1. Application and roles
This Data Processing Addendum applies only when it is incorporated into an approved customer order, service agreement or other written agreement with ModuAxis LLC. For customer personal data, the customer generally acts as controller or business and ModuAxis acts as processor or service provider, unless applicable law or the processing context requires a different allocation. The applicable order identifies the contracted service and any product-specific processing terms.
2. Processing details
The subject matter of processing is the provision, administration, security, support and maintenance of the contracted ModuAxis service. Processing may include collection, recording, organisation, storage, retrieval, consultation, analysis, transmission, restriction, deletion and other operations reasonably necessary to provide the approved service.
Processing continues for the subscription or service term and for the limited period afterwards needed to complete return, deletion, backup expiry, security, legal or contractual obligations. The customer controls the approved service configuration and lawful instructions within the functionality and terms of the service.
3. Data subjects and personal-data categories
Depending on the contracted product and customer configuration, data subjects may include:
- customer administrators and authorised users;
- employees, contractors or other workforce users included in an approved Workforce deployment;
- business contacts and support contacts; and
- individuals referenced in customer-provided operational, asset or assignment records where applicable.
Personal-data categories may include:
- name, business contact information, organisation, role and user identifiers;
- account, authentication, permission and audit information;
- device, agent, browser, network, security and diagnostic metadata;
- approved Workforce activity metadata such as active and idle time, foreground application identity, active website hostname, device or agent status, classification results and work summaries;
- customer-entered operational, asset, assignment, inventory or support records where the applicable service permits them; and
- billing or transaction metadata where a commercial payment process is activated.
ModuAxis services are not designed to require special-category or highly sensitive personal data unless expressly agreed in writing. Customers must not intentionally provide such data unless the processing is lawful, necessary for the approved service and specifically authorised.
4. Documented instructions and purpose limitation
ModuAxis will process customer personal data only to provide, administer, secure, support and maintain the contracted service, comply with documented lawful customer instructions, or meet a legal requirement. ModuAxis will inform the customer if an instruction appears to violate applicable data protection law unless prohibited from doing so. ModuAxis will not sell customer personal data or use it for cross-context behavioural advertising.
5. Confidentiality and security measures
Personnel authorised to process customer personal data are subject to confidentiality obligations. ModuAxis will maintain reasonable administrative, technical and organisational safeguards appropriate to the contracted service, processing risk and state of implementation.
Depending on the approved service, safeguards may include:
- role-based access and least-privilege controls;
- authentication controls and protected administrative access;
- transport encryption and appropriate protection of stored data and secrets;
- tenant and customer access boundaries appropriate to the service architecture;
- security logging, audit records and monitoring appropriate to the service;
- secure software-change, dependency, patch and vulnerability-management practices;
- backup and restore controls established for the applicable production service;
- incident-response and access-revocation procedures; and
- vendor and subprocessor review proportionate to the data and service risk.
Product-specific commitments, certifications, recovery objectives or security schedules are binding only when expressly stated in an approved written agreement or service schedule.
6. Personal-data breaches
ModuAxis will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data, to the extent required by applicable law and the customer agreement. ModuAxis will provide information reasonably available to assist the customer in meeting applicable notification obligations, including the nature of the incident, affected data or systems where known, relevant containment or remediation measures and an appropriate contact point. Notification does not constitute an admission of fault or liability.
7. Subprocessors
ModuAxis may engage subprocessors where reasonably necessary to deliver, secure, communicate, support, back up or operate an approved service. ModuAxis will require subprocessors that process customer personal data to accept appropriate confidentiality, security and data-protection obligations and remains responsible for its contractual obligations to the customer.
Current provider information is maintained on the Subprocessor Information page. ModuAxis will use reasonable efforts to update that page before a new material production subprocessor begins processing customer personal data. Where the applicable customer agreement provides advance notice or objection rights, ModuAxis will follow those requirements and address reasonable objections based on legitimate data-protection grounds.
8. Data-subject and compliance assistance
Taking into account the nature of processing and the information available, ModuAxis will provide reasonable assistance with data-subject requests, regulatory enquiries, data-protection impact assessments and prior consultations where required by applicable law and the customer agreement. Where a request relates to data controlled by the customer, ModuAxis may direct the individual to the customer and will act on lawful customer instructions.
9. International transfers
Product hosting and data-location commitments are identified in the applicable order or service schedule. Where customer personal data is subject to a restricted international transfer, the parties will use an applicable lawful transfer mechanism and supplementary safeguards where required. For transfers governed by European or United Kingdom data protection law, the applicable customer agreement may incorporate the relevant approved standard contractual clauses, United Kingdom addendum or other legally recognised transfer mechanism.
10. Return, deletion and retention
After termination or expiry, customer personal data will be returned, exported or deleted according to the applicable agreement, available service functionality, customer instructions, backup cycle and legal retention requirements. Data required for security, accounting, legal claims or compliance may be restricted from ordinary use and retained only for the necessary period. Backup copies expire through the applicable backup cycle unless preservation is legally required.
11. Audit and compliance information
ModuAxis will provide information reasonably necessary to demonstrate compliance with this Addendum. Where additional audit activity is required by applicable law or an approved customer agreement, it must protect other customers, confidential information and security controls and must follow a reasonable scope, notice, frequency and cost arrangement. Remote records and independent evidence may be used before an on-site audit where they reasonably satisfy the requirement.
12. Order of precedence and changes
If this Addendum conflicts with an approved product-specific data protection schedule or signed customer agreement, the more specific written term controls for that processing. ModuAxis may update the public form of this Addendum for legal, security or operational changes, but changes to an active contracted processing arrangement apply only as permitted by the applicable customer agreement or mandatory law.
Contact
Questions, legal notices and privacy requests may be sent to office@moduaxis.com.
ModuAxis LLC8606 Rising Ridge Ct
Bristow, VA 20136
United States