Skip to content

Axiom is in pre-release. What you see here is designed and being built.

Axiom Data Processing Addendum

Addendum to the Axiom Terms of Service · Effective: October 1, 2026 · Version 1.0

This Data Processing Addendum ("DPA") forms part of the Axiom Terms of Service (the "Terms") between Iterix Systems, LLC ("Iterix" or "Processor") and the Customer ("Customer" or "Controller"). It is accepted together with the Terms. Capitalized terms not defined here have the meanings given in the Terms.

1. Definitions and Interpretation

1.1 Definitions

2. Scope and Roles

2.1 Scope of Processing

This DPA applies to Processor's processing of Personal Data on behalf of Controller in connection with the Services, including Personal Data in Customer Data and in Work Product.

2.2 Roles

Controller is the controller (or "business") and Processor is the processor (or "service provider") with respect to Personal Data in Customer Data and Work Product. Controller determines the purposes and means of processing. Processor is responsible for the account and website data it collects directly, as described in its Privacy Policy; this DPA does not cover that data.

2.3 Details of Processing

3. Processor Obligations

3.1 Processing Instructions

Processor shall process Personal Data only on documented instructions from Controller, unless required to do otherwise by applicable law. The Terms, Controller's plan, and Controller's use and configuration of the Services (including its goals, charter and approvals) constitute Controller's documented instructions. Processor shall not sell or share Personal Data, retain, use or disclose it outside the direct business relationship with Controller, or combine it with personal information from other sources except as permitted by Data Protection Laws.

3.2 Confidentiality

Processor shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations.

3.3 Security Measures

Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage or disclosure, as described in Annex A.

3.4 Sub-processing

3.5 Data Subject Rights

Taking into account the nature of the processing, Processor shall assist Controller by appropriate technical and organizational measures in responding to requests from individuals exercising their rights under Data Protection Laws. If Processor receives such a request directly, it shall promptly forward it to Controller and shall not respond except on Controller's instruction or as required by law.

3.6 Breach Notification

Processor shall notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller's Personal Data. The notice shall include the information then available and Processor shall give reasonable assistance to Controller in meeting its own notification obligations.

3.7 Assessments

Processor shall give reasonable assistance to Controller in conducting any risk or data-protection assessment Data Protection Laws require of Controller, to the extent the assistance concerns processing within Processor's control.

3.8 Deletion and Return

After termination of the Terms, Controller may request an export of Personal Data by email to [email protected] within 30 days, and Processor shall provide it, as provided in the Terms. Within 90 days after that period ends, Processor shall delete Personal Data, except where retention is required by law. Personal Data in backup systems is deleted within a further 90 days.

3.9 Audit Rights

3.10 Information and Records

Processor shall maintain records of its processing activities as required by Data Protection Laws.

4. Data Location

4.1 Location of Processing

The Services are offered only to Customers in the United States, and Processor processes Personal Data in the United States. Any Sub-processor that processes Personal Data outside the United States is identified, with its location, in Annex B.

4.2 Transfers Outside the United States

If Controller submits Personal Data originating outside the United States, or a Sub-processor processes Personal Data outside the United States, the parties will cooperate in good faith to put in place any transfer mechanism that Data Protection Laws require.

5. Liability and Indemnification

5.1 Liability

Each party's liability under this DPA is subject to the limitations and exclusions in Section 11 and Section 2.5.2 of the Terms. The aggregate liability cap in the Terms applies to all claims under the Terms and this DPA combined.

5.2 Processor Indemnity

Processor shall indemnify Controller against third-party claims, losses and damages arising from Processor's breach of this DPA, except to the extent caused by Controller's instructions or actions, subject to the terms and limitations of Section 10 of the Terms.

6. Term and Termination

This DPA takes effect when Controller accepts the Terms and remains in effect for as long as Processor processes Personal Data on Controller's behalf. Sections 3.8 and 5 survive termination.

7. General

7.1 Order of Precedence

In the event of conflict between this DPA and the Terms, this DPA prevails with respect to data protection matters.

7.2 Governing Law

This DPA is governed by the same law as the Terms, except where Data Protection Laws require otherwise.

7.3 Amendment

Processor may amend this DPA as necessary to comply with changes in Data Protection Laws on 30 days' notice to Controller.

Annex A — Security Measures

Processor implements the following technical and organizational measures. Each measure below was read on Processor's production systems; a measure is added to this Annex only once it has been verified.

1. Workspace Isolation and Access Control

2. Monitoring

3. Retention of Operational Records

Annex B — Sub-processors

The current list of Sub-processors — purpose, the data each handles, and processing location — is maintained on the Sub-processors page of the Axiom website, with notice of changes as set out in Section 3.4. At the date of this DPA: