011. Incorporation and Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Astrixy LLC ("Astrixy", "Processor") and the customer accepting those Terms ("Customer", "Controller"). It applies whenever Astrixy processes personal data on the Customer's behalf in the course of providing the Service, and it takes precedence over the Terms in the event of conflict on data protection matters.
No signature is required: acceptance of the Terms constitutes acceptance of this DPA. A countersigned PDF is available on request from dpo@astrixy.app for procurement processes that require one.
022. Roles of the Parties
For end-customer data flowing through storefronts, checkouts, support inboxes, and marketing tools, the Customer is the Controller and Astrixy is the Processor. For account registration data, billing records, security logs, and product telemetry, Astrixy acts as an independent Controller and processes that data under the Privacy Policy.
033. Details of Processing
Subject matter: provision of a hosted commerce, automation, and analytics platform.
Duration: the term of the Customer's subscription, plus the retention periods in section 9.
Nature and purpose: hosting, storage, transmission, order fulfilment, payment orchestration, transactional and marketing messaging, analytics, fraud prevention, and support.
Categories of data subjects: the Customer's shoppers, prospects, newsletter subscribers, staff users, and support contacts.
Categories of personal data: identifiers (name, email, phone), shipping and billing addresses, order and transaction history, support correspondence, device and browser identifiers, IP address, and behavioural analytics.
Special categories: none are required by the Service. The Customer must not upload health, biometric, genetic, or other Article 9 data.
044. Processor Obligations
- Process personal data only on documented instructions from the Controller, including for international transfers, unless required otherwise by law.
- Ensure personnel with access are bound by confidentiality obligations that survive their engagement.
- Implement the technical and organisational measures described in section 6.
- Assist the Controller with data subject requests, data protection impact assessments, and prior consultations, taking into account the nature of processing.
- Notify the Controller without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting Controller data.
- At the Controller's election, delete or return personal data at the end of the engagement.
055. Controller Obligations
The Controller warrants that it has a valid lawful basis for the data it uploads or collects through the Service, that it has provided any required notices to data subjects, and that its instructions do not require Astrixy to breach applicable law. The Controller is responsible for configuring retention, consent banners, and access permissions appropriately for its own jurisdiction.
066. Security Measures
- TLS 1.2+ for all data in transit; HSTS enforced on all public hostnames.
- Encryption at rest for the primary datastore and object storage; AES-256-GCM application-layer encryption for third-party API credentials and webhook secrets.
- Row-level security on every tenant-scoped table, enforcing isolation at the database engine rather than in application code alone.
- Role-based access control with least-privilege service roles; production access is limited to named administrators and is logged.
- Immutable audit logging of privileged operations, retained for 12 months.
- Automated dependency and secret scanning on every merge, with a deploy gate on critical findings.
- Continuous error and anomaly monitoring with alerting on authentication, payment, and fulfilment failures.
- Encrypted, point-in-time-recoverable backups with documented restore procedures.
077. Subprocessors
The Controller grants general authorisation for Astrixy to engage subprocessors. The current list is published at astrixy.app/subprocessors. Astrixy imposes data protection obligations on each subprocessor that are no less protective than this DPA and remains liable for their performance.
We give at least 30 days' notice before adding or replacing a subprocessor. Subscribe to notifications at dpo@astrixy.app. If the Controller reasonably objects on data protection grounds within that period, it may terminate the affected Service without penalty for the unused prepaid term.
088. International Transfers
Where personal data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor) or Module Three (Processor to Processor) as applicable, which are incorporated into this DPA by reference. The UK International Data Transfer Addendum and the Swiss addendum apply to those respective transfers. Astrixy performs transfer impact assessments for each subprocessor located outside the EEA.
099. Retention and Deletion
Live tenant data is deleted within 30 days of account termination. Encrypted backups age out on a 35-day rolling cycle. Financial records required for tax and anti-fraud purposes are retained for the statutory period, in a restricted-access archive. Deletion requests for individual data subjects are executed within 30 days and propagated to subprocessors.
1010. Audit Rights
Astrixy will make available the information necessary to demonstrate compliance with Article 28, including our security documentation and, when available, third-party assessment reports. On reasonable written notice, no more than once per twelve months, and subject to confidentiality, the Controller may conduct or commission an audit. Astrixy may satisfy an audit request by providing an existing independent report where it covers the scope requested.
1111. Liability and Governing Law
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is governed by the law stated in the Terms, except where mandatory data protection law requires otherwise.
1212. Contact
Data Protection Officer: dpo@astrixy.app
Privacy: privacy@astrixy.app
Security incidents: security@astrixy.app