Legal
Data Processing Addendum
Controller/Processor terms for customers who need one on file.
This DPA is offered as a one-click acceptance from the dashboard. The full text below is a template; consult counsel before launch.
Roles and definitions
You are the Controller; Axiomatic Tools is the Processor. “Personal Data” follows the GDPR definition. “Subprocessors” are listed in our privacy policy.
Processing instructions
We process Personal Data only to provide the services you've requested: file transformation, AI inference on the files you submit, account management, billing, and security monitoring.
Confidentiality
Personnel with access to Personal Data are under written confidentiality obligations.
Security measures
See the technical and organisational measures described on our security page: envelope encryption at rest, TLS 1.3 in transit, per-tenant encryption keys, RBAC, audit log, sandboxed worker execution, vulnerability scanning in CI.
Subprocessors
We give 30 days' notice before adding or replacing a subprocessor. Current list lives in our privacy policy.
International transfers
Customer Personal Data is hosted in the EU by default. Transfers outside the EEA rely on the EU SCCs (Module 3, Processor-to-Processor) where applicable.
Sub-processor obligations
We impose terms on each subprocessor that are no less protective than those in this DPA.
Audits
On request, we share our SOC 2 Type II report and answer reasonable security questionnaires. On-site audits are available to Enterprise customers.
Returning or deleting data
On termination, we delete Personal Data within 30 days unless retention is required by law. Backups are aged out within 90 days.
Counter-signature
Email [email protected] with your entity details for a signed copy. A click-to-accept version is also available in the dashboard.