Data Processing Agreement (DPA)
We process customer data on the customer's instructions, isolated and auditable. Here is the summary.
1. Parties and roles
Data controller: the business using the service (the customer). Data processor: PROCUX Technology Inc. ("Aircux"). Aircux processes customer data only in line with the customer's documented instructions.
2. Subject, duration and purpose of processing
- Subject: end-user data coming from the channels the customer connects.
- Purpose: providing the growth intelligence service (visibility, identity, journeys, attribution, approved actions).
- Duration: for the term of the agreement; on termination the deletion/return provisions apply.
3. Sub-processors
Aircux may use a limited number of sub-processors (e.g. a hosting provider in the EU region) to provide the service. All sub-processors must provide at least the level of protection in this agreement. The customer is informed in advance of any change of sub-processor and keeps the right to object.
4. Technical and organisational measures
- Tenant isolation: each customer's data runs technically separated from the others.
- Access control: least privilege, logged and auditable access.
- Encryption in transit and at rest and regular backups.
- Approval gate & audit trail: every outbound action goes through approval and is recorded.
5. Data breach notification
If a personal data breach is detected, the customer is informed without undue delay, including the nature of the breach, the categories of data affected and the measures taken.
6. Deletion and return
When the agreement ends, customer data is returned or permanently deleted, as the customer chooses. The customer can take a single-command export at any time; KVKK/GDPR erasure requests are handled in the product.