Axiom Data Processing Addendum
Addendum to the Axiom Terms of Service · Effective: October 1, 2026 · Version 1.0
This Data Processing Addendum ("DPA") forms part of the Axiom Terms of Service (the "Terms") between Iterix Systems, LLC ("Iterix" or "Processor") and the Customer ("Customer" or "Controller"). It is accepted together with the Terms. Capitalized terms not defined here have the meanings given in the Terms.
1. Definitions and Interpretation
1.1 Definitions
- "Data Protection Laws" means all laws of the United States and its states relating to privacy, data protection and data security that apply to the processing of Personal Data under the Terms, including the California Consumer Privacy Act as amended.
- "Personal Data" means any information relating to an identified or identifiable natural person that Processor processes on behalf of Controller in connection with the Services.
- "Processing" has the meaning given in applicable Data Protection Laws.
- "Sub-processor" means any entity engaged by Processor to process Personal Data on behalf of Controller.
2. Scope and Roles
2.1 Scope of Processing
This DPA applies to Processor's processing of Personal Data on behalf of Controller in connection with the Services, including Personal Data in Customer Data and in Work Product.
2.2 Roles
Controller is the controller (or "business") and Processor is the processor (or "service provider") with respect to Personal Data in Customer Data and Work Product. Controller determines the purposes and means of processing. Processor is responsible for the account and website data it collects directly, as described in its Privacy Policy; this DPA does not cover that data.
2.3 Details of Processing
- Subject matter: provision of the Services.
- Duration: the term of the Terms, plus the export and deletion periods in Section 3.8.
- Nature and purpose: running AI Roles that work toward goals set by Controller, within Controller's budget ceiling and approvals, and producing Work Product for Controller.
- Types of Personal Data: as determined by Controller; may include names, email addresses, job titles, business contact details and other data Controller submits, or that Roles include in Work Product at Controller's direction.
- Categories of data subjects: Controller's employees, contractors and customers, and other individuals — including third parties named in Work Product — whose data Controller submits or directs Roles to process.
3. Processor Obligations
3.1 Processing Instructions
Processor shall process Personal Data only on documented instructions from Controller, unless required to do otherwise by applicable law. The Terms, Controller's plan, and Controller's use and configuration of the Services (including its goals, charter and approvals) constitute Controller's documented instructions. Processor shall not sell or share Personal Data, retain, use or disclose it outside the direct business relationship with Controller, or combine it with personal information from other sources except as permitted by Data Protection Laws.
3.2 Confidentiality
Processor shall ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations.
3.3 Security Measures
Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, damage or disclosure, as described in Annex A.
3.4 Sub-processing
- Controller gives general authorization for Processor to engage the Sub-processors listed in Annex B.
- Processor shall give at least 30 days' notice before adding or replacing a Sub-processor.
- Controller may object to a new Sub-processor on reasonable data-protection grounds within 15 days of notice. The parties will then work in good faith toward a commercially reasonable solution; if none is found, Controller may terminate the Terms without penalty and receive a refund of unused Prepaid Balance.
- Processor shall ensure each Sub-processor is bound by written obligations substantially equivalent to those in this DPA, and remains responsible for each Sub-processor's performance of them.
3.5 Data Subject Rights
Taking into account the nature of the processing, Processor shall assist Controller by appropriate technical and organizational measures in responding to requests from individuals exercising their rights under Data Protection Laws. If Processor receives such a request directly, it shall promptly forward it to Controller and shall not respond except on Controller's instruction or as required by law.
3.6 Breach Notification
Processor shall notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Controller's Personal Data. The notice shall include the information then available and Processor shall give reasonable assistance to Controller in meeting its own notification obligations.
3.7 Assessments
Processor shall give reasonable assistance to Controller in conducting any risk or data-protection assessment Data Protection Laws require of Controller, to the extent the assistance concerns processing within Processor's control.
3.8 Deletion and Return
After termination of the Terms, Controller may request an export of Personal Data by email to [email protected] within 30 days, and Processor shall provide it, as provided in the Terms. Within 90 days after that period ends, Processor shall delete Personal Data, except where retention is required by law. Personal Data in backup systems is deleted within a further 90 days.
3.9 Audit Rights
- Processor shall make available to Controller, on request and subject to confidentiality, the information reasonably necessary to demonstrate its compliance with this DPA.
- Controller may audit Processor's compliance once per calendar year on 30 days' written notice, during regular business hours and without unreasonable interference with Processor's operations. Processor may satisfy an audit request by providing current third-party audit reports or certifications where it holds them, or other documentation reasonably demonstrating compliance.
- If Controller reasonably believes a breach has occurred, or an audit is required by a regulator, Controller may conduct an additional audit on reasonable notice.
- Each party bears its own audit costs unless the audit finds material non-compliance, in which case Processor bears Controller's reasonable audit costs.
3.10 Information and Records
Processor shall maintain records of its processing activities as required by Data Protection Laws.
4. Data Location
4.1 Location of Processing
The Services are offered only to Customers in the United States, and Processor processes Personal Data in the United States. Any Sub-processor that processes Personal Data outside the United States is identified, with its location, in Annex B.
4.2 Transfers Outside the United States
If Controller submits Personal Data originating outside the United States, or a Sub-processor processes Personal Data outside the United States, the parties will cooperate in good faith to put in place any transfer mechanism that Data Protection Laws require.
5. Liability and Indemnification
5.1 Liability
Each party's liability under this DPA is subject to the limitations and exclusions in Section 11 and Section 2.5.2 of the Terms. The aggregate liability cap in the Terms applies to all claims under the Terms and this DPA combined.
5.2 Processor Indemnity
Processor shall indemnify Controller against third-party claims, losses and damages arising from Processor's breach of this DPA, except to the extent caused by Controller's instructions or actions, subject to the terms and limitations of Section 10 of the Terms.
6. Term and Termination
This DPA takes effect when Controller accepts the Terms and remains in effect for as long as Processor processes Personal Data on Controller's behalf. Sections 3.8 and 5 survive termination.
7. General
7.1 Order of Precedence
In the event of conflict between this DPA and the Terms, this DPA prevails with respect to data protection matters.
7.2 Governing Law
This DPA is governed by the same law as the Terms, except where Data Protection Laws require otherwise.
7.3 Amendment
Processor may amend this DPA as necessary to comply with changes in Data Protection Laws on 30 days' notice to Controller.
Annex A — Security Measures
Processor implements the following technical and organizational measures. Each measure below was read on Processor's production systems; a measure is added to this Annex only once it has been verified.
1. Workspace Isolation and Access Control
- Row-level security is enabled on every application table in the production database.
- The public client roles hold no direct access to any application table or view.
2. Monitoring
- Automated health checks, including a security-signal scan, run on the production database on fixed schedules, most of them every one to five minutes.
3. Retention of Operational Records
- Scheduled jobs on the production database delete operational records after fixed periods: scheduler run details after 7 days, scheduler heartbeats after 30 days, instrumentation heartbeats after 12 weeks, the task-queue archive after 90 days, and instrumentation events after 1 year.
Annex B — Sub-processors
The current list of Sub-processors — purpose, the data each handles, and processing location — is maintained on the Sub-processors page of the Axiom website, with notice of changes as set out in Section 3.4. At the date of this DPA:
- Supabase — database, authentication and in-database search indexing — United States (AWS us-east-2).
- Railway — application, worker and website hosting — United States (us-west2).
- OpenAI — AI model inference — United States.
- Grafana Labs (Grafana Cloud) — service monitoring; website analytics — United States.
- Resend — transactional email — United States.
- Cloudflare — domain name service and network proxy for the Axiom website — global network; requests may be handled in data centers outside the United States.
- Stripe — payment processing — United States (planned; not yet enabled).
- HubSpot — customer relationship management for website enquiries, the waitlist, accounts, payment records and mail to our support, privacy and security addresses — United States; HubSpot may process in other locations through its affiliates and sub-processors (planned; not yet enabled).
