Data Processing Agreement
Last updated: 31 August 2026
- Your customers' data stays yours. We process it only to do what you ask Hamla to do.
- We never sell it, and we never train AI models on it.
- Everyone we rely on to run Hamla is named on this page, with 30 days' notice before that list changes.
- Ask us to delete it and we do — within 90 days of you leaving.
This summary is for convenience only — the full text below is what's binding.
This Agreement governs our processing of the personal data you instruct us to process on your behalf when you use the Hamla platform. It forms part of the Terms of Service, and is made between you — as controller of your customers' data — and ALIENZHOUSE LTD as processor.
Your own data — your account and billing details — is data for which we are the controller. That is governed by the Privacy Policy, not by this Agreement.
1. Roles
You are the controller of personal data about your customers, prospective customers and site visitors. We are the processor, acting only on your documented instructions.
Your instructions are given by your use of the platform: the sources you connect, the segments you define, the campaigns you launch and the settings you choose. We do not process personal data for any other purpose.
- ALIENZHOUSE LTD — a private limited company registered in Rwanda, TIN 155603688
- Address: Westerwelle Startup Haus, Gasabo, Kigali, Rwanda
- Data protection contact: dpo@hamla.io
2. Scope of processing
Subject matter: provision of the Hamla platform. Duration: for as long as you hold a Hamla account, plus the retention periods in §7.
Nature and purpose: to receive, store, organise, segment and analyse personal data you supply or authorise us to collect, and to send marketing communications on your behalf through the channels you configure.
We do not sell personal data, and we do not use your customers' personal data to train machine learning models.
3. Data we process
Data subjects: your customers, prospective customers, subscribers, and visitors to your website and connected storefronts. The categories are determined by which sources you connect:
- Identifiers — name, email address, phone number
- Location — city and country (we do not retain full street addresses)
- Commercial — order history, order value and currency, cart and checkout contents, purchase timestamps
- Behavioural — page views, sessions, campaign opens and clicks, on-site events, an anonymous visitor identifier
- Communication — channel subscription status and consent decisions, message delivery and engagement history
We request the minimum from each platform. From a connected Shopify store we read orders, products and customers and nothing else, under read-only scopes that permit no writes.
4. Sub-processors
You give general authorisation for the sub-processors below. We give at least 30 days' notice before adding or replacing one, and you may object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected service without penalty. Each is bound by a written agreement imposing protections no less protective than this Agreement.
4.1 Infrastructure
- Vercel — application hosting (USA)
- Neon — primary database (USA)
- Amazon Web Services — object storage, transactional email (USA)
- Upstash — cache and job queues
4.2 Delivery channels
- Resend — email delivery
- Twilio — SMS and WhatsApp delivery
4.3 Operations
- Sentry — error monitoring
- Better Stack — application logging
- Polar — subscription billing: your billing details only, never your customers' data
4.4 AI model providers
Hamla uses large language models to draft campaign content and to answer your questions about your own data. Where you ask the assistant about your contacts, or ask it to write copy referencing them, personal data may be transmitted to the provider of the model you have selected.
- Anthropic — default models (USA)
- OpenAI — where selected (USA)
- Google — where selected (USA)
These providers are engaged under terms that prohibit training on data submitted through their APIs. You control exposure by choosing which model to use and what you ask the assistant to do.
4.5 At your direction only
Where you connect an advertising or social platform (for example Meta or TikTok), Hamla transmits data to it only to execute what you have configured — conversion measurement, audience sync, or publishing. That platform acts under its own terms with you, and is not a sub-processor of Alienzhouse.
5. International transfers
Alienzhouse is established in Rwanda and its sub-processors are principally in the United States. Cross-border transfer to the United States is authorised by Rwanda's National Cyber Security Authority (NCSA) under Law N° 058/2021.
Where personal data originates in a jurisdiction requiring an additional transfer mechanism, transfers are made under Standard Contractual Clauses or an equivalent mechanism, incorporated into this Agreement by reference.
6. Security measures
We implement appropriate technical and organisational measures, reviewed at least annually:
- Encryption in transit and at rest, and encrypted backups
- Staff access to personal data is limited, and that access is logged
- Development and test environments are separate from production
- Tenant isolation, so one business cannot reach another's data
- Third-party access tokens stored apart from configuration, and erased when a connection is removed
- Managed, encrypted, point-in-time backups and redundant hosting
- A documented security incident response procedure
7. Retention & deletion
- Transaction and order records — 5 years
- Support correspondence — 2 years
- Analytics and behavioural events — 12 months
- Contact records — for the life of your account, then as below
When a data subject's deletion request reaches us — from you, directly, or through a connected platform — we erase that contact's identifying fields and retain the record only in de-identified form, so your historical reporting does not silently change. Where a platform sends a shop-level erasure request, we erase the personal data received from that platform and revoke the stored credentials.
On termination you may export your data. We then delete it within 90 days, except where retention is required by law, in which case it is isolated and protected until deletion is permitted.
8. Data subject rights
We assist you, at our own cost and within a reasonable time, with your obligations to data subjects: access, rectification, erasure, restriction, portability and objection. Contact records can be exported and deleted from the dashboard; where a request cannot be satisfied that way, contact our data protection address.
We also assist with impact assessments and prior consultation, taking into account the nature of processing and the information available to us. Every marketing message carries a working unsubscribe link, inbound opt-out keywords are honoured automatically, and consent state is recorded per channel, per contact, with its source.
9. Data breaches
We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data, with the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken.
10. Confidentiality
Personnel authorised to process personal data are bound by written confidentiality obligations, and access is limited to those who need it to perform their role.
11. Audit
We make available the information necessary to demonstrate compliance with this Agreement, and allow for and contribute to audits by you or an auditor you mandate, on reasonable notice, no more than once per year unless a breach or a regulator requires otherwise.
12. Governing law
Liability is as set out in the Terms of Service. This Agreement is governed by the laws of the Republic of Rwanda, and by any data protection law applicable to you that imposes stricter obligations, which prevail to that extent. In conflict, this Agreement prevails over the Terms of Service on matters of personal data processing.