HabitHabitant
Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the Terms of Service and governs how HabitHabitant LLC ("HabitHabitant") processes personal data on behalf of its users, in accordance with applicable data protection laws including the GDPR and Japan's APPI.
1. Controller / Processor
When users interact with HabitHabitant's services, the user acts as the Controller — the party that determines the purposes and means of processing their personal data. HabitHabitant acts as the Processor, processing personal data solely on the Controller's behalf and in accordance with documented instructions.
HabitHabitant will not process personal data for any purpose beyond what is necessary to provide and maintain the services, unless required to do so by applicable law.
2. Sub-processors
HabitHabitant may engage third-party sub-processors to assist in delivering its services (for example, cloud infrastructure, analytics, or communication providers). HabitHabitant ensures that each sub-processor is bound by data protection obligations at least as protective as those set out in this DPA.
HabitHabitant will provide notice of any new or changed sub-processors by updating this DPA. Users who object to a sub-processor change may contact us before the change takes effect. A list of current sub-processors is available upon request at our contact page.
3. Deletion
Upon termination of the service relationship, or upon a user's request, HabitHabitant will delete or render anonymous all personal data in its possession unless retention is required by applicable law.
Users may request deletion of their personal data at any time by contacting us at our contact page. Deletion requests will be processed within 30 days.
4. Breach Notification
In the event of a personal data breach — meaning any unauthorized access, disclosure, alteration, or loss of personal data — HabitHabitant will notify affected users without undue delay, and no later than 72 hours after becoming aware of the breach where feasible.
Notification will include: the nature of the breach; the categories and approximate number of data subjects affected; the likely consequences; and the measures taken or proposed to address the breach. If a full notification cannot be provided within 72 hours, an initial notice will be sent with further information to follow.