Haul

Data Processing Agreement

Last updated: 12 July 2026

This DPA applies between the coordinating organisation using Haul (the “Controller”) and the operator of Haul (the “Processor”), and forms part of the Terms of Service. It reflects Article 28 of the GDPR. A signed copy is available on request.

1. Roles

The organisation that manages a project in Haul is the Controller: it decides which participant data is entered and why. Haul is the Processor: it processes that data only to provide the service, on the Controller's documented instructions (which include using the tool as designed).

2. Subject matter, nature and purpose

Processing consists of storing and computing grant estimates and generating budget documents for European youth mobility projects. It lasts for as long as the Controller keeps a project in Haul.

3. Categories of data and data subjects

  • Data subjects: project participants (which may include minors), group leaders, facilitators, accompanying persons, and coordinator account holders.
  • Data: names, roles, sending country, origin city and travel distance, green-travel and fewer-opportunities flags, and any documents the Controller chooses to upload; coordinator email and organisation name.
  • No special-category data is required by the tool. A “fewer opportunities” flag is a yes/no indicator only.

4. Processor obligations

  • Process personal data only on the Controller's documented instructions.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures (see section 7).
  • Assist the Controller in responding to data-subject requests (access, rectification, erasure).
  • Notify the Controller without undue delay after becoming aware of a personal-data breach.
  • Delete or return all personal data at the end of the service, unless retention is legally required.
  • Make available information needed to demonstrate compliance and allow for reasonable audits.

5. Sub-processors

The Controller authorises the following sub-processors:

  • Supabase — database, authentication and file storage, hosted in the European Union.
  • Vercel — application hosting and delivery.
  • A transactional email provider — solely for sending login codes and service emails.

Haul remains responsible for its sub-processors and will inform the Controller of intended changes, giving the opportunity to object.

6. International transfers

Personal data is stored in the European Union. Where any sub-processor operates outside the EU, transfers are covered by appropriate safeguards (such as Standard Contractual Clauses).

7. Security measures

  • Per-organisation data isolation enforced at the database level (row-level security on every table).
  • Encryption of data in transit (HTTPS/TLS).
  • Private file storage — uploaded documents are never publicly accessible.
  • Access to production secrets restricted to server-side use; no secrets exposed to browsers.
  • An append-only audit log of key actions.
  • Data minimisation — the tool asks only for what the funding rules require.

8. Deletion and export

On request, the Controller can obtain an export of its data and have all of it deleted. Deleting an organisation removes its projects, activities, participants, documents and calculation records.

Contact