Data processing agreement
Last updated: 12 September 2026
If your app holds personal data about your own customers, European and UK data protection law expects a written agreement between you and whoever hosts it. This is that agreement. You do not need to sign anything or ask us for a copy — it applies automatically from the moment you use Hatchik, and this page is the whole of it.
1. Who is who
You are the controller. You decide what personal data your app collects, why, and for how long. The people whose data it is are your customers, your users or your members — not ours.
Hatchik is the processor. We hold and serve that data on your instructions so that your app runs. We are Namaa Solutions SPC, registered at Al Ghushbah, Sohar, North Al Batinah Governorate, Sultanate of Oman, Commercial Registration 1594367.
Separately from this agreement, Hatchik is the controller of the small amount of data we hold about you as our customer — your sign-in email, your projects, your billing record. The privacy policy covers that. This page is only about the data inside your app.
2. What this covers, and for how long
This agreement covers the personal data your app stores on Hatchik: whatever is in its database, its uploaded files and its logs. The subject matter is hosting; the nature and purpose of the processing is storing, serving, backing up and transmitting that data so your app works. The categories of data and of people are whatever you choose to put in — we do not inspect it, so we cannot narrow that for you.
It starts when you first deploy something to Hatchik and ends when you delete the project or close your account. It also ends if you stop paying and the project is eventually removed; the terms set out the warnings and the wait before that happens.
3. We act on your instructions
We process the personal data in your app only to provide the service, and only as you instruct. Your instructions are the things you do: creating a project, deploying code, publishing a draft, restoring an earlier version, exporting, deleting. Asking your AI tool to do one of those counts as you instructing us, because the connector acts with your authority and nothing else.
We do not use your app's data for our own purposes. In particular we do not sell it, share it for advertising, use it to train any AI model, publish it, or show it to anyone else as an example or a template.
Three honest exceptions, and they are the only ones.
- We will process your data differently from your instructions where a law that applies to us requires it — and, unless that law forbids us from saying so, we will tell you first.
- Our automated abuse check reads the files of a site at the moment it is published, looking for phishing and malware. It is a machine, it does not read your database, and no person looks at what it scans unless it flags something.
- Once a night an automated count asks your app's database how many sign-ups it holds that are not yours, and asks the same of your contact-form enquiries. Only the number comes back — the question is answered inside your database and no row, name or address leaves it. It tells us whether the projects on Hatchik are being used by anybody, which is the only measure we have of whether this service is worth running. It is never used to decide anything about your account, and it is not shown to anyone outside Hatchik.
4. Confidentiality
Hatchik is run by one person, and that person is the only human with access to the infrastructure. Access is used to operate and repair the service, not to browse customer data. There is no support desk, and nobody at Hatchik opens a customer's database to answer a question — there is nobody to ask. Anyone we ever give access to would be under a written duty of confidentiality first.
5. Security
These are the measures actually in place. We have deliberately not listed anything aspirational.
- Encryption in transit. HTTPS everywhere — the dashboard, the connector, and every site and app we serve. Certificates are issued and renewed automatically.
- Separation between projects. Each project runs in its own container with its own database. One project cannot reach another's data.
- The database is not on the internet. Your app's Postgres has no public address and its port is closed at the firewall. It is reachable only by your own app.
- Secrets are encrypted at rest. The environment values you store for your app — API keys, passwords, anything you mark as a setting — are encrypted in our database. Access tokens and deploy keys are stored only as irreversible hashes and cannot be read back.
- Nothing goes live by accident. Every project has a locked draft and a live version. Publishing is a separate, deliberate step, and the last ten published versions are kept so a change can be undone.
- Encrypted backups. Everything is backed up nightly into an encrypted store, and a separate daily check confirms a copy exists somewhere other than the machine itself and raises an alarm if the newest such copy is more than 36 hours old.
- Access control. Sign-in is Google OAuth; we never see or hold your password. Connector access is scoped to your own account and projects and can be revoked instantly.
What we do not have, stated plainly so you are not surprised later: Hatchik has no SOC 2 report, no ISO 27001 certificate, no penetration test, and no appointed data protection officer. If your own compliance requires any of those, Hatchik is not the right host for you yet.
6. The other companies we use
We cannot run the service without these six, and you are agreeing to them by using Hatchik. Each one is bound by its own data protection terms with us.
| Company | What it does | Where |
|---|---|---|
| Hetzner | The servers your projects actually run on, and their databases | Germany (EU) |
| Backblaze | The off-site copy of the nightly encrypted backup | United States |
| Cloudflare | DNS for Hatchik addresses and custom domains | Global |
| Let's Encrypt | Issues the HTTPS certificates for your domains | United States |
| Sign-in only. Google never sees your app's data | Global | |
| Resend | Sends Hatchik's own emails to you. Not your app's email | United States |
Paddle handles payment for Hatchik's own subscriptions. Paddle is the merchant of record and is a controller in its own right for that, not our processor — it never touches your app's data.
If this list changes we will update this page and email the address on your account at least 30 days before the new company starts handling anything. If you object, you can export everything and close your account before the change takes effect. We do not have a mechanism for keeping one customer on the old arrangement, and it would be dishonest to pretend otherwise.
7. Where your data is
Your app and its database run in Germany. The off-site backup copy is encrypted before it leaves the machine and is stored in the United States, so it does cross a border; the encryption key stays with us and the storage provider cannot read what it holds. Cloudflare's DNS and Let's Encrypt's certificate service are global by nature, and neither handles the contents of your app.
Hatchik itself is an Omani company, so the European Commission's adequacy decisions do not cover us. For transfers out of the European Economic Area or the United Kingdom we rely on the standard contractual clauses, which are incorporated into this agreement by reference: module four (processor to controller) does not apply, and module two (controller to processor) governs the transfer from you to us, with you as data exporter and Namaa Solutions SPC as data importer. Where the UK's international data transfer addendum is needed it applies on the same terms.
8. Requests from the people whose data it is
If one of your customers asks you for a copy of their data, or asks you to correct or delete it, that request is yours to answer — you are the controller and only you know what the data means.
Hatchik's job is to make sure you can answer it without needing us. You can, at any time and without asking anyone: download everything — a single archive containing every file, the whole database as readable SQL and as a Postgres dump, your settings, and a written guide to running it elsewhere; edit or remove any record, through your own app or your AI tool; and delete the whole project, which removes its files, its database, its draft and its live site. Those tools are the assistance, and they are available immediately rather than when someone gets round to it.
If a request genuinely cannot be answered that way — for example a regulator or a court orders Hatchik directly to produce or erase something — email hello@hatchik.com. That address is read by the founder and is for legal and data-protection requests, billing disputes and abuse reports. It is not a support desk and there is no response-time commitment attached to it; we will act as quickly as one person reasonably can, and we will tell you if a demand relates to your data unless we are legally prohibited from doing so.
9. If there is a breach
If we discover a breach affecting personal data in your app, we will email the address on your account without undue delay and in any event within 48 hours of becoming aware of it. We will tell you what we know: what happened, when, which projects are affected, what kind of data was involved, what we have done about it, and what we do not yet know.
You then decide whether your regulator and your customers need to be told — that is the controller's call and the clock on it is yours, not ours. We will give you whatever information you need to make that decision and to make that report.
10. Getting your data back, and its deletion
You can export everything at any point during the agreement and for as long as your account exists — it is a button on the project page, or you can ask your AI tool for it, and the download link works for 24 hours. Export what you need before you delete anything, because deletion is final.
When you delete a project or close your account, its files, its database, its draft and its live site are decommissioned and we keep no copy. Encrypted backups made before that point age out on the ordinary backup rotation rather than being reached into and edited; they are encrypted and are not accessible to anyone but us. We keep the minimum billing and security records the law requires us to keep, and nothing else.
11. Audit
This page, the privacy policy and the terms are the record of what we do, and they are written to be checked rather than to sound reassuring. If you need something more than that, write to hello@hatchik.com with what you need and why; we will answer questions in writing and provide what we have. We do not offer on-site inspections and we do not have third-party audit reports to hand you, because they do not exist. Where the law gives you an audit right that this cannot satisfy, that right still stands and we will not obstruct it.
12. What this does not change
Nothing on this page reduces the duties either of us has under data protection law. Where this agreement and the terms of service disagree about the personal data in your app, this page wins. Everything else — fees, acceptable use, liability, which country's courts — is governed by the terms.
If we change this agreement we will revise the date at the top and, for anything material, email the address on your account.