Last updated April 24, 2026

Data Processing Addendum

This DPA summary outlines SharpHaw's data processing commitments for SharpOS where it is incorporated into a client agreement.

Roles

For client workspace content and user data, the client is typically the controller and SharpHaw acts as processor or service provider. SharpHaw may act as controller for account administration, billing, security, and business operations.

Processing instructions

SharpHaw processes personal data to provide SharpOS, follow documented client instructions, maintain security, support users, and meet legal obligations. The client remains responsible for determining whether it has a lawful basis to collect, upload, or otherwise make personal data available through its workspace.

Security

  • Access controls and organization-scoped authorization.
  • Role-based permissions for platform and organization users.
  • Encryption in transit through HTTPS and provider-managed infrastructure protections.
  • Operational monitoring, logging, and incident response practices appropriate for the service.

Confidentiality and assistance

Access to client workspace data is controlled by authenticated, organisation-scoped roles. SharpHaw will provide reasonable assistance with data-subject requests, security enquiries, and impact assessments where required by the applicable agreement and law.

Subprocessors

SharpHaw uses subprocessors to host, operate, secure, and support SharpOS. The current list is published on the Subprocessors page and may be updated as the service evolves.

Deletion and return

On termination or written request, SharpHaw will delete or return client personal data where reasonably possible, unless retention is required by law, security, dispute resolution, backup, or legitimate business obligations.

International transfers

SharpHaw and its subprocessors may process data in multiple countries. Where required, appropriate contractual, organizational, or provider safeguards are used for transfers.