This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms of Service between Hlinix sp. z o.o. and the Customer (together, the "Agreement") for the provision of managed Claude Code VPS hosting (the "Service"). It reflects the parties' agreement with regard to the processing of personal data in accordance with the requirements of Regulation (EU) 2016/679 (the "GDPR"), in particular Article 28.
In the event of a conflict between this DPA and the Terms of Service in respect of the processing of personal data, this DPA prevails.
Contents
- Parties & roles
- Subject matter & scope
- Processing on instructions
- Confidentiality
- Security of processing
- Sub-processors
- International transfers
- Assistance to the Controller
- Personal data breaches
- Deletion & return of data
- Audits
- Liability & term
- Annex 1 — Details of processing
- Annex 2 — Technical & organisational measures
- Annex 3 — Approved sub-processors
1. Parties & roles
For the purposes of this DPA:
- The Customer is the Controller in respect of the personal data processed through the Service.
- Hlinix sp. z o.o., ul. Marcina Kasprzaka 31/119, 01-234 Warsaw, Poland (KRS 0001237324), is the Processor, acting on behalf of the Controller.
Where the Controller is itself acting as a processor for a third party, the Controller warrants that it is authorised to engage Hlinix as a sub-processor on the terms of this DPA.
2. Subject matter & scope
The subject matter, nature and purpose of the processing, the types of personal data, the categories of data subjects, and the duration of the processing are set out in Annex 1. Hlinix processes personal data only to the extent necessary to provide and support the Service.
3. Processing on instructions
Hlinix shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law to which Hlinix is subject; in such a case, Hlinix shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and the Controller's use and configuration of the Service constitute the Controller's complete and documented instructions. Hlinix shall inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
4. Confidentiality
Hlinix shall ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to provide the Service.
5. Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Hlinix shall implement appropriate technical and organisational measures pursuant to Article 32 GDPR. The measures in place are described in Annex 2. Hlinix may update these measures from time to time provided the level of protection is not reduced.
6. Sub-processors
The Controller grants Hlinix general authorisation to engage sub-processors to provide the Service. The sub-processors currently engaged are listed in Annex 3. Hlinix shall impose on each sub-processor, by way of a contract, data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Controller for the performance of that sub-processor's obligations.
Hlinix shall inform the Controller of any intended addition or replacement of a sub-processor with reasonable prior notice, thereby giving the Controller the opportunity to object on reasonable data-protection grounds. If the Controller reasonably objects and the parties cannot agree on a resolution, the Controller may terminate the affected part of the Service.
7. International transfers
The personal data processed under this DPA in the operation of the VPS is stored exclusively within the European Union (Hetzner data centre, Helsinki, Finland). Hlinix does not transfer such data outside the European Economic Area (EEA).
Where a sub-processor used for ancillary functions (for example, payment processing) may process limited personal data outside the EEA, any such transfer is carried out on the basis of an adequacy decision or appropriate safeguards under Chapter V GDPR, including the European Commission's Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR. Details are set out in Annex 3.
8. Assistance to the Controller
Taking into account the nature of the processing, Hlinix shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR. Hlinix shall also assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to Hlinix.
9. Personal data breaches
Hlinix shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting the personal data processed on behalf of the Controller. The notification shall, to the extent available, describe the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for further information. Hlinix shall cooperate with the Controller and take reasonable steps to mitigate the effects of the breach.
10. Deletion & return of data
Upon termination or expiry of the Service, Hlinix shall, at the Controller's choice, delete or return the personal data processed on behalf of the Controller, and delete existing copies, within fourteen (14) days, unless Union or Member State law requires storage of the personal data. Where the Controller requires a return or export of data, it must be requested and completed before termination takes effect. Deletion covers the VPS and its associated backups within the retention window described in Annex 2.
11. Audits
Hlinix shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. The Controller may exercise this right on reasonable prior written notice (ordinarily at least thirty (30) days), no more than once per calendar year except where required by a supervisory authority or following a personal data breach, during business hours, and in a manner that does not disrupt Hlinix's operations or compromise the confidentiality or security of other customers' data.
12. Liability & term
This DPA takes effect on the effective date of the Agreement and remains in force for as long as Hlinix processes personal data on behalf of the Controller. The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Questions relating to this DPA may be addressed to hello@hlinix.com.
Annex 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of a managed VPS with resident Claude Code, including hosting, backups, logging, and security operations. |
| Nature & purpose | Hosting, storage, transmission, backup, and logging of data on the Controller's VPS as required to deliver and support the Service. |
| Duration | For the duration of the subscription, plus the deletion window described in Section 10. |
| Types of personal data | IP addresses; log data (including audit logs and structured application/system logs); email addresses; and any other personal data the Controller chooses to store or process on the VPS. |
| Special categories | Not intended. The Controller shall not upload special-category data (Article 9 GDPR) to the VPS unless separately agreed with appropriate safeguards. |
| Categories of data subjects | The Controller's personnel (e.g. employees, contractors) and the Controller's end users, as determined by the Controller's use of the VPS. |
Annex 2 — Technical & organisational measures
Hlinix maintains, at a minimum, the following measures pursuant to Article 32 GDPR:
- Isolation: a dedicated single-tenant VPS per Customer (one Customer, one server).
- Access control: SSH key-based authentication only (password authentication disabled); least-privilege administrative access limited to authorised personnel.
- Encryption: encryption of data in transit (TLS/SSH). Payment data is handled by the payment processor over encrypted channels.
- Network security: host firewalling, network-level DDoS mitigation, rate limiting, and intrusion-prevention (fail2ban).
- Hardening & updates: baseline OS hardening and automatic security updates.
- Backups: daily automated backups with seven (7) generations retained within the EU.
- Logging & monitoring: audit logging and structured log retention for ninety (90) days.
- Resilience & restoration: the ability to restore availability and access to personal data in a timely manner following an incident.
- Data location: processing and storage within the EU (Helsinki, Finland).
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location / transfer basis |
|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure hosting the VPS, backups, and logs. | Helsinki, Finland (EEA). No transfer outside the EEA. |
| Stripe Payments Europe, Ltd. | Payment processing for subscription billing (account/billing contact data). | Ireland (EEA); any onward transfer to Stripe, Inc. (USA) is governed by the European Commission's Standard Contractual Clauses. |
Anthropic PBC is not a sub-processor of Hlinix. Under the BYOK model, the Customer uses its own Anthropic API Key, and any processing by Anthropic occurs under the Customer's own agreement with Anthropic. Hlinix does not store the Customer's API Key.