Legal

Data processing addendum

Article 28 GDPR terms for personal data that Axelion processes on behalf of its business customers.

Last updated and effective: 14 September 2026

This Data Processing Addendum (the "DPA") forms part of the Terms of Service between the operator of the website at axelion.ai and provider of the Axelion service ("Axelion", the "Processor") and the business customer (the "Customer", the "Controller"). It is concluded automatically when the Customer accepts the Terms and requires no separate signature. Capitalised terms not defined in this DPA have the meaning given to them in the Terms or in Regulation (EU) 2016/679 (the "GDPR").

1. Scope and roles

1.1 This DPA applies to personal data contained in Customer Data that Axelion processes on behalf of the Customer in providing the Service ("Customer Personal Data").

1.2 The Customer acts as controller and Axelion as processor. Where the Customer itself acts as a processor on behalf of a third-party controller, the Customer warrants that its instructions, including the engagement of Axelion as sub-processor, are authorised by that controller; Axelion then acts as sub-processor, and the Customer remains Axelion's sole point of contact.

1.3 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

1.4 This DPA prevails over the Terms only in relation to the processing of Customer Personal Data. In all other respects, including limitation of liability, the Terms apply.

1.5 This DPA does not apply to personal data for which Axelion is a controller, such as account, billing, usage and security data, which is governed by the Privacy Policy.

2. Customer obligations

2.1 As controller, the Customer is responsible for compliance with the GDPR and other applicable data protection law, including: (a) having a valid legal basis for all processing of Customer Personal Data, including its collection, its processing through the Service and its transmission to Connected Platforms; (b) providing End Users with all information required under Articles 13 and 14 GDPR, including about the use of an AI agent and of Axelion as processor; (c) obtaining all consents required, including for electronic marketing and messaging-platform opt-ins; and (d) carrying out any data protection impact assessment required under Article 35 GDPR.

2.2 The Customer is solely responsible for the accuracy, quality and lawfulness of Customer Personal Data and of the means by which it was obtained, and for ensuring that its instructions comply with applicable law.

2.3 The Customer must not submit to the Service special categories of personal data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR), personal data of children under 16, national identification numbers, payment card data or authentication credentials of End Users, unless Axelion has agreed in writing.

2.4 The Customer is responsible for configuring the Service appropriately, including retention settings, access rights and the security of its account, and for responding to data subject requests.

3. Processing on documented instructions

3.1 Axelion processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to third countries (Article 28(3)(a) GDPR). The Terms, this DPA and the Customer's configuration and use of the Service constitute the Customer's complete and final instructions at the time of acceptance.

3.2 Any additional or amended instructions require Axelion's prior written agreement and may be subject to additional fees. If Axelion does not agree, the Customer's sole remedy is to terminate the affected Service.

3.3 Axelion may process Customer Personal Data where required to do so by EU or Member State law to which Axelion is subject; in that case Axelion will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.4 Axelion will immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data protection provisions, and may suspend the performance of that instruction until it is confirmed or modified by the Customer. Axelion is not obliged to carry out a legal review of the Customer's instructions.

4. Confidentiality

Axelion ensures that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it (Article 28(3)(b) GDPR).

5. Security

5.1 Axelion implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR (Article 28(3)(c) GDPR).

5.2 Axelion may update these measures from time to time, provided that the overall level of security is not materially reduced.

5.3 The Customer has assessed these measures and agrees that they provide an appropriate level of security for Customer Personal Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing.

6. Sub-processors

6.1 The Customer grants Axelion a general written authorisation under Article 28(2) GDPR to engage sub-processors, including providers of hosting, content delivery, AI model, messaging, email, storage and support services. The current list of sub-processors is available on request through our contact form.

6.2 Axelion will inform the Customer of any intended addition or replacement of sub-processors at least 14 days in advance by email to the Customer's account address.

6.3 The Customer may object to such a change on reasonable data protection grounds by written notice through the contact form referred to in section 6.1 within that 14-day period. The parties will discuss the objection in good faith. If it cannot be resolved, the Customer's sole and exclusive remedy is to terminate the affected Service with effect from the date on which the new sub-processor is engaged, in which case Axelion will refund prepaid fees for the unused part of the subscription term. If the Customer does not object in time, the change is deemed accepted.

6.4 Axelion imposes on each sub-processor, by contract, the same data protection obligations as set out in this DPA, to the extent applicable to the services provided by that sub-processor, in particular providing sufficient guarantees to implement appropriate technical and organisational measures (Article 28(4) GDPR).

6.5 Where a sub-processor fails to fulfil its data protection obligations, Axelion remains liable to the Customer for the performance of that sub-processor's obligations, subject to section 13.

6.6 Connected Platforms that the Customer chooses to connect, such as WhatsApp, Telegram, email services or CRMs, are not sub-processors of Axelion. They are engaged by the Customer under the Customer's own agreements, and any transmission of data to them is carried out on the Customer's instruction.

7. International transfers

7.1 The Customer authorises Axelion and its sub-processors to transfer Customer Personal Data to countries outside the European Economic Area, provided that the transfer complies with Chapter V GDPR, in particular on the basis of an adequacy decision (including the EU–US Data Privacy Framework), the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, or other appropriate safeguards.

7.2 Where Standard Contractual Clauses are required for a transfer by Axelion to a sub-processor, Axelion will conclude Module 3 (processor to processor) of those clauses with that sub-processor.

7.3 If a transfer mechanism is invalidated or suspended, Axelion may suspend the affected transfer, and the parties will cooperate in good faith to implement an alternative mechanism. Axelion is not liable for such suspension.

8. Data subject requests

8.1 Taking into account the nature of the processing, Axelion assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests from data subjects (Article 28(3)(e) GDPR), primarily by making self-service functions such as export and deletion available in the Service.

8.2 If Axelion receives a request directly from a data subject relating to Customer Personal Data, it will not respond to it other than to refer the data subject to the Customer, where the Customer can be identified, and will inform the Customer without undue delay.

8.3 Assistance beyond the self-service functions of the Service is provided at the Customer's cost, at Axelion's then-current rates.

9. Personal data breaches

9.1 Axelion notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data (Article 33(2) GDPR), by email to the Customer's account address.

9.2 The notification will contain, to the extent available, the information referred to in Article 33(3) GDPR. Where not all information is available at the same time, it may be provided in phases without undue further delay.

9.3 Axelion takes reasonable measures to contain the breach and to mitigate its possible adverse effects.

9.4 The Customer is responsible for notifying the supervisory authority and affected data subjects where required. Axelion does not notify them on the Customer's behalf unless required by law.

9.5 A notification of a breach is not an acknowledgement of fault or liability. Unsuccessful attempts and activities that do not compromise the security of Customer Personal Data, such as pings, port scans or failed log-in attempts, are not personal data breaches.

10. Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to it, Axelion provides reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR (Article 28(3)(f) GDPR), primarily by making available the information described in section 11.1. Further assistance is provided at the Customer's cost.

11. Information and audits

11.1 Axelion makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR (Article 28(3)(h) GDPR) in the form of this DPA, a description of its security measures, the list of sub-processors and responses to reasonable security questionnaires, the latter not more than once in any twelve-month period.

11.2 If this information is insufficient to demonstrate compliance, or where an audit is required by a supervisory authority or follows a personal data breach, the Customer may carry out an audit, including an inspection, subject to the following conditions: (a) at least 30 days' prior written notice with a proposed scope and plan; (b) not more than once in any twelve-month period, except where required by a supervisory authority or following a personal data breach; (c) during normal business hours, without unreasonable disruption to Axelion's operations, and remotely where possible; (d) conducted by the Customer or by an independent auditor that is not a competitor of Axelion and is bound by confidentiality obligations; (e) without access to data of other customers, to information subject to third-party confidentiality obligations, or to information whose disclosure would compromise the security of the Service; and (f) at the Customer's expense, including reimbursement of Axelion's reasonable costs and time at its then-current rates.

11.3 Audits of sub-processors are satisfied by making available their certifications or audit reports, such as ISO/IEC 27001 certificates or SOC 2 reports, where available.

11.4 All audit information and results constitute Axelion's Confidential Information.

12. Deletion and return

12.1 After termination or expiry of the Service, the Customer may export Customer Personal Data during the retrieval period set out in section 15.6 of the Terms. By exporting its data, the Customer exercises its choice of return. The Customer may instead instruct deletion at any time; the periods in section 12.2 then run from that instruction.

12.2 After the retrieval period, Axelion deletes Customer Personal Data from production systems within 30 days and from backups in the ordinary backup cycle within 90 days, unless EU or Member State law requires its storage (Article 28(3)(g) GDPR). Until overwritten, backup data remains protected and is not actively processed.

12.3 Axelion confirms deletion in writing at the Customer's request.

13. Liability

13.1 Axelion's liability arising out of or in connection with this DPA, whether in contract, tort or otherwise, is subject to the exclusions and limitations of liability in section 13 of the Terms. A single aggregate cap applies to the Terms and this DPA together.

13.2 Nothing in this DPA limits liability towards data subjects under Article 82 GDPR, or any liability that cannot be limited under applicable law.

13.3 The Customer shall reimburse Axelion, in proportion to the Customer's responsibility, for (a) compensation paid by Axelion to data subjects, in accordance with Article 82(5) GDPR, and (b) administrative fines imposed on Axelion, to the extent permitted by law, in each case where the damage or infringement was caused in whole or in part by the Customer, including through unlawful instructions, the absence of a legal basis or a failure to inform data subjects.

14. Term and governing law

14.1 This DPA applies for as long as Axelion processes Customer Personal Data and survives termination of the Terms until all Customer Personal Data has been deleted or returned.

14.2 This DPA is governed by the law and subject to the jurisdiction set out in section 20 of the Terms. Where Standard Contractual Clauses apply, their provisions on governing law and jurisdiction prevail for matters within their scope.

Annex 1 — Details of processing

Subject matterProvision of the Axelion Service: an AI sales agent that answers End User messages, recommends products, prepares quotes and invoices, hands conversations to the Customer's staff and provides analytics.
DurationThe term of the Terms, plus the transitional, retrieval and deletion periods set out in the Terms and in section 12.
Nature of processingCollection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, analysis and automated generation of responses by AI models, disclosure by transmission to End Users and Connected Platforms, combination, restriction, anonymisation and erasure.
PurposeProviding, maintaining, securing and supporting the Service, including improving the Customer's own AI agent based on its conversations; detecting and preventing abuse and illegal content; enforcing the Terms; and anonymising Customer Personal Data under section 7.5 of the Terms — all as instructed by the Customer by accepting the Terms.
Categories of data subjectsEnd Users (the Customer's customers, prospects and other persons who contact the Customer through connected channels); the Customer's personnel whose data appears in Customer Data; other individuals referred to in conversations.
Types of personal dataIdentification and contact data (such as name, phone number, messaging identifiers and email address); content of messages and attachments; order, quote and invoice data (such as products, quantities, prices, delivery and billing details); CRM records; lead qualification data; technical metadata (such as timestamps, channel and message identifiers, language and delivery status).
Special categoriesNone. The Customer must not submit special categories of personal data (section 2.3).
FrequencyContinuous.
RetentionAs configured by the Customer in the Service and, in any event, no longer than set out in section 12.

Annex 2 — Security measures

  • Encryption: encryption of data in transit using TLS; encryption of data at rest as provided by Axelion's infrastructure providers.
  • Access control: role-based access on a least-privilege and need-to-know basis; individual user accounts; multi-factor authentication for administrative and infrastructure access; prompt revocation of access that is no longer required.
  • Separation: logical separation of each customer's data within the Service.
  • Logging and monitoring: logging of administrative access and security-relevant events, and monitoring for abuse and anomalies.
  • Availability and resilience: use of established cloud infrastructure providers with redundancy; regular backups.
  • Vulnerability management: timely application of security updates to systems and dependencies.
  • Personnel: confidentiality obligations and data protection instructions for all persons with access to Customer Personal Data.
  • Sub-processor management: due diligence before engagement and data processing agreements in accordance with section 6.
  • Incident management: documented procedures for detecting, assessing, containing and notifying personal data breaches.
  • AI model providers: engagement only of AI model providers whose terms do not permit them to use Customer Personal Data submitted through the Service to train their models.
  • Data minimisation and deletion: configurable retention, and deletion of Customer Data on termination in accordance with section 12.