Hectofy — Data Processing Addendum (DPA) & Security Policy

Effective Date: August 12, 2026
Last Updated: August 2026


1. Executive Summary

This Data Processing Addendum ("DPA") supplements the Hectofy Master Terms of Service and sets forth the technical, organizational, and security measures implemented by Hectofy Inc. to protect Customer Personal Data and confidential portfolio company financial metrics.


2. Technical & Organizational Security Controls (SOC 2 Alignment)

2.1 Encryption Standards

2.2 Multi-Tenant Cryptographic Isolation

2.3 Access Control & Employee "Break-Glass" Policies

2.4 Data Backup & Disaster Recovery


3. Sub-Processor Registry

Hectofy engages trusted sub-processors for infrastructure, database hosting, and report rendering:

Sub-processor Purpose Location Security Certification
Render Services Inc. Cloud Application Hosting & API Nodes USA SOC 2 Type II, ISO 27001
Resend Inc. Transactional Email Dispatch (Resend API) USA SOC 2 Type II
Google Cloud Platform Gemini 3.5 Pro Enterprise AI Processing USA SOC 2 Type II, ISO 27001
Plaid Inc. Read-Only Financial Ledger Integrations USA SOC 2 Type II, ISO 27001

4. Security Incident Notification

In the event of a confirmed Security Incident impacting Customer Data, Hectofy will notify affected Customers via email without undue delay and no later than 72 hours after becoming aware of the incident, providing detailed remediation steps.


5. Contact Information

Security Team: security@hectofy.com | Hectofy (Registered entity address details will be updated upon final incorporation).