This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and Axion (“Processor”) and governs the processing of personal data Axion carries out on the customer's behalf.
1. Roles
The customer is the Controller of conversation and lead data processed within its workspace. Axion is the Processor and processes such data only on the Controller's documented instructions.
2. Scope of processing
- Subject matter: qualifying, scoring, and routing inbound conversations.
- Duration: for the term of the agreement plus any agreed retention window.
- Data subjects: the customer's leads and end-users who message its WhatsApp number.
- Data types: message content and structured fields extracted from it (e.g. name, budget, timeline).
3. Confidentiality
Axion ensures personnel authorised to process personal data are bound by confidentiality.
4. Security
Axion implements appropriate technical and organisational measures, including encryption in transit, tenant isolation, role-based access control, and audit logging. See our Security page.
5. Sub-processors
Axion engages sub-processors (e.g. cloud hosting and model providers) under written contracts with equivalent obligations. A current list is available on request, and Axion will give notice of intended changes.
6. Data subject requests
Axion assists the Controller in responding to data-subject requests, taking into account the nature of the processing.
7. International transfers
Where personal data is transferred across borders, appropriate safeguards such as standard contractual clauses apply.
8. Deletion & return
On termination, Axion deletes or returns personal data as instructed, subject to legal retention requirements.
9. Audits
Axion makes available information necessary to demonstrate compliance and allows for audits as set out in the agreement.
10. Contact
To request a signable DPA, email legal@axion.ai.