Data Processing Agreement
Effective Date: September 20, 2026 | Version 1.1
1. Definitions
| Controller | The entity determining the purposes and means of processing personal data (You, the customer) |
| Processor | Zencraft Consultancy Private Ltd. (operating Gixo.ai) |
| Data Subject | An identified or identifiable natural person whose data is processed |
| Personal Data | Any information relating to a Data Subject |
| Processing | Any operation performed on Personal Data (collection, storage, use, deletion, etc.) |
| Sub-processor | Any third party engaged by Processor to process Personal Data |
2. Scope and Application
This Data Processing Agreement ("DPA") applies when Processor processes Personal Data on behalf of Controller in connection with Gixo.ai services. This DPA supplements and forms part of the Terms of Service between Controller and Processor.
3. Processor Obligations
3.1 General Obligations
The Processor shall:
Process Personal Data only on documented instructions from Controller
Ensure persons authorized to process Personal Data are bound by confidentiality
Implement appropriate technical and organizational security measures
Engage Sub-processors only with Controller's prior written consent
Assist Controller in responding to Data Subject requests
Delete or return all Personal Data upon termination of services
3.2 Security Measures
Encryption in transit and at rest
Access controls and authentication
Incident triage, containment and post-incident review
Structured audit log, retained 365 days
Automated dependency updates and secret scanning
Pre-release test gate on every production change
4. Sub-processors
4.1 Authorized Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenAI | AI Text & Image Generation (GPT, DALL-E) | United States |
| Anthropic | AI Text Generation (Claude) | United States |
| Google (Gemini) | AI Multimodal Generation | United States |
| Microsoft Azure | Cloud Infrastructure & Storage | Central US. Requests reach the application through Azure Front Door, which terminates TLS at global edge locations. |
| Azure Cosmos DB for MongoDB | Managed Database Services | Central US |
| Microsoft Application Insights | Telemetry, Diagnostics, and Performance Monitoring | Central US |
| Polar | Payment Processing (Merchant of Record) | United States |
| Descope | Authentication and Identity (CIAM) | United States |
| Replicate | AI Image Generation | United States |
| Resend | Transactional E-mail Delivery | United States |
| Lemon Squeezy | Payment Processing (superseded — Polar is the merchant of record for new purchases; a legacy Lemon Squeezy checkout path remains configured as a fallback for individual shop items) | United States |
| PayPal | Payment Processing (historical — removed from the product on 2 August 2026) | United States |
5. Data Subject Rights
Processor shall assist Controller in fulfilling obligations to respond to Data Subject requests for:
Access to Personal Data
Rectification or erasure
Restriction of processing
Data portability
Objection to processing
Right to be forgotten
6. Data Breach Notification
The notification shall include:
Nature of the breach including categories of data and subjects affected
Approximate number of Data Subjects and data records concerned
Likely consequences of the breach
Measures taken or proposed to address the breach and mitigate effects
Contact details of Data Protection Officer or other contact point
7. International Data Transfers
Processor may transfer Personal Data internationally only with appropriate safeguards:
EU Standard Contractual Clauses (SCCs)
Adequacy decisions by relevant authorities
Other mechanisms approved under applicable data protection laws
Encryption and pseudonymization where appropriate
8. Audit Rights
Controller's Audit Rights
30 days advance notice required
During regular business hours
Maximum once per calendar year
Subject to confidentiality agreement
Audit Process
Gixo holds no security certification of its own and no SOC 2 or ISO 27001 report is available. Microsoft's certifications for the Azure platform can be supplied, and are Microsoft's rather than Gixo's.
Questionnaire-based assessments, answered directly
Controller may appoint an independent auditor at its own cost; Processor commissions no third-party audit of its own
Controller bears audit costs
9. Liability and Indemnification
Each party shall be liable for damages caused by its processing in violation of applicable data protection laws. Processor shall indemnify Controller for damages arising from Processor's breach of this DPA, subject to the limitation of liability provisions in the Terms of Service. Neither party excludes or limits liability for gross negligence, willful misconduct, or where prohibited by applicable law.
10. Term and Termination
This DPA remains in effect for the duration of the Service agreement. Upon termination:
Processor shall delete or de-identify Personal Data in accordance with the Service agreement, documented retention schedule, and Controller instructions
Controller may request return of data in standard format
Exception: Retention required by applicable law, billing, security, or backup operations
Processor shall provide written confirmation of deletion or de-identification where contractually required
11. Contact Information
Data Protection Officer
Zencraft Consultancy Private Ltd.
A/10, Nootan Nagar, First Floor,
Bandra West, Mumbai 400050
Maharashtra, India
Email: dpo@gixo.ai
Privacy: privacy@gixo.ai
Phone: Available upon request