Hyperloop
Legal

HyperloopAI Inc. — Data Processing Agreement

Version: 2026-08-24 · Contact: [email protected] · Incorporated by reference into the Terms of Service.

⚠️ DRAFT — for review by counsel before publication. Annex II should be adjusted to match Hyperloop's actual current security program, and bracketed placeholders completed, before this is relied upon.

This Data Processing Agreement (“DPA”) forms part of the agreement between HyperloopAI Inc., a Delaware corporation (“Hyperloop”), and the customer that accepts the HyperloopAI Terms of Service or another agreement governing the customer’s use of the Services (the “Agreement”) (such customer, “Customer”). This DPA applies where and to the extent Hyperloop processes Personal Data on behalf of Customer in connection with the Services.

Contents
  1. How this DPA Is Executed
  2. Definitions
  3. Roles and Scope
  4. Processing Instructions
  5. Confidentiality
  6. Security
  7. Sub-processors
  8. Assistance with Data Subject Requests
  9. Personal Data Breach
  10. DPIAs and Consultation
  11. Deletion and Return
  12. Audits and Information
  13. International Transfers
  14. US State Privacy Laws
  15. Liability; Term; General
  16. Annex I — Description of Processing
  17. Annex II — Technical & Organizational Measures
  18. Annex III — Sub-processors

1. How this DPA Is Executed

This DPA is automatically incorporated into the Agreement and takes effect upon the earlier of (a) Customer’s acceptance of the Agreement (including by clicking “I agree,” creating an account, or using the Services), or (b) Customer’s execution of an order form referencing the Agreement (the “Effective Date”). No signature is required. Customers who require a countersigned copy may request one at [email protected]. In case of conflict, this DPA prevails over the Agreement with respect to the processing of Personal Data, and the Standard Contractual Clauses prevail over this DPA.

2. Definitions

Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including, as applicable: (i) Regulation (EU) 2016/679 (“GDPR”); (ii) the GDPR as incorporated into United Kingdom law (“UK GDPR”) and the UK Data Protection Act 2018; (iii) the Swiss Federal Act on Data Protection (“FADP”); and (iv) the California Consumer Privacy Act as amended, and other applicable US state privacy laws (collectively, “US Privacy Laws”).

Personal Data” means any information relating to an identified or identifiable natural person that Hyperloop processes on behalf of Customer in connection with the Services.

SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj, as amended or replaced from time to time.

UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the UK Information Commissioner’s Office, available at https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/.

Services” means Hyperloop’s accounts-receivable and finance automation platform and related services described in the Agreement.

Sub-processor” means a third party engaged by Hyperloop to process Personal Data on Customer’s behalf. The terms “controller,” “processor,” “data subject,” “processing,” and “personal data breach” have the meanings given in the GDPR.

3. Roles and Scope

As between the parties, Customer is the controller (or a processor acting on behalf of a third-party controller) and Hyperloop is the processor of Personal Data. Each party shall comply with its obligations under applicable Data Protection Laws. The subject matter, duration, nature and purpose of the processing, and the categories of Personal Data and data subjects, are set out in Annex I. Customer is responsible for the accuracy and lawfulness of the Personal Data it submits to the Services and for having a lawful basis for the processing, including any required notices to and consents from data subjects (such as Customer’s payers and their personnel).

4. Processing Instructions

Hyperloop shall process Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Hyperloop is subject (in which case Hyperloop shall inform Customer of that legal requirement before processing, unless the law prohibits this). The Agreement, this DPA, and Customer’s configuration and use of the Services constitute Customer’s documented instructions. Hyperloop shall promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

5. Confidentiality

Hyperloop shall ensure that persons authorized to process Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and that access to Personal Data is limited to personnel who require it to perform the Services.

6. Security

Hyperloop shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Hyperloop’s current measures are described in Annex II. Hyperloop may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.

7. Sub-processors

Customer provides general written authorization for Hyperloop to engage Sub-processors to provide the Services. Hyperloop’s current Sub-processors are listed at https://hyperloopai.io/legal/subprocessors (the “Sub-processor Page”). Hyperloop shall provide notice of any intended addition or replacement of a Sub-processor (including via a subscription mechanism on the Sub-processor Page) at least thirty (30) days before the change takes effect. Customer may object on reasonable, documented data-protection grounds within that period; if the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees. Hyperloop shall impose on each Sub-processor data protection obligations materially no less protective than those in this DPA and remains fully liable to Customer for each Sub-processor’s performance.

8. Assistance with Data Subject Requests

Taking into account the nature of the processing, Hyperloop shall assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling Customer’s obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, and objection). If Hyperloop receives a request directly from a data subject relating to Customer’s Personal Data, Hyperloop shall promptly forward it to Customer and shall not respond except to direct the data subject to Customer, unless legally required.

9. Personal Data Breach

Hyperloop shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer’s Personal Data. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Hyperloop shall cooperate with Customer and take reasonable steps to remediate the breach. Hyperloop’s notification is not an acknowledgement of fault or liability.

10. DPIAs and Consultation

Taking into account the nature of the processing and the information available to it, Hyperloop shall provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required of Customer under Data Protection Laws.

11. Deletion and Return

Upon termination or expiration of the Agreement, Hyperloop shall, at Customer’s choice, delete or return all Personal Data (and delete existing copies) within ninety (90) days, unless retention is required by applicable law, in which case Hyperloop shall protect the retained data in accordance with this DPA and cease further processing. During the term, Customer may export its data through the Services’ standard functionality.

12. Audits and Information

Hyperloop shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and security certifications that Hyperloop maintains from time to time. No more than once per twelve (12) months (except following a personal data breach or where required by a supervisory authority), Customer may conduct an audit, including inspections, by submitting a written request; the parties shall agree in advance on the scope, timing, and duration, the audit shall be conducted during business hours with minimal disruption, at Customer’s expense, and subject to the confidentiality terms of the Agreement. Where the SCCs apply, this Section applies to audits under Clauses 8.9(c) and (d) of the SCCs.

13. International Transfers

(a) EU transfers. Where Personal Data protected by the GDPR is transferred to Hyperloop in a country not covered by an adequacy decision, the parties are deemed to have entered into the SCCs, Module Two (Controller to Processor), which are incorporated by reference into this DPA, with Customer as “data exporter” and Hyperloop as “data importer,” and completed as follows: Clause 7 (docking clause) is included; under Clause 9(a), Option 2 (general written authorization) applies with the notice period in Section 7 of this DPA; the optional language in Clause 11(a) is not included; under Clause 17, Option 1 applies and the clauses are governed by the law of Ireland; under Clause 18(b), disputes shall be resolved before the courts of Ireland. Annexes I, II, and III to the SCCs are completed by Annexes I and II of this DPA and the Sub-processor Page, respectively.

(b) UK transfers. Where Personal Data protected by the UK GDPR is transferred, the SCCs as completed above apply as amended by the UK Addendum. For the purposes of Table 1 of the UK Addendum the parties are as set out in Annex I; Tables 2 and 3 are completed by reference to Section 13(a) and the Annexes; and for Table 4, either party may end the UK Addendum as set out in Section 19 of the UK Addendum.

(c) Swiss transfers. Where Personal Data protected by the FADP is transferred, the SCCs apply with the following adaptations: references to the GDPR are to be read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; references to “EU Member State” shall be read to include Switzerland; and data subjects in Switzerland may enforce their rights in Switzerland.

(d) If Hyperloop certifies to the EU-U.S. Data Privacy Framework (or a successor lawful transfer mechanism becomes available), Hyperloop may rely on that mechanism instead, provided the transfer remains lawful. If any transfer mechanism is invalidated, the parties shall cooperate in good faith to implement a lawful alternative.

14. US State Privacy Laws

Where US Privacy Laws apply, Hyperloop acts as a “service provider” or “processor.” Hyperloop shall not: (a) sell or share Personal Data (as those terms are defined in US Privacy Laws); (b) retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by US Privacy Laws; (c) retain, use, or disclose Personal Data outside of the direct business relationship between the parties; or (d) combine Personal Data with personal information it receives from other sources, except as permitted by US Privacy Laws. Hyperloop certifies that it understands and will comply with these restrictions, shall notify Customer if it can no longer meet its obligations under US Privacy Laws, and grants Customer the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.

15. Liability; Term; General

Each party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set out in the Agreement, except where prohibited by Data Protection Laws or the SCCs with respect to data subjects’ rights. This DPA remains in effect for as long as Hyperloop processes Personal Data on behalf of Customer. Hyperloop may update this DPA from time to time as required to reflect changes in Data Protection Laws or the Services, provided updates do not materially reduce the protection of Personal Data; material updates will be notified in accordance with the Agreement.

Annex I — Description of Processing (Annex I to the SCCs)

A. List of parties.

Data exporter: Customer (name, address, and contact details as provided in Customer’s account); activities: use of the Services; role: controller (or processor on behalf of a third-party controller). Data importer: HyperloopAI Inc., a Delaware corporation, [registered address], contact: [email protected]; activities: provision of the Services; role: processor.

B. Categories of data subjects.

Customer’s customers, payers, vendors, and other business counterparties and their personnel (e.g., accounts-payable contacts); Customer’s personnel and authorized users of the Services.

C. Categories of Personal Data.

Business contact information (name, job title, business email, phone, address); invoice, billing, payment, credit, and remittance data associated with identifiable contacts; communications and correspondence relating to invoices, collections, disputes, and payment plans (email, SMS, messaging-platform and letter content, including via Slack or Microsoft Teams where connected by Customer); account credentials and usage data of authorized users; data from systems Customer connects to the Services (ERP, CRM, billing, and banking systems).

D. Sensitive data.

None intended. The Services are not designed for special categories of data, and Customer agrees not to submit them.

E. Frequency of the transfer.

Continuous, for the duration of the Agreement.

F. Nature and purpose of the processing.

Hosting, storage, analysis, and orchestration of accounts-receivable and related finance workflows, including automated collections outreach and dunning, billing-query response, cash application and remittance matching, dispute detection and resolution, payment-plan negotiation within Customer-approved policies, forecasting, and reporting; customer support; and service improvement as permitted by the Agreement.

G. Retention.

For the duration of the Agreement plus the deletion period in Section 11, or as otherwise required by applicable law.

H. Competent supervisory authority.

Determined in accordance with Clause 13 of the SCCs (the supervisory authority of the data exporter’s establishment or, where the exporter is not established in the EEA, of its Article 27 representative or of the Member State where the relevant data subjects are located).

Annex II — Technical and Organizational Measures (Annex II to the SCCs)

Hyperloop maintains, at a minimum: encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256); logical tenant separation; role-based access control, least-privilege access, single sign-on and multi-factor authentication for personnel access to production systems; logging and monitoring of production access; vulnerability management and periodic penetration testing; secure software development practices, including code review and dependency scanning; backup and disaster-recovery procedures with defined recovery objectives; personnel security measures, including background checks where permitted by law, confidentiality agreements, and security training; vendor risk assessment of Sub-processors; an incident response plan with defined escalation paths; physical security provided by the certified data centers of Hyperloop’s cloud hosting providers; and a process for regularly testing and evaluating the effectiveness of these measures. [Adjust this Annex to match Hyperloop’s actual current security program before publication.]

Annex III — Sub-processors (Annex III to the SCCs)

The authorized Sub-processors are listed at https://hyperloopai.io/legal/subprocessors, which sets out each Sub-processor’s name, purpose, and location, and is incorporated into this DPA by reference.