Legal

Data Processing Addendum.

GDPR Article 28 data processor commitments for customers utilizing Hop managed services.

Effective date: September 4, 2026

1. Scope and Roles

This Data Processing Addendum ("DPA") supplements the Hop Terms of Service entered into by and between Customer and Hop Mesh, LLC ("Hop", "we", "us", or "our") [Counsel placeholder: state of organization to be inserted upon confirmation of corporate filings], when Customer personal data is processed through the Hop Hosted Services. In the context of applicable data protection legislation (including the EU General Data Protection Regulation (GDPR) and UK GDPR):

2. Nature and Architecture of Processing

Hop is engineered around cryptographic zero-knowledge principles:

3. Security Measures (GDPR Article 32)

Hop implements technical and organizational security measures designed to protect customer data:

4. Processor Obligations (GDPR Article 28.3)

Hop, in its capacity as a Data Processor, contractually commits to the following covenants:

5. Subprocessors (GDPR Article 28.2 & 28.4)

Customer provides general authorization for Hop to engage the following third-party subprocessors:

Subprocessor Notice and Customer Objection: Hop shall notify Customer at least thirty (30) days in advance of engaging any new subprocessor or replacing an existing subprocessor. Customer may object to a new subprocessor on reasonable data protection grounds by providing written notice within fourteen (14) days of receipt of notice. In the event of an objection, the parties will consult in good faith to achieve an alternative. If no resolution is reached, Customer may terminate the affected Hosted Services without penalty. Hop imposes data protection obligations on subprocessors no less protective than those set out in this DPA.

6. International Data Transfers (GDPR Chapter V)

Hop stores and processes cloud backbone data within Google Cloud facilities in the United States. Where transfers of personal data from the EEA, UK, or Switzerland to the United States occur, they are governed by the EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914):

Customer may access the template EU Standard Contractual Clauses (SCC) Template Package (available to be formally executed upon request with customer) and view our Transfer Impact Assessment (TIA) evaluating US legal authorities (including FISA 702 and Executive Order 14086) and supplemental cryptographic safeguards.

7. Execution & Inquiries

Enterprise and regulated customers requiring a countersigned DPA, executed SCC annexes, or custom contractual terms may request standard execution packages by contacting privacy@hopme.sh.