1. What this addendum covers
This Data Processing Addendum (“DPA”) is part of our Terms of Service. It applies whenever Imagiax (“Imagiax”, “we”) processes personal information on behalf of a client (“you”) while providing our services: for example, your customers’ enquiries passing through a form or automation we run, contacts synced to your CRM, or messages handled by an AI assistant we operate for you (“Client Personal Data”).
It doesn’t cover personal information we handle for our own business, such as your team’s contact details and invoices; our Privacy Policy covers that.
If this DPA and the Terms disagree about personal information, this DPA wins. If you need a countersigned copy, email privacy@imagiax.com.
2. Our roles
For Client Personal Data, you are the controller (or “business”) and we are your processor (or “service provider” / “contractor” under US state laws such as the California Consumer Privacy Act). The details of the processing are in Annex 1 (section 12).
You are responsible for having a lawful basis and any consents or notices needed for the processing you ask us to do, and for your instructions complying with data protection law.
3. What we commit to
For Client Personal Data, we will:
- process it only on your documented instructions (the Terms, your proposal, and your configuration and written requests), unless the law requires otherwise, in which case we will tell you first unless the law forbids that;
- tell you straight away if we think an instruction breaks data protection law;
- make sure everyone who can access it is bound by confidentiality;
- protect it with the security measures in Annex 2 (section 13);
- help you, as far as we reasonably can, to respond to people exercising their rights, to keep the data secure, to handle personal data breaches, and to carry out impact assessments or consult regulators;
- keep records of our processing, and make available the information you reasonably need to show compliance (section 8).
US state law commitments. As your service provider or contractor, we will not sell or share Client Personal Data; retain, use or disclose it for any purpose other than providing the services to you, or outside our direct business relationship with you; or combine it with personal information from other sources, except as those laws allow. We will comply with the applicable laws, give the same level of protection they require, tell you if we can no longer meet these obligations, and let you take reasonable steps to stop and fix any unauthorised use.
4. Subprocessors
You authorise us to use the subprocessors below, and any others named in your proposal for your project (for example a messaging, telephony, CRM or AI provider chosen together with you). We will:
- give each subprocessor data protection obligations at least as protective as this DPA;
- remain responsible to you for their performance;
- tell you at least 14 days before adding or replacing a subprocessor for your project, so you can object on reasonable data protection grounds. If we can’t resolve the objection, either of us may end the affected service.
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Hosting and running websites and automation code | United States and global edge network |
| Google LLC (Firebase / Google Cloud) | Databases and authentication | United States |
| Cloudflare, Inc. | File storage (R2) and network services | Global |
| Resend | Sending transactional email | United States |
| Project-specific providers | As named in your proposal (for example messaging, calendar, CRM or AI services) | As stated in the proposal |
Where a service runs on accounts you hold yourself (for example your own CRM or messaging account), that provider works for you directly under its terms with you, rather than as our subprocessor.
AI providers. We only use AI services under business or API terms that prevent them from training their models on Client Personal Data.
5. International transfers
We and our subprocessors may process Client Personal Data in the United States and other countries. Where personal data from the UK, the European Economic Area or Switzerland is transferred to a country without an adequacy decision, the transfer is covered by the provider’s certification under the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where available, and otherwise by the European Commission’s Standard Contractual Clauses (Module Two, controller to processor, or Module Three, processor to processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and the Swiss adaptations where relevant. If those clauses conflict with this DPA, the clauses win. On request, we will sign them with you as a separate document.
6. Personal data breaches
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Client Personal Data, we will tell you without undue delay, and in any case within 48 hours. We will give you the information we have about what happened, the data and people affected, the likely consequences and what we are doing about it, and keep you updated. We will help you meet your own duties to notify regulators and the people affected; you decide whether and how to notify them.
7. Requests from individuals
If someone contacts us to exercise their rights over Client Personal Data, we will pass the request to you promptly and not answer it ourselves unless you ask us to. We will help you respond, including by finding, correcting, exporting or deleting the data, within the time the law gives you.
8. Information and audits
We will answer your reasonable written questions about our processing and share relevant documentation, including our subprocessors’ security certifications or reports where they make them available. If that isn’t enough to show compliance, or a regulator requires it, you may audit our processing once a year, on at least 30 days’ notice, during business hours, at your cost, and subject to confidentiality. Audits must not give access to other clients’ data.
9. Deletion at the end
When our services end, or earlier on your request, we will delete Client Personal Data, or return it to you first if you ask within 30 days of the end. Deletion is completed within 90 days, except where the law requires us to keep a copy, which we will keep protected and use for no other purpose. Backups held by our providers are overwritten on their normal schedule.
10. Liability
Each party’s liability under this DPA is subject to the limits in the Terms of Service, except where the law doesn’t allow those limits to apply, and except that nothing limits any rights individuals have directly under data protection law or the Standard Contractual Clauses.
11. Changes to this DPA
We may update this DPA to reflect changes in the law or our services. We will tell clients with active services about material changes at least 30 days in advance. Changes will never reduce the overall protection of Client Personal Data.
12. Annex 1: Details of the processing
| Details | |
|---|---|
| Subject matter and duration | Providing the services in the Terms and your proposal, for as long as we provide them, plus the deletion period in section 9 |
| Nature and purpose | Hosting, collecting, storing, organising, transmitting and deleting data so that your website, forms, automations, AI assistants, integrations and reports work as agreed |
| Types of personal data | Usually contact details (name, email, phone), enquiry and booking details, messages and call transcripts, order and invoice details, and technical data such as IP addresses. Further types only as described in your proposal |
| Special categories | None, unless your proposal expressly says so and we have agreed extra safeguards |
| Data subjects | Your customers, prospective customers, website visitors, employees and contractors |
| Frequency | Continuous while the services run |
13. Annex 2: Security measures
- Encryption in transit (TLS) for all services we operate; encryption at rest provided by our hosting, database and storage providers.
- Access limited to people who need it, using individual accounts, strong passwords and multi-factor authentication where available.
- Secrets and API keys kept out of code and stored in protected environment settings.
- Least-privilege access for integrations: we ask for the narrowest permissions a connection needs.
- Private storage for files, with short-lived, signed download links.
- Input validation, rate limits and abuse protection on public forms and uploads.
- Data minimisation: automations only move the fields they need, and test with sample data where possible.
- Prompt removal of access when a project or team member’s involvement ends.
- Reputable providers with recognised security programmes, reviewed when we choose them.
14. Contact
Email privacy@imagiax.com. You can also reach us through the project form on our homepage or on WhatsApp. We read every message and reply as soon as we can, and always within the time limits the law sets.