Help Centre Contact Sales
Sign in
Noxtill
Skip to content
ENTERPRISE

Data Processing Addendum

Processor/service-provider instructions, Article 28 terms, technical and organizational measures, subprocessor authority and transfer safeguards.

Version
1.0
Last updated
October 10, 2026
Reading time
3 min

Noxtill LLC · Data Processing Addendum · Version 1.0 · noxtill.com/legal/dpa

AT A GLANCE

  • Processing instructions

    Noxtill processes Customer Content only on documented instructions, to the extent it acts as processor, including hosting, support, backup, AI processing and authorized integration transfer.

  • Confidentiality and security

    Authorized personnel are bound to confidentiality and Noxtill implements reasonable technical and organizational measures appropriate to assessed risks and actual deployment.

  • Subprocessors

    Customer grants general authorization for contracted subprocessors described in the register, subject to notice and a contractual objection mechanism consistent with Article 28 GDPR where applicable.

  • Rights and incidents

    Noxtill assists customers with rights requests, security incident duties, assessments and legally required information, using documented request routes and proportional assistance.

  • Termination and transfer

    Following expiry or documented instruction, return or delete Customer Content subject to retention obligations, backup lifecycle and transfer mechanisms such as SCC/UK addendum where applicable.

This DPA forms part of the agreement between the customer and Noxtill where Noxtill processes personal data on behalf of the customer. The customer is the controller/business or a processor acting for another controller; Noxtill is processor/service provider/contractor as applicable law defines the roles.

Noxtill processes Customer Personal Data only on documented instructions in the agreement, product configuration and authorized-user actions unless law requires otherwise. If an instruction appears unlawful, Noxtill may notify the customer and suspend affected processing pending clarification.

Personnel authorized to process Customer Personal Data must be subject to appropriate confidentiality duties and receive access only as needed.

Noxtill will implement appropriate technical and organizational measures proportionate to risk. The security annex must reflect actual production controls.

Customer authorizes subprocessors on the current Subprocessors page. Noxtill will impose appropriate data-protection obligations and remains responsible for subprocessors to the extent required by applicable law.

Noxtill should provide advance notice of material new subprocessors and a reasonable objection path for legitimate data-protection concerns.

Taking into account the nature of processing, Noxtill will reasonably assist the customer with requests to access, correct, delete, restrict or port Customer Personal Data where required.

If Noxtill receives a request directly about Customer Content, it may direct the requester to the customer unless law requires Noxtill to respond directly.

Noxtill will provide reasonable information about the Service to support legally required DPIAs and regulatory consultation, subject to confidentiality and security restrictions.

Noxtill will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required. Notice should include available information about nature, likely consequences, affected data/subjects, mitigation and contact point, and may be supplemented as investigation continues.

On termination and subject to agreed recovery/retention rules, the customer may export Customer Personal Data and Noxtill will delete or return it unless law requires retention. Backup deletion follows the controlled backup lifecycle; retained data remains protected and isolated from ordinary use.

Noxtill will make available information reasonably necessary to demonstrate processor obligations, such as Trust Center material, security documentation, third-party assurance reports if available and reasonable questionnaires.

On-site audits should be limited to legally required circumstances or situations where equivalent evidence is insufficient, subject to reasonable notice, confidentiality, security restrictions and cost allocation.

For EEA restricted transfers without adequacy, the parties should incorporate the appropriate modules of Commission Implementing Decision (EU) 2021/914 SCCs. UK transfers should use a valid UK mechanism. Parties will cooperate with legally required transfer assessments/supplementary measures.

Where Noxtill acts as a processor/service provider/contractor, it will process data for limited and specified purposes, not sell/share it except as legally permitted, apply required confidentiality/purpose limitations and provide legally required assistance.

Customer warrants its instructions are lawful; it has provided required notices/consents; and it will not instruct Noxtill to process data unlawfully. Customer must determine whether special-category, health, financial, biometric, children’s or regulated data may lawfully be placed in the Service.

If this DPA conflicts with the Terms on personal-data processing, the DPA controls. Mandatory SCCs or other transfer terms control over inconsistent commercial language where legally required.

FieldSpecification
Subject matterProvision of Noxtill Business Operating System and enabled modules.
DurationSubscription term plus documented retention/deletion period.
NatureHosting, organizing, retrieving, transmitting, analyzing, automating, securing, backing up, supporting and deleting data.
PurposesProvide Service, execute customer-configured workflows, support/security and processor legal duties.
Data subjectsCustomer personnel, end customers, prospects, suppliers, contractors, applicants and service recipients.
Data categoriesIdentity/contact, CRM, transactions, bookings, messages, workforce/payroll, location, documents/signatures, support, commerce, finance/accounting, usage and AI prompts/outputs.
Sensitive dataOnly where the customer lawfully enters/configures it; minimize and specially protect where feasible.

  • tenant isolation and authorization;
  • RBAC and field restrictions;
  • MFA capability and privileged-access controls;
  • encryption in transit and appropriate at-rest encryption;
  • secure secrets/OAuth handling;
  • high-impact audit logging;
  • backups and restore testing;
  • secure development and vulnerability management;
  • incident detection/response;
  • vendor risk management;
  • retention/deletion controls; and
  • AI context isolation and approval gates.

The live /trust/subprocessors register is incorporated by reference after it is populated from the actual production vendor inventory.

Questions about this document: support@noxtill.com · Privacy: privacy@noxtill.com · Noxtill LLC, 4539 N 22nd St, Ste R, Phoenix, AZ 85016, United States.

Related documents