Data protection

Data Processing Addendum

1. Definitions and roles

“Agreement” means the accepted order form, the SaaS Terms, this DPA, and their incorporated documents. “Customer Personal Data” means personal data in Customer Data that Provider processes on Customer's behalf. “Data Protection Laws” means privacy and data-protection laws applicable to that processing. “Personal Data Breach,” “process,” “processor,” “controller,” “service provider,” and “subprocessor” have the meanings given by applicable Data Protection Laws.

Customer is controller or business and Provider is processor or service provider for Customer Personal Data. Each party remains independently responsible for personal data it processes as its own controller, including its business contacts, account administration, fraud prevention, and legal compliance.

2. Instructions and purpose limitation

Provider will process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's authorized use and configuration of the Service, support requests, and lawful written instructions consistent with the Agreement. Provider will tell Customer if it reasonably believes an instruction violates Data Protection Laws, unless law prohibits notice, and may pause the affected processing while the parties resolve it.

Provider will not sell or share Customer Personal Data for cross-context behavioral advertising, retain or use it outside the direct business relationship except as permitted by law, or combine it with personal data from another source except as needed to provide and secure the Service or as law permits a processor or service provider.

3. Customer responsibilities

Customer will ensure that its instructions and Customer Personal Data are lawful, accurate, limited to what is needed, and covered by appropriate notices, rights, permissions, and legal bases. Customer will not provide prohibited sensitive data described in the SaaS Terms unless the parties first amend the Agreement with appropriate safeguards. Customer is responsible for handling requests and communications from its data subjects, with Provider's assistance under this DPA.

4. Confidentiality and personnel

Provider will limit Customer Personal Data access to personnel and contractors who need it to provide, secure, support, or legally administer the Service. They must be bound by confidentiality obligations and receive access appropriate to their role. Provider remains responsible for their compliance with this DPA.

5. Security

Taking account of the service's early-access scope, the state of the art, implementation cost, processing context, and risk, Provider will maintain appropriate technical and organizational measures described in Schedule 2. Provider may update the measures as technology and risks change, but will not materially reduce the overall protection of Customer Personal Data during the term.

6. Personal Data Breaches

Provider will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. As information becomes available, notice will describe the nature and known scope, likely consequences, containment or remediation, and a contact point. Provider will take reasonable steps to contain, investigate, and mitigate the breach and will provide information reasonably needed for Customer's legal notifications. Notice is not an admission of fault.

7. Data-subject and regulatory assistance

Taking account of the nature of processing, Provider will reasonably assist Customer with requests to access, correct, delete, restrict, object to, or export Customer Personal Data. If Provider receives a request directly, it will not independently respond about Customer-controlled data except on Customer's instruction or where law requires it, and will route the request to Customer where permitted.

Provider will also provide reasonable information and cooperation for Customer's security obligations, breach assessments, data-protection impact assessments, and prior consultation with a regulator, considering the information available to Provider. Customer remains responsible for its response, legal conclusions, and regulator relationship.

8. Subprocessors

Customer gives general authorization for the subprocessors on the current Subprocessors page. Provider will ensure, before a relevant provider processes Customer Personal Data, that a written agreement imposes data-protection obligations appropriate to the processing and required by applicable law. Provider remains responsible for a subprocessor's performance of those obligations.

Provider will give at least 14 calendar days' advance notice of a new core subprocessor where reasonably practicable. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on an alternative. If no reasonable solution is available, Customer may terminate the affected Service and use the export and deletion process. An urgent replacement needed for security or continuity may occur sooner, with notice as soon as reasonably practicable.

9. International transfers

Customer authorizes processing in the locations described on the Subprocessors page, subject to Data Protection Laws and the Agreement. If a transfer of Customer Personal Data requires an adequacy decision, certification, Standard Contractual Clauses, UK Addendum, or another safeguard, the parties will execute or document the applicable mechanism before that transfer begins.

This DPA does not itself incorporate the European Commission Standard Contractual Clauses or UK Addendum and does not claim that a provider's public privacy policy is a transfer mechanism. The order form must record any required transfer document. If no lawful mechanism can be established, Provider will not activate the affected processing.

10. Return, export, and deletion

At Customer's choice, Provider will return or delete Customer Personal Data after the end of the relevant Service and delete existing copies, unless applicable law requires storage. Because Warpix does not yet have self-service or a general full-workspace export or purge tool, the order form must record the available machine-readable export scope and format, request window, active-system deletion or irreversible de-identification method, completion target, retained audit fields, and secure delivery method. Provider will document and rehearse that customer-specific operator procedure before activation and will not accept processing whose legally required outcome it cannot safely perform.

Current backups are local, weekly, and retained for 14 days. Data may remain in an inaccessible backup until normal expiry and will not be restored except for recovery. Provider keeps each open deletion instruction in a protected request record outside the application database; after a backup restore, the operator checks that record and re-applies the agreed procedure before re-opening the affected service. Provider may retain narrowly limited information where law requires it or where reasonably necessary for security, fraud prevention, audit integrity, or legal claims, while continuing to protect it and limiting use to that purpose.

11. Information and audits

Provider will make available information reasonably necessary to demonstrate compliance with this DPA, starting with current documentation, test evidence, architecture, and security summaries. No more than once annually, or after a relevant confirmed breach or regulator request, Customer may request a reasonable remote audit at its expense. Any broader inspection requires reasonable advance notice, confidentiality, coordination to protect other tenants and system security, and avoidance of access to another customer's data. The parties may agree to an independent assessor instead.

12. Government requests

Unless prohibited by law, Provider will notify Customer of a legally binding request for Customer Personal Data before disclosure and will reasonably challenge overbroad requests. Provider will disclose only the information legally required.

13. Duration, priority, and liability

This DPA begins with the Agreement, continues while Provider processes Customer Personal Data, and survives only as needed to complete return, deletion, or lawful retention. It controls over conflicting data-processing language in the SaaS Terms. The order form controls party identity, commercial liability allocation, governing law, and venue. Nothing in this DPA changes a liability limitation in the Agreement or limits rights that applicable law does not permit the parties to limit.

Schedule 1: Processing details

Schedule 2: Technical and organizational measures

The early-access Service does not currently include an external status page, 24-hour monitoring commitment, off-server backup, formal certification, or guaranteed recovery objective unless an order form is amended to add it.

Schedule 3: Approved subprocessors

The current approved list, processing purposes, location descriptions, provider links, and change-notice process are maintained at warpix.io/subprocessors.

Contact

Data-protection notices and requests may be sent to hello@warpix.io and any additional notice address in the order form.