Data Processing Addendum
For customers subject to GDPR, UK GDPR, or similar laws.
This Data Processing Addendum ("DPA") supplements the Odexa Terms of Service between Odexa, Inc. ("Processor") and the Customer ("Controller"). When Customer submits personal data to the Odexa Service, this DPA governs Processor's handling of that data.
Scope & roles. Processor processes personal data only to provide the Service and per Controller's documented instructions. Controller determines the purposes and means of processing.
Sub-processors. Processor engages sub-processors to deliver the Service (hosting, database, email delivery, AI inference, payments). A current list is available on request; Processor will notify Controller of material changes.
Security. Processor maintains administrative, technical, and organizational safeguards including encryption in transit and at rest, least-privilege access, and audit logging.
Data subject rights. Processor will assist Controller in responding to data-subject requests. Individuals may contact privacy@odexa.ai.
International transfers. Where personal data is transferred outside the EEA/UK/Switzerland, Processor relies on Standard Contractual Clauses or an equivalent transfer mechanism.
Termination. On termination Processor will delete or return Customer personal data within a reasonable period, subject to legal retention obligations.
To execute a countersigned DPA for your organization, email legal@odexa.ai.