Legal

Data Processing Agreement

Last updated: September 1, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Data Controller") and Drixavo, Inc. ("Data Processor", "Drixavo"). By accepting the Terms of Service, Customer enters into this DPA on behalf of itself.

1. Scope and Applicability

This DPA applies where and only to the extent that Drixavo processes Personal Data on behalf of the Customer in the course of providing the Service and such Personal Data is subject to Data Protection Laws of the European Union, the European Economic Area and/or their member states, Switzerland and/or the United Kingdom.

2. Processing Details

Nature and Purpose: Drixavo processes Personal Data to provide the Service, including task management, communications, and AI operational recommendations.

Categories of Data Subjects: Customer's employees, contractors, and other authorized users of the Workspace.

Categories of Personal Data: Profile data (names, emails), user-generated content (tasks, comments, AI prompts), and operational metadata.

3. Controller Obligations

Customer agrees that it is responsible for obtaining any necessary consents and ensuring a valid legal basis for the processing of Personal Data in the Service. Customer shall ensure that its use of the Service complies with Data Protection Laws.

4. Processor Obligations

Drixavo shall process Personal Data only on documented instructions from the Customer, unless required otherwise by law. Drixavo ensures that persons authorised to process the Personal Data have committed themselves to confidentiality.

5. Sub-processors

Customer provides a general authorization for Drixavo to engage sub-processors. The current list of approved sub-processors is available at our Sub-processors Register. Drixavo will notify the Customer of any intended changes concerning the addition or replacement of other sub-processors.

6. Security

Drixavo shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including access controls, encryption of data in transit and at rest, and regular backups.

7. Personal Data Breach Notification

Drixavo shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer's Personal Data. Drixavo will provide reasonable assistance to the Customer in fulfilling its obligations to notify supervisory authorities and data subjects.

8. Audit and Inspection Rights

Drixavo shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA. Customer may conduct audits, including inspections, by an independent auditor mandated by the Customer, provided such audits are conducted during regular business hours and do not unreasonably interfere with Drixavo's business operations.

9. International Data Transfers and SCCs

Before making a restricted transfer of Personal Data from the EEA, Switzerland, or the UK, Drixavo and the Customer will enter into an applicable lawful transfer mechanism. This may include executed Standard Contractual Clauses with completed annexes. This webpage does not by itself execute or incorporate SCCs.

10. Deletion of Data

Upon termination of the Service, Drixavo will, at the choice of the Customer, delete or return all Personal Data to the Controller after the end of the provision of services relating to processing, unless Union or Member State law requires storage of the Personal Data.