← All legal documents

Data Processing Addendum

Version 1.0 · effective 14/07/2026

This DPA forms part of the agreement between Customer ("Controller") and CapIX ("Processor") where CapIX processes personal data on Customer's behalf. "Data Protection Law" includes applicable UK GDPR, Data Protection Act 2018 and EU GDPR requirements. Customer may instead be a processor appointing CapIX as subprocessor. Each party remains independently responsible for processing for which it is controller.

1. Processing details and instructions

The subject is decentralised routing, hosting, execution, storage, support, security, metering and deletion of Customer workloads. Processing lasts for the Services term plus documented deletion and backup periods. Data subjects may include Customer users, personnel, customers and persons represented in Customer Content. Data may include identifiers, contact and network data, code, prompts, files, inputs and outputs. Special-category or high-risk data is prohibited unless an accepted order expressly authorises it and specifies safeguards.

Customer instructs CapIX to process data to provide the Services, accepted orders, documented configuration and lawful written instructions. Customer warrants its instructions and disclosures are lawful and will not submit data beyond the contracted security level.

2. Processor obligations

CapIX will process only on documented instructions unless law requires otherwise; notify Customer of that law where permitted; ensure authorised personnel are bound by confidentiality; implement appropriate technical and organisational measures; assist with data-subject requests, impact assessments and consultations; maintain required records; and notify Customer if an instruction appears unlawful.

Measures include least-privilege access, multifactor authentication for privileged access, encryption in transit and at rest where supported, secrets management, tenant isolation, secure development, vulnerability management, monitoring, incident response, recovery, supplier review and verified deletion. CapIX will not materially reduce these measures during the term.

3. Subprocessors and decentralised Providers

Customer gives general authorisation for subprocessors listed in the current Subprocessor List, including independent node operators selected under Customer routing policy. CapIX will impose appropriate written obligations and remains responsible to the extent required by law. Enabling unrestricted or global routing instructs CapIX to use eligible Providers in selected locations. Customer should restrict regions and Providers where required.

4. International transfers

No restricted transfer will occur without a lawful mechanism. Where needed, the EU Standard Contractual Clauses 2021/914, Module Two or Three as appropriate, and the UK International Data Transfer Addendum are incorporated. General subprocessor authorisation applies. The agreement, this DPA, Subprocessor List and security documentation complete the relevant annexes. Parties will apply supplementary measures identified by a transfer assessment.

5. Incidents

CapIX will notify Customer without undue delay and target within 24 hours after confirming a personal data breach affecting Customer data. Notice will describe the nature, likely consequences, affected data and subjects, mitigation and contact as information becomes available. CapIX will investigate, mitigate and cooperate. Customer controls regulatory and data-subject notices unless law requires CapIX to notify.

6. Return, deletion and audit

On termination or documented request, CapIX will make Customer data available for export and delete it within 30 days, with backups expiring within 90 days, unless law requires retention. Public blockchain data and data independently held by Customer-selected Providers may not be technically erasable; CapIX will apply available minimisation controls. CapIX will provide available audit reports and answer a reasonable annual questionnaire. If insufficient or after a material incident, Customer may conduct one annual audit through an independent bound auditor on reasonable notice, without compromising other customers or security.

7. Liability and hierarchy

Liability is subject to the agreement's limitations to the extent lawful. If documents conflict on personal-data protection, this DPA prevails, followed by mandatory transfer terms. This DPA terminates when CapIX no longer processes Customer personal data. Governing law follows the agreement except where Data Protection Law requires otherwise. Acceptance of the main agreement incorporates this DPA.

Publication fingerprint

SHA-256 d5a9a76bc51486358d93f8bbda6bee1e79b43416b0a2cd1b9ba9bf6fe99920be