1. Purpose & structure
This Data Processing Addendum ("DPA") forms part of the agreement between Maxor Global LLC ("Processor", "Maxor", "we") and the customer entity that accepts our Terms or executes an Order ("Controller", "Customer", "you") for the MaxorConnect Service. It applies when we process Customer Personal Data on your behalf in providing the Service.
This public DPA describes our standard processor terms. Enterprise customers may request a countersigned PDF (including SCCs modules) via ${EMAIL}. If a signed DPA conflicts with this page, the signed document controls. Capitalized terms not defined here have the meaning in the Terms of Service or Privacy Policy.
2. Definitions
- "Applicable Data Protection Law" means GDPR, UK GDPR, Swiss FADP, CCPA/CPRA (as a service provider), Canadian privacy laws including Québec Law 25, and other laws applicable to the processing of Customer Personal Data under the Agreement.
- "Customer Personal Data" means personal data contained in Customer Data that we process as your processor.
- "GDPR" means Regulation (EU) 2016/679.
- "Personal data", "process", "controller", "processor", "data subject", "supervisory authority" have the meanings in the GDPR (or nearest equivalents under other laws).
- "SCCs" means the European Commission's Standard Contractual Clauses for international transfers (2021/914) and UK addendum where applicable.
- "Sub-processor" means a third party engaged by Maxor to process Customer Personal Data in providing the Service.
3. Roles of the parties
For Customer Personal Data, you are the controller (or business) and we are the processor (or service provider). We will not process Customer Personal Data except on your documented instructions, unless required by law (in which case we inform you before processing where legally permitted). Your configuration of the Service, APIs and integrations constitutes documented instructions.
We act as an independent controller for account administration data, billing records we create, website analytics and our own marketing/sales records, as described in the Privacy Policy — those activities are outside this DPA's processor scope.
4. Details of processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of MaxorConnect for Customer's organization |
| Duration | For the term of the Agreement plus the deletion/return period in §11 |
| Nature & purpose | Storage, retrieval, transmission, structuring, AI-assisted processing you enable, security logging, support — solely to provide the Service |
| Types of personal data | As determined by Customer; typically identity/contact data of Customer's users and end-customers, commercial and operational records Customer stores (see Privacy Policy categories) |
| Categories of data subjects | Customer's personnel, contractors, end-customers, prospects and other individuals whose data Customer submits |
| Special categories | Not required for the Service; Customer shall not submit special-category or HIPAA PHI data unless a separate written agreement covers it |
5. Customer instructions & compliance
- You warrant that your instructions comply with Applicable Data Protection Law and that you have provided all notices and obtained all consents required for us to process Customer Personal Data as instructed.
- We will inform you if, in our opinion, an instruction infringes GDPR (Art. 28(3)) or equivalent — without obligation to provide legal advice.
- You are responsible for the lawfulness of Customer Data you submit and for your use of integrations that export data to third parties.
6. Confidentiality of processing personnel
We ensure that persons authorized to process Customer Personal Data are under an appropriate obligation of confidentiality (contractual or statutory) and receive security awareness appropriate to their role.
7. Security measures
Taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, we implement appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction or damage, including as relevant:
- Encryption in transit (TLS) and at rest for primary data stores
- Organization-level logical isolation of Customer Data
- Attribute-based access control (ABAC), least privilege, and step-up MFA on sensitive admin actions
- Authentication controls, session management and API key hashing
- Audit logging of security-relevant events
- Vulnerability management and dependency hygiene practices
- Backup and recovery procedures appropriate to the Service
- Vendor security review for material sub-processors
A more detailed security overview is available on our Security page and under NDA for enterprise reviews. Controls are engineered toward SOC 2 / ISO 27001 practices; certification status is only as we publish or provide under NDA.
8. Sub-processors
You authorize us to engage Sub-processors to process Customer Personal Data for the Service. Our current list is published at /legal/subprocessors. We remain responsible for Sub-processors' performance of our data-protection obligations.
We will impose written terms on each Sub-processor that provide data-protection obligations no less protective in substance than those in this DPA with respect to Customer Personal Data. We will update the public list when Sub-processors change. Where your signed enterprise DPA grants an objection right, that procedure applies; otherwise, continued use after notice of a change constitutes acceptance for online Terms customers.
9. International transfers
We may process and transfer Customer Personal Data in the United States and other countries where we or our Sub-processors operate. Where a transfer from the EEA, UK or Switzerland requires a transfer mechanism, we rely on SCCs (and UK Addendum / Swiss adaptations as applicable) and implement supplementary measures where appropriate. Regional residency options for core data stores, where offered in product, will be applied per your configuration and Order.
On request for enterprise onboarding, we will provide the applicable SCC module and transfer impact information reasonably available to us.
10. Assistance with data-subject rights & compliance
Taking into account the nature of processing, we will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise rights under Applicable Data Protection Law. If we receive a request that identifies you as controller, we will promptly redirect the request to you or notify you, unless prohibited by law.
We will also assist you, where required by law and taking into account the nature of processing and information available to us, with data-protection impact assessments and prior consultations with supervisory authorities related to the Service.
11. Personal-data breach notice
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your notification obligations (nature of the breach, approximate data subjects/records affected where known, likely consequences, and measures taken or proposed). Notification is not an admission of fault.
Target contractual timeline for initial notice to enterprise customers is within 72 hours of confirming a breach affecting their Customer Personal Data, where feasible — faster where risk is clearly high. You are responsible for notifications to data subjects and regulators as controller, except where law requires us to notify directly.
12. Return & deletion
During the term, you may export Customer Data using product features. Upon termination of the Service, we will, at your choice communicated within the export window (typically 30 days), make Customer Data available for export and then delete Customer Personal Data from active systems within a commercially reasonable period (typically 30–90 days), except: (a) backup copies that expire on a rolling schedule; (b) data we must retain under law; (c) data subject to a legal hold. Anonymized or aggregate data that is no longer personal data may be retained.
13. Audit & information rights
Upon written request no more than once per twelve (12) months (unless a competent authority or confirmed breach requires more), we will make available information reasonably necessary to demonstrate compliance with this DPA, which may include responses to security questionnaires, summaries of controls, and, where available, third-party audit reports or certifications under NDA.
On-site audits are available only under a signed enterprise DPA, with reasonable notice, during business hours, subject to confidentiality, and at your expense unless a material breach of this DPA is found. We may require audits to be performed by an independent third party bound by confidentiality.
14. US state privacy (service provider)
To the extent CCPA/CPRA or similar US state laws apply to Customer Personal Data, we act as a service provider / processor. We will not: (a) sell or share Customer Personal Data; (b) retain, use or disclose it outside the business purpose of providing the Service or as otherwise permitted by law; (c) combine it with personal information from other sources except as permitted for service providers. We certify that we understand these restrictions. We will notify you if we can no longer meet our obligations under this section.
15. Liability
Liability arising under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent Applicable Data Protection Law prohibits limiting liability for a party's obligations. Each party remains responsible for its own fines imposed by a supervisory authority to the extent caused by that party's breach.
16. Order of precedence & changes
If this DPA conflicts with the Terms regarding processing of Customer Personal Data, this DPA controls. We may update this public DPA for legal or product changes; material reductions of your protection will be notified as described in the Terms. Signed enterprise DPAs are amended only in writing.
17. Contact
Privacy and DPA requests: [email protected]. Postal: Maxor Global LLC, 2915 Ogletown Road #5188, Newark, Delaware 19713, USA. Request a countersigned DPA package for enterprise procurement via the same email.