Last updated: April 14, 2026
This Data Processing Agreement ("DPA") is made between:
1. Controller: The Customer utilizing Hiro Analytics' services ("Customer" or "Agency").
2. Processor: Hiro Analytics Inc., a company incorporated under the laws of the State of Delaware, located at 1111b S Governors Ave STE 25084, Dover, DE 19904, USA ("Hiro" or "Service Provider").
This DPA outlines the terms under which personal data will be processed by the Processor on behalf of the Controller, in compliance with relevant data protection laws.
The subject of this DPA is the processing of data by Hiro Analytics for the purpose of providing analytics and retention marketing services, including AI-assisted analytics features. This agreement is effective for the duration of the Controller's use of the services, including any backup retention periods necessary under legal obligations.
The data processing activities involve collecting, storing, organizing, and analyzing:
These processing activities are conducted solely to deliver the services contracted by the Controller, such as generating reports, tracking marketing attribution, analyzing sales trends, and providing AI-assisted analytics responses through Hiro's platform features. Data is never shared with any third party except for the sub-processors listed in Section 5.
All data is processed in the United States. The Processor ensures that adequate measures are in place to protect the data transferred, in compliance with applicable data protection laws.
The Processor engages the following sub-processors for data processing:
The Processor ensures that these sub-processors comply with data protection obligations consistent with this DPA.
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
The Processor shall assist the Controller in responding to requests from data subjects, in accordance with applicable data protection laws, including requests to access, correct, delete, or restrict processing of personal data.
Upon termination of the service, the Processor shall, at the Controller's request, delete or return all personal data, except where retention is required by law. With respect to AI-assisted features, Anthropic retains API inputs and outputs for up to 7 days for trust and safety purposes before automatic deletion; Hiro does not retain query content beyond what is necessary to deliver the service response.
The Controller acknowledges that the use of the Service is at its own risk. The Service is provided in a competent and professional manner but is offered "AS IS." Hiro makes no representations, warranties, or guarantees, express or implied, regarding the Service, including but not limited to any implied warranties of fitness for a particular purpose, non-infringement, or quality.
To the fullest extent allowed by law, Hiro shall not be liable for any direct, indirect, incidental, special, or consequential damages, lost profits, or business interruptions arising from the Controller's use of, or inability to use, the Service, or any errors or omissions, even if Hiro has been advised of the possibility of such damages.
For the avoidance of doubt, Hiro shall not be liable for any claims, damages, or losses arising from or related to the independent data practices of any sub-processor, including without limitation any use of data by a sub-processor for artificial intelligence model training or improvement purposes.
Hiro does not use Controller data or End-Client data to train, fine-tune, benchmark, or otherwise improve any artificial intelligence or machine learning model operated by Hiro. Data processed through Hiro's AI-assisted features is used solely to generate real-time responses to the Controller's queries and for no other purpose.
Hiro engages third-party AI inference providers as sub-processors (see Section 5). While Hiro requires its sub-processors to comply with data protection obligations consistent with this DPA, Hiro does not accept liability for the independent data practices of sub-processors, including any use of data by a sub-processor for model training purposes. The Controller acknowledges that sub-processor data practices are governed by the sub-processor's own terms of service and data processing agreements, and that the Controller should independently review those terms prior to use of any AI-assisted feature.
Model Context Protocol Integration — Agency Responsibilities & Data Use
The following terms apply specifically to Agency customers who activate and use Hiro's Model Context Protocol integration (the "MCP Feature"), which enables AI-assisted querying of client analytics data. Part II supplements and is governed by the terms of Part I. In the event of conflict, Part II prevails with respect to MCP Feature use.
The MCP Feature allows Agency users to submit natural language queries about their clients' marketing and sales data. Queries are processed in real time by Anthropic, Inc. as AI inference sub-processor (see Section 5) and return analytical responses. Each Agency account is logically isolated — no client data is accessible to or shared with any other Agency account through the MCP Feature.
By activating or using the MCP Feature, Agency represents, warrants, and covenants to Hiro as follows:
Agency has reviewed its service agreements, statements of work, and any applicable data processing or confidentiality agreements with each end-client whose data may be queried through the MCP Feature. Agency has the contractual right and authority to access and process such data using third-party AI-assisted analytics tools.
Agency has assessed whether its use of AI-assisted tools to access data held within third-party marketing platforms (including without limitation Klaviyo and Shopify) on behalf of end-clients is consistent with those platforms' applicable terms of service and data use policies. Agency will not use the MCP Feature in a manner that causes a breach of any such platform terms.
Agency is responsible for ensuring its use of the MCP Feature complies with all applicable data protection and privacy laws, including but not limited to:
Where required, Agency shall ensure a valid legal basis exists for processing personal data through the MCP Feature and shall execute any required data processing agreements with end-clients prior to use.
Consistent with Section 3 of this DPA, Agency shall not intentionally structure queries through the MCP Feature to retrieve, reconstruct, or expose personally identifiable information of end-client customers.
Where required by applicable law, contractual obligation, or end-client agreement, Agency shall disclose to its end-clients that AI-assisted analytics tools are used in connection with their data, and shall obtain any required consents or authorizations prior to use of the MCP Feature for that end-client's data.
Agency shall defend, indemnify, and hold harmless Hiro Analytics Inc., its officers, directors, employees, contractors, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:
By accessing or using the Hiro Analytics platform, you agree to be bound by the terms of this Data Processing Agreement on behalf of yourself and the agency you represent. If you do not agree to these terms, you may not use the Hiro Analytics platform.
Hiro Analytics Inc. reserves the right to update this DPA from time to time. Continued use of the platform following notice of any update constitutes acceptance of the revised terms.