Legal
Data processing addendum
Preamble
This Data Processing Addendum ("DPA") is entered into between the Customer identified in the underlying Master Subscription Agreement ("MSA" or "Agreement") (the "Customer" or "Business / Controller") and ScaleAxis LLC (the "Service Provider / Processor"). This DPA forms part of the Agreement and addresses the parties' obligations under U.S. state privacy laws applicable to processors and service providers (including, as of Jan. 1, 2026: CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, NHPA, NJDPA, TIPA, FDBR, ICDPA (IN), KCDPA, RIDTPPA, MODPA (effective Apr. 1, 2026), DPDPA, NDPA, MCDPA (MT), and ICDPA (IA)).
1. Definitions
Capitalized terms not defined here have the meanings in the Agreement. In addition:
- "Applicable Privacy Laws" means all U.S. state privacy laws applicable to the processing.
- "Personal Information" means information processed by ScaleAxis on Customer's behalf that identifies, relates to, or could reasonably be linked with a particular consumer or household.
- "Security Incident" means a confirmed breach of ScaleAxis's security leading to the unauthorized access, acquisition, disclosure, alteration, or destruction of Personal Information.
- "Sub-processor" as defined in the Global Defined Terms.
2. Roles; scope of processing
2.1 Roles. Customer is the Business / Controller. ScaleAxis is the Service Provider / Processor.
2.2 Subject Matter and Duration. ScaleAxis processes Personal Information for the Subscription Term and a transition period of up to 90 days after termination, as required to provide the Service.
2.3 Nature and Purpose. Hosting, storing, transmitting, processing, and analyzing Personal Information to provide the Service (including CRM, scheduler, email, SMS, voice, AI Features, and integrations) as documented in the Agreement and any Order Form.
2.4 Types of Personal Information (illustrative; depends on Customer use): contact details, business contact lists, communications, sales/CRM records, calendar data, billing data (handled via Stripe), authentication metadata.
2.5 Categories of Data Subjects: Customer's employees, contractors, prospects, customers, leads, business contacts.
3. Processor obligations
3.1 Documented Instructions. ScaleAxis will process Personal Information only on Customer's documented instructions (the Agreement, this DPA, and Customer's reasonable use of the Service constitute such instructions), except as required by law. ScaleAxis will inform Customer if instructions appear to violate Applicable Privacy Laws.
3.2 Confidentiality of Personnel. ScaleAxis personnel with access to Personal Information are bound by written confidentiality obligations.
3.3 No Sale / No Share / No Combination. ScaleAxis will not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information outside the direct business relationship; (c) combine Personal Information received from Customer with Personal Information from any other source except as permitted by 11 CCR § 7050(b) (or analogous provisions); or (d) train its own AI models on Personal Information.
3.4 Cooperation with Data Subject Requests. ScaleAxis will assist Customer in responding to consumer requests under Applicable Privacy Laws (access, deletion, correction, portability, opt-out, appeal), taking into account the nature of processing and information available.
3.5 Security. ScaleAxis will implement the technical and organizational measures set forth in Schedule 2.
3.6 Security Incident Notification. ScaleAxis will notify Customer of a confirmed Security Incident affecting Personal Information without undue delay and in any event within seventy-two (72) hours of confirmation. Notice will include, to the extent available, the nature of the incident, categories and approximate number of records affected, likely consequences, and mitigation steps.
3.7 Audit Rights. Once per twelve-month period, with at least thirty (30) days' prior written notice, and subject to confidentiality and reasonable scope, Customer may either (a) review ScaleAxis's most recent third-party security audit reports (e.g., SOC 2 Type II once available) or (b) conduct an on-site audit during ordinary business hours. ScaleAxis may charge reasonable fees for excessive audit requests. Auditors must execute an NDA acceptable to ScaleAxis.
3.8 Return / Deletion. Within ninety (90) days of termination, Customer may export Personal Information through the Service's export tools. After 90 days, ScaleAxis will delete Personal Information from its production systems within a reasonable period and from backups in accordance with its backup retention schedule.
4. Sub-processors
4.1 General Authorization. Customer grants ScaleAxis general authorization to engage Sub-processors as listed in Schedule 3 (and the Sub-processor List).
4.2 New Sub-processors. ScaleAxis will give at least thirty (30) days' advance notice (via in-product notice, email to the account administrator, or update to the Sub-processor List page) before engaging or replacing a Sub-processor. Customer may object in writing on reasonable data-protection grounds within the notice period; if the objection cannot be resolved, Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused Fees.
4.3 Sub-processor Obligations. ScaleAxis will impose data-protection terms on each Sub-processor at least equivalent to this DPA. ScaleAxis remains liable for its Sub-processors' performance, subject to the limitations in the Agreement.
5. Cross-border transfers
The Service is currently U.S.-only. To the extent Personal Information is transferred internationally in the future, the parties will execute the legal mechanisms required (e.g., EU Standard Contractual Clauses, UK IDTA, Swiss equivalents).
6. Liability; order of precedence
6.1 Each party's liability under this DPA is subject to the limitation of liability in the Agreement.
6.2 In a conflict between this DPA and the Agreement (other than Order Forms), this DPA controls with respect to Personal Information processing.
7. Term; survival
This DPA continues for as long as ScaleAxis processes Personal Information on Customer's behalf. Sections that by their nature survive (security, confidentiality, deletion, audit) survive termination.
Schedule 1: Processing details
- Subject matter: processing of Personal Information necessary to provide ScaleAxis OS.
- Duration: Subscription Term + transition period.
- Nature and purpose: as set forth in Section 2.
- Categories of data subjects: as set forth in Section 2.5.
- Categories of Personal Information: as set forth in Section 2.4.
- Special categories: none knowingly processed.
- Frequency: continuous during the Subscription Term.
Schedule 2: Technical and organizational measures
ScaleAxis maintains the following measures (subject to evolution with industry standards):
- Encryption: TLS 1.2+ in transit; AES-256 at rest for production databases.
- Access controls: role-based access; least privilege; multi-factor authentication for all administrative access.
- Network security: firewalls, intrusion detection at hosting layer (via Vercel and Supabase).
- Tenant isolation: row-level security in Supabase; per-tenant scoping for all data, including AI Business Context.
- Logging and monitoring: system, security, and access logs; alerting for anomalous activity.
- Vulnerability management: routine dependency scanning, prompt patching.
- Backup and disaster recovery: managed backups via Supabase; documented restoration procedures.
- Personnel: background checks where lawful; confidentiality agreements; security training.
- Vendor management: Sub-processor due diligence and contractual flow-down.
- Incident response: documented runbook; escalation procedures.
Schedule 3: Sub-processors
See Document 8 (Sub-processor List).