This DPA forms part of the agreement between the customer and Noxtill where Noxtill processes personal data on behalf of the customer. The customer is the controller/business or a processor acting for another controller; Noxtill is processor/service provider/contractor as applicable law defines the roles.
Noxtill processes Customer Personal Data only on documented instructions in the agreement, product configuration and authorized-user actions unless law requires otherwise. If an instruction appears unlawful, Noxtill may notify the customer and suspend affected processing pending clarification.
Personnel authorized to process Customer Personal Data must be subject to appropriate confidentiality duties and receive access only as needed.
Noxtill will implement appropriate technical and organizational measures proportionate to risk. The security annex must reflect actual production controls.
Customer authorizes subprocessors on the current Subprocessors page. Noxtill will impose appropriate data-protection obligations and remains responsible for subprocessors to the extent required by applicable law.
Noxtill should provide advance notice of material new subprocessors and a reasonable objection path for legitimate data-protection concerns.
Taking into account the nature of processing, Noxtill will reasonably assist the customer with requests to access, correct, delete, restrict or port Customer Personal Data where required.
If Noxtill receives a request directly about Customer Content, it may direct the requester to the customer unless law requires Noxtill to respond directly.
Noxtill will provide reasonable information about the Service to support legally required DPIAs and regulatory consultation, subject to confidentiality and security restrictions.
Noxtill will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where notification is required. Notice should include available information about nature, likely consequences, affected data/subjects, mitigation and contact point, and may be supplemented as investigation continues.
On termination and subject to agreed recovery/retention rules, the customer may export Customer Personal Data and Noxtill will delete or return it unless law requires retention. Backup deletion follows the controlled backup lifecycle; retained data remains protected and isolated from ordinary use.
Noxtill will make available information reasonably necessary to demonstrate processor obligations, such as Trust Center material, security documentation, third-party assurance reports if available and reasonable questionnaires.
On-site audits should be limited to legally required circumstances or situations where equivalent evidence is insufficient, subject to reasonable notice, confidentiality, security restrictions and cost allocation.
For EEA restricted transfers without adequacy, the parties should incorporate the appropriate modules of Commission Implementing Decision (EU) 2021/914 SCCs. UK transfers should use a valid UK mechanism. Parties will cooperate with legally required transfer assessments/supplementary measures.
Where Noxtill acts as a processor/service provider/contractor, it will process data for limited and specified purposes, not sell/share it except as legally permitted, apply required confidentiality/purpose limitations and provide legally required assistance.
Customer warrants its instructions are lawful; it has provided required notices/consents; and it will not instruct Noxtill to process data unlawfully. Customer must determine whether special-category, health, financial, biometric, children’s or regulated data may lawfully be placed in the Service.
If this DPA conflicts with the Terms on personal-data processing, the DPA controls. Mandatory SCCs or other transfer terms control over inconsistent commercial language where legally required.
| Field | Specification |
|---|---|
| Subject matter | Provision of Noxtill Business Operating System and enabled modules. |
| Duration | Subscription term plus documented retention/deletion period. |
| Nature | Hosting, organizing, retrieving, transmitting, analyzing, automating, securing, backing up, supporting and deleting data. |
| Purposes | Provide Service, execute customer-configured workflows, support/security and processor legal duties. |
| Data subjects | Customer personnel, end customers, prospects, suppliers, contractors, applicants and service recipients. |
| Data categories | Identity/contact, CRM, transactions, bookings, messages, workforce/payroll, location, documents/signatures, support, commerce, finance/accounting, usage and AI prompts/outputs. |
| Sensitive data | Only where the customer lawfully enters/configures it; minimize and specially protect where feasible. |
- tenant isolation and authorization;
- RBAC and field restrictions;
- MFA capability and privileged-access controls;
- encryption in transit and appropriate at-rest encryption;
- secure secrets/OAuth handling;
- high-impact audit logging;
- backups and restore testing;
- secure development and vulnerability management;
- incident detection/response;
- vendor risk management;
- retention/deletion controls; and
- AI context isolation and approval gates.
The live /trust/subprocessors register is incorporated by reference after it is populated from the actual production vendor inventory.
