Effective date: September 4, 2026
1. Scope and Roles
This Data Processing Addendum ("DPA") supplements the Hop Terms of Service entered into by and between Customer and Hop Mesh, LLC ("Hop", "we", "us", or "our") [Counsel placeholder: state of organization to be inserted upon confirmation of corporate filings], when Customer personal data is processed through the Hop Hosted Services. In the context of applicable data protection legislation (including the EU General Data Protection Regulation (GDPR) and UK GDPR):
- Customer as Controller: Customer acts as a Data Controller (or Processor on behalf of third-party Controllers) for all message content, metadata, and device identifiers submitted to the network.
- Hop as Processor: Hop acts as a Data Processor solely to the extent our hosted backbone relays, spools, or translates envelope routing metadata on Customer's behalf.
2. Nature and Architecture of Processing
Hop is engineered around cryptographic zero-knowledge principles:
- Payload Ciphertext: User payloads are end-to-end encrypted (X25519 + ChaCha20-Poly1305) on device before transmission. Hop does not hold decryption keys and cannot view, decrypt, or process payload text or media.
- Routing Envelopes: Relays process sealed bundle headers containing destination public keys, hop limits, time-to-live (TTL) timestamps, and size attributes solely to achieve message delivery.
- Relay Session & Device Metadata: To manage connection state, active peer routing, and network rate limiting, relay instances store session state in Google Cloud Firestore under
relays/{node}/kv. This metadata includes base58 device public keys and timestamps. While held bundle payloads in transit are transient, these session and device metadata records persist across connections subject to automated TTL retention policies (30 days for session state, 24 hours for carrier streams, 7 days for seen bundle identifiers, and a 30-day default TTL for transient records; financial ledger records and telemetry deduplication markers have no automated expiry). - Billing Metrics: Usage billing relies on pseudonymous device address counters and aggregated delivery counts, never message content.
3. Security Measures (GDPR Article 32)
Hop implements technical and organizational security measures designed to protect customer data:
- Transport Security: All peer connections authenticate with the Noise Protocol Framework or TLS 1.3.
- Spool Durability & Isolation: Held bundles rest in encrypted storage (Google Cloud multi-region) and are deleted upon verified delivery or TTL expiration. Session and device metadata in
relays/{node}/kv are maintained under strict IAM access controls to support network routing and abuse prevention. - Access Controls: Infrastructure access is restricted to authorized personnel via multi-factor authentication, least privilege, and audited logging.
4. Processor Obligations (GDPR Article 28.3)
Hop, in its capacity as a Data Processor, contractually commits to the following covenants:
- Documented Instructions (Art. 28(3)(a)): Hop shall process Customer personal data only on documented instructions from Customer (including with respect to transfers of personal data to a third country), as set forth in the Terms, this DPA, and Customer's use of the Hosted Services, unless required to do so by applicable European Union or Member State law.
- Personnel Confidentiality (Art. 28(3)(b)): Hop ensures that all employees, contractors, and agents authorized to process Customer personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Data Subject Rights Assistance (Art. 28(3)(e)): Taking into account the nature of the processing and the zero-knowledge architecture (where payloads are end-to-end encrypted with endpoint-held keys), Hop shall assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to data subject rights requests under GDPR Chapter III.
- Personal Data Breach Notification (Art. 28(3)(f)): Hop shall notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a confirmed personal data breach affecting Customer personal data. Hop will provide reasonable information and assistance to enable Customer to comply with its breach reporting obligations.
- Deletion or Return upon Termination (Art. 28(3)(g)): Upon termination of the Hosted Services, Hop shall, at Customer's choice, delete or return all Customer personal data and delete existing copies, unless applicable European Union or Member State law requires continued retention.
- Audits and Inspection Cooperation (Art. 28(3)(h)): Hop shall make available to Customer all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, upon reasonable notice and subject to mutual confidentiality agreements.
5. Subprocessors (GDPR Article 28.2 & 28.4)
Customer provides general authorization for Hop to engage the following third-party subprocessors:
- Google Cloud Platform (GCP): Cloud hosting, compute (Cloud Run), and persistent storage (Firestore) in the United States region.
- Stripe, Inc.: Metered billing, subscription administration, and payment processing.
Subprocessor Notice and Customer Objection: Hop shall notify Customer at least thirty (30) days in advance of engaging any new subprocessor or replacing an existing subprocessor. Customer may object to a new subprocessor on reasonable data protection grounds by providing written notice within fourteen (14) days of receipt of notice. In the event of an objection, the parties will consult in good faith to achieve an alternative. If no resolution is reached, Customer may terminate the affected Hosted Services without penalty. Hop imposes data protection obligations on subprocessors no less protective than those set out in this DPA.
6. International Data Transfers (GDPR Chapter V)
Hop stores and processes cloud backbone data within Google Cloud facilities in the United States. Where transfers of personal data from the EEA, UK, or Switzerland to the United States occur, they are governed by the EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914):
- Module 2 (Controller-to-Processor): Applicable when Customer acts as Data Controller.
- Module 3 (Processor-to-Processor): Applicable when Customer acts as Data Processor.
Customer may access the template EU Standard Contractual Clauses (SCC) Template Package (available to be formally executed upon request with customer) and view our Transfer Impact Assessment (TIA) evaluating US legal authorities (including FISA 702 and Executive Order 14086) and supplemental cryptographic safeguards.
7. Execution & Inquiries
Enterprise and regulated customers requiring a countersigned DPA, executed SCC annexes, or custom contractual terms may request standard execution packages by contacting privacy@hopme.sh.