Legal documentation

EU Standard Contractual Clauses (SCC) Template.

Hop Mesh EU Standard Contractual Clauses (SCC) Template Package

This document constitutes a template EU Standard Contractual Clauses (SCCs) package available to be formally executed between Customer and Hop Mesh, LLC ("Hop") [Counsel placeholder: state of organization to be inserted upon confirmation of corporate filings] for cross-border transfers of personal data under GDPR Chapter V.

These Clauses comply with European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

Applicable Modules

Depending on Customer's regulatory role:

Execution and Parties

This package is a template to be executed upon request with the customer, never pre-executed. Where international data transfers require formal bilateral execution of these Clauses, customers may request, complete, and execute a countersigned package by contacting privacy@hopme.sh.


SECTION I: CLAUSES (MODULE 2 AND MODULE 3)

Clause 1: Purpose and scope

(a) The purpose of these standard contractual clauses is to ensure compliance with the requirements of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) for the transfer of personal data to a third country. (b) The Parties: (i) the natural or legal person(s), public authorit(y/ies), agency/ies or other body/ies (hereinafter "data exporter(s)") transferring the personal data, as listed in Annex I.A, and (ii) the legal entity in a third country (hereinafter "data importer", Hop Mesh, LLC), as listed in Annex I.A, have agreed to these standard contractual clauses ("Clauses"). (c) These Clauses apply with respect to the transfer of personal data as specified in Annex I.B.

Clause 2: Effect and invariability of the Clauses

(a) These Clauses set out appropriate safeguards, including enforceable data subject rights and effective legal remedies, pursuant to Article 46(1) and Article 46(2)(c) of Regulation (EU) 2016/679. (b) These Clauses are without prejudice to obligations to which the data exporter is subject by virtue of Regulation (EU) 2016/679.

Clause 3: Third-party beneficiaries

Data subjects may invoke and enforce these Clauses as third-party beneficiaries against the data exporter and/or data importer, with the exceptions specified in Clause 3.

Clause 4: Interpretation

Where these Clauses use terms that are defined in Regulation (EU) 2016/679, those terms shall have the same meaning as in that Regulation.

Clause 5: Hierarchy

In the event of a contradiction between these Clauses and the provisions of related agreements between the Parties, these Clauses shall prevail.

Clause 6: Description of the transfer(s)

The details of the transfer(s), and in particular the categories of personal data that are transferred and the purpose(s) for which they are transferred, are specified in Annex I.B.

Clause 7: Docking clause

An entity that is not a Party to these Clauses may, with the agreement of the Parties, accede to these Clauses at any time, either as a data exporter or as a data importer.

Clause 8: Data protection safeguards

The data exporter warrants that it has used reasonable efforts to determine that the data importer is able, through the implementation of appropriate technical and organizational measures, to satisfy its obligations under these Clauses. (Module 2 and Module 3): The data importer shall process the personal data only on documented instructions from the data exporter. The data importer shall immediately inform the data exporter if, in the data importer's opinion, instructions given by the data exporter infringe Regulation (EU) 2016/679 or other applicable data protection law. The data importer shall implement technical and organizational measures to ensure the security of the personal data, including protection against a breach of security (Annex II).

Clause 9: Use of subprocessors

(Module 2 and Module 3): The data importer has the data exporter's general authorization for the engagement of subprocessors from an agreed list (Annex III). The data importer shall specifically inform the data exporter in writing of any intended changes to that list through the addition or replacement of subprocessors at least 30 days in advance, thereby giving the data exporter sufficient time to be able to object to such changes prior to the engagement of the subprocessor(s).

Clause 10: Data subject rights

The data importer shall promptly notify the data exporter of any request it has received from a data subject. It shall not respond to that request itself unless it has been authorized to do so by the data exporter. Taking into account the nature of the processing and the cryptographic architecture of the network, the data importer shall assist the data exporter in fulfilling its obligations to respond to data subjects' requests.

Clause 11: Redress

The data importer shall inform data subjects in a transparent and easily accessible format of a contact point authorized to handle complaints.

Clause 12: Liability

Each Party shall be liable to the other Party/Parties for any damages it causes the other Party/Parties by any breach of these Clauses.

Clause 13: Supervision

The supervisory authority with responsibility for ensuring compliance by the data exporter with Regulation (EU) 2016/679 shall act as the competent supervisory authority.

Clause 14: Local laws and practices affecting compliance with the Clauses

The Parties warrant that they have no reason to believe that the laws and practices in the third country of destination applicable to the processing of the personal data by the data importer, including any requirements to disclose personal data or measures authorizing access by public authorities, prevent the data importer from fulfilling its obligations under these Clauses. This is based on an understanding that laws and practices that respect the essence of the fundamental rights and freedoms and do not exceed what is necessary and proportionate in a democratic society are not in contradiction with these Clauses (see Transfer Impact Assessment).

Clause 15: Obligations of the data importer in case of access by public authorities

The data importer agrees to notify the data exporter promptly if it receives a legally binding request from a public authority, including judicial or national security authorities, under the laws of the country of destination for the disclosure of personal data transferred pursuant to these Clauses. Because Hop uses end-to-end encryption with keys held solely on endpoint devices, payloads cannot be decrypted by Hop in response to any government demand.

Clause 17: Governing law

These Clauses shall be governed by the law of one of the EU Member States, provided such law allows for third-party beneficiary rights. The Parties select the laws of the Republic of Ireland.

Clause 18: Choice of forum and jurisdiction

Any dispute arising from these Clauses shall be resolved by the courts of an EU Member State. The Parties agree to submit to the jurisdiction of the courts of Dublin, Ireland.


ANNEX I: LIST OF PARTIES AND DESCRIPTION OF TRANSFER

A. List of Parties

B. Description of Transfer


ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES

The data importer maintains the following technical and organizational security measures:

  1. End-to-End Cryptography: All message payloads are encrypted on device using authenticated ciphers (ChaCha20-Poly1305) and ephemeral or ratchet key exchange (X25519 / Double Ratchet). Relays operate as zero-knowledge transit forwarders unable to read payload plaintext.
  2. Transit Encryption: Peer-to-peer and relay connections enforce authenticated session encryption via the Noise Protocol Framework or TLS 1.3 with modern cipher suites.
  3. Storage Security: Held message spools and persistent key-value metadata in Google Cloud Firestore are encrypted at rest using AES-256 with Google-managed or customer-managed keys.
  4. Access Control and Least Privilege: Production cloud environments require multi-factor authentication, hardware security keys, role-based access control, and audited session logs.
  5. Physical and Environmental Security: Infrastructure is hosted in SOC 2 Type II and ISO 27001 certified Google Cloud data center facilities with 24/7 biometric physical access security.
  6. Vulnerability and Incident Response: Automated dependency auditing, static analysis, and a monitored vulnerability disclosure program with personal data breach response within 48 hours.

ANNEX III: LIST OF SUBPROCESSORS

The data importer engages the following approved subprocessors:

  1. Google Cloud Platform (Google LLC, USA):
    • Service: Cloud Run (compute), Cloud Firestore (spool and metadata storage), Cloud Logging.
    • Location: United States multi-region.
    • Safeguards: ISO 27001, SOC 1/2/3, Google Cloud Model Contract Clauses.
  2. Stripe, Inc. (Stripe Payments Europe, Ltd. / Stripe, Inc., USA):
    • Service: Billing aggregation, payment card processing, subscription management.
    • Location: United States / European Union.
    • Safeguards: PCI-DSS Level 1 Service Provider, Stripe EU Data Transfer Agreement.