Effective Date: July 23, 2026
Last Updated: July 23, 2026
This Data Processing Addendum (“DPA“) forms part of the Service Agreement, Terms of Service, or any other written or electronic agreement (the “Agreement“) between:
Neuzenix LLC, a New Mexico limited liability company with its principal place of business at 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA (“Processor” or “Neuzenix“),
and
the client identified in the Agreement (“Controller” or “Client“),
each a “Party” and together the “Parties.”
This DPA governs the processing of personal data by Neuzenix on behalf of the Client in connection with the Services. It reflects the Parties’ agreement on:
- Compliance with applicable data protection laws
- Rights and obligations under GDPR, UK-GDPR, CCPA/CPRA, PIPEDA, and the Australian Privacy Act
- The use of Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum for international transfers
- Subprocessor arrangements, security measures, and data subject rights
In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to matters concerning the processing of personal data.
1. DEFINITIONS
Terms used in this DPA have the meanings given below. Where a term is defined in GDPR (Regulation (EU) 2016/679) or the UK-GDPR, it carries the same meaning here unless otherwise stated.
- “Applicable Data Protection Laws” means all laws, regulations, and binding regulatory guidance applicable to the processing of Personal Data under this DPA, including but not limited to: (i) the EU General Data Protection Regulation (GDPR); (ii) the UK General Data Protection Regulation (UK-GDPR) and the Data Protection Act 2018; (iii) the California Consumer Privacy Act and California Privacy Rights Act (collectively “CCPA/CPRA”); (iv) the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA); (v) the Australian Privacy Act 1988 and the Australian Privacy Principles; and (vi) any other applicable federal, state, provincial, or national law governing the protection of personal data.
- “Client Personal Data” means any Personal Data that Neuzenix processes on behalf of the Client under the Agreement in the course of providing the Services.
- “Controller” means the Client, who determines the purposes and means of processing Client Personal Data. Where required by CCPA/CPRA, the Client is the “Business.”
- “Data Subject” means an identified or identifiable natural person to whom Client Personal Data relates. Under CCPA/CPRA, this includes “Consumers.”
- “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data transmitted, stored, or otherwise processed.
- “Processor” means Neuzenix. Under CCPA/CPRA, Neuzenix is the “Service Provider.”
- “Processing” and its cognates have the meaning set out in GDPR Article 4(2): any operation or set of operations performed on Personal Data.
- “Sub-processor” means any third party engaged by Neuzenix to process Client Personal Data on behalf of the Client.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission under Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
- “UK IDTA” means the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner’s Office and in force from 21 March 2022.
- “Services” has the meaning given in the Agreement.
2. SCOPE AND ROLES OF THE PARTIES
2.1 Roles
The Parties acknowledge that with respect to Client Personal Data:
- The Client is the Controller (or “Business” under CCPA/CPRA)
- Neuzenix is the Processor (or “Service Provider” under CCPA/CPRA)
Neuzenix will only process Client Personal Data in accordance with the Client’s documented lawful instructions, this DPA, the Agreement, and Applicable Data Protection Laws.
2.2 Instructions
The Client’s documented instructions include:
- The Agreement (including any Service Agreement, order form, or configuration selected by the Client)
- This DPA
- Any additional instructions from the Client that are reasonable, lawful, and technically feasible
If Neuzenix believes an instruction violates Applicable Data Protection Laws, Neuzenix will promptly notify the Client, and the Client will amend the instruction or accept responsibility for the direction it has given.
2.3 Client Responsibilities
The Client warrants and represents that:
- It has a valid lawful basis under Applicable Data Protection Laws for the Processing of Client Personal Data
- It has provided all required notices to, and obtained all required consents from, Data Subjects
- Its instructions to Neuzenix comply with Applicable Data Protection Laws
- It is responsible for the accuracy, quality, and legality of Client Personal Data and the means by which it was acquired
- It has appropriately configured any AI outputs, automated communications, or workflows to comply with law (including TCPA, CAN-SPAM, GDPR, CCPA, and equivalent frameworks)
Neuzenix has no independent obligation to verify the lawfulness of the Client’s collection or use of Client Personal Data.
3. SUBJECT MATTER AND DETAILS OF PROCESSING
The following table sets out the details of Processing required under GDPR Article 28(3) and equivalent laws.
| Item | Detail |
|---|
| Subject matter | Provision of AI automation Services under the Agreement |
| Duration | For the term of the Agreement plus applicable data retention periods |
| Nature and purpose | Storing, retrieving, transmitting, analyzing, generating, and routing communications, contact records, and business data to deliver the Services |
| Type of Personal Data | Contact details (name, phone, email); communication content (calls, SMS, chat, email); business identifiers; behavioral data (e.g., booking activity); technical identifiers; and any other categories provided by the Client through use of the Services |
| Categories of Data Subjects | The Client’s customers, prospects, leads, staff, vendors, and other individuals whose data the Client provides to Neuzenix |
| Special Categories (if any) | Neuzenix does not intentionally process special-category data. Where the Client’s use of the Services results in incidental collection of such data (e.g., health information disclosed by a caller to a Voice AI in a medical practice), the Client is responsible for lawful processing under GDPR Article 9 or equivalent |
4. OBLIGATIONS OF NEUZENIX
Neuzenix will:
4.1 Process Personal Data Only on Instructions
Process Client Personal Data only on the Client’s documented instructions, including with regard to international transfers, unless required by law. Where required by law to process outside these instructions, Neuzenix will notify the Client before processing, unless the law prohibits such notice on important grounds of public interest.
4.2 Confidentiality of Personnel
Ensure that all personnel authorized to process Client Personal Data are bound by written confidentiality obligations and have been trained on data protection.
4.3 Security Measures
Implement and maintain appropriate technical and organizational measures as set out in Annex II to protect Client Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure.
4.4 Sub-processor Management
Engage Sub-processors only in accordance with Section 6 of this DPA.
4.5 Assist with Data Subject Rights
Taking into account the nature of the Processing, provide reasonable assistance to the Client (by appropriate technical and organizational measures) to fulfill the Client’s obligations to respond to Data Subject rights requests, including access, rectification, erasure, restriction, portability, and objection.
If Neuzenix receives a request directly from a Data Subject about Client Personal Data, Neuzenix will not respond substantively and will promptly redirect the Data Subject to the Client, notifying the Client where appropriate.
4.6 Assist with Compliance Obligations
Provide reasonable assistance to the Client with:
- Data protection impact assessments (DPIAs) under GDPR Article 35
- Prior consultations with supervisory authorities under GDPR Article 36
- Ensuring compliance with security obligations under GDPR Article 32
- Personal Data Breach notification obligations under GDPR Articles 33 and 34
4.7 Deletion or Return
At the Client’s choice, delete or return all Client Personal Data at the end of the Services, in accordance with Section 9 below.
4.8 Records and Audits
Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in Section 10.
4.9 CCPA/CPRA Specific Obligations
To the extent CCPA/CPRA applies, Neuzenix as Service Provider will:
- Process Client Personal Data solely for the business purposes specified in the Agreement
- Not “sell” or “share” Client Personal Data as those terms are defined under CCPA/CPRA
- Not retain, use, or disclose Client Personal Data for any purpose other than for the specified business purpose or as otherwise permitted by CCPA/CPRA
- Not combine Client Personal Data with data received from other sources, except as permitted for the business purpose
- Notify the Client if Neuzenix can no longer meet its CCPA/CPRA obligations
- Cooperate with the Client’s response to verifiable consumer requests
The Client certifies that it understands and will comply with its own CCPA/CPRA obligations.
5. PERSONAL DATA BREACHES
5.1 Notification to Client
Neuzenix will notify the Client without undue delay, and where feasible within 72 hours of becoming aware, of a Personal Data Breach affecting Client Personal Data.
5.2 Content of Notification
Where possible, the notification will include:
- A description of the nature of the Breach, including categories and approximate number of Data Subjects and records concerned
- The likely consequences of the Breach
- Measures taken or proposed to address the Breach and mitigate its adverse effects
- Contact details for further information
Where all information is not available at the time of initial notification, Neuzenix will provide it in phases as it becomes available.
5.3 Cooperation
Neuzenix will provide reasonable assistance to the Client with respect to the Client’s obligation to notify supervisory authorities and Data Subjects under Applicable Data Protection Laws, at the Client’s cost where such assistance requires more than de minimis effort.
5.4 No Admission
A notification of, or response to, a Personal Data Breach under this DPA is not an acknowledgment of fault or liability.
6. SUB-PROCESSORS
6.1 General Authorization
The Client provides Neuzenix with general written authorization to engage Sub-processors to assist in providing the Services, subject to the requirements in this Section 6.
6.2 Current Sub-processors
The list of Neuzenix’s current Sub-processors is set out in Annex III. This list may include (without limitation):
- Cloud infrastructure and hosting providers
- AI model providers (e.g., OpenAI, Anthropic, Google AI)
- Voice, SMS, and messaging infrastructure providers (e.g., Twilio)
- Payment processors (e.g., Stripe) — for Client billing
- Workflow automation providers (e.g., Make)
- Analytics and monitoring providers
6.3 Obligations on Sub-processors
Neuzenix will:
- Enter into a written contract with each Sub-processor imposing data protection obligations substantially equivalent to those in this DPA
- Remain fully liable to the Client for the performance of each Sub-processor’s obligations
- Assess each Sub-processor’s ability to comply with Applicable Data Protection Laws prior to engagement
6.4 Changes to Sub-processors
Neuzenix will inform the Client of any intended addition or replacement of Sub-processors that will process Client Personal Data, giving the Client at least thirty (30) days’ advance notice (or such shorter period as may be operationally necessary for security or continuity reasons, in which case Neuzenix will provide such notice as soon as reasonably practicable).
6.5 Objection Right
The Client may object in writing to a new Sub-processor within fifteen (15) days of notice, on reasonable data protection grounds. If the Client objects:
- Neuzenix will use reasonable efforts to make available a change to the Services or recommend a commercially reasonable modification to avoid the Client Personal Data being processed by the objected-to Sub-processor
- If Neuzenix cannot make such change available within a reasonable time, the Client may terminate the affected portion of the Services on written notice, without penalty other than payment for Services rendered up to the effective termination date
Absent timely written objection, the Sub-processor is deemed approved.
7. INTERNATIONAL DATA TRANSFERS
7.1 Cross-Border Transfers
Neuzenix is established in the United States, and Sub-processors operate internationally. Client Personal Data may be transferred to and processed in the United States and other countries where Neuzenix or its Sub-processors operate.
7.2 EU Standard Contractual Clauses
Where Client Personal Data is transferred from the European Economic Area (EEA) to a country not benefiting from an adequacy decision:
- The Parties incorporate by reference the EU Standard Contractual Clauses (Module 2: Controller to Processor) issued under Commission Implementing Decision (EU) 2021/914, which apply to that transfer
- The Client is the “data exporter” and Neuzenix is the “data importer”
- Clause 7 (Docking clause) is not used
- Clause 9(a) — Option 2 (general written authorization) applies; the notice period for Sub-processor changes is set at 30 days
- Clause 11(a) — the optional independent dispute resolution language is not used
- Clause 17 — the governing law is the law of the Republic of Ireland
- Clause 18(b) — disputes are resolved by the courts of Ireland
- Annexes are populated by Annex I, Annex II, and Annex III to this DPA
7.3 UK International Data Transfer Addendum
Where Client Personal Data is transferred from the United Kingdom to a country not benefiting from a UK adequacy decision:
- The Parties incorporate by reference the UK International Data Transfer Addendum (“UK IDTA”) to the EU SCCs, in the form issued by the UK Information Commissioner’s Office
- The Annexes to this DPA populate the corresponding tables of the UK IDTA
- Where the UK IDTA and the EU SCCs conflict, the UK IDTA prevails for transfers subject to UK-GDPR
7.4 Swiss Transfers
Where Client Personal Data is transferred from Switzerland, the EU SCCs apply with the following modifications required by the Swiss Federal Data Protection and Information Commissioner:
- References to GDPR are interpreted as references to the Swiss Federal Act on Data Protection (FADP)
- The competent supervisory authority is the Swiss FDPIC
- References to Member States include Switzerland
7.5 Other Jurisdictions
For transfers subject to other cross-border restrictions (e.g., PIPEDA, the Australian Privacy Act), the Parties will implement appropriate transfer mechanisms consistent with those laws.
7.6 Supplementary Measures
Neuzenix will implement the technical and organizational measures set out in Annex II and any additional supplementary measures reasonably required to ensure a level of data protection substantially equivalent to that afforded under the EU/UK-GDPR.
8. DATA SUBJECT REQUESTS
Neuzenix will provide the Client with the tools and information reasonably necessary to allow the Client to respond to Data Subject requests, including through Neuzenix’s platform features (e.g., data export, deletion, correction functions).
If Neuzenix receives a Data Subject request directly (for example, an email sent to contact@neuzenix.com concerning a Data Subject whose data belongs to the Client), Neuzenix will:
- Not respond to the substantive request
- Promptly forward the request to the Client, where feasible
- Advise the Data Subject to contact the relevant Controller directly
Where the Client requires assistance to comply with a Data Subject request, Neuzenix will provide reasonable cooperation, at the Client’s cost for effort exceeding standard platform features.
9. RETURN AND DELETION OF PERSONAL DATA
9.1 Upon Termination
Upon termination or expiry of the Services, at the Client’s choice communicated in writing within thirty (30) days of termination, Neuzenix will:
- Return the Client Personal Data to the Client in a machine-readable format, and/or
- Delete the Client Personal Data from Neuzenix’s active systems
9.2 Retention
Neuzenix may retain Client Personal Data:
- For the periods and purposes described in the Neuzenix Privacy Policy
- To comply with legal, tax, audit, or accounting obligations
- In encrypted backups for a rolling period not exceeding ninety (90) days, after which backup data is overwritten
- In aggregated or anonymized form that no longer identifies any Data Subject
9.3 Certification
Upon written request, Neuzenix will provide written certification of the deletion of Client Personal Data from active systems.
10. AUDIT RIGHTS
10.1 Records
Neuzenix will maintain records of its processing activities as required under GDPR Article 30 and equivalent laws, and will make relevant records available to the Client upon reasonable written request to demonstrate compliance with this DPA.
10.2 Audit Mechanism
To the extent required by Applicable Data Protection Laws, the Client may audit Neuzenix’s compliance with this DPA once per twelve (12) month period. Audits will be conducted through one of the following mechanisms, at Neuzenix’s option:
- Provision of the most recent third-party security certifications, attestations, or audit reports (e.g., SOC 2, ISO 27001) held by Neuzenix or its Sub-processors
- Written responses to a reasonable, documented security questionnaire
- Where the above are insufficient to demonstrate compliance, a mutually agreed on-site or remote audit by a qualified independent auditor bound by confidentiality obligations
10.3 Conduct of Audits
Audits will:
- Be conducted during normal business hours
- Be scheduled with at least thirty (30) days’ advance written notice
- Not unreasonably disrupt Neuzenix’s operations
- Not access data of other Neuzenix clients or Neuzenix’s confidential information
- Be at the Client’s expense, unless the audit reveals a material breach of this DPA by Neuzenix
10.4 Regulator Audits
Nothing in this Section 10 limits the audit or investigation rights of a competent supervisory authority under Applicable Data Protection Laws.
11. LIABILITY AND INDEMNIFICATION
11.1 Liability Cap
Each Party’s liability under this DPA is subject to the limitations of liability set out in the Agreement, including any aggregate liability cap.
11.2 GDPR Article 82
Where GDPR applies, nothing in the Agreement or this DPA limits either Party’s liability to Data Subjects under GDPR Article 82. Where a Party has paid compensation for damage caused by a joint breach, that Party may claim back from the other Party the part of the compensation corresponding to the other Party’s part of the responsibility.
11.3 Indemnification
The Client will indemnify and hold Neuzenix harmless from any third-party claim (including regulatory action) arising from:
- The Client’s failure to have a lawful basis for the Processing of Client Personal Data
- The Client’s instructions being unlawful under Applicable Data Protection Laws
- The Client’s use of the Services in violation of the Agreement, this DPA, or applicable law
- Content of communications the Client instructs Neuzenix to send on the Client’s behalf
12. TERM AND TERMINATION
This DPA will remain in effect for the duration of the Agreement and any period during which Neuzenix processes Client Personal Data on behalf of the Client. Sections that by their nature should survive (including Sections 5, 9, 10, 11, and 13) will survive termination.
13. GENERAL PROVISIONS
13.1 Order of Precedence
In the event of any conflict between this DPA and any other terms of the Agreement, this DPA prevails with respect to matters governing the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or UK IDTA, the SCCs or UK IDTA prevail with respect to the international transfers to which they apply.
13.2 Governing Law
This DPA is governed by the laws of the State of New Mexico, United States, except where the SCCs or UK IDTA prescribe a different governing law for the specific matters they govern.
13.3 Severability
If any provision of this DPA is held invalid or unenforceable, the remaining provisions will continue in full force and effect, and the invalid provision will be modified to the minimum extent necessary to make it enforceable while preserving the Parties’ original intent.
13.4 Amendments
Neuzenix may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, guidance from supervisory authorities, or Neuzenix’s operational practices. Material changes will be communicated to Clients with reasonable advance notice. Continued use of the Services after the effective date of an updated DPA constitutes acceptance.
13.5 Notices
Notices under this DPA are to be given as set out in the Terms of Service. Data-protection specific correspondence should be addressed to:
Neuzenix LLC
Attention: Data Protection
1209 Mountain Road PL NE, STE R
Albuquerque, NM 87110, USA
Email: contact@neuzenix.com
13.6 Electronic Acceptance
This DPA may be accepted electronically, by signature, click-through, or by continued use of the Services following notification. Electronic acceptance is legally binding to the same extent as a wet-ink signature.
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
Data Exporter (Controller / Client):
- Name: As identified in the Agreement
- Address: As identified in the Agreement
- Contact: As identified in the Agreement
- Activities relevant to the transfer: Provision of business operations that require AI automation for customer engagement, appointment booking, communications, and revenue operations
- Role: Controller
Data Importer (Processor / Neuzenix):
- Name: Neuzenix LLC
- Address: 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA
- Contact: contact@neuzenix.com
- Activities relevant to the transfer: Provision of AI automation Services including Voice AI, Conversation AI, AI Employee Pro, Review AI, AI Client Acquisition Engine, and related infrastructure
- Role: Processor
B. Description of Transfer
- Categories of Data Subjects: The Client’s customers, prospects, leads, employees, vendors, and any other individuals whose Personal Data the Client provides to Neuzenix
- Categories of Personal Data: Names, contact details (email, phone), business identifiers, appointment and booking data, communication content (voice, SMS, chat, email), technical data (IP addresses, device identifiers), behavioral and interaction data
- Special Categories (if any): None intentionally processed. Where incidentally collected (e.g., in medical or legal contexts), the Client is responsible for lawful processing under GDPR Article 9 or equivalent
- Frequency of Transfer: Continuous
- Nature of Processing: Storage, retrieval, transmission, analysis, generation of AI outputs, routing, and automation
- Purpose: Provision of the Services under the Agreement
- Retention Period: For the duration of the Services and thereafter as described in the Neuzenix Privacy Policy and Section 9 of this DPA
C. Competent Supervisory Authority
- For EU transfers under the EU SCCs: the supervisory authority of the Member State in which the Controller is established or the representative is designated
- For UK transfers under the UK IDTA: the UK Information Commissioner’s Office (ICO)
- For Swiss transfers: the Swiss Federal Data Protection and Information Commissioner (FDPIC)
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
Neuzenix implements and maintains the following technical and organizational measures to protect Client Personal Data:
1. Access Controls
- Role-based access controls limiting access to Client Personal Data to authorized personnel with a business need
- Multi-factor authentication for administrative access to systems containing Client Personal Data
- Unique user credentials; shared accounts are prohibited
- Regular review and revocation of access rights
2. Encryption
- Transport Layer Security (TLS 1.2 or higher) for data in transit
- Encryption at rest for databases and storage systems containing sensitive Client Personal Data, where technically feasible
- Encryption of payment data by our payment processor (Stripe) in accordance with PCI-DSS
3. Network Security
- Firewalls, intrusion detection, and monitoring on production infrastructure
- Segregation of production and non-production environments
- Regular vulnerability scanning of externally exposed services
4. Operational Security
- Documented change management procedures
- Documented incident response procedures, including breach detection, containment, and notification workflows
- Regular backups with the ability to restore Client Personal Data in the event of loss
- Retention of backups for a rolling ninety (90) day cycle, after which backup data is overwritten
5. Personnel Security
- Written confidentiality obligations for all personnel with access to Client Personal Data
- Data protection and security awareness training upon onboarding and periodically thereafter
- Background checks where legally permissible and relevant to the role
6. Vendor Security
- Due diligence on Sub-processors before engagement, including review of publicly available security certifications and privacy commitments
- Contractual data protection obligations imposed on Sub-processors substantially equivalent to those in this DPA
7. Physical Security
- Cloud infrastructure hosted in facilities that maintain industry-standard physical access controls, environmental controls, and 24/7 monitoring, as documented by the relevant cloud provider
8. Data Minimization and Retention
- Collection and processing of Personal Data limited to what is necessary for the Services
- Retention periods aligned with the Neuzenix Privacy Policy and the Client’s documented instructions
9. Continuous Improvement
- Periodic review and update of these measures to reflect evolving threats, technology, and regulatory expectations
The Client acknowledges that these measures are subject to technical progress and development and that Neuzenix may update them from time to time, provided that the overall level of protection is not reduced.
ANNEX III — LIST OF SUB-PROCESSORS
The following Sub-processors are engaged by Neuzenix as of the Effective Date. This list may be updated in accordance with Section 6 of this DPA.
| Sub-processor | Purpose | Location of Processing |
|---|
| Stripe, Inc. | Payment processing for Client billing | United States (global availability) |
| OpenAI, L.L.C. | AI language model processing | United States |
| Anthropic, PBC | AI language model processing | United States |
| Google LLC (Google AI, Analytics, Cloud) | AI processing, analytics, cloud infrastructure | United States (global availability) |
| Twilio Inc. | Voice, SMS, and messaging infrastructure | United States (global availability) |
| Make (Celonis SE / Make.com) | Workflow automation | European Union |
| Perplexity AI | AI research and content assistance | United States |
| WordPress hosting provider (as engaged from time to time) | Website hosting | United States |
Additional Sub-processors may be engaged from time to time in accordance with Section 6 of this DPA. The current list of Sub-processors will be maintained and made available upon request to contact@neuzenix.com.
End of Data Processing Addendum.