Contractual privacy
Data Processing Addendum
Article 28 terms governing Aixy's processing of customer personal data.
This Data Processing Addendum (“DPA”) is a template. It becomes effective only when incorporated into a signed service agreement between the customer (“Controller”) and Aixy — contracting operator or entity details to be completed before execution (“Processor”).
1. Scope and hierarchy
This DPA applies when Aixy processes personal data on behalf of the Controller in connection with the Aixy gateway service. If this DPA conflicts with the service agreement on personal-data protection, this DPA prevails.
2. Documented instructions
Aixy will process customer personal data only to provide, secure, support and improve the contracted service in accordance with the Controller's documented instructions, including its configuration, requests, selected model providers and the service agreement. Aixy will inform the Controller if it believes an instruction infringes applicable data-protection law, unless prohibited by law.
3. Confidentiality and security
Aixy will ensure that authorized personnel are bound by confidentiality and will maintain measures appropriate to the processing risk. The current measures are described in the Technical and Organizational Measures.
4. Subprocessors
The Controller gives general authorization for the subprocessors listed on the subprocessor page. Aixy will impose data-protection obligations materially equivalent to this DPA and remain responsible for its subprocessor obligations under applicable law.
The executed agreement must specify the notice period and objection process for a new subprocessor. If a reasonable objection cannot be resolved, the parties may terminate the affected service under the agreed terms.
5. Data-subject requests
Taking into account the nature of the processing, Aixy will provide reasonable assistance for access, rectification, erasure, restriction, portability, objection and automated-decision requests. If Aixy receives a request relating to customer-controlled data, it will refer the requester to the Controller unless authorized to respond.
6. Security incidents
Aixy will notify the Controller without undue delay after confirming a personal-data breach affecting customer personal data and will provide available information reasonably needed for the Controller's assessment and notification obligations. Notification does not admit fault or liability.
7. Assistance and accountability
Aixy will provide information reasonably necessary to demonstrate compliance with Article 28 and assist with security, breach, DPIA and supervisory-authority obligations, taking into account the processing and information available to Aixy.
Audits should first use current documentation, evidence and independent reports. On-site or bespoke audits require reasonable advance notice, confidentiality, scope controls and reimbursement of disproportionate costs, except where law or a regulator requires otherwise.
8. Return and deletion
At the Controller's choice and subject to applicable law, Aixy will return or delete customer personal data after service termination. The executed DPA must align live-data deletion, recoverable account deletion, encrypted backups, audit evidence, billing records and legal holds with the approved retention schedule.
9. International transfers
Aixy will not transfer customer personal data outside the EEA except on documented instructions and using a valid Chapter V mechanism. Where required, the parties will incorporate the applicable European Commission Standard Contractual Clauses and document transfer-impact and supplementary-measure assessments.
Annex A — Processing details
- Subject matter
- Managed routing, governance, security, observability and support for customer LLM requests.
- Duration
- The service term plus the agreed deletion and backup-expiry period.
- Nature
- Receive, inspect under configured controls, route, transmit, meter, secure, troubleshoot, store bounded metadata and, only when enabled, store encrypted prompt or response content.
- Purpose
- Provide and secure the service on the Controller's instructions.
- Data subjects
- Controller users, employees, contractors, customers and other people whose data the Controller submits.
- Data
- Account identifiers, business contact data, workload metadata, IP and user-agent security data, prompts, responses and any personal data included by the Controller.
- Special categories
- Not intentionally required. The Controller must not submit special-category or criminal-offence data unless explicitly agreed and appropriately safeguarded.
Contact and signature block
Privacy contact: compliance@aixy-gateway.com
Before signature, complete both parties' legal details, governing agreement, effective date, subprocessor notice period, deletion option, transfer modules and authorized signatories.