Last updated April 24, 2026
Data Processing Addendum
This DPA summary outlines SharpHaw's data processing commitments for SharpOS where it is incorporated into a client agreement.
Roles
For client workspace content and user data, the client is typically the controller and SharpHaw acts as processor or service provider. SharpHaw may act as controller for account administration, billing, security, and business operations.
Processing instructions
SharpHaw processes personal data to provide SharpOS, follow documented client instructions, maintain security, support users, and meet legal obligations. The client remains responsible for determining whether it has a lawful basis to collect, upload, or otherwise make personal data available through its workspace.
Security
- Access controls and organization-scoped authorization.
- Role-based permissions for platform and organization users.
- Encryption in transit through HTTPS and provider-managed infrastructure protections.
- Operational monitoring, logging, and incident response practices appropriate for the service.
Confidentiality and assistance
Access to client workspace data is controlled by authenticated, organisation-scoped roles. SharpHaw will provide reasonable assistance with data-subject requests, security enquiries, and impact assessments where required by the applicable agreement and law.
Subprocessors
SharpHaw uses subprocessors to host, operate, secure, and support SharpOS. The current list is published on the Subprocessors page and may be updated as the service evolves.
Deletion and return
On termination or written request, SharpHaw will delete or return client personal data where reasonably possible, unless retention is required by law, security, dispute resolution, backup, or legitimate business obligations.
International transfers
SharpHaw and its subprocessors may process data in multiple countries. Where required, appropriate contractual, organizational, or provider safeguards are used for transfers.