Legal
Data Processing Addendum
Processor terms for nox.markets workspace data: roles, instructions, security, subprocessors, breach notice, deletion, audits, and no-training commitments.
Last updated: 16 September 2026
Processor: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA (Processor)
Controller: the Customer organization identified in the workspace or order form (Controller)
Governing law of this DPA: the laws of the State of Wyoming, USA.
This Data Processing Addendum (DPA), including Exhibits A–D, forms part of the agreement between Controller and Processor for the nox.markets Service (the Agreement). Standard DPA is click-wrap on Growth and above; custom DPA is Enterprise.
Order of precedence. On data protection, this DPA prevails over the MSA / Terms.
HIPAA and a Business Associate Agreement are not part of this standard DPA. A BAA is a separate Enterprise exhibit, not offered until 2027-06-30 (see /trust). Until then, ePHI is forbidden under the Acceptable Use Policy.
1. Definitions
Terms such as personal data, processing, controller, processor, sub-processor, data subject, and personal data breach have their customary meaning under Applicable Data Protection Law. Under the CCPA/CPRA, controller corresponds to business, and processor to service provider or contractor.
Customer Personal Data means personal data in the classes in Exhibit A that Processor processes on Controller’s behalf in the Service (including run_payload, workspace_config, connector_secrets, run_metadata, audit_event, and workspace-side account_data beyond Processor’s own billing records).
Applicable Data Protection Law means the CCPA/CPRA (with Processor acting as a service provider or contractor) and other US federal and state laws applicable to the processing under this DPA.
Capitalized terms not defined here have the meaning in the Terms or on /security.
2. Roles
2.1 Controller is the controller of Customer Personal Data (or a processor for Controller’s own customers, in which case Processor is a sub-processor and Controller will flow these clauses down).
2.2 Processor is the processor of Customer Personal Data.
2.3 Processor is controller of its own billing and account records as described in the Privacy Policy, and of website visitor data. That controller processing is not Customer Personal Data under this DPA.
2.4 CCPA/CPRA: Processor is a service provider / contractor. Processor will not sell or share Customer Personal Data, and will not combine it with other customers’ personal information to train or to profile, except as needed to provide the Service to that Controller.
3. Instructions
3.1 Processor will process Customer Personal Data only on documented instructions from Controller: namely, use of the Service as Controller configures it (products, integrations, retention, approvals, region), this DPA, and the Agreement.
3.2 Processor will not follow an instruction that violates Applicable Data Protection Law, and will notify Controller of that legal conflict unless law prohibits the notice.
3.3 Controller is responsible for the lawfulness of its instructions, for notices to data subjects, and for not submitting forbidden classes (including ePHI until a BAA exists).
3.4 Human approval defaults for finance-backoffice agents and workflows are a product requirement. This DPA does not treat model output as “human reviewed” unless a human actually approved it in the Service.
4. Confidentiality of persons
Processor will ensure that persons authorized to process Customer Personal Data are bound to confidentiality and receive access on a need-to-know basis. Standing production access to run_payload is not granted. Break-glass access is ticketed, time-boxed (≤ 4 hours), MFA-gated, logged as an audit_event, and notified to Enterprise customers if the MSA requires it (default: yes for payload access, no for infrastructure-only).
5. Security measures
Processor will implement the technical and organizational measures in Exhibit B and as described on /security, including encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256), envelope encryption for connector_secrets, logical tenancy isolation, logging, and vulnerability handling.
/security is incorporated by reference for operational detail. If /security and Exhibit B conflict, the stricter control applies until counsel reconciles them.
SOC 2 Type I, SOC 2 Type II, and ISO/IEC 27001 are Planned (see /trust); they are not held as of 15 September 2026. Processor will not represent them as Held.
6. Subprocessors
6.1 Controller gives general written authorization for Processor to engage subprocessors to process Customer Personal Data, provided Processor remains liable for their performance as required by GDPR Art. 28.
6.2 The current list is Exhibit D and /legal/subprocessors (same table). Model providers are listed even when Controller does not choose them below Scale.
6.3 Processor will give 30 days’ notice before a new subprocessor processes Customer Personal Data, emailed to the workspace owner and posted on /legal/subprocessors with a dated changelog. Removals may be immediate; the changelog is still updated.
6.4 Controller may object in writing within 15 days of notice. If Processor cannot reasonably accommodate the objection, Controller may terminate the affected service before the add date; prepaid unused platform fees for that remainder are refunded pro-rata. That is the exclusive commercial remedy for a sustained objection.
6.5 Customer-facing systems Controller connects (QuickBooks Online, Xero, HubSpot, Gmail, and similar) are Controller’s processors, not Processor’s subprocessors.
7. Assistance (DSRs, DPIA, consultations)
7.1 Processor will assist Controller, taking into account the nature of processing, with data subject requests, using the Service’s export and deletion tools first.
7.2 Requests that hit Processor directly: Processor notifies Controller within 5 business days and does not respond on Controller’s behalf except to redirect.
7.3 Manual assistance: within 15 business days on Scale and Enterprise; 30 business days on Starter and Growth.
7.4 Processor will assist with DPIAs and prior consultations reasonably, at Enterprise under the MSA’s professional-services rates if the request exceeds ordinary support.
8. Personal data breach
8.1 Processor will notify Controller without undue delay and no later than 72 hours after Processor confirms a personal data breach affecting Customer Personal Data.
8.2 If a breach is likely but not yet confirmed, Processor will notify as likely and update when confirmed. Processor will not sit on a likely breach for a week “waiting to be sure,” and will not start the 72-hour clock on every availability incident.
8.3 Notice will describe, as then known: nature of the breach, classes of data, what is known and not yet known, and recommended steps (for example reset IdP sessions, rotate keys). First notice will not speculate about root cause.
8.4 Controller is responsible for notifying supervisory authorities and data subjects where Controller is required to do so. Processor will assist. If Processor is controller (website visitors, its employees), Processor notifies the relevant authority within 72 hours where required.
8.5 Operational severity (P1/P2/P3) and non-personal-data security incidents follow /security §9 (P1 availability: 24 hours from declare; P2: 72 hours). Those clocks do not replace this Section 8 for personal data.
8.6 Post-incident report: to affected Scale and Enterprise customers within 10 business days of close. Starter and Growth: summary on /status if availability; email if their data was involved.
Redlines that would drop personal-data breach notice below 72 hours after confirmation are rejected.
9. Return and deletion
9.1 On termination of the Service or upon Controller’s instruction, Processor will make export available and primary-delete Customer Personal Data within 30 days, except records Processor must retain (tax invoices: 7 years; legal hold).
9.2 Encrypted backups expire on the 35-day rolling clock and are not scrubbed on demand (gone by day 65 after closure, 30 + 35).
9.3 Connector secrets are deleted within 24 hours of disconnect. connected data already in Controller’s systems of record is not deleted by Processor.
9.4 Run-level deletion in the UI is queued immediately and applied to primary storage within 24 hours; backups follow the 35-day clock.
10. Audits
10.1 Once a SOC 2 Type II report is Held, that report (under NDA, Growth+) is the default audit artifact. Until then, Processor will answer a reasonable written questionnaire no more than once per 12 months, unless a material incident warrants another.
10.2 On-site audits or extra questionnaires: Enterprise MSA, reasonable costs, once per 12 months unless a material incident.
10.3 Independent penetration test: first test Planned 2026-12-15. Letter of attestation may be public; full report under NDA on Scale+.
11. Processing location
11.1 Processor processes Customer Personal Data in a Hetzner Online GmbH data center in Nuremberg, Germany, on every tier and offers no other processing region.
11.2 Subprocessors process Customer Personal Data under their own data processing terms, as listed on /legal/subprocessors.
12. No-training (locked)
Processor will not train models on Customer Personal Data or Customer Content, and will not permit model subprocessors Processor routes to to train on that data, as detailed in Exhibit C. Custom DPA redlines that would allow training are rejected.
13. Term and miscellaneous
This DPA lasts as long as Processor processes Customer Personal Data. Survival: Sections 4, 8, 9, 12, Exhibit C, and audit confidentiality.
Liability under this DPA is subject to the Agreement’s limitation of liability, except where Applicable Data Protection Law makes a limit unenforceable.
Governing law: the laws of the State of Wyoming, USA. Notices: workspace owner email and 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA.
Exhibit A — Description of processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of nox.markets tools, agents, workflows, and packs in hosted and connected deployments; license telemetry for self-hosted |
| Duration | Term of the Agreement + retention in Section 9 and the Privacy Policy table |
| Nature | Storage, transmission, computation, model inference where the product requires it, logging, backup, support |
| Purpose | Provide, secure, meter, and support the Service as configured by Controller |
| Frequency | Continuous / on trigger or schedule set by Controller |
| Data classes | account_data (workspace users), workspace_config, connector_secrets, run_payload, run_metadata, audit_event, support_data; telemetry_self_hosted for self-hosted only |
| Special categories | Not intended. ePHI forbidden until BAA. Controller must not submit them |
| Data subjects | Controller’s employees and contractors; Controller’s customers, vendors, and other individuals as they appear on invoices, bills, tickets, mail, CRM records, and similar business documents Controller submits or connects |
| Location | Hetzner data center in Nuremberg, Germany, on every tier |
Exhibit B — Technical and organizational measures (short form)
Measures as of the 15 September 2026 design; implementation status is operational design, not a completed audit.
- Access control. MFA required for password accounts; SAML on Growth+; SCIM on Scale+; IP allowlist on Growth+; RBAC (
owner/admin/member, custom roles on Scale+); 7-day idle / 30-day absolute sessions. - Staff. Background checks before production access where lawful; hardware-backed MFA; no standing payload access; production and staging separated; production data not copied to staging.
- Logging.
audit_eventfor auth, RBAC, integrations, runs (metadata + hash, not body), exports, staff break-glass. Retention: 30 days Starter; 12 months Growth; 36 months Scale/Enterprise (or MSA). SIEM stream on Scale+. - Tenancy. Logical isolation; dedicated VPC or self-hosted on Enterprise.
- Vulnerabilities. Critical (actively exploited or CVSS ≥ 9 and reachable): 24 hours. High: 7 days. Medium: 30 days. Low: 90 days.
- Incidents. Section 8 clocks;
/statusfor availability; security breaches not first announced only on social media.
Exhibit C — No-training and model processing
- Processor does not train on Customer Content or Customer Personal Data, and does not use Customer runs to improve other customers’ products.
- Processor will execute zero data retention / no-training API terms with each model subprocessor where the endpoint offers them. If an endpoint cannot be put on those terms, Processor will not route Customer data to it.
- What may leave the platform on a model call: minimum retrieved context, system instructions, completion. Not
connector_secrets, not other tenants, not full-system exports. - Below Scale, Processor selects the model; legal entities remain those on
/legal/subprocessors. Adding or replacing a legal entity starts the 30-day notice clock even if the UI still says Processor picks the model. - BYOK (Scale+): Controller’s agreement with the provider applies in addition. Processor refuses keys set to train on API data if Processor cannot verify otherwise.
- Aggregated non-content metrics (run counts, latency, credit burn, eval scores on Processor’s fixtures) may be used to operate the platform.
Exhibit D — Subprocessors and notice mechanics
The table, conditional subprocessors, notice, objection, and changelog requirements in /legal/subprocessors are incorporated by reference. Processor will keep at least 24 months of changelog history on that page.
URL: https://nox.markets/legal/subprocessors
Notice: email to workspace owner plus the public changelog.
