Last updated: October 8, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you, the creator who runs an app, game, website or agent on Harbor (“you”, the controller), and LastLap Lab LLC, 928 Lovell Ave NW, Bainbridge Island, Washington 98110-1722, United States (“Harbor”, the processor). It applies whenever Harbor processes personal data about the users of your project on your behalf, and it meets Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR. You accept it by using Harbor; no signature is needed.
Harbor processes this personal data only on your documented instructions, which are these Terms, this DPA, and how you configure and use your project. If Harbor is required by law to process it otherwise, we will tell you first unless the law forbids it. We will tell you if we believe an instruction breaks data protection law.
Everyone at Harbor who can access this data is bound by confidentiality, and accesses it only where needed to run, support or secure the service.
Harbor takes appropriate technical and organisational measures (Article 32 GDPR), including: encryption in transit; encryption at rest for secrets and connected-service tokens; private storage for source code and private files; access to each project limited to its workspace and checked on every request; a per-app audit log of changes; rate limits and abuse controls; and deletion and retention schedules.
You give Harbor general authorisation to use the subprocessors listed on our subprocessors page. Harbor binds each one by a written contract with data protection obligations equivalent to this DPA and remains responsible for them. We will update that page at least 30 days before adding or replacing a subprocessor; you can object by email within that time on reasonable data protection grounds, and if we cannot address the objection you may stop using the affected feature or delete your account.
Harbor is based in the United States and processes data there and wherever its subprocessors operate. For transfers of personal data from the EU/EEA, the parties incorporate the Standard Contractual Clauses adopted by European Commission Decision (EU) 2021/914, Module Two (controller to processor), with you as data exporter and Harbor as data importer; Clause 7 (docking) applies; option 2 of Clause 9 (general authorisation, with the notice period in section 5) applies; the optional wording in Clause 11 does not; Clause 17 is governed by Irish law and Clause 18 disputes go to the courts of Ireland; Annex I is section 1 of this DPA and Annex II is section 4. For the UK, the International Data Transfer Addendum issued by the Information Commissioner applies to those clauses; for Switzerland, references to the GDPR include the Swiss Federal Act on Data Protection. Harbor relies on equivalent safeguards (Standard Contractual Clauses or the EU-US Data Privacy Framework) with its own subprocessors.
Harbor gives you tools to answer requests from your users: each app's settings can export or delete one person's data, users can delete their own data in an app where you offer it, and a whole app's data can be exported. If a user contacts Harbor about your project, we will pass the request to you rather than answer it ourselves, unless it concerns their Harbor sign-in, which Harbor controls. Harbor will also give you reasonable help with data protection impact assessments and consultations with authorities, as far as they concern Harbor's processing.
Harbor will notify you without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting your project, with what we know about its nature, the likely consequences, the data and people concerned, and what we are doing about it, and will update you as we learn more.
When you delete a project or your account, Harbor deletes the personal data it processed for that project, including stored files, within the backup cycle of its providers (normally within 30 days), except where law requires us to keep it (for example payment records). You can export your project's data at any time before deleting it.
On request, Harbor will provide the information reasonably necessary to demonstrate compliance with this DPA, including a written description of its security measures and its subprocessors' certifications. Where that is not enough, you may carry out an audit at your own cost, with 30 days' notice, no more than once a year, under confidentiality, and in a way that does not disrupt the service or expose other customers' data.
You are responsible for having a lawful basis for the processing, giving your users the information the law requires (you can link your privacy policy on your app's sign-in screen), and making sure your instructions are lawful.
If this DPA conflicts with the Terms, this DPA prevails for personal data; if it conflicts with the Standard Contractual Clauses, the Clauses prevail. Liability under this DPA is subject to the limits in the Terms, except where the law does not allow that. Questions and notices: [email protected].