Data Processing Addendum
Last updated September 17, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer", the controller) and axonpush ("we", the processor) for your use of the hosted service. It describes how we process personal data on your behalf. Where it conflicts with the rest of the agreement on the subject of data protection, this DPA controls. A countersigned copy is available on request at privacy@axonpush.xyz.
1. Roles and scope
For personal data contained in the events and traffic you route through the hosted service, you are the controller and we are the processor. We process that data only to provide the service and only on your documented instructions, which include this DPA and your configuration of the service. For your account information we act as an independent controller as described in our privacy policy.
A BYOC deployment stores your event data in your own AWS account, which we cannot access. For BYOC we process only the licence record and the check-in telemetry described in the privacy policy.
2. Nature of processing
We process the personal data you route through the gateway to proxy, record, moderate and report on model and tool calls as you configure: storing event metadata and payloads, applying the rules and spend policies you define, and making the results available in the dashboard and audit trail. The duration is the term of your subscription plus the retention and deletion described below.
3. Your instructions
We will process personal data only as needed to provide the service and as instructed by you, and will tell you if we believe an instruction breaches applicable data protection law. Redaction rules run inline before a call leaves your network, and optional semantic analysis sends configured content to the model provider you choose; you control both.
4. Confidentiality
Our personnel who process personal data are bound by confidentiality obligations and access data only as needed to provide and support the service.
5. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, tenant-level isolation of event data enforced at the query layer, access controls, and logging. These measures are summarised in section 3 of the privacy policy.
6. Subprocessors
You authorise us to engage the subprocessors listed at axonpush.xyz/subprocessors. We impose data protection terms on each subprocessor no less protective than this DPA and remain responsible for their performance. We will update that page before adding or replacing a subprocessor that processes your personal data, and you may object on reasonable data protection grounds.
7. Data subject requests
Taking into account the nature of the processing, we will assist you with appropriate measures to respond to requests from data subjects to exercise their rights. For hosted accounts many requests can be actioned directly in the dashboard; for anything else, contact privacy@axonpush.xyz.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
9. International transfers
Where processing involves transferring personal data across borders, we rely on a lawful transfer mechanism, such as the European Commission's Standard Contractual Clauses, incorporated by reference where they apply.
10. Return and deletion
On termination, and on request during the term, we will delete or return personal data we process on your behalf, subject to the retention periods in section 4 of the privacy policy and any retention required by law.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable and confidential terms, support audits mandated by applicable data protection law.
12. Contact
For anything relating to this DPA, or to request a countersigned copy, contact privacy@axonpush.xyz.