Data Processing Agreement
Last updated: 2026-06-24
This Data Processing Agreement (the "DPA") governs the processing of personal data that Swat.io GmbH carries out on behalf of its customers when providing the Hush comment-moderation service. It forms part of, and is concluded under, theHush Terms of Service (the "Main Agreement") and implements Article 28 of the EU General Data Protection Regulation (GDPR). For personal data collected via the publicusehush.io website, see ourPrivacy Policy instead.
1. Scope
1.1 Swat.io GmbH, registered in the commercial register of the Commercial Court of Vienna under FN 348798 p (the "Processor"), processes personal data on behalf of its customer (the"Controller"; the Controller and Processor together the"Parties") on the basis of this DPA, in the version valid when the Main Agreement is concluded.
1.2 The Processor may amend this DPA with at least 30 days' notice, announced on its website and sent to the Controller's last-notified email address. If the Controller does not object in writing tolab@swat.io within 30 days, the amendment is deemed accepted. On timely objection, the prior version continues to apply and the Processor may terminate on 14 days' notice to the end of the month.
1.3 The Processor carries out the processing described in the Annex (the "Data Processing") under the Main Agreement for the use of the Hush service.
2. Place of processing
2.1 The Data Processing takes place within the European Union or the European Economic Area. Processing by the sub-processors named in the Annex is deemed approved at the locations named there.
2.2 Any transfer of Data Processing to a third country requires the Controller's prior consent and is permitted only if the requirements of Art. 44 et seq. GDPR are met.
3. Obligations of the Processor
3.1 The Processor processes personal data exclusively on the Controller's documented instructions (the configuration of the Hush service by the Controller constitutes such instructions). If the Processor considers an instruction unlawful, it may suspend it until confirmed or amended.
3.2 The Processor keeps the personal data confidential and binds the persons authorised to process it to confidentiality; this survives termination of the DPA.
3.3 The Processor implements appropriate technical and organisational measures within the meaning of Art. 32 GDPR (the "TOMs"), appropriate to the risk. The TOMs in their current version are available atswat.io/en/legaland on request.
3.4 The Processor assists the Controller, by appropriate technical and organisational measures, in responding to data-subject requests under Chapter III GDPR within the legal time limits, so far as the Processor holds the necessary information. If a data subject contacts the Processor directly, the Processor forwards the request to the Controller.
3.5 The Processor supports the Controller in complying with Art. 32–36 GDPR (security measures, breach notification, and, where applicable, data-protection impact assessments).
3.6 On expiry of the retention periods set out in the Main Agreement, or without undue delay at the Controller's request, the Processor deletes the personal data; if the Controller expressly requests it, the data is returned. Statutory retention obligations remain unaffected.
3.7 The Processor provides the Controller, on request, with the information needed to demonstrate compliance with Art. 28 GDPR and supports verification in accordance with Section 5.
4. Sub-processors
4.1 The Controller authorises the use of sub-processors. The sub-processors listed in the Annex are deemed approved on conclusion of the contract.
4.2 The Processor informs the Controller of any intended change of sub-processor. The Controller may object in writing tolab@swat.io within 30 working days of notification; absent a timely objection the change is deemed approved.
4.3 Where the Processor engages a sub-processor, it concludes an agreement under Art. 28(4) GDPR imposing the same obligations as this DPA.
5. Rights of control and inspection
5.1 The Controller may, in agreement with the Processor, audit the Data Processing (itself or through an auditor) after reasonable notice, during business hours, and not more than once every twelve months. Where the Processor evidences correct implementation of its obligations, checks are limited to random samples.
5.2 The Processor bears its reasonable internal costs for one audit per calendar year; the Controller bears costs beyond that and any external auditor's costs.
6. Remuneration
The Processor assists with the Controller's data-protection obligations to a reasonable extent at no additional cost. Assistance beyond a reasonable extent is provided against a prior cost estimate after the Controller's commission.
7. Term
This DPA runs for the term of the Main Agreement plus the retention period provided for in it.
8. Final provisions
8.1 The law of the Main Agreement (Austrian law) applies to this DPA.
8.2 Should any provision be or become invalid, the remaining provisions stay in force; the invalid provision is replaced by a valid one that comes as close as possible to its economic intent.
Annex — Description of the Data Processing
1. Subject
Operation of Hush, an automated comment-moderation service that classifies comments and, according to the Controller's settings, hides, flags, or routes them on the Controller's connected social-media channels and via the Hush API, MCP server, and CLI.
2. Duration
For the term of the Main Agreement and the retention periods provided for in it.
3. Nature and purpose
Comments and related metadata are received from the connected social-media platforms (via their webhooks and APIs) or submitted by the Controller through the API, MCP server, or CLI, then automatically classified by Hush's three-tier detection engine (rules, corpus matching, and — for ambiguous cases — an EU-hosted large language model) and acted upon according to the Controller's configuration (e.g. automatically hiding spam). The purpose is to protect the Controller's channels from spam, scam, and hateful or explicit comments.
4. Categories of personal data
Commenter user IDs and usernames, display names, profile pictures and profile URLs; comment text and content metadata (timestamps, comment and post IDs); and author profile signals used for detection (e.g. follower, following, and post counts). The Controller should not submit special categories of data via the free-text API beyond what comment moderation requires.
5. Categories of data subjects
Users who comment on the Controller's connected social-media channels, and the authors of any text the Controller submits through the Hush API, MCP server, or CLI.
6. Authorised sub-processors
All sub-processors process within the European Union.
- Amazon Web Services EMEA SARL — 38 Avenue John F. Kennedy, L-1855 Luxembourg
- Hosting and database storage, automated classification via Amazon Bedrock (large-language-model inference), and transactional email. Region: eu-central-1 (Frankfurt, Germany).
- PostHog, Inc. — EU Cloud
- Product analytics and AI/LLM observability. Servers located in Frankfurt, Germany, under EU Cloud terms with a Data Processing Addendum in place.
Provider and contact
Swat.io GmbH · Schönbrunner Straße 213–215, 3rd floor, 1120 Vienna, Austria · FN 348798 p (Commercial Court of Vienna) · VAT ATU 65871657. Data-protection contact: lab@swat.io. Company details: swat.io/en/imprint.