When this applies
This Data Processing Addendum (the DPA) forms part of the Terms of Service between you (Customer) and Axis Marketing AI, Inc. (Axis) whenever Axis processes personal data on the Customer's behalf.
It applies automatically. No signature is required, and it takes effect when you accept the Terms. If your organization requires a countersigned copy, request one at legal@axismarketing.ai.
Terms such as controller, processor, personal data, processing, data subject and supervisory authority carry the meanings given in the applicable data protection law, including the EU and UK GDPR and the US state privacy laws.
Roles
- For personal data the Customer puts into the Service, or that Axis retrieves from the Customer's connected accounts, the Customer is the controller and Axis is the processor. Under US state laws Axis acts as a service provider or processor and not as a third party.
- For account, billing and usage data about the Customer's own users, Axis is a controller in its own right, and the Privacy Policy governs.
- Axis will not sell personal data, will not share it for cross-context behavioral advertising, and will not retain, use or disclose it for any purpose other than performing the Service, except as the law requires.
What we process
The details required by Article 28(3) are in Annex A. In summary, Axis processes the personal data the Customer chooses to submit or connect, for as long as the Customer uses the Service, in order to generate, schedule, publish and report on marketing content at the Customer's direction.
Our obligations
Axis will:
- process personal data only on the Customer's documented instructions, which include the Terms, this DPA and the Customer's use of the Service, unless required otherwise by law, in which case Axis will tell the Customer first unless the law prohibits it;
- tell the Customer if, in its opinion, an instruction infringes data protection law;
- ensure people authorized to process the data are bound by confidentiality;
- implement the security measures in Annex B;
- assist the Customer, taking account of the nature of processing, with data subject requests, security, breach notification, impact assessments and prior consultation;
- make available the information needed to demonstrate compliance.
Subprocessors
The Customer gives general authorization for Axis to engage subprocessors. The current list is published at axismarketing.ai/subprocessors and is part of this DPA.
- Axis will give at least 30 days notice before adding or replacing a subprocessor, by email to the account address and by updating that page.
- The Customer may object on reasonable data protection grounds within that period. Axis and the Customer will work in good faith to resolve it. If it cannot be resolved, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
- Axis imposes on each subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for their performance.
Your instructions and rights
The Customer is responsible for having a lawful basis for the personal data it submits or connects, for issuing any notices and obtaining any consents its own data subjects require, and for the accuracy of the data.
Where a data subject contacts Axis directly about data Axis processes for the Customer, Axis will not respond substantively, will refer them to the Customer, and will tell the Customer promptly.
Security
Axis implements appropriate technical and organizational measures, described in Annex B, and reviews them regularly. Axis may update them provided the level of protection is not reduced.
Personal data breach
Axis will notify the Customer without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting the Customer's personal data. The notice will describe what is known, the likely consequences, and the measures taken or proposed, and Axis will provide further information as it becomes available.
Axis will not notify the Customer's data subjects or any authority on the Customer's behalf unless the Customer asks or the law requires it.
International transfers
Axis processes personal data in the United States. Where personal data is transferred out of the EEA, the United Kingdom or Switzerland to a country without an adequacy decision:
- the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA, with Module Two applying where the Customer is a controller and Module Three where the Customer is itself a processor;
- the UK International Data Transfer Addendum applies to UK transfers;
- the Swiss addendum applies to Swiss transfers, with references to the supervisory authority read as the Federal Data Protection and Information Commissioner.
For the Clauses: the Customer is the data exporter and Axis the data importer; the optional docking clause applies; the governing law and forum are those of Ireland for Module Two and Three unless the Customer's establishment requires otherwise; Annex A supplies the description of processing and Annex B the technical and organizational measures. Where the Clauses conflict with the rest of this DPA, the Clauses prevail.
Deletion and return
On termination, Axis will delete or return the Customer's personal data at the Customer's choice, and delete existing copies, unless law requires storage. Absent an instruction, Axis deletes or anonymises within 90 days of account closure, with backups ageing out within a further 90 days. Export is available in the Service before closure and on request for a limited period afterwards.
Audits
Axis will make available information necessary to demonstrate compliance and will contribute to audits. In the first instance Axis will respond to a reasonable written questionnaire, no more than once a year. Where the Customer reasonably requires an on-site audit, the parties will agree scope, timing and cost in advance, it will happen no more than once a year outside a breach, and it must not compromise the confidentiality or security of other customers.
Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. Nothing here limits a data subject's rights under the Standard Contractual Clauses.
This DPA takes effect when the Customer accepts the Terms and continues while Axis processes personal data on the Customer's behalf. Where it conflicts with the Terms on data protection, this DPA prevails.
Annexes
Annex A. Description of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Axis AI marketing platform. |
| Duration | For the term of the Terms, plus the retention periods in section 10. |
| Nature and purpose | Hosting, storage, generation, scheduling, publication, analysis and reporting of marketing content at the Customer's direction. |
| Types of personal data | Identifiers and contact details of the Customer's personnel; and, where connected, data exposed by the Customer's social, advertising and analytics accounts, which may include profile information, audience and follower data, comments, messages and engagement metrics. Special category data is not requested and should not be submitted. |
| Categories of data subject | The Customer's personnel and authorized users; the Customer's audience, followers, and people who interact with the Customer's connected accounts. |
| Frequency | Continuous for the duration of the Service. |
| Sensitive data | None requested. Not permitted without a prior written agreement. |
Annex B. Technical and organizational measures
- Encryption of personal data in transit using TLS, and at rest.
- Role-based access control on a least-privilege basis, with access reviewed periodically and removed on departure.
- Multi-factor authentication required for administrative access to production systems.
- Logical separation of customer data, with automated testing that one account cannot access another's data.
- Logging and monitoring of access to production systems, retained for 12 months.
- Encrypted backups with tested restoration.
- A documented incident response process with defined roles and escalation.
- Confidentiality obligations and security awareness training for personnel with access.
- Written data protection terms with every subprocessor before data is shared.
- A published vulnerability disclosure process.
Annex C. Subprocessors
The current list is published and maintained at axismarketing.ai/subprocessors.