g., SOC 2 reports from Supabase or Cloudflare) or completed security questionnaire responses.

11. Return and Deletion of Data

11.1 On termination or expiry of Customer's subscription, RequirementsHub shall, at Customer's election:

  • Make Customer's Personal Data available for export via the self-service data export function (requirementshub.ai/account/data) for a period of 30 days following termination; or
  • Delete Customer's Personal Data upon written request to privacy@requirementshub.ai

11.2 Following the 30-day post-termination window, RequirementsHub shall delete Customer's Personal Data from active systems within 30 days, unless retention is required by law.

11.3 Deletion from encrypted backup systems will occur as backup cycles expire, within a maximum of 90 days from the deletion of the primary data.

11.4 RequirementsHub shall provide written confirmation of deletion upon Customer's request.

12. Liability and Indemnification

12.1 Each party's liability under this DPA is subject to the limitations set out in the RequirementsHub Terms of Service.

12.2 In the event of a claim by a data subject, the parties shall cooperate in good faith to determine the appropriate allocation of responsibility. Each party shall indemnify the other against claims, fines, and penalties arising from that party's own failure to comply with its obligations under applicable Data Protection Laws.

13. Term and Termination

13.1 This DPA is effective on the date Customer first accepts the Terms of Service and continues for the duration of the Customer's use of the Services.

13.2 Termination of the Terms of Service automatically terminates this DPA, subject to obligations that survive termination (including Sections 11 and 9).

14. Order of Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.

15. Governing Law

This DPA is governed by the same law as the Terms of Service, except that the Standard Contractual Clauses (Annex A) shall be governed by the law of the EU Member State in which the EU data protection supervisory authority is located, or as otherwise required by the SCCs.

Annex A — Standard Contractual Clauses (EEA/UK Transfers)

Module Two applies: Transfer from Controller (Customer) to Processor (RequirementsHub)

Clause 1 — Purpose and Scope

These Standard Contractual Clauses implement Regulation (EU) 2016/679 for the transfer of personal data to a third country. They apply to the transfer of Personal Data as described in the DPA above from Customers in the EEA or UK (data exporter) to RequirementsHub in the United States (data importer).

Data Exporter: Customer, as identified by their RequirementsHub account registration.

Data Importer: RequirementsHub, Inc., reachable at privacy@requirementshub.ai

Clause 2 — Effect and Invariability

These SCCs set out appropriate safeguards for the purposes of Article 46(1) and Article 46(2)(c) GDPR. They shall not be modified except to select applicable modules or to add supplementary measures, provided such measures do not contradict these SCCs.

Clause 3 — Third-Party Beneficiaries

Data subjects may invoke these SCCs against the data exporter and data importer as third-party beneficiaries where their rights have been infringed.

Clause 4 — Interpretation

Where these SCCs use terms defined in GDPR, those terms shall have the same meaning. These SCCs shall be read and interpreted in light of GDPR.

Clause 5 — Hierarchy

In the event of a conflict between these SCCs and the provisions of related agreements, these SCCs shall prevail.

Clause 6 — Description of Transfer

ElementDetail
Categories of data subjectsWorkspace members, invited collaborators, and individuals whose data appears in Customer project content
Categories of personal dataIdentity/contact data, account data, project content, usage data — as described in DPA Section 3.5
Sensitive dataNone — Customer is prohibited from submitting special category data
Frequency of transferContinuous (on use of the Services)
Nature of processingStorage, analysis, display, deletion
Purpose of transferProvision of the RequirementsHub platform
Retention periodPer DPA Section 11
SubprocessorsPer requirementshub.ai/trust/subprocessors

Clause 7 — Docking Clause

An entity may accede to these SCCs as a data exporter or data importer by executing a separate addendum referencing this DPA and these SCCs.

Clause 8 — Data Protection Safeguards

The data importer shall comply with the obligations described in Sections 4–11 of this DPA. Customer (data exporter) warrants that it has a lawful basis for the transfer and that the data it submits is accurate and limited to what is necessary.

Clause 9 — Subprocessors

The data importer has general authorization from Customer (data exporter) to engage Subprocessors per DPA Section 5. Subprocessors are listed at requirementshub.ai/trust/subprocessors. The data importer shall inform the data exporter of any intended changes at least 30 days in advance.

Clause 10 — Data Subject Rights

The data importer shall assist the data exporter in meeting its obligations to data subjects per DPA Section 7.

Clause 11 — Redress

Data subjects may lodge a complaint with a supervisory authority or seek judicial remedy against the data exporter (Customer) in their country of residence.

Clause 12 — Liability

Each party is liable for damage caused by its own breach of these SCCs. The parties are jointly and severally liable for breaches caused by both parties.

Clause 13 — Supervision

The supervisory authority of the EU Member State in which the data exporter is established shall act as the competent supervisory authority.

Clause 14 — Local Laws

The data importer warrants that it has no reason to believe that applicable US laws prevent it from fulfilling its obligations under these SCCs. If the data importer becomes aware of a change in law that would materially affect these SCCs, it shall notify the data exporter promptly.

Clause 15 — Obligations of the Data Importer in Case of Government Access

The data importer shall notify the data exporter of any legally binding request for disclosure of personal data by a public authority, to the extent permitted by law. The data importer shall challenge overbroad or unlawful requests.

Clause 16 — Non-Compliance and Termination

If the data importer is in material breach of these SCCs, the data exporter may suspend transfers and terminate the relevant portions of this DPA.

Clause 17 — Governing Law

These SCCs shall be governed by the law of the Republic of Ireland, as the primary EEA jurisdiction for US-based processors serving EEA data exporters.

Clause 18 — Choice of Forum

Any dispute arising under these SCCs shall be resolved by the courts of the Republic of Ireland.

Annex B — Technical and Organizational Security Measures

This Annex is incorporated into and forms part of the DPA.

CategoryMeasures in Place
Pseudonymization and encryptionAES-256 encryption at rest (Supabase/AWS); TLS 1.3 in transit; authentication credentials are not stored — magic link authentication eliminates stored password risk entirely
ConfidentialityLogical tenant isolation via row-level security; workspace role-based access control (owner, editor, viewer); least-privilege internal access
IntegrityDatabase constraints and application-layer validation; audit logging of workspace actions
Availability and resilienceSupabase managed database with automated backups; Cloudflare edge routing with DDoS mitigation
RestorationSupabase point-in-time recovery; backup restoration tested periodically
EvaluationSecurity measures reviewed on material changes to architecture or threat environment; SOC 2 compliance in evaluation
Subprocessor managementSubprocessors evaluated for security posture before engagement; contractual data protection obligations imposed

Privacy & data inquiries: privacy@requirementshub.ai

Legal & agreement requests: legal@requirementshub.ai

Last updated: June 2026