Data Processing Addendum
Governing the processing of personal data on behalf of Customers.
Version 1.0.0 · Effective Date: April 9, 2026
This Data Processing Addendum (“DPA”) forms part of the Subscription Service Agreement between Pax App (“Processor”) and the Customer (“Controller”). This DPA applies to the extent that the Company processes personal data on behalf of the Customer in connection with providing the Service.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable natural person that is submitted to the Service by the Customer.
“Processing” means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.
“Data Subject” means the individual to whom Personal Data relates.
2. Roles of the Parties
The Customer acts as the data Controller, determining the purposes and means of processing Personal Data. The Company acts as a data Processor, processing Personal Data only on documented instructions from the Customer, as set forth in this DPA and the Service Agreement.
3. Processing Instructions
The Company shall process Personal Data only for the purposes of: (a) providing and maintaining the Service; (b) processing payments and managing the Customer account; (c) providing customer support; and (d) complying with legal obligations. The Company shall not process Personal Data for any other purpose, including its own marketing or commercial purposes, and shall not sell Personal Data to third parties.
4. Confidentiality of Processing
The Company shall ensure that all personnel authorized to process Personal Data are under appropriate confidentiality obligations. Access to Personal Data is restricted to personnel with a legitimate need to access it for Service-related purposes.
5. Security Measures
The Company shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, consistent with those described in the Privacy Policy. The Customer acknowledges that no security system is impenetrable, and that highly sensitive information — including confessional records, privileged communications, and sensitive personal data — should not be stored in the Service.
6. Sub-Processors
The Customer authorizes the Company to engage sub-processors (such as cloud hosting, payment processing, and email service providers) to assist in providing the Service. The Company shall ensure sub-processors are bound by data protection obligations no less stringent than those in this DPA.
7. Data Subject Rights
The Company shall reasonably assist the Customer in fulfilling its obligations to respond to Data Subject requests (such as requests for access, correction, or deletion of Personal Data), to the extent technically feasible. The Customer is responsible for managing and responding to such requests.
8. Data Breach Notification
In the event of a confirmed security breach affecting Customer Personal Data, the Company shall notify the Customer within seventy-two (72) hours of becoming aware of the breach, to the extent practicable, and shall provide information reasonably necessary for the Customer to fulfill any applicable breach notification obligations.
9. Return and Deletion of Data
Upon termination of the Service Agreement, the Company shall, at the Customer's election, either return or delete Customer Personal Data within thirty (30) days, except to the extent retention is required by applicable law.
10. Audits
The Customer may request written information from the Company to verify compliance with this DPA no more than once per calendar year, with reasonable advance notice and at Customer's expense. The Company may fulfill audit requests by providing relevant documentation and attestations in lieu of on-site audits.
11. Limitation of Liability
The Company's liability under this DPA shall be subject to the limitations set forth in the Subscription Service Agreement and Terms and Conditions. The Company's maximum liability for claims arising under this DPA shall not exceed the total fees paid by Customer in the one (1) month preceding the claim.
12. Governing Law
This DPA is governed by the laws of the State of Kansas. Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Subscription Service Agreement, with exclusive venue in Topeka, Kansas.
Terms · Privacy · Subscription Agreement · Acceptable Use · Data Processing