Data Processing Addendum
Last updated: September 3, 2026
This addendum applies when you use a Buhata Space for an organization rather than for yourself, and it forms part of the Terms and Conditions. You do not need to sign or return anything. If you use Buhata personally or with your household, this page does not apply to you and the Privacy Policy is the document that governs your data.
1. Who is who
For anything your members write inside your Space, you are the controller and Buhata LLC is your processor. You decide what the Space is for, who joins it, what your forms ask and what is kept in it. We hold it, serve it back to your members, and do nothing else with it.
Two things sit outside that. Your own account and billing details are ours to control, because we decide what we need to run a subscription. And what a person does with the personal tools attached to their own account, their money, their notes, their calendar, stays theirs and is covered by the Privacy Policy rather than by this page.
2. What we are allowed to do with it
We process Space data only to provide the service, and only on your instructions. Your instructions are this addendum, the Terms, and whatever you do through the app. If a law obliges us to process it some other way, we tell you before we do unless the law forbids us to say.
We do not sell it. We do not use it for advertising. We do not train any model on it. We do not read it to build a profile of you or your members.
3. What is covered
Subject matter and duration. Hosting and serving the contents of your Space, for as long as your Space exists.
Nature and purpose. Storage, transmission, backup, display to the members you authorize, and the safety checks described in section 7.
Types of personal data. Names and Space usernames, email addresses, whatever your members write in posts, threads, chat, tasks and files, and whatever your forms ask for, which is your choice rather than ours.
Categories of data subject. The members of your Space, and anyone your members write about.
4. Confidentiality and our people
The people who can reach Space data are bound to keep it confidential and are reviewed on a schedule. Staff access happens through a console that writes an audit record naming who acted, on what, and when. We do not read your Space content except to answer a support request you raised, to act on a report, or where the law requires it.
5. Security
We keep the measures Article 32 requires, appropriate to the risk. In plain terms: data is encrypted in transit and at rest, access is limited to the few people who need it and reviewed quarterly, every staff account carries multi-factor authentication, and the Security page sets out the rest in ordinary language.
6. Sub-processors
You give us general written authorization to use sub-processors. The current list is published at buhata.com/subprocessors.html, and each of them is bound by written terms no weaker than these. We give notice before a new one starts handling Space data, and you may object; if we cannot offer you an alternative you may end the subscription for that Space and we refund the unused part of the period. We stay responsible to you for what a sub-processor does.
7. Safety checks you cannot switch off
Every picture and document shared in a Space is checked for child sexual abuse material before anybody can open it, and every file is scanned for malware. This is not an instruction you can vary, and it is a condition of using Buhata for shared content. The organization that performs the child-safety check acts as an independent controller rather than as our sub-processor, and the Privacy Policy describes what they receive.
8. Helping you meet your own obligations
If one of your members asks you for their data, to correct it, or to have it deleted, the tools in the app let you answer without us. Where you cannot, write to [email protected] and we will help within the time your own deadline allows.
We will also give you the information you reasonably need for a data protection impact assessment or a consultation with your regulator.
9. If something goes wrong
If we become aware of a personal data breach affecting your Space we tell you without undue delay, with what we know at the time: what happened, who is affected as far as we can tell, what the likely consequences are, and what we are doing about it. We follow up as we learn more. Notifying your regulator is your decision and your deadline, and we give you what you need to make it.
10. International transfers
Buhata LLC is a United States company, so Space data is processed in the United States. Where you are in the EEA, the Standard Contractual Clauses adopted by the European Commission apply and are incorporated into this addendum by reference, with Buhata as data importer. Where you are in the United Kingdom, the ICO's International Data Transfer Addendum applies on the same basis. Our EEA and UK Article 27 representatives are named in the Privacy Policy.
11. Audit
We will answer your reasonable questions about how we handle Space data, in writing, once a year, and will share what we have. We are a small company and do not currently hold a SOC 2 or ISO 27001 report; if that changes we will say so here. Where written answers genuinely will not settle a question, we will agree a proportionate way forward with you rather than refuse.
12. Deletion and return
You can export your Space's contents from inside the app at any time, on any plan. When your Space is deleted we remove its data on the schedule in the Privacy Policy, and backups age out on their own cycle. We keep only what a law obliges us to keep, and only for as long as it obliges us.
13. Conflicts
Where this addendum and the Terms disagree about personal data in a Space, this addendum wins. Everything else in the Terms stands.
Questions go to [email protected].
