1Scope and Effect
This Data Processing Addendum (the "Addendum" or "DPA") is entered into between you ("Customer") and Neox ("we," "us," "NeoX") and is incorporated into the Terms of Service. It applies whenever we process personal data protected by applicable data protection law on your behalf in the course of your use of the Service.
This Addendum takes effect automatically when you accept the Terms of Service; no separate signature is required. If your procurement process requires a separately executed copy, contact us and we will provide one.
"Applicable data protection law" means the GDPR (EU Regulation 2016/679), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data protection law applicable to the processing. Terms not defined here have the meaning given in the GDPR.
2Roles of the Parties
- Customer = controller
- For the personal data you submit to or generate through the Service ("Customer Data"), you are the data controller (or a processor acting for a third-party controller). You determine the purposes and means of processing and are responsible for its lawfulness.
- NeoX = processor
- For Customer Data, we are the data processor and process it only on your instructions.
- NeoX = controller (limited)
- For account information, billing records, security logs, and aggregated usage statistics that we process for our own purposes, we act as an independent controller. The Privacy Policy governs that processing, not this Addendum.
You represent and warrant that you have a valid legal basis for collecting and providing Customer Data, that you have given data subjects any required notices, and that you are entitled to instruct us to process it as set out in this Addendum.
3Details of the Processing
- Subject matter
- Processing of Customer Data in order to provide the Neox services described in the Terms of Service.
- Duration
- From the date the Customer begins using the Service until the Service ends and Customer Data has been deleted or returned in accordance with the "Deletion and Return" section below.
- Nature and purpose
- Receiving, transmitting, routing, temporarily caching, metering, storing, and deleting Customer Data in order to carry out the Customer's requests — including forwarding request content to upstream model providers to produce output, maintaining accounts and configuration, and preserving the security and availability of the Service.
- Processing operations
- Collection, recording, organization, storage, retrieval, use, transmission, restriction, erasure, or destruction.
We do not profile or sell Customer Data for our own purposes, and we do not use Customer Data to train or fine-tune any model.
4Data Subjects and Categories of Personal Data
| Item | Detail |
|---|---|
| Categories of data subjects | The Customer's employees, contractors, and authorized users; the Customer's end users and clients; and any individual appearing in content the Customer submits to the Service |
| Personal data — users | Name or display name, email address, account identifiers, authentication credentials, IP address, device and client information, usage records |
| Personal data — content | Any personal data the Customer includes in prompts, code, files, or attachments. Content is determined by the Customer; we do not proactively inspect it |
| Special categories | The Service is not designed to process special category data under GDPR Article 9. Customers should not submit it; if they do, the Customer is responsible for ensuring a lawful basis and appropriate safeguards |
| Frequency | Continuous, in line with the Customer's use of the Service |
The Customer has full control over what is submitted to the Service. We neither require nor expect the submission of special category data, children's personal data, or data subject to sector-specific regulation (such as protected health information under HIPAA), unless separately agreed in writing.
5Processing on Documented Instructions Only
We process Customer Data only on the Customer's documented instructions, including with regard to international transfers. The Customer's complete instructions consist of the Terms of Service, this Addendum, and the Customer's use of the Service's features and configuration (such as selecting models, enabling features, and setting retention options).
We will not process Customer Data for any other purpose without the Customer's further written instruction.
If we consider an instruction to infringe applicable data protection law, we will inform the Customer immediately and may suspend performance of that instruction until it is resolved. Where law requires us to process Customer Data without the Customer's instruction, we will inform the Customer beforehand unless the law prohibits it.
If carrying out additional Customer instructions requires effort beyond the ordinary course, the parties may agree reasonable fees.
6Confidentiality of Personnel
We ensure that everyone authorized to process Customer Data:
- is bound by a written confidentiality undertaking or an appropriate statutory obligation of confidentiality that survives the end of their role or engagement;
- has access only to the extent necessary for their duties (least privilege), subject to access approval and logging;
- receives data protection and information security training;
- has undergone background screening proportionate to the risk of the role, where permitted by applicable law.
Access to Customer Data in production is logged and reviewed periodically. We revoke access that is no longer required.
7Security Measures (Article 32)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons, we implement appropriate technical and organizational measures, including:
- Encryption — TLS throughout in transit; database backups are AES-encrypted and stored off-site; sensitive fields such as upstream credentials are encrypted at the field level in the database; API keys you configure locally are encrypted on your own device. The volume hosting the database is not full-disk encrypted, and we do not claim otherwise;
- Access control — role-based permissions and unique identities; production access is limited to the operator, over key-based credentials on a restricted network path, with administrative interfaces requiring a separate admin token. TOTP two-step verification is available to end users; we do not claim that multi-factor authentication is enforced on all internal access;
- Network and system security — environment isolation, minimized exposure, dependency and vulnerability management, and timely security updates;
- Data minimization — the gateway does not retain full prompts by default; request logs are stripped of content before storage, keeping only the metadata needed for metering and troubleshooting;
- Retention controls — automated deletion per the periods in the Privacy Policy, with technical request logs purged after 30 days;
- Availability and resilience — backups, recovery procedures, and periodic validation of restore capability;
- Monitoring and logging — security event recording, anomaly detection, rate limiting, and anti-abuse controls;
- Change management — code review, deployment approval, and revertible releases;
- Effectiveness testing — regular review and testing of the measures above.
We may update these measures over time to reflect technical developments, but will not materially reduce the overall level of protection.
8Subprocessors
The Customer gives general authorization for our engagement of subprocessors. The current list is available on request at support@neox-dev.com.
- Prior notice
- At least 30 calendar days before adding or replacing a subprocessor, we update the list and notify customers who have subscribed to change notifications.
- Right to object
- The Customer may object in writing within 30 days of notice on reasonable data protection grounds. We will discuss alternatives in good faith; if no agreement is reached, the Customer may terminate the affected subscription and receive a pro rata refund for the unused term.
- Flow-down
- We use each subprocessor under its terms of service and data processing terms, preferring providers that offer data processing terms. Some providers — including most upstream model providers — work only on their published standard terms, and the applicable data protection commitments are the ones in those published terms; business customers may request the specific list and terms from us.
- Our liability
- We remain fully liable to the Customer for a subprocessor's performance of its data protection obligations as if we had performed them ourselves.
9Assistance with Data Subject Requests (Articles 12–23)
Taking into account the nature of the processing, we assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling its obligation to respond to requests from data subjects exercising their rights — including access, rectification, erasure, restriction, portability, and objection.
The Service provides self-service capabilities that let the Customer access, correct, export, and delete Customer Data directly. In most cases the Customer can satisfy a request without involving us.
If a data subject contacts us directly about Customer Data, we will not respond ourselves (unless legally required) and will forward the request to the Customer within a reasonable time so the Customer can handle it as controller.
Where the Customer needs assistance beyond the self-service capabilities, we will cooperate reasonably. For repetitive or unusually costly requests beyond that scope, we may charge a reasonable fee.
10Assistance with Articles 32–36
- Security (Article 32)
- We maintain and can evidence appropriate technical and organizational measures as set out in the Security Measures section, and will provide relevant documentation on request.
- Data protection impact assessments (Article 35)
- Taking into account the nature of processing and the information available to us, we provide reasonable assistance and the information necessary for the Customer to carry out a DPIA, including a description of the processing activities and the security measures.
- Prior consultation (Article 36)
- We provide reasonable assistance where the Customer must consult a supervisory authority in advance under Article 36.
11Personal Data Breach Notification (Article 33)
We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will use reasonable efforts to provide initial notice within 72 hours of becoming aware.
The notification will include, to the extent known to us at the time:
- the nature of the breach and, where possible, the categories and approximate number of data subjects and personal data records concerned;
- a contact point for further information;
- the likely consequences of the breach;
- the measures taken or proposed to address and mitigate it.
Where all information cannot be provided at once, we will supply it in phases without undue delay. We will cooperate with the Customer in meeting its own notification obligations to supervisory authorities and data subjects, and will document the incident.
Our notification of a breach is not an acknowledgement of fault or liability.
12Deletion and Return at End of Service
On termination or expiry of the Service, the Customer has 30 days to retrieve Customer Data using the Service's export capabilities. Within that period the Customer may choose whether we delete or return Customer Data.
Unless EU or Member State law requires continued storage, we delete all Customer Data, including existing copies, after that 30-day period. Data on backup media expires with the backup rotation cycle and remains encrypted and access-isolated until it does.
Data we must retain to meet a legal obligation (such as tax and accounting records) is restricted from further processing, used only for that legal purpose, and deleted at the end of the retention period.
On the Customer's written request, we will provide written confirmation that deletion has been completed.
13Audit and Information Rights
We make available to the Customer all information necessary to demonstrate compliance with the obligations in this Addendum and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
- Written materials first
- To minimize disruption to production systems, the Customer will first accept the written materials we provide — this Addendum, our security description, the subprocessor list, and our written responses to security questionnaires. Where these adequately demonstrate compliance, they satisfy the audit and inspection right. We do not currently hold SOC 2, ISO 27001, or comparable third-party audit reports or certifications, and nothing here commits us to obtaining them.
- Remote audits
- Where those materials do not address the Customer's reasonable concern, the Customer may request a remote audit once every 12 months, on at least 30 days' written notice, conducted through written questions and answers, review of configuration and log evidence, and screen-sharing walkthroughs where needed. Because the Service is operated by an independent developer with no business premises and infrastructure hosted with third-party cloud providers, physical on-site inspection is not practicable and the parties agree remote means substitute for it; this does not limit an inspection lawfully required by a supervisory authority.
- Scope and confidentiality
- Audits are limited to systems and controls relevant to the processing of that Customer's data and must not extend to other customers' data, our trade secrets, or unrelated internal information. Auditors must sign a confidentiality agreement and must not be our competitors.
- Frequency and cost
- The Customer bears its own costs for the annual audit. Additional audits, or audits triggered by a supervisory authority or a confirmed breach, are subject to reasonable fees agreed between the parties. The Customer may audit immediately following a confirmed material breach.
- Supervisory authorities
- We cooperate with competent supervisory authorities exercising their statutory powers.
14International Transfers
The Customer authorizes us and our subprocessors to transfer and process Customer Data across borders as necessary to provide the Service.
Where Customer Data is transferred out of the EEA, UK, or Switzerland to a country without an adequacy decision, transfers are made under:
- the Standard Contractual Clauses adopted by European Commission Implementing Decision 2021/914 — Module Two where the Customer is a controller and we are a processor, and Module Three where the Customer is itself a processor — which are incorporated into this Addendum by reference;
- the UK Information Commissioner's International Data Transfer Addendum (UK Addendum) for transfers subject to the UK GDPR;
- the SCCs as adapted for the Swiss Federal Act on Data Protection;
- an adequacy decision, where applicable.
Where the SCCs require details to be specified, the "Details of the Processing" and "Data Subjects and Categories of Personal Data" sections of this Addendum populate Annex I, the "Security Measures" section populates Annex II, and the subprocessor list provided on request populates Annex III. We carry out transfer impact assessments and implement supplementary measures where required.
15Liability and Order of Precedence
For matters concerning the processing of personal data, this Addendum prevails over the Terms of Service. In the event of a conflict between this Addendum and the Terms of Service, this Addendum controls; in the event of a conflict between this Addendum and the incorporated Standard Contractual Clauses, the Standard Contractual Clauses control.
Except as stated in this section, the limitations of liability and disclaimers in the Terms of Service apply equally to claims arising under this Addendum, and the parties' aggregate liability under the Terms of Service and this Addendum is combined rather than cumulative.
Those limitations do not apply to liability that cannot be limited under applicable law, including liability to data subjects under GDPR Article 82, fines lawfully imposed by a supervisory authority, and liability arising from fraud or wilful misconduct.
If any provision of this Addendum is held invalid or unenforceable, the remaining provisions stay in full force.
16Contact and Changes
Send notices under this Addendum, data protection enquiries, and requests for compliance documentation to support@neox-dev.com.
We may update this Addendum to reflect changes in applicable data protection law, regulatory guidance, or the capabilities of the Service. We give customers at least 30 days' notice of material changes, except where a change is required to comply with law or to keep the Standard Contractual Clauses valid, which may take effect immediately.
Nothing in this Addendum reduces any mandatory right the Customer or a data subject has under applicable data protection law.

