This Data Processing Addendum ("DPA") forms part of the agreement between TECHALEXUS LLC ("TECHALEXUS," "Processor") and the client ("Client," "Controller") for the provision of services that involve processing personal data. It reflects the parties' commitment to handling personal data lawfully and securely.
1. Introduction & roles
When TECHALEXUS processes personal data contained in Client's content or systems in order to deliver the Services, Client acts as the Controller (or as a processor acting for its own customers) and TECHALEXUS acts as the Processor. TECHALEXUS will process such personal data only on documented instructions from Client, including as described in the applicable Order and this DPA, unless required to do otherwise by law.
2. Definitions
- "Personal Data" means information relating to an identified or identifiable natural person that TECHALEXUS processes on behalf of Client.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, or deletion.
- "Data Protection Laws" means all privacy and data-protection laws applicable to the processing, which may include the EU/UK GDPR, the CCPA/CPRA, and other U.S. state laws.
- "Subprocessor" means a third party engaged by TECHALEXUS to process Personal Data.
3. Details of processing
Unless otherwise specified in an Order, the processing is described as follows:
| Item | Description |
|---|---|
| Subject matter | Provision of AI automation, AI agents, and digital marketing services. |
| Duration | The term of the engagement, plus any legally required retention period. |
| Nature & purpose | Building and operating automations that collect, organize, analyze, store, and act on data to deliver the Services. |
| Categories of data subjects | Client's customers, prospects, employees, and contacts, as determined by Client. |
| Categories of personal data | Contact details, account and usage data, communications content, and other data Client chooses to provide. |
| Special categories | Not intended; Client should not provide sensitive data unless agreed in writing with appropriate safeguards. |
4. TECHALEXUS obligations
TECHALEXUS will:
- Process Personal Data only on Client's documented instructions and for the purpose of providing the Services;
- Ensure that personnel authorized to process Personal Data are bound by confidentiality;
- Implement appropriate technical and organizational security measures (see Section 5);
- Assist Client, taking into account the nature of processing, with data subject requests, security, breach notification, and data protection impact assessments; and
- Not sell Personal Data or use it for our own independent purposes.
5. Security measures
TECHALEXUS maintains administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, loss, or disclosure. A summary of our practices is available on our Security page. Client is responsible for configuring its own systems and access controls appropriately.
6. Subprocessors
Client authorizes TECHALEXUS to engage Subprocessors (such as cloud hosting, analytics, communications, and AI model providers) to support the Services. TECHALEXUS will impose data-protection obligations on each Subprocessor that are no less protective than those in this DPA and remains responsible for their performance. We will inform Client of material changes to Subprocessors on request and give Client a reasonable opportunity to object on legitimate data-protection grounds.
7. Data subject requests
If TECHALEXUS receives a request from an individual to exercise rights under Data Protection Laws relating to Client's Personal Data, we will promptly notify Client and will not respond directly except on Client's instructions or as legally required. We will provide reasonable assistance to help Client respond.
8. Personal data breach notification
TECHALEXUS will notify Client without undue delay after becoming aware of a personal data breach affecting Client's Personal Data, and will provide information reasonably available to help Client meet its notification obligations.
9. International transfers
Where TECHALEXUS transfers Personal Data across borders, it will implement a lawful transfer mechanism where required by Data Protection Laws, such as standard contractual clauses or another approved safeguard.
10. Return & deletion
Upon termination of the Services, TECHALEXUS will, at Client's choice, delete or return Personal Data processed on Client's behalf, except where retention is required by law. Backups are deleted in the ordinary course of our retention cycle.
11. Audits
Upon reasonable written request, and subject to confidentiality, TECHALEXUS will make available information necessary to demonstrate compliance with this DPA and will contribute to audits conducted by Client or an agreed independent auditor, at reasonable intervals and during business hours.
Order of precedence. If there is a conflict between this DPA and the Terms of Service regarding the processing of Personal Data, this DPA controls. To request a countersigned copy for your records, contact us.
12. Contact
For data-processing questions or to put a signed DPA in place, contact contact@techalexus.com. TECHALEXUS LLC is located in Martinsburg, West Virginia, United States.