Last Updated: December 11, 2024
This Data Processing Agreement ("DPA") forms part of the Service Agreement between you ("Customer", "Data Controller") and DXSignal ("Processor", "we", "us") and governs the processing of Personal Data in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by us on your behalf through the DXSignal service.
"Processing" has the meaning given in the GDPR and includes any operation performed on Personal Data.
"Sub-processor" means any third party appointed by us to process Personal Data on your behalf.
"Data Subject" means the individual to whom Personal Data relates.
We process Personal Data solely for the purpose of providing the DXSignal service, which includes:
We may process the following categories of Personal Data:
Personal Data may relate to:
We will process Personal Data for the duration of the Service Agreement and as necessary to comply with legal obligations or resolve disputes.
3.1 Instructions: We will process Personal Data only on documented instructions from you, unless required to do so by applicable law.
3.2 Confidentiality: We ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3 Security: We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
3.4 Sub-processing: We will not engage another processor without your prior written authorization. Current sub-processors are listed in Annex A below.
3.5 Data Subject Rights: We will assist you in responding to requests for exercising Data Subject rights under GDPR, including access, rectification, erasure, and data portability.
3.6 Data Breach: We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data.
3.7 Deletion: We will delete or return all Personal Data to you at the end of the provision of services, unless retention is required by law.
3.8 Audit: We will make available all information necessary to demonstrate compliance with this DPA and allow for audits by you or an auditor mandated by you.
4.1 Location: Personal Data is primarily processed and stored within the European Union and the United States using Microsoft Azure infrastructure.
4.2 Safeguards: Where Personal Data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:
4.3 Azure Compliance: Our primary infrastructure provider, Microsoft Azure, maintains GDPR compliance and provides appropriate data processing agreements and safeguards.
We implement the following security measures:
We will assist you in fulfilling your obligations to respond to Data Subject requests:
For assistance with Data Subject requests, contact us at privacy@dxsignal.com
In the event of a Personal Data breach, we will notify you without undue delay and within 72 hours of becoming aware of the breach. The notification will include:
8.1 Liability: Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability in the Service Agreement.
8.2 Indemnification: We will indemnify you against claims by Data Subjects arising from our failure to comply with this DPA, subject to you providing prompt notice and reasonable cooperation.
This DPA will commence on the date of the Service Agreement and will remain in effect for the duration of the Service Agreement. Upon termination:
We currently engage the following sub-processors to provide the DXSignal service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud infrastructure and hosting | EU / US |
| Auth0 (Okta) | Authentication and identity management | US |
| Stripe | Payment processing | US |
| Anthropic | AI-powered insights | US |
We will notify you of any changes to sub-processors at least 30 days in advance. You may object to the appointment of a new sub-processor on reasonable grounds.
Data Protection Officer:
Email: privacy@dxsignal.com
Address:
DXSignal
[Your Company Address]
[City, State, Country]
For questions about this DPA or our data processing practices, please contact our Data Protection Officer.
By using the DXSignal service, you acknowledge that you have read and agree to this Data Processing Agreement.