Legal
Data Processing Addendum
Contractual data-processing terms for business customers.
Last updated 17 August 2026
Scope and roles
This Addendum forms part of the Terms between the customer, as controller, and Auxo (Auxo), as processor, when Auxo processes personal data the customer submits or connects to the service. Privacy terms have the meaning given by applicable law, including the GDPR where it applies.
Processing details and instructions
Processing lasts for the subscription and a reasonable deletion period afterward. Its purpose is to provide automation, lead follow-up, optional consent-based banking views, storage, support and security. Data subjects may include the customer’s prospects, customers, personnel, suppliers and users; data may include contact details, message content, documents, business and bank-transaction records, and activity metadata.
The Terms, product settings, user actions and support records are the customer’s documented instructions. Auxo will process data only on those instructions or as law requires, and will notify the customer of such a requirement where permitted.
Party obligations
- The customer is responsible for lawful collection, instructions, messages and transfer of data to Auxo, including notices and consents where required.
- Auxo will ensure authorised personnel are bound by confidentiality, limit access by need and apply appropriate security measures.
- Auxo will notify the customer if it believes an instruction violates data-protection law and may suspend it pending clarification.
Security and incidents
Controls include TLS, encryption of integration tokens at rest, signed secure session cookies, scoped permissions, account separation, hosted payments and activity records. Current details and limitations are on the Security page.
Auxo will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provide available information and reasonable assistance needed for notification and mitigation.
Sub-processors
The customer gives general authorisation to use sub-processors for infrastructure, database, AI, email and payment, plus providers the customer chooses to connect. Current categories and names appear in the Privacy Policy or are available on request.
Auxo will impose appropriate data-protection duties on a sub-processor and remains responsible for its obligations under this Addendum. We will give reasonable notice of a new sub-processor; a substantiated privacy objection will be discussed in good faith, and if unresolved the customer may stop the affected service.
International transfers
Where EEA, Swiss or UK data is transferred to a country without an adequacy decision, the parties will rely as needed on the 2021 EU Standard Contractual Clauses in the applicable module and the UK Addendum. This Addendum, the order, Privacy Policy and Security page supply the annex information where relevant.
Rights, assessments and audits
Taking account of the processing, Auxo will reasonably assist with data-subject requests, impact assessments, regulator consultation and demonstrating compliance. If a request reaches us for customer-controlled data, we will refer it to the customer unless law prohibits that.
Once annually, the customer may request information reasonably needed for an audit. An on-site audit is available only if documents are insufficient, on advance notice, under confidentiality and without unreasonable disruption, at the customer’s cost unless a material breach is found.
Return, deletion and priority
At service end, at the customer’s choice and subject to legal retention, Auxo will return or delete customer data and existing copies within a reasonable period. Data in isolated backups will expire in the ordinary cycle and will not be restored to active use.
For a conflict about data processing, this Addendum controls over the Terms. The Terms’ liability limits also apply here where law permits. Questions go to [email protected].