Effective Date: March 16, 2025
This Data Processing Agreement ("DPA") is entered into between Panoraxis AI ("Processor") and the entity using its services ("Controller") in compliance with applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and other relevant privacy laws.
Any information relating to an identified or identifiable natural person.
Any operation performed on Personal Data, including collection, storage, use, modification, disclosure, or deletion.
The entity determining the purposes and means of processing Personal Data.
The entity processing Personal Data on behalf of the Controller.
The natural person to whom the Personal Data relates.
Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
Controller engages Processor to process Personal Data in accordance with the terms of this DPA.
Processor shall process Personal Data only for the following purposes:
Processing shall continue for the duration of the Controller's use of Processor's services unless otherwise agreed.
Processor shall process Personal Data only in accordance with applicable laws, this DPA, and the Controller's documented instructions.
Processor ensures that personnel processing Personal Data are subject to strict confidentiality obligations.
Processor shall assist Controller in fulfilling requests from Data Subjects, including:
Controller must ensure that all Personal Data processed has a lawful basis under applicable data protection laws.
Controller shall provide documented processing instructions to Processor.
Controller is responsible for ensuring the accuracy and legality of Personal Data provided.
Controller must inform Processor of any changes in data processing requirements.
Processor shall ensure data transfers comply with applicable laws (e.g., Standard Contractual Clauses (SCCs), UK International Data Transfer Agreement, or equivalent safeguards).
Personal Data is processed and stored in secure data centers within the EEA, UK, or other approved jurisdictions.
Controller may audit Processor's compliance with this DPA once per year, subject to reasonable notice.
Personal Data shall be retained only as long as necessary for processing purposes.
Upon termination of services, Processor shall delete or return all Personal Data unless legal obligations require retention.
Processor's liability for breaches of this DPA is limited to direct damages, except in cases of gross negligence or intentional misconduct.
Processor shall indemnify Controller against third-party claims arising from Processor's non-compliance with this DPA.
Either party may terminate this DPA if the other party materially breaches its terms.
Processor shall cease all processing activities and ensure data is securely deleted or returned.
This DPA is governed by the laws of England and Wales.
Processor reserves the right to update this DPA with prior written notice to Controller.
Controller will be notified of material changes via email or an official notice.
For questions regarding this DPA, contact our Data Protection Officer (DPO) at privacy@panoraxis.tech.
Last updated: March 16, 2025
If you have any questions about this Data Processing Agreement, please contact us at privacy@panoraxis.tech