Data Processing Addendum.
The Aplexica DPA covers the processor obligations under the GDPR, the UK GDPR, and the Swiss FADP. Customers on every paid Aplexica Cloud tier can request a signable copy without negotiation.
- Version
- 1.0
- Effective
- On signature
- SCCs
- EU 2021/914 available
What the DPA covers
- Aplexica's role as Processor with respect to customer personal data
- Subject matter, duration, nature, and purpose of processing
- Categories of data subjects and personal data
- Security measures (Annex A — derived from our Trust page)
- Approved sub-processors (Annex B — see sub-processors)
- EU Standard Contractual Clauses Module 2 (Controller-to-Processor) for non-EEA transfers
- UK International Data Transfer Addendum to the SCCs
- Swiss FADP addendum
Request
Signable DPA PDF
Email privacy@aplexica.com. We send the current PDF and signature instructions within one business day.
Request
Countersigned copy
Email privacy@aplexica.com. We return signed paper within one business day.
What we don't process
Per the Trust center, Aplexica Cloud handles only ciphertext of customer agent state — we cannot decrypt content under any circumstance. Personal data processed by Aplexica as Processor is therefore limited to: account metadata, billing metadata, audit log entries, and encrypted artifact bodies with their routing envelopes. The DPA's Annex A documents the security measures in detail.
Procurement reviewing the DPA?
Ask sales for the full procurement pack — DPA, sub-processor list, SIG-Lite, CAIQ-Lite, mutual NDA.