Skip to main content
About Horizon RunwayOpen the app

For organizations

Data Processing Agreement

The agreement an organization signs when its people use Horizon Runway. It sets out what we process, on whose instructions, who else can see it, how long we keep it, and what happens when the relationship ends.

Before you read

This is an unsigned template, published so you can review our terms before you ask for them. It has not yet been through outside counsel and is not legal advice. We will countersign a final version — ours or yours — as part of an agreement.

Prefer your own paper? Send it. We would rather sign your DPA than argue about ours, and this template exists so you can see we have nothing to hide in the exchange.

Version 2026-08-02

To be completed on execution

  • Customer legal name and address
  • Effective date
  • The service being provided, if narrower than general access to Horizon Runway
  • Notice contacts on both sides
  • Horizon Runway's registered entity name and state, once formation completes (today: Horizon Runway, formation in progress)

1. Parties, scope, and order of precedence

1.1Parties

This Data Processing Agreement ("DPA") is entered into between Horizon Runway ("Processor", "we", "us") and the organization identified in the order or agreement it is attached to ("Customer", "you").

It forms part of, and is governed by, the agreement between the parties for the use of Horizon Runway (the “Agreement”).

1.2Roles

For personal data processed on Customer's behalf, Customer is the controller (or business) and Processor is the processor (or service provider). Processor processes that data only on Customer's documented instructions, which the Agreement and this DPA constitute in full.

Where an individual uses Horizon Runway on their own account rather than under Customer's instruction, Processor acts as controller for that individual's data under its published privacy policy, and this DPA does not apply to it.

1.3Precedence

If this DPA conflicts with the Agreement on the handling of personal data, this DPA governs. If a signed data protection addendum on Customer's own form is executed by both parties, that form governs over this one.

1.4The nature of the service

Horizon Runway is a Financial Forecasting calculator. It does not hold, move, or transmit funds, it is not a bank, broker, lender, or financial adviser, and it does not connect to financial institutions. Processor gives no investment, tax, or legal advice, and forecasts are estimates produced from figures the user enters.

Processor holds no certification or audit attestation (including SOC 2, ISO 27001, PCI-DSS, HIPAA, or GDPR certification) and makes no representation that it does. Nothing in this DPA should be read as such a claim.

2. What is processed

Annex A sets out the full detail. This section states the boundary, because the boundary is the substance of this agreement.

2.1Subject matter and duration

Subject matter: providing the Horizon Runway forecasting service to Customer's users. Duration: the term of the Agreement, plus the deletion window in clause 8.

2.2Architecture, and why the processing is minimal

By default, a user's forecast data — balances, bills, income, scenarios — is stored in that user's own browser on their own device and is never transmitted to Processor. Cloud storage occurs only where an individual user switches on cloud backup for their own account.

The practical consequence is that for most users Processor holds no forecast data at all. This is a design choice, and Processor will not change it without updating its public trust page and giving Customer notice under clause 5.3.

2.3Categories of data

The categories Processor may process are:

  • Forecast data, on the device — Balances, bills, income, and scenarios are stored in the browser by default and never leave it unless cloud backup is switched on.
  • Cloud backup, if enabled — One copy of the same forecast data, held on Lovable Cloud and readable only by the signed-in account. It can be deleted from Settings at any time.
  • Account identity — An email address, and — if the person signs in with Google — the identifier Google returns. Used for sign-in and support, nothing else.
  • Support and feedback messages — What someone chooses to write to us, and our replies.
  • Operational records — Standard request logs and crash reports produced by the hosting platform, used to keep the service working.

2.4Categories expressly excluded

Processor does not collect, request, or provide any field for the following. Customer must not submit them, and Processor's systems are not designed to receive them:

  • No bank credentials: There is no field for a bank username or password anywhere in Horizon.
  • No bank connections: Horizon does not connect to financial institutions today. If that ever ships it will be opt-in, and this page will change first.
  • No card or payment details: Payments, when they start, are handled entirely by Stripe. Card numbers never reach Horizon's systems.
  • No Social Security or government ID numbers: Horizon has no use for them and no place to put them.
  • No credit reports or scores: Horizon does not pull, hold, or resell credit data.
  • No advertising trackers or third-party analytics SDKs: Horizon is not funded by advertising and does not sell or share data.

2.5Data subjects

Individuals who use Horizon Runway under the Agreement — Customer's employees, members, students, or clients as applicable — and Customer personnel who correspond with Processor for support.

2.6Special categories and children

Processor does not intentionally process special category data, government identifiers, health data, or biometric data, and the service is not directed to children under 13. Customer must not use the service to submit such data.

3. Processor obligations

3.1Instructions only

Processor processes Customer personal data only to provide and support the service, and only on Customer's instructions, unless a law it is subject to requires otherwise — in which case Processor will tell Customer before processing, unless that law forbids it.

3.2No sale, no sharing, no advertising

Processor does not sell or share personal data, does not use it for cross-context behavioural advertising, does not retain, use, or disclose it for any purpose other than providing the service, and does not combine it with data from other sources except as permitted for a service provider under applicable law. Processor certifies that it understands and will comply with these restrictions. Processor runs no advertising trackers and no third-party analytics SDKs.

3.3Confidentiality

Access to Customer personal data is limited to personnel who need it to provide or support the service. Those personnel are bound by confidentiality obligations that survive the end of their engagement. Processor is a small team, and administrative access is limited accordingly — there is no shared login.

3.4Assistance to Customer

Taking into account the nature of the processing and the information available to it, Processor will provide reasonable assistance with Customer's obligations for data subject requests, data protection impact assessments, prior consultations, and security of processing. Because most data is device-local, in many cases the honest answer will be that Processor holds nothing responsive, and Processor will say so in writing.

3.5Data subject requests

Where Processor receives a request from one of Customer's data subjects, it will not respond directly except to confirm receipt and to direct them to Customer, unless legally required or authorised by Customer. Processor will forward the request without undue delay. Requests may be sent to support@horizonrunway.com.

Processor acknowledges deletion and access requests within three business days and completes them within 30 days.

4. Customer obligations

4.1Lawful basis and notice

Customer is responsible for having a lawful basis for the processing it instructs, for giving its data subjects any required notice, and for the accuracy of instructions it issues.

4.2What Customer decides

Customer's users decide whether to enable cloud backup at all, are responsible for protecting their own sign-in and device, and own the figures they enter and any financial decision they take from a forecast. Processor is responsible for producing an accurate projection from the figures given to it.

4.3No employer or institutional visibility

Horizon Runway is an individual tool. There is no administrator dashboard and no per-person reporting, and Customer will not receive its users' financial data through the service. Where a usage report is agreed, it contains anonymous aggregate counts only.

5. Subprocessors

5.1General authorisation

Customer gives general authorisation for Processor to engage the subprocessors listed in Annex B. Processor remains fully liable to Customer for their performance.

5.2Flow-down

Processor imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, by written contract, before that subprocessor processes Customer personal data.

5.3Changes and objection

We keep this list current. If we add a subprocessor that can see customer data, we update this page, and organizational customers on a signed agreement get notice before the change takes effect.

Processor gives Customer at least 30 days' written notice before a new subprocessor with access to Customer personal data begins processing. Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected part of the Agreement without penalty and receive a pro-rata refund of prepaid fees.

6. Security

6.1Technical and organisational measures

Processor maintains appropriate technical and organisational measures for the risk presented, described in Annex C. Processor may update those measures, provided it does not materially reduce the overall level of protection.

6.2Encryption

All traffic is served over HTTPS, and data stored in the managed database is encrypted at rest by the platform. Processor does not claim end-to-end encryption and will not represent otherwise.

6.3Audits and evidence

Processor holds no third-party audit report today. In place of one, Processor will complete Customer's security questionnaire (including HECVAT Lite for higher education), provide its published subprocessor list, retention schedule, and continuity summary, and answer follow-up questions in writing.

Where Customer's own regulator or policy requires an on-site or documentary audit, the parties will agree scope and timing in advance, and Customer bears its own costs. Where a certificate of insurance or a third-party penetration test attestation becomes a condition of the Agreement, the parties will record that as a dated commitment rather than imply either exists today.

7. Personal data breach

7.1Notification

Processor notifies Customer without undue delay, and in any case within 72 hours, after confirming a personal data breach affecting Customer personal data it holds. Notice goes to Customer's stated contact, and Processor will not delay it to finish a communications plan.

7.2Contents of the notice

The notice states what happened, what data was involved, what Processor has done and is doing, and what Customer and affected people should do. Where the full picture is not yet known, Processor sends what it has and follows up as it learns more.

7.3Cooperation

Processor cooperates reasonably with Customer's own regulatory notification obligations. Notification under this clause is not an admission of fault by either party.

7.4Reporting a vulnerability

Security issues may be reported to support@horizonrunway.com with “Security report” in the subject line. Processor acknowledges within three business days and does not pursue good-faith researchers.

8. Retention, return, and deletion

8.1Retention schedule

Processor applies the following retention rules:

  • Device data: Lives until the person clears it. Settings → Clear everything removes it immediately, along with any cloud copy.
  • Cloud backup: Kept while the account exists. Deleting the account removes it; backups age out of platform storage within 30 days.
  • Support and feedback: Kept for up to 24 months so we can follow a conversation, then deleted. We erase sooner on request.
  • Operational logs: Retained by the hosting platform on its standard short rolling window and used only for reliability and abuse handling.
  • Erasure requests: Email support@horizonrunway.com and we erase everything held for that address. We acknowledge within three business days and complete within 30 days.

8.2On termination

At Customer's choice, Processor deletes or returns Customer personal data it holds within 30 days of the end of the Agreement, and deletes existing copies unless a law requires it to keep them — in which case Processor tells Customer what it must keep and why. Platform backups age out within 30 days.

8.3Portability

Every user can export their complete data as plain JSON at any time, without contacting Processor. There is no export fee and no lock-in period.

9. International transfers

9.1Location

Processor and its subprocessors are established in the United States, and processing takes place there.

9.2Transfer mechanism

Where Customer is established in the EEA, Switzerland, or the United Kingdom and a transfer mechanism is required, the parties will execute the European Commission's Standard Contractual Clauses (Module Two, controller to processor) together with the UK International Data Transfer Addendum where applicable. Those clauses, once executed, are incorporated into this DPA, and Annexes A to C serve as their annexes.

10. US state privacy terms

10.1Service provider status

For the CCPA/CPRA and comparable state laws, Processor is a service provider or processor. It receives personal information only to perform the service, and clause 3.2 states the restrictions it accepts. Customer may take reasonable and appropriate steps to confirm Processor's use of personal information is consistent with its obligations.

10.2Financial services boundary

Under the current design, Processor does not receive non-public personal information from a financial institution Customer: individuals enter their own figures, and Processor does not access Customer's systems. If a future integration changes that, the parties will address GLBA and Safeguards Rule obligations, including a written safeguards commitment, before that integration is enabled.

10.3Education records

Processor receives no roster, enrollment data, or student records, and is not designated a school official with a legitimate educational interest unless the parties separately agree it in writing.

11. General

11.1Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.

11.2Governing law

Horizon Runway is a United States company whose formation is being completed. Until we name the home state here, these terms are governed by United States law and the law of the state where the company is registered, without regard to conflict-of-law rules.

11.3Changes to this DPA

This template is versioned. The current version is 2026-08-02, and the version in force between the parties is the one executed, not whatever is published later.

11.4Signatures

Signed for and on behalf of each party by an authorised representative. Name, title, and date to be completed on execution.

Annex A — Details of processing

Nature and purpose: providing a Financial Forecasting calculator to individual users. Frequency: continuous for the term. Categories of data processed:

  • Forecast data, on the device — Balances, bills, income, and scenarios are stored in the browser by default and never leave it unless cloud backup is switched on.
  • Cloud backup, if enabled — One copy of the same forecast data, held on Lovable Cloud and readable only by the signed-in account. It can be deleted from Settings at any time.
  • Account identity — An email address, and — if the person signs in with Google — the identifier Google returns. Used for sign-in and support, nothing else.
  • Support and feedback messages — What someone chooses to write to us, and our replies.
  • Operational records — Standard request logs and crash reports produced by the hosting platform, used to keep the service working.

Forecast data is processed on the user's own device by default. Processor holds a copy only where a user enables cloud backup for their own account.

Annex B — Approved subprocessors

The list below is the same one published at horizonrunway.com/trust.

  • Lovable — Application hosting and content delivery. Standard web request metadata: IP address, user agent, timestamps.
  • Lovable Cloud — Managed database, authentication, and optional cloud backup. Account email, and forecast data only for people who turn cloud backup on. Encrypted in transit and at rest by the platform.
  • Resend — Transactional email delivery — invites, replies, account mail. Recipient email address and the contents of the message being sent.
  • Google — Optional sign-in with Google. Only for people who choose it: the email address and account identifier Google returns. Engaged only where the Customer's users choose that feature.
  • Stripe — Payment processing for paid plans. Billing details entered directly with Stripe. Horizon receives a subscription status, never card data. Engaged only where the Customer's users choose that feature.

We keep this list current. If we add a subprocessor that can see customer data, we update this page, and organizational customers on a signed agreement get notice before the change takes effect.

Annex C — Technical and organisational measures

Processor operates the following measures today:

  • Accounts are optional: Horizon works fully without an account. Signing in exists to sync devices and survive a cleared browser.
  • Row-level isolation: Every stored record is scoped to its owner at the database level, so one account's data is not reachable from another.
  • Least privilege: Administrative access is limited to the founder and used only for support and incident response. There is no shared login.
  • Encryption in transit and at rest: All traffic is served over HTTPS. Cloud backups are encrypted by Horizon with a per-account key before they are written, on top of the managed platform's own at-rest encryption.
  • Data minimisation: the product is designed so that most personal data never reaches Processor's systems.
  • No credential storage: there is no field anywhere in the product for a bank username, password, or account number.
  • Payment isolation: card details are entered directly with the payment processor and never reach Processor's systems.
  • Managed backups with point-in-time recovery on the cloud database.
  • Published vulnerability disclosure policy with a three-business-day acknowledgement.
  • Breach notification within 72 hours of confirmation.

Measures not yet in place, stated plainly: no third-party penetration test attestation, no SOC 2 or ISO 27001 report, no cyber liability certificate of insurance, and no SAML SSO. Each is available to discuss as a dated commitment.

Next step

Write to support@horizonrunway.com and we will complete your questionnaire and send a version ready for signature. The facts behind every clause here are published on the trust page.