Data Processing Addendum
This Data Processing Addendum ("DPA") is incorporated into and forms part of the Apodex Commercial Terms of Service or other agreement between Customer and Apodex US, Inc. ("Apodex", "we", "us", "our"), that references this DPA and governs Customer's use of the Services (the "Agreement"), and applies to Apodex's processing of Personal Data on Customer's behalf. Capitalized terms used but not otherwise defined in this DPA will have the meaning set forth in the Agreement. This DPA is governed by, and disputes under it are resolved in accordance with, the governing-law and dispute-resolution provisions of the Agreement. Apodex may amend this DPA from time to time on reasonable notice to Customer to the extent such changes are required due to changes in Data Protection Laws. If there is any conflict between the terms of this DPA and the Agreement, the conflicting terms in this DPA will govern.
1. Definitions
1. "Personal Data" means any information relating to an identified or identifiable natural person processed by Apodex on behalf of the Customer.
2. "Data Protection Laws" means all privacy and data protection laws applicable to the processing under this DPA, which may include the California Consumer Privacy Act (CCPA/CPRA), Singapore's Personal Data Protection Act (PDPA), and, to the extent applicable, the EU/UK GDPR, in each case as amended from time to time.
3. "Sub-processor" means any third party appointed by Apodex to process Personal Data in connection with the Services.
4. "Standard Contractual Clauses" means the standard contractual clauses approved by the European Commission for the transfer of personal data to third countries, which apply only to the extent Apodex processes personal data subject to the EU/UK GDPR.
5. "Customer" means the customer, organization, or other entity that has entered into the Agreement with Apodex and on whose behalf Apodex processes Personal Data under this DPA.
2. Processing of Personal Data
1. Roles of the Parties. The parties agree that Customer is the Controller and Apodex is the Processor. Apodex shall process Personal Data only in accordance with Customer's documented instructions.
2. Customer Instructions. This DPA and the Agreement constitute Customer's complete and final instructions to Apodex for the Processing of Personal Data. Processing outside the scope of these instructions shall require a prior written agreement between the parties.
3. Limitation of Purpose. Apodex shall process Personal Data only for the purposes described in Annex I (e.g., providing the AI Services, troubleshooting, and improving service performance) and on Customer's documented instructions. Apodex will not use Personal Data contained in Customer Content to train Apodex's foundational models, except to the extent expressly authorized in the Agreement (for example, where Customer participates in a free, trial, or promotional program and has not opted out of model training). Where the Agreement authorizes such use, Apodex will first de-identify or aggregate the data and acts as an independent controller with respect to that de-identified data; Apodex remains the Processor for all other Processing of Personal Data under this DPA.
4. Compliance. Apodex shall comply with all Data Protection Laws applicable to its role as a Processor. If Apodex believes an instruction from the Customer violates applicable law, it shall inform the Customer immediately.
3. Personnel & Confidentiality
1. Confidentiality. Apodex shall ensure that its personnel engaged in the processing of Personal Data are informed of the confidential nature of the data, have received appropriate training, and have executed written confidentiality agreements.
2. Reliability. Apodex shall take commercially reasonable steps to ensure the reliability of any Apodex personnel engaged in the processing of Personal Data.
4. Appointment of Sub-processors
1. Authorization. Customer authorizes Apodex to engage Sub-processors (such as cloud hosting and infrastructure providers) to process Personal Data on Customer's behalf.
2. Obligations and liability. Apodex will bind each Sub-processor to data protection obligations that are, in substance, at least as protective as those in this DPA, and remains responsible for its Sub-processors' performance.
3. Notice and objection. Apodex will provide its current list of Sub-processors (including each Sub-processor's function and processing region) to Customer on request, will notify Customer of any intended addition or replacement of a Sub-processor, and Customer may object on reasonable data-protection grounds.
5. Security & Audits
1. Technical and Organizational Measures. Apodex shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or alteration, including: (1) Encryption of data at rest and in transit; (2) Strict physical and logical access controls to computing clusters and code repositories; and (3) Isolation mechanisms to prevent unauthorized cross-border access in sensitive scenarios.
2. Breach Notification. Apodex shall notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident affecting Customer's Personal Data, and shall provide sufficient information to allow the Customer to meet its obligations under Data Protection Laws.
6. Data Subject Rights
1. Assistance. Taking into account the nature of the processing, Apodex shall provide reasonable assistance to the Customer (at Customer's expense) to fulfil Customer's obligation to respond to requests from individuals exercising their rights.
7. Audit
1. Self-Certification and Audit. Apodex shall provide Customer with reasonable information to demonstrate compliance with this DPA. Customer's audit right shall be satisfied by the provision of Apodex's internal security summaries or existing third-party audit reports (if available).
2. Cost and Scope. Without prejudice to any mandatory audit or inspection rights Customer has under applicable Data Protection Laws, any further audit or inspection requested by the Customer shall be: (i) conducted at Customer's sole expense; (ii) limited to once every two years (unless more frequent audits are required by a supervisory authority or following a Security Incident); (iii) subject to a minimum of 60 days' prior notice; and (iv) restricted to systems strictly necessary for the Services, excluding any of Apodex's proprietary AGI models or core compute infrastructure code.
8. Data Deletion and Return
1. Termination. Upon termination of the Services or at the Customer's written request, Apodex shall, at the Customer's option, delete or return all Personal Data in its possession, unless applicable law requires continued storage of such data.
2. Certification. Apodex shall, upon request, provide written certification that it has complied with its deletion obligations under this Section.
9. Contact
Questions about this DPA, and any data-protection notices, may be sent to Apodex's Data Protection Officer at dpo@apodex.com.
Annex I — Details of Processing
1. Subject Matter. The Personal Data provided by the Customer or its end-users in connection with the use of Apodex's AI services, reasoning engines, and related technical support.
2. Duration. For the duration of the Agreement, plus the period until all Personal Data is deleted or returned.
3. Nature and Purpose. Service delivery, optimization, support, and compliance.
4. Categories of Data Subjects. Customer's employees, contractors, and authorized representatives; Customer's end-users; and any other individuals whose Personal Data is included in the Input.
5. Categories of Personal Data. Identification and contact information; technical data (IP addresses, device identifiers, logs, metadata); and user-generated content.
6. Sensitive Data. The parties do not anticipate the processing of sensitive data. If the Customer intends to process such data, it must provide prior written notice to Apodex and comply with additional security requirements.