DATA PROCESSING
Data Processing Addendum
Processing terms for customer personal data handled through Pactenix.Last updated: 3 August 2026Roles and scope
This Addendum applies where Pactenix processes personal data on behalf of a customer through the subscribed service. The customer is the controller and Pactenix is the processor, except where each party independently determines its own legal purposes, such as account administration, security, fraud prevention, billing or legal compliance.
Customer instructions
Pactenix will process customer personal data only to provide, secure and support the service, according to the Terms, the customer's documented configuration and lawful written instructions. The customer is responsible for the legality, accuracy and scope of its instructions and for providing required notices to data subjects.
Processing details
- Subject: operation of AI-agent jobs, workflows, evidence, integrations and organization controls.
- Duration: the subscription term plus documented deletion and legal-retention periods.
- Data subjects: customer personnel, authorized users, contacts and people represented in submitted job data.
- Data types: identifiers, contact information, business records, workflow inputs and outputs, usage events, support data and security logs.
- Purpose: hosting, transmission, execution, verification, support, security, audit and deletion of customer-configured workloads.
Confidentiality and security
Pactenix limits access to personnel and service providers who need it and are bound by confidentiality duties. Technical and organizational measures include tenant access controls, role permissions, encryption in transit, scoped secrets, signed integrations, audit records, rate limiting, backups and incident procedures appropriate to the service risk.
Subprocessors
The customer authorizes subprocessors needed for hosting, authentication, communications, monitoring and support. Paddle handles payment data as Merchant of Record under its own role and terms. Pactenix remains responsible for processor obligations delegated to subprocessors and will provide reasonable notice of material subprocessor changes through the service or registered email.
International transfers
Where protected data is transferred across borders, Pactenix will use a lawful transfer mechanism required for the relevant parties and destination, which may include standard contractual clauses or an adequacy framework. Customers must identify workloads with special localization requirements before using the service for them.
Data-subject requests
Taking into account the nature of processing, Pactenix will provide reasonable assistance with access, correction, deletion, restriction, portability and objection requests. The customer remains responsible for responding to requests and verifying the requester's identity and legal entitlement.
Security incidents
Pactenix will notify the affected customer without undue delay after confirming a personal-data breach involving customer data and will provide available information reasonably required for the customer's legal assessment. Notification is not an admission of fault or liability.
Deletion, audit and contact
At the end of service, Pactenix will delete or return customer personal data according to available product controls, backups and mandatory retention duties. Pactenix will provide reasonable compliance information and cooperate with proportionate audits subject to confidentiality, security and cost safeguards.
Data-processing questions and requests should be sent to office@pactenix.com.
