SKIP TO CONTENT
369 Hertz

369 HERTZ · CREATIVE TECHNOLOGY STUDIORECORD 003 / SECURITY & PRIVACY

Written for your security reviewer.

Everything procurement usually has to ask for, published up front. Anything this page doesn't answer: security@369hertz.com (PGP available).

DPA · SUB-PROCESSORS · QUESTIONNAIRES · SECURITY.TXT

369 HertzCREATIVE TECHNOLOGY STUDIO
DOC 369-SEC-01REV 2026-07EFFECTIVE 2026-07-01SUPERSEDES 2026-01

0.0 · IN SHORT

PRODUCTION DATA ACCESS
NONE, BY DESIGN
DPA
READY TO COUNTERSIGN
SUB-PROCESSORS
PUBLISHED BELOW
QUESTIONNAIRES (SIG/CAIQ)
5 BUSINESS DAYS

1.0 · DATA WE HANDLE

The engagement model keeps the data surface small: we design and build the interface layer against fixtures and staging environments. We never hold production data.

Categories of data we handle, with what each one covers, where it is stored, and how long it is retained.
CATEGORYWHATWHERERETENTION
1.1Contact & contractNames, work emails, agreements, invoicesEncrypted storage, EURelationship + statutory period
1.2Project artifactsResearch notes, designs, code, documentationYour repo + encrypted storageTransferred or deleted ≤ 90 days after close
1.3Research recordingsSession recordings, only with participant consentEncrypted, access-limitedDeleted ≤ 90 days after synthesis
1.4Production dataNone. Fixtures and staging only. The boundary is contractual, not aspirational.

2.0 · SECURITY POSTURE

2.1ACCESS

Hardware-key MFA on every account. Least-privilege access to client systems, requested per engagement, revoked at close, same day.

2.2DEVICES

Managed, full-disk-encrypted machines with screen locks and automatic updates enforced. No client work on personal devices.

2.3ENCRYPTION

All data encrypted in transit (TLS 1.2+) and at rest. Secrets in a managed vault, never in repositories or documents.

2.4DEVELOPMENT

Dependencies pinned and audited. Code reaches your repo through reviewed pull requests only: no direct pushes, no side channels.

2.5INCIDENTS

Documented response plan. Affected clients notified within 72 hours of a confirmed incident, with a written post-mortem.

2.6INSURANCE

Professional liability and cyber coverage held; certificates available on request.

3.0 · DPA & CONTRACTS

Paper that doesn't need a redline round.

Standard terms drafted to pass review as-is. Your paper works too; we've signed plenty of it.

  • 3.1Data Processing Agreement (GDPR Art. 28), ready to countersignSTANDARD
  • 3.2Standard Contractual Clauses for any cross-border transferINCLUDED
  • 3.3Mutual NDA before any product detail is shared, including in the contact formDEFAULT
  • 3.4Breach notification within 72 hours, in writingCONTRACTUAL
  • 3.5IP assignment on payment: code merged into your repo is yoursSTANDARD

4.0 · SUB-PROCESSORS

The complete list. There is no shadow tooling. Changes are announced 30 days in advance to active clients.

Every sub-processor we use, with its purpose, hosting region, and the transfer safeguard in place.
PROVIDERPURPOSEREGIONSAFEGUARD
4.1GitHubSource code hosting and reviewUSDPA + SCCs
4.2Google WorkspaceEmail, documents, video callsEU-pinnedDPA
4.3HetznerEncrypted project file storageEU (DE)DPA
4.4PlausibleSite analytics: cookieless, aggregate onlyEUDPA

RESEARCH RECORDINGS AND CLIENT ARTIFACTS NEVER TOUCH TOOLS OUTSIDE THIS LIST.

5.0 · VENDOR QUESTIONNAIRES

SIG Lite, CAIQ, and custom questionnaires returned within five business days. A call with your security team is available at no charge during evaluation. Bring the hard questions.

6.0 · REPORTING A CONCERN

security@369hertz.com has its PGP key published alongside /.well-known/security.txt. Good-faith reports acknowledged within one business day.

Send this page to procurement. Then let's talk about the work.

START A CONVERSATION DPA, sub-processor list, and questionnaire answers on request.

NEXT · RECORD 004 / WRITING & BUILDS