Data Processing Agreement
Effective: July 13th, 2026 · Version: 1.0
Abusix processes personal data on behalf of its customers under a Data Processing Agreement based on the open oneDPA standard. It incorporates, for restricted (cross-border) transfers, the EU Standard Contractual Clauses (Module 2 controller-to-processor and Module 3 for onward transfers) and the UK International Data Transfer Addendum.
Key terms
| Item | Value |
|---|---|
| Processor | Abusix GmbH (Roonstrasse 23a, 76137 Karlsruhe, Germany) for EEA/UK customers; Abusix, Inc. (One Boston Place, 201 Washington Street, Boston, MA 02108, USA) for US / rest-of-world customers |
| Controller | The Customer under the Cloud Services Agreement |
| Data Protection Laws | EU GDPR; UK GDPR & Data Protection Act 2018; Swiss FADP; CCPA / CPRA |
| Nature & purpose of processing | Provision of the Abusix services as described in the Cloud Services Agreement and applicable Order Form |
| Personal data breach notification | Without undue delay, and in any event within 72 hours of awareness |
| Sub-processor change notice | 30 days in advance, with a right to object (subscribe for notifications at the Trust Center) |
| Transfer mechanism | EU Standard Contractual Clauses (Module 2 & Module 3) and the UK International Data Transfer Addendum |
| Governing law of the Clauses | Germany |
| Technical & organisational measures | As described in Abusix’s security documentation and SOC 2 Type II report at trust.abusix.com |
| Sub-processor list | Maintained at trust.abusix.com |
Processor obligations (summary)
Under the DPA, Abusix will: process personal data only on the Customer’s documented instructions; ensure personnel are bound by confidentiality; apply appropriate technical and organisational security measures; engage sub-processors only under equivalent terms and remain responsible for them; assist the Customer with data-subject requests, data protection impact assessments, and regulator engagement; notify the Customer of personal data breaches within the period above; and return or delete personal data at the end of the Term. This is a summary — the full Data Processing Agreement governs.
Requesting or signing the DPA
The full executable Data Processing Agreement (oneDPA standard, with the EU SCCs and UK IDT Addendum) is provided as part of the contract package and is available on request at [email protected].