Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between Office-X LLC, a Wyoming limited liability company (“Office-X”), and the customer identified in the Agreement (“Customer”). It applies when Office-X Processes Customer Personal Data on Customer’s behalf in connection with the Services.
By entering into the Agreement, Customer enters into this DPA on behalf of itself and, where required by Data Protection Laws, its authorized Affiliates. Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
1.1 “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
1.2 “Applicable Data Protection Laws” means privacy, data-protection, data-security, and breach-notification laws applicable to Office-X’s Processing of Customer Personal Data under the Agreement, including where applicable:
- Regulation (EU) 2016/679 (“EU GDPR”);
- the EU GDPR as incorporated into EEA law;
- the United Kingdom GDPR and Data Protection Act 2018 (“UK Data Protection Laws”);
- the Swiss Federal Act on Data Protection (“Swiss FADP”);
- the California Consumer Privacy Act, as amended (“CCPA”); and
- other applicable United States state comprehensive privacy laws.
Applicable Data Protection Laws do not include laws that apply to Customer or a Data Subject solely because of circumstances unrelated to Office-X’s Processing, such as Customer’s industry-specific regulatory status, unless the parties expressly agree otherwise in writing.
1.3 “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Process,” “Processing,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given under applicable Data Protection Laws. “Controller” includes a “business,” and “Processor” includes a “service provider” or “contractor,” where those terms are used by applicable United States privacy law.
1.4 “Customer Personal Data” means Personal Data contained in Customer Data that Office-X Processes on Customer’s behalf to provide the Services. It excludes Personal Data for which Office-X independently determines the purposes and means of Processing, such as Office-X’s own account administration, billing, security, fraud-prevention, and business-contact data, as described in the Office-X Privacy Policy.
1.5 “EU SCCs” means the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended, replaced, or superseded.
1.6 “Restricted Transfer” means a transfer of Customer Personal Data that requires an approved transfer mechanism under applicable Data Protection Laws.
1.7 “Subprocessor” means a third party appointed by or on behalf of Office-X to Process Customer Personal Data. It does not include Office-X personnel or a third-party service that Customer directly contracts with, independently enables, or instructs Office-X to connect to, except to the extent Applicable Data Protection Laws treat that provider as Office-X’s Subprocessor.
2. Scope, precedence, and duration
2.1 This DPA applies only to Processing of Customer Personal Data by Office-X as Processor. The subject matter, duration, nature, purposes, data categories, and Data Subjects are described in Schedule 1.
2.2 If this DPA conflicts with the Agreement on a data-protection matter, this DPA controls. If the EU SCCs, approved UK transfer terms, or another mandatory transfer mechanism conflicts with this DPA, the mandatory transfer mechanism controls for the affected Restricted Transfer.
2.3 This DPA begins when Office-X first Processes Customer Personal Data and continues until Office-X no longer Processes Customer Personal Data, including during the post-termination retention and deletion period.
3. Roles and instructions
3.1 Customer is the Controller and Office-X is the Processor of Customer Personal Data. If Customer is itself a Processor, Office-X is Customer’s Subprocessor, and Customer represents that the relevant Controller has authorized Customer to appoint Office-X.
3.2 Office-X will Process Customer Personal Data only:
- on Customer’s documented instructions;
- to provide, secure, maintain, support, and improve the Services for Customer;
- to prevent or address fraud, abuse, security, or technical problems;
- as necessary to comply with the Agreement; or
- as required by applicable law.
The Agreement, this DPA, Customer’s authorized configurations and feature use, support requests, and other written directions consistent with the Agreement constitute Customer’s documented instructions.
3.3 If law requires Office-X to Process Customer Personal Data contrary to Customer’s instructions, Office-X will inform Customer before Processing unless law prohibits notice. Office-X will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws. Office-X may suspend the affected Processing until the parties agree on a lawful instruction.
3.4 Office-X will not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for targeted advertising, or use it to train a generalized artificial-intelligence model made available to other customers unless Customer expressly opts in. Office-X may use properly aggregated or de-identified information as permitted by the Agreement and Applicable Data Protection Laws.
4. Customer obligations
4.1 Customer will comply with its obligations under Applicable Data Protection Laws and represents that:
- it has provided all required notices and has a valid legal basis for Office-X’s Processing;
- its instructions are lawful and consistent with the rights of Data Subjects;
- it has authority to disclose Customer Personal Data to Office-X and its authorized Subprocessors;
- it will collect only data reasonably necessary for its use of the Services;
- it will configure access, permissions, retention, integrations, and security controls appropriately; and
- if Customer is a Processor, its instructions and appointment of Office-X are authorized by the relevant Controller and consistent with Customer’s own processing agreement.
4.2 Customer is responsible for determining whether the Services are appropriate for Customer’s legal and regulatory requirements. Customer must not submit protected health information governed by HIPAA, payment-card authentication data, biometric identifiers, government-classified data, or other data prohibited by the Agreement unless Office-X has expressly agreed in a signed addendum.
4.3 Customer acknowledges that workforce, payroll, performance, leave, incident, voice, recording, and electronic-signature data may be sensitive. Customer is responsible for required employee, worker, caller, signer, and client notices and consents, including any consultation with works councils or labor representatives.
5. Office-X Processing obligations
Office-X will:
5.1 comply with Applicable Data Protection Laws that apply directly to Office-X as Processor;
5.2 ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security instruction;
5.3 implement and maintain the technical and organizational measures described in Schedule 2;
5.4 taking into account the nature of Processing, assist Customer through appropriate technical and organizational measures with Data Subject requests as required by Section 8;
5.5 provide reasonable assistance with security, breach response, data-protection impact assessments, and prior consultations as described below;
5.6 maintain records of Processing where required and cooperate with a competent Supervisory Authority as required by law;
5.7 notify Customer if Office-X can no longer meet its obligations under this DPA and, where required by law, allow Customer to take reasonable steps to stop and remediate unauthorized Processing; and
5.8 not materially decrease the overall security of the Services during the applicable Subscription Term.
6. Confidentiality
6.1 Customer Personal Data is Customer’s Confidential Information under the Agreement.
6.2 Office-X will limit access to persons who need access to perform obligations under the Agreement. Office-X is responsible for its personnel’s compliance with the confidentiality and data-protection obligations applicable to their work.
6.3 Confidentiality obligations survive termination for as long as Office-X retains Customer Personal Data.
7. Security
7.1 Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of Processing, as well as risks to Data Subjects, Office-X will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
7.2 The current categories of measures are described in Schedule 2. Office-X may update specific controls where the update does not materially reduce the overall level of protection.
7.3 Customer is responsible for secure endpoints, credential protection, Authorized User administration, permission settings, Customer-controlled SMTP and integration credentials, lawful configuration, and promptly disabling unauthorized or departed users.
8. Data Subject requests
8.1 Office-X will promptly notify Customer if it receives a request from a Data Subject concerning Customer Personal Data, unless law prohibits notice. Office-X will not independently respond except on Customer’s documented instruction or as legally required.
8.2 Taking into account the nature of Processing, Office-X will provide reasonable assistance through available Service functionality and, where necessary, additional measures to help Customer respond to requests for access, correction, deletion, restriction, portability, objection, or withdrawal of consent.
8.3 Customer is responsible for verifying requesters, determining whether a request is valid, communicating with Data Subjects, and meeting response deadlines. Office-X may charge reasonable fees for assistance that is unusually burdensome, repetitive, or outside standard functionality, to the extent permitted by law.
9. Personal Data Breaches
9.1 Office-X will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
9.2 To the extent known and reasonably available, the notice will describe:
- the nature of the Personal Data Breach;
- affected data categories and approximate numbers of Data Subjects or records;
- likely consequences;
- measures taken or proposed to contain, investigate, and mitigate it; and
- a contact for follow-up.
Information may be provided in phases. Office-X’s notification is not an admission of fault or liability.
9.3 Office-X will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and will provide reasonable cooperation needed for Customer’s legally required notices. Customer is responsible for determining whether to notify Data Subjects, regulators, employees, clients, or other parties unless law places that duty directly on Office-X.
9.4 Unsuccessful attempts, scans, pings, blocked attacks, and incidents that do not compromise Customer Personal Data are not Personal Data Breaches under this DPA, but Office-X will maintain appropriate security monitoring and records.
10. Impact assessments and regulatory assistance
Taking into account the nature of Processing and information available to Office-X, Office-X will provide reasonable assistance with Customer’s data-protection impact assessments and legally required prior consultations with Supervisory Authorities. Customer remains responsible for determining whether an assessment or consultation is required and for its content. Office-X may charge reasonable fees for substantial assistance beyond standard documentation and Service functionality.
11. Subprocessors
11.1 Customer gives Office-X general written authorization to appoint Subprocessors needed to provide the Services, subject to this Section.
11.2 Office-X will maintain a current list identifying each Subprocessor, its general purpose, and its processing country or region. To avoid publicly exposing unnecessary infrastructure information, the current list is available to Customer upon written request to [email protected]. Office-X may later make the list available through a customer portal or public compliance page.
11.3 Office-X will provide at least 30 days’ advance notice before a new Subprocessor begins Processing Customer Personal Data, except where an urgent replacement is reasonably necessary to maintain availability, security, or legal compliance. Customer may subscribe to notices through the method Office-X makes available.
11.4 Customer may object in writing within 15 days after notice based on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If no commercially reasonable alternative is available, Office-X may permit Customer to terminate the affected Service without penalty and receive a pro rata refund of prepaid Fees for its unused term. This is Customer’s sole remedy for an unresolved Subprocessor objection.
11.5 Office-X will enter into a written agreement with each Subprocessor imposing data-protection obligations that are no less protective in substance than those applicable to Office-X under this DPA, to the extent relevant to the Subprocessor’s services. Office-X remains responsible for a Subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Laws.
11.6 Customer-controlled integrations. When Customer directly contracts with, supplies credentials for, or independently enables a third-party integration—including an AI voice, telephony, email, calendar, payment, or storage provider—Customer instructs Office-X to disclose and receive Customer Personal Data as necessary for that integration. Customer is responsible for evaluating and authorizing the provider. This Section does not reduce any obligation that applies if Office-X separately appoints the same provider as its Subprocessor.
12. Return, export, and deletion
12.1 During the Subscription Term, Customer may export available Customer Personal Data using Service functionality.
12.2 Following expiration or termination, Office-X will retain Customer Personal Data for up to 180 days solely to permit authorized export, restore an account at Customer’s request, maintain security, resolve billing or legal disputes, or comply with law. Customer may request earlier deletion by contacting [email protected], subject to legal-retention requirements and reasonable identity and authority verification.
12.3 At the end of the 180-day period, or earlier upon a valid deletion instruction, Office-X will delete or de-identify Customer Personal Data in active systems and delete backup copies through its normal backup-rotation process, unless applicable law requires retention. Customer Personal Data retained in backups or under legal hold will be isolated from ordinary use, protected under this DPA, and Processed only for disaster recovery, security, or legal compliance until deletion is possible.
12.4 Upon written request, Office-X will provide reasonable confirmation of deletion. Office-X may retain de-identified data that cannot reasonably be linked to Customer or a Data Subject.
13. Audits and compliance information
13.1 Upon reasonable written request, Office-X will provide information necessary to demonstrate compliance with this DPA, which may include current security summaries, third-party audit reports or certifications if available, penetration-test summaries, and responses to a reasonable security questionnaire, subject to confidentiality and security restrictions.
13.2 If the information in Section 13.1 is reasonably insufficient to satisfy a legal audit obligation, Customer may request an additional audit no more than once in any 12-month period, except after a Personal Data Breach or where a Supervisory Authority requires more frequent review.
13.3 An audit must:
- be conducted by an independent, qualified auditor bound by confidentiality;
- occur on at least 30 days’ notice during normal business hours;
- avoid accessing other customers’ data or compromising security;
- minimize disruption; and
- comply with Office-X’s reasonable safety and confidentiality procedures.
Customer bears its audit costs and will reimburse Office-X’s reasonable costs unless the audit identifies a material breach by Office-X. The parties will first use remote review and documentation; an on-site audit is permitted only where legally required or remote evidence is reasonably insufficient.
14. Government and legal requests
14.1 Office-X will review binding government demands for Customer Personal Data and, where there are reasonable grounds, challenge demands that are unlawful, overbroad, or disproportionate.
14.2 Unless prohibited by law, Office-X will notify Customer before disclosing Customer Personal Data and provide available information so Customer may seek protection. Office-X will disclose only the data legally required.
14.3 Office-X will not voluntarily provide bulk, indiscriminate access to Customer Personal Data to a government authority and will not create a backdoor or encryption key for such access unless legally compelled.
15. International data transfers
15.1 Office-X may Process Customer Personal Data in the United States and in countries where authorized Subprocessors operate, subject to this DPA and an applicable transfer mechanism.
15.2 The parties will rely first on an applicable adequacy decision, certification, or other lawful transfer mechanism. If a Restricted Transfer of EEA Personal Data to Office-X is not covered by another valid mechanism, the EU SCCs are incorporated by reference as follows:
- Module Two applies when Customer is a Controller and Office-X is a Processor.
- Module Three applies when Customer is a Processor and Office-X is a Subprocessor.
- Clause 7 (docking) applies.
- In Clause 9, Option 2 (general written authorization) applies; the time period is 30 days as stated in Section 11.
- The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and the law is the law of Ireland.
- Under Clause 18(b), the courts of Ireland have jurisdiction.
- Annexes I and II are completed by Schedules 1 and 2 of this DPA. Annex III consists of the current Subprocessor list that Office-X provides to Customer upon request and updates through the notice procedure in Section 11.
- The competent Supervisory Authority is determined under Clause 13 based on Customer’s establishment, representative, or affected Data Subjects.
15.3 The parties will not modify the EU SCCs in a way that conflicts with their mandatory text. If this DPA conflicts with the EU SCCs, the EU SCCs control for the Restricted Transfer.
15.4 For a Restricted Transfer subject to UK Data Protection Laws, the then-current mandatory clauses of the UK International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner are incorporated by reference. The information in Schedules 1–3 completes the applicable tables; either party may end the affected Restricted Transfer if the approved addendum is materially revised and the parties cannot implement a lawful alternative.
15.5 For a Restricted Transfer subject to the Swiss FADP, references in the EU SCCs to the EU GDPR include the Swiss FADP as applicable; references to a Member State or Supervisory Authority include Switzerland and the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce the clauses. The governing law and forum selections apply only to the extent permitted by the Swiss FADP.
15.6 The parties will reasonably cooperate on transfer impact assessments and supplementary safeguards. Customer will provide information about its transfer circumstances that Office-X cannot reasonably know.
16. United States state privacy terms
16.1 To the extent the CCPA or a similar United States state privacy law applies, Office-X acts as Customer’s service provider, contractor, or Processor for the specific business purposes in Schedule 1.
16.2 Office-X will not:
- sell or share Customer Personal Data;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a purpose other than the specific purposes in Schedule 1, except as permitted by applicable law;
- combine Customer Personal Data with Personal Data received from another person or collected from Office-X’s own interaction with a Data Subject, except as permitted by applicable law; or
- use Customer Personal Data for targeted advertising or profiling in furtherance of decisions producing legal or similarly significant effects, unless expressly instructed by Customer and legally permitted.
16.3 Customer may take reasonable and appropriate steps to help ensure Office-X uses Customer Personal Data consistently with Customer’s obligations. Office-X will notify Customer if it determines it can no longer meet applicable obligations. Customer may take reasonable steps to stop and remediate unauthorized use, subject to the audit procedures in Section 13.
16.4 Office-X certifies that it understands and will comply with the restrictions in this Section.
17. Liability
Each party’s liability arising from this DPA, including the EU SCCs to the extent their mandatory terms permit, is subject to the exclusions and limitations in the Agreement. Nothing in the Agreement or this DPA limits a Data Subject’s rights or a party’s liability to a Data Subject or Supervisory Authority where such limitation is prohibited by law.
18. General provisions
18.1 Office-X may update this DPA where required by law, to adopt a new approved transfer mechanism, or to reflect changes that do not materially reduce protection. Material changes will follow the notice provisions in the Agreement.
18.2 If a provision is invalid or unenforceable, it will be interpreted to best accomplish its lawful purpose, and the remainder remains effective.
18.3 Except as modified by this DPA, the Agreement remains in effect. The governing-law and dispute provisions in the Agreement apply, except where mandatory Data Protection Laws or transfer terms require otherwise.
18.4 Notices under this DPA must be sent according to the Agreement. Privacy notices to Office-X must be sent to [email protected].
Schedule 1 — Details of Processing
A. Parties
Data exporter / Customer
Name: Customer identified in the Agreement
Address: Customer address in the Agreement or account record
Contact: Customer’s account administrator or privacy contact
Role: Controller or Processor, as applicable
Signature and date: The Agreement’s acceptance or signature constitutes execution of this DPA and applicable transfer terms
Data importer / Office-X
Name: Office-X LLC
Entity: Wyoming limited liability company
Contact: [email protected]
Registered agent for service of process: Company Sage Agents LLC, 1095 Sugarview Dr, Ste 100, Sheridan, Wyoming 82801, USA
Role: Processor or Subprocessor, as applicable
Signature and date: The Agreement’s acceptance or signature constitutes execution of this DPA and applicable transfer terms
B. Subject matter and duration
Processing Customer Personal Data to provide, host, secure, maintain, support, and improve the Office-X workforce, HR, attendance, payroll, approvals, operations, CRM, document, booking, task, support, asset, incident, communication, integration, and related Services selected by Customer.
Processing lasts for the Subscription Term and the limited post-termination retention and deletion period described in Section 12.
C. Nature and purposes
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, calculation, comparison, transmission, making available, restriction, export, deletion, and other Processing needed to:
- authenticate users and administer accounts, roles, permissions, and security;
- manage employees, contractors, teams, departments, work schedules, performance, and workplace records;
- record attendance, work hours, overtime categories, leave, holidays, and approvals;
- calculate and document payroll, taxes, deductions, benefits, expenses, and paystubs as configured by Customer;
- manage bills, travel, purchases, assets, incidents, and support requests;
- manage clients, contacts, items, estimates, agreements, electronic signatures, bookings, tasks, and related documents;
- send Customer-configured email and other communications;
- connect Customer-enabled integrations, including AI voice and telephony services;
- provide reports, exports, audit trails, fraud prevention, troubleshooting, support, and service security; and
- comply with Customer’s lawful instructions and applicable law.
D. Categories of Data Subjects
- Customer’s employees, former employees, applicants, contractors, temporary workers, managers, administrators, owners, and representatives;
- dependants, beneficiaries, emergency contacts, and related persons whose data Customer enters;
- Customer’s clients, prospects, vendors, suppliers, service providers, and their personnel;
- agreement signers, booking participants, website booking users, callers, and communication recipients;
- persons named in incident, support, expense, travel, purchase, asset, performance, or approval records; and
- other individuals whose Personal Data Customer submits under the Agreement.
E. Categories of Personal Data
- Identity and contact: names, photographs, email addresses, phone numbers, physical addresses, dates of birth, signatures, internal IDs, and emergency contacts.
- Employment and organization: job title, designation, department, team, manager, employment status, start/end dates, schedules, work location, benefits, leave, performance criteria, scores, comments, and disciplinary or incident information.
- Attendance and technical: check-in/check-out times, work hours, overtime, break time, holiday/rest-day categories, IP addresses, approved networks, device/browser information, timestamps, login records, and activity logs.
- Payroll, tax, and financial: salary, hourly rates, overtime rates, bonuses, allowances, deductions, benefits, bank-account details, tax identifiers, tax settings, paystubs, year-to-date amounts, expense claims, receipts, travel costs, and purchase values.
- CRM and transactional: client details, products and services, estimates, pricing, taxes, discounts, agreements, signer details, audit evidence, bookings, tasks, addresses, and activity history.
- Communications and content: emails, templates, support requests, comments, notes, attachments, uploaded documents, recordings, transcripts, summaries, call metadata, and Customer-provided AI knowledge content.
- Security and integration: authentication data, password hashes, one-time-password events, permissions, API-key metadata, encrypted integration credentials, webhook identifiers, and security events.
- Other Customer-submitted data: information Customer or its Authorized Users choose to enter, upload, generate, or transmit through enabled features.
F. Sensitive or special-category data
Depending on Customer’s configuration and use, Customer Personal Data may include financial account details, government or tax identifiers, compensation, health-related information in leave or incident records, union or employee-representation information, and other data treated as sensitive or special-category data by applicable law. Customer must avoid entering such data unless necessary, lawful, and supported by appropriate safeguards and legal bases.
Office-X does not intentionally Process biometric identifiers, protected health information governed by HIPAA, or payment-card authentication data as part of the standard Services unless a signed addendum expressly authorizes it.
G. Processing frequency
Continuous or as initiated by Customer and Authorized Users during the Subscription Term, with limited Processing during the post-termination retention and deletion period.
H. Retention
For the Subscription Term, Customer’s configured retention where available, and up to 180 days following expiration or termination as described in Section 12, subject to earlier deletion requests, backup rotation, legal holds, and statutory retention requirements.
I. Competent Supervisory Authority
For EU SCC purposes, the authority determined under Clause 13 based on the data exporter’s establishment, appointed representative, or affected Data Subjects. Customer will identify the authority on reasonable request if it is not apparent from the Agreement.
Schedule 2 — Technical and Organizational Measures
Office-X maintains the following categories of measures, as applicable to the Services and proportionate to risk. This Schedule intentionally describes controls at a high level and does not disclose security-sensitive architecture or configuration.
1. Security governance
- Assigned responsibility for application, infrastructure, privacy, and incident security.
- Documented access, incident-response, change-management, backup, retention, and vendor-management procedures.
- Periodic risk review and remediation tracking.
- Confidentiality commitments and security training for personnel with access to Customer Personal Data.
2. Identity and access management
- Unique accounts, role-based permissions, least-privilege access, tenant-scoped authorization, multi-factor authentication for privileged access, and procedures to revoke access when no longer required.
3. Encryption and credential protection
- Industry-standard encryption in transit and appropriate encryption or equivalent protection for sensitive data at rest.
- Protected credential storage, password hashing, restricted secrets access, and credential rotation or revocation procedures.
4. Data and tenant protection
- Logical tenant separation, authorization checks, data minimization, protected-file access controls, and separation of production from non-production environments.
5. Logging and monitoring
- Logging and monitoring of authentication, administrative, security, and material service events, with access to logs restricted according to operational need.
6. Application and software security
- Controlled development and deployment practices, code review and testing, vulnerability management, input validation, authentication, authorization, and security review of sensitive interfaces.
7. Infrastructure, storage, and availability
- Infrastructure and storage providers subject to appropriate contractual safeguards.
- Restricted administrative access, service-health monitoring, encrypted or otherwise appropriately protected backups, restoration procedures, and business-continuity measures appropriate to service risk.
8. Incident response
- Documented process to identify, contain, investigate, remediate, and document security incidents.
- Escalation to appropriate technical, legal, privacy, and management personnel.
- Preservation of relevant evidence and phased customer notification where required.
- Post-incident review and corrective-action tracking for material incidents.
9. Subprocessor and personnel controls
- Risk-based review of Subprocessors that Process Customer Personal Data.
- Written privacy, confidentiality, and security obligations.
- Access limited to personnel and providers with a business need.
- Removal of access when no longer required.
10. Deletion and media handling
- Application-level deletion or de-identification processes for active systems.
- Backup expiry through documented rotation.
- Secure disposal or sanitization of storage media according to provider and industry practices.
- Legal-hold controls that restrict retained data to the required purpose.
Schedule 3 — Subprocessor Information
Office-X may use Subprocessors in the following service categories:
- application hosting, networking, and content delivery;
- database, object-storage, backup, and caching services;
- transactional email and customer-support infrastructure;
- payment and subscription administration;
- security, error, performance, and availability monitoring; and
- optional communication or integration services enabled for Customer.
To minimize public disclosure of security-sensitive infrastructure information, this DPA does not publish hostnames, account identifiers, data-center addresses, network configuration, or similar technical details.
The current Subprocessor list—including each provider’s legal name, general function, and processing country or region—is available to Customer upon written request to [email protected]. For Restricted Transfers, that confidential list constitutes Annex III of the EU SCCs. Office-X will notify Customer of intended additions or replacements and permit objections under Section 11.
Third-party services that Customer independently contracts with, credentials, or enables are governed by Section 11.6 and are not automatically Office-X Subprocessors. Office-X will disclose Customer Personal Data to such providers only as instructed by Customer and as necessary to operate the enabled integration.