APLEXICA

Data Processing Addendum.

The Aplexica DPA covers the processor obligations under the GDPR, the UK GDPR, and the Swiss FADP. Customers on every paid Aplexica Cloud tier can request a signable copy without negotiation.

Version
1.0
Effective
On signature
SCCs
EU 2021/914 available

What the DPA covers

  • Aplexica's role as Processor with respect to customer personal data
  • Subject matter, duration, nature, and purpose of processing
  • Categories of data subjects and personal data
  • Security measures (Annex A — derived from our Trust page)
  • Approved sub-processors (Annex B — see sub-processors)
  • EU Standard Contractual Clauses Module 2 (Controller-to-Processor) for non-EEA transfers
  • UK International Data Transfer Addendum to the SCCs
  • Swiss FADP addendum

What we don't process

Per the Trust center, Aplexica Cloud handles only ciphertext of customer agent state — we cannot decrypt content under any circumstance. Personal data processed by Aplexica as Processor is therefore limited to: account metadata, billing metadata, audit log entries, and encrypted artifact bodies with their routing envelopes. The DPA's Annex A documents the security measures in detail.

Procurement reviewing the DPA?

Ask sales for the full procurement pack — DPA, sub-processor list, SIG-Lite, CAIQ-Lite, mutual NDA.