⚡ Free 30-day AI Employee pilot — answers every call, books every job. Fully installed. Claim your spot →

Neuzenix | Data Processing Addendum

Data Processing Addendum

Effective Date: July 23, 2026
Last Updated: July 23, 2026

This Data Processing Addendum (“DPA“) forms part of the Service Agreement, Terms of Service, or any other written or electronic agreement (the “Agreement“) between:

Neuzenix LLC, a New Mexico limited liability company with its principal place of business at 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA (“Processor” or “Neuzenix“),

and

the client identified in the Agreement (“Controller” or “Client“),

each a “Party” and together the “Parties.”

This DPA governs the processing of personal data by Neuzenix on behalf of the Client in connection with the Services. It reflects the Parties’ agreement on:

  • Compliance with applicable data protection laws
  • Rights and obligations under GDPR, UK-GDPR, CCPA/CPRA, PIPEDA, and the Australian Privacy Act
  • The use of Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum for international transfers
  • Subprocessor arrangements, security measures, and data subject rights

In the event of any conflict between this DPA and the Agreement, this DPA prevails with respect to matters concerning the processing of personal data.


1. DEFINITIONS

Terms used in this DPA have the meanings given below. Where a term is defined in GDPR (Regulation (EU) 2016/679) or the UK-GDPR, it carries the same meaning here unless otherwise stated.

  • “Applicable Data Protection Laws” means all laws, regulations, and binding regulatory guidance applicable to the processing of Personal Data under this DPA, including but not limited to: (i) the EU General Data Protection Regulation (GDPR); (ii) the UK General Data Protection Regulation (UK-GDPR) and the Data Protection Act 2018; (iii) the California Consumer Privacy Act and California Privacy Rights Act (collectively “CCPA/CPRA”); (iv) the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA); (v) the Australian Privacy Act 1988 and the Australian Privacy Principles; and (vi) any other applicable federal, state, provincial, or national law governing the protection of personal data.
  • “Client Personal Data” means any Personal Data that Neuzenix processes on behalf of the Client under the Agreement in the course of providing the Services.
  • “Controller” means the Client, who determines the purposes and means of processing Client Personal Data. Where required by CCPA/CPRA, the Client is the “Business.”
  • “Data Subject” means an identified or identifiable natural person to whom Client Personal Data relates. Under CCPA/CPRA, this includes “Consumers.”
  • “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data transmitted, stored, or otherwise processed.
  • “Processor” means Neuzenix. Under CCPA/CPRA, Neuzenix is the “Service Provider.”
  • “Processing” and its cognates have the meaning set out in GDPR Article 4(2): any operation or set of operations performed on Personal Data.
  • “Sub-processor” means any third party engaged by Neuzenix to process Client Personal Data on behalf of the Client.
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission under Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
  • “UK IDTA” means the UK International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner’s Office and in force from 21 March 2022.
  • “Services” has the meaning given in the Agreement.

2. SCOPE AND ROLES OF THE PARTIES

2.1 Roles

The Parties acknowledge that with respect to Client Personal Data:

  • The Client is the Controller (or “Business” under CCPA/CPRA)
  • Neuzenix is the Processor (or “Service Provider” under CCPA/CPRA)

Neuzenix will only process Client Personal Data in accordance with the Client’s documented lawful instructions, this DPA, the Agreement, and Applicable Data Protection Laws.

2.2 Instructions

The Client’s documented instructions include:

  • The Agreement (including any Service Agreement, order form, or configuration selected by the Client)
  • This DPA
  • Any additional instructions from the Client that are reasonable, lawful, and technically feasible

If Neuzenix believes an instruction violates Applicable Data Protection Laws, Neuzenix will promptly notify the Client, and the Client will amend the instruction or accept responsibility for the direction it has given.

2.3 Client Responsibilities

The Client warrants and represents that:

  • It has a valid lawful basis under Applicable Data Protection Laws for the Processing of Client Personal Data
  • It has provided all required notices to, and obtained all required consents from, Data Subjects
  • Its instructions to Neuzenix comply with Applicable Data Protection Laws
  • It is responsible for the accuracy, quality, and legality of Client Personal Data and the means by which it was acquired
  • It has appropriately configured any AI outputs, automated communications, or workflows to comply with law (including TCPA, CAN-SPAM, GDPR, CCPA, and equivalent frameworks)

Neuzenix has no independent obligation to verify the lawfulness of the Client’s collection or use of Client Personal Data.


3. SUBJECT MATTER AND DETAILS OF PROCESSING

The following table sets out the details of Processing required under GDPR Article 28(3) and equivalent laws.

ItemDetail
Subject matterProvision of AI automation Services under the Agreement
DurationFor the term of the Agreement plus applicable data retention periods
Nature and purposeStoring, retrieving, transmitting, analyzing, generating, and routing communications, contact records, and business data to deliver the Services
Type of Personal DataContact details (name, phone, email); communication content (calls, SMS, chat, email); business identifiers; behavioral data (e.g., booking activity); technical identifiers; and any other categories provided by the Client through use of the Services
Categories of Data SubjectsThe Client’s customers, prospects, leads, staff, vendors, and other individuals whose data the Client provides to Neuzenix
Special Categories (if any)Neuzenix does not intentionally process special-category data. Where the Client’s use of the Services results in incidental collection of such data (e.g., health information disclosed by a caller to a Voice AI in a medical practice), the Client is responsible for lawful processing under GDPR Article 9 or equivalent

4. OBLIGATIONS OF NEUZENIX

Neuzenix will:

4.1 Process Personal Data Only on Instructions

Process Client Personal Data only on the Client’s documented instructions, including with regard to international transfers, unless required by law. Where required by law to process outside these instructions, Neuzenix will notify the Client before processing, unless the law prohibits such notice on important grounds of public interest.

4.2 Confidentiality of Personnel

Ensure that all personnel authorized to process Client Personal Data are bound by written confidentiality obligations and have been trained on data protection.

4.3 Security Measures

Implement and maintain appropriate technical and organizational measures as set out in Annex II to protect Client Personal Data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, or disclosure.

4.4 Sub-processor Management

Engage Sub-processors only in accordance with Section 6 of this DPA.

4.5 Assist with Data Subject Rights

Taking into account the nature of the Processing, provide reasonable assistance to the Client (by appropriate technical and organizational measures) to fulfill the Client’s obligations to respond to Data Subject rights requests, including access, rectification, erasure, restriction, portability, and objection.

If Neuzenix receives a request directly from a Data Subject about Client Personal Data, Neuzenix will not respond substantively and will promptly redirect the Data Subject to the Client, notifying the Client where appropriate.

4.6 Assist with Compliance Obligations

Provide reasonable assistance to the Client with:

  • Data protection impact assessments (DPIAs) under GDPR Article 35
  • Prior consultations with supervisory authorities under GDPR Article 36
  • Ensuring compliance with security obligations under GDPR Article 32
  • Personal Data Breach notification obligations under GDPR Articles 33 and 34

4.7 Deletion or Return

At the Client’s choice, delete or return all Client Personal Data at the end of the Services, in accordance with Section 9 below.

4.8 Records and Audits

Make available to the Client all information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in Section 10.

4.9 CCPA/CPRA Specific Obligations

To the extent CCPA/CPRA applies, Neuzenix as Service Provider will:

  • Process Client Personal Data solely for the business purposes specified in the Agreement
  • Not “sell” or “share” Client Personal Data as those terms are defined under CCPA/CPRA
  • Not retain, use, or disclose Client Personal Data for any purpose other than for the specified business purpose or as otherwise permitted by CCPA/CPRA
  • Not combine Client Personal Data with data received from other sources, except as permitted for the business purpose
  • Notify the Client if Neuzenix can no longer meet its CCPA/CPRA obligations
  • Cooperate with the Client’s response to verifiable consumer requests

The Client certifies that it understands and will comply with its own CCPA/CPRA obligations.


5. PERSONAL DATA BREACHES

5.1 Notification to Client

Neuzenix will notify the Client without undue delay, and where feasible within 72 hours of becoming aware, of a Personal Data Breach affecting Client Personal Data.

5.2 Content of Notification

Where possible, the notification will include:

  • A description of the nature of the Breach, including categories and approximate number of Data Subjects and records concerned
  • The likely consequences of the Breach
  • Measures taken or proposed to address the Breach and mitigate its adverse effects
  • Contact details for further information

Where all information is not available at the time of initial notification, Neuzenix will provide it in phases as it becomes available.

5.3 Cooperation

Neuzenix will provide reasonable assistance to the Client with respect to the Client’s obligation to notify supervisory authorities and Data Subjects under Applicable Data Protection Laws, at the Client’s cost where such assistance requires more than de minimis effort.

5.4 No Admission

A notification of, or response to, a Personal Data Breach under this DPA is not an acknowledgment of fault or liability.


6. SUB-PROCESSORS

6.1 General Authorization

The Client provides Neuzenix with general written authorization to engage Sub-processors to assist in providing the Services, subject to the requirements in this Section 6.

6.2 Current Sub-processors

The list of Neuzenix’s current Sub-processors is set out in Annex III. This list may include (without limitation):

  • Cloud infrastructure and hosting providers
  • AI model providers (e.g., OpenAI, Anthropic, Google AI)
  • Voice, SMS, and messaging infrastructure providers (e.g., Twilio)
  • Payment processors (e.g., Stripe) — for Client billing
  • Workflow automation providers (e.g., Make)
  • Analytics and monitoring providers

6.3 Obligations on Sub-processors

Neuzenix will:

  • Enter into a written contract with each Sub-processor imposing data protection obligations substantially equivalent to those in this DPA
  • Remain fully liable to the Client for the performance of each Sub-processor’s obligations
  • Assess each Sub-processor’s ability to comply with Applicable Data Protection Laws prior to engagement

6.4 Changes to Sub-processors

Neuzenix will inform the Client of any intended addition or replacement of Sub-processors that will process Client Personal Data, giving the Client at least thirty (30) days’ advance notice (or such shorter period as may be operationally necessary for security or continuity reasons, in which case Neuzenix will provide such notice as soon as reasonably practicable).

6.5 Objection Right

The Client may object in writing to a new Sub-processor within fifteen (15) days of notice, on reasonable data protection grounds. If the Client objects:

  • Neuzenix will use reasonable efforts to make available a change to the Services or recommend a commercially reasonable modification to avoid the Client Personal Data being processed by the objected-to Sub-processor
  • If Neuzenix cannot make such change available within a reasonable time, the Client may terminate the affected portion of the Services on written notice, without penalty other than payment for Services rendered up to the effective termination date

Absent timely written objection, the Sub-processor is deemed approved.


7. INTERNATIONAL DATA TRANSFERS

7.1 Cross-Border Transfers

Neuzenix is established in the United States, and Sub-processors operate internationally. Client Personal Data may be transferred to and processed in the United States and other countries where Neuzenix or its Sub-processors operate.

7.2 EU Standard Contractual Clauses

Where Client Personal Data is transferred from the European Economic Area (EEA) to a country not benefiting from an adequacy decision:

  • The Parties incorporate by reference the EU Standard Contractual Clauses (Module 2: Controller to Processor) issued under Commission Implementing Decision (EU) 2021/914, which apply to that transfer
  • The Client is the “data exporter” and Neuzenix is the “data importer”
  • Clause 7 (Docking clause) is not used
  • Clause 9(a) — Option 2 (general written authorization) applies; the notice period for Sub-processor changes is set at 30 days
  • Clause 11(a) — the optional independent dispute resolution language is not used
  • Clause 17 — the governing law is the law of the Republic of Ireland
  • Clause 18(b) — disputes are resolved by the courts of Ireland
  • Annexes are populated by Annex I, Annex II, and Annex III to this DPA

7.3 UK International Data Transfer Addendum

Where Client Personal Data is transferred from the United Kingdom to a country not benefiting from a UK adequacy decision:

  • The Parties incorporate by reference the UK International Data Transfer Addendum (“UK IDTA”) to the EU SCCs, in the form issued by the UK Information Commissioner’s Office
  • The Annexes to this DPA populate the corresponding tables of the UK IDTA
  • Where the UK IDTA and the EU SCCs conflict, the UK IDTA prevails for transfers subject to UK-GDPR

7.4 Swiss Transfers

Where Client Personal Data is transferred from Switzerland, the EU SCCs apply with the following modifications required by the Swiss Federal Data Protection and Information Commissioner:

  • References to GDPR are interpreted as references to the Swiss Federal Act on Data Protection (FADP)
  • The competent supervisory authority is the Swiss FDPIC
  • References to Member States include Switzerland

7.5 Other Jurisdictions

For transfers subject to other cross-border restrictions (e.g., PIPEDA, the Australian Privacy Act), the Parties will implement appropriate transfer mechanisms consistent with those laws.

7.6 Supplementary Measures

Neuzenix will implement the technical and organizational measures set out in Annex II and any additional supplementary measures reasonably required to ensure a level of data protection substantially equivalent to that afforded under the EU/UK-GDPR.


8. DATA SUBJECT REQUESTS

Neuzenix will provide the Client with the tools and information reasonably necessary to allow the Client to respond to Data Subject requests, including through Neuzenix’s platform features (e.g., data export, deletion, correction functions).

If Neuzenix receives a Data Subject request directly (for example, an email sent to contact@neuzenix.com concerning a Data Subject whose data belongs to the Client), Neuzenix will:

  • Not respond to the substantive request
  • Promptly forward the request to the Client, where feasible
  • Advise the Data Subject to contact the relevant Controller directly

Where the Client requires assistance to comply with a Data Subject request, Neuzenix will provide reasonable cooperation, at the Client’s cost for effort exceeding standard platform features.


9. RETURN AND DELETION OF PERSONAL DATA

9.1 Upon Termination

Upon termination or expiry of the Services, at the Client’s choice communicated in writing within thirty (30) days of termination, Neuzenix will:

  • Return the Client Personal Data to the Client in a machine-readable format, and/or
  • Delete the Client Personal Data from Neuzenix’s active systems

9.2 Retention

Neuzenix may retain Client Personal Data:

  • For the periods and purposes described in the Neuzenix Privacy Policy
  • To comply with legal, tax, audit, or accounting obligations
  • In encrypted backups for a rolling period not exceeding ninety (90) days, after which backup data is overwritten
  • In aggregated or anonymized form that no longer identifies any Data Subject

9.3 Certification

Upon written request, Neuzenix will provide written certification of the deletion of Client Personal Data from active systems.


10. AUDIT RIGHTS

10.1 Records

Neuzenix will maintain records of its processing activities as required under GDPR Article 30 and equivalent laws, and will make relevant records available to the Client upon reasonable written request to demonstrate compliance with this DPA.

10.2 Audit Mechanism

To the extent required by Applicable Data Protection Laws, the Client may audit Neuzenix’s compliance with this DPA once per twelve (12) month period. Audits will be conducted through one of the following mechanisms, at Neuzenix’s option:

  • Provision of the most recent third-party security certifications, attestations, or audit reports (e.g., SOC 2, ISO 27001) held by Neuzenix or its Sub-processors
  • Written responses to a reasonable, documented security questionnaire
  • Where the above are insufficient to demonstrate compliance, a mutually agreed on-site or remote audit by a qualified independent auditor bound by confidentiality obligations

10.3 Conduct of Audits

Audits will:

  • Be conducted during normal business hours
  • Be scheduled with at least thirty (30) days’ advance written notice
  • Not unreasonably disrupt Neuzenix’s operations
  • Not access data of other Neuzenix clients or Neuzenix’s confidential information
  • Be at the Client’s expense, unless the audit reveals a material breach of this DPA by Neuzenix

10.4 Regulator Audits

Nothing in this Section 10 limits the audit or investigation rights of a competent supervisory authority under Applicable Data Protection Laws.


11. LIABILITY AND INDEMNIFICATION

11.1 Liability Cap

Each Party’s liability under this DPA is subject to the limitations of liability set out in the Agreement, including any aggregate liability cap.

11.2 GDPR Article 82

Where GDPR applies, nothing in the Agreement or this DPA limits either Party’s liability to Data Subjects under GDPR Article 82. Where a Party has paid compensation for damage caused by a joint breach, that Party may claim back from the other Party the part of the compensation corresponding to the other Party’s part of the responsibility.

11.3 Indemnification

The Client will indemnify and hold Neuzenix harmless from any third-party claim (including regulatory action) arising from:

  • The Client’s failure to have a lawful basis for the Processing of Client Personal Data
  • The Client’s instructions being unlawful under Applicable Data Protection Laws
  • The Client’s use of the Services in violation of the Agreement, this DPA, or applicable law
  • Content of communications the Client instructs Neuzenix to send on the Client’s behalf

12. TERM AND TERMINATION

This DPA will remain in effect for the duration of the Agreement and any period during which Neuzenix processes Client Personal Data on behalf of the Client. Sections that by their nature should survive (including Sections 5, 9, 10, 11, and 13) will survive termination.


13. GENERAL PROVISIONS

13.1 Order of Precedence

In the event of any conflict between this DPA and any other terms of the Agreement, this DPA prevails with respect to matters governing the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or UK IDTA, the SCCs or UK IDTA prevail with respect to the international transfers to which they apply.

13.2 Governing Law

This DPA is governed by the laws of the State of New Mexico, United States, except where the SCCs or UK IDTA prescribe a different governing law for the specific matters they govern.

13.3 Severability

If any provision of this DPA is held invalid or unenforceable, the remaining provisions will continue in full force and effect, and the invalid provision will be modified to the minimum extent necessary to make it enforceable while preserving the Parties’ original intent.

13.4 Amendments

Neuzenix may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, guidance from supervisory authorities, or Neuzenix’s operational practices. Material changes will be communicated to Clients with reasonable advance notice. Continued use of the Services after the effective date of an updated DPA constitutes acceptance.

13.5 Notices

Notices under this DPA are to be given as set out in the Terms of Service. Data-protection specific correspondence should be addressed to:

Neuzenix LLC
Attention: Data Protection
1209 Mountain Road PL NE, STE R
Albuquerque, NM 87110, USA
Email: contact@neuzenix.com

13.6 Electronic Acceptance

This DPA may be accepted electronically, by signature, click-through, or by continued use of the Services following notification. Electronic acceptance is legally binding to the same extent as a wet-ink signature.


ANNEX I — DETAILS OF PROCESSING

A. List of Parties

Data Exporter (Controller / Client):

  • Name: As identified in the Agreement
  • Address: As identified in the Agreement
  • Contact: As identified in the Agreement
  • Activities relevant to the transfer: Provision of business operations that require AI automation for customer engagement, appointment booking, communications, and revenue operations
  • Role: Controller

Data Importer (Processor / Neuzenix):

  • Name: Neuzenix LLC
  • Address: 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA
  • Contact: contact@neuzenix.com
  • Activities relevant to the transfer: Provision of AI automation Services including Voice AI, Conversation AI, AI Employee Pro, Review AI, AI Client Acquisition Engine, and related infrastructure
  • Role: Processor

B. Description of Transfer

  • Categories of Data Subjects: The Client’s customers, prospects, leads, employees, vendors, and any other individuals whose Personal Data the Client provides to Neuzenix
  • Categories of Personal Data: Names, contact details (email, phone), business identifiers, appointment and booking data, communication content (voice, SMS, chat, email), technical data (IP addresses, device identifiers), behavioral and interaction data
  • Special Categories (if any): None intentionally processed. Where incidentally collected (e.g., in medical or legal contexts), the Client is responsible for lawful processing under GDPR Article 9 or equivalent
  • Frequency of Transfer: Continuous
  • Nature of Processing: Storage, retrieval, transmission, analysis, generation of AI outputs, routing, and automation
  • Purpose: Provision of the Services under the Agreement
  • Retention Period: For the duration of the Services and thereafter as described in the Neuzenix Privacy Policy and Section 9 of this DPA

C. Competent Supervisory Authority

  • For EU transfers under the EU SCCs: the supervisory authority of the Member State in which the Controller is established or the representative is designated
  • For UK transfers under the UK IDTA: the UK Information Commissioner’s Office (ICO)
  • For Swiss transfers: the Swiss Federal Data Protection and Information Commissioner (FDPIC)

ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES

Neuzenix implements and maintains the following technical and organizational measures to protect Client Personal Data:

1. Access Controls

  • Role-based access controls limiting access to Client Personal Data to authorized personnel with a business need
  • Multi-factor authentication for administrative access to systems containing Client Personal Data
  • Unique user credentials; shared accounts are prohibited
  • Regular review and revocation of access rights

2. Encryption

  • Transport Layer Security (TLS 1.2 or higher) for data in transit
  • Encryption at rest for databases and storage systems containing sensitive Client Personal Data, where technically feasible
  • Encryption of payment data by our payment processor (Stripe) in accordance with PCI-DSS

3. Network Security

  • Firewalls, intrusion detection, and monitoring on production infrastructure
  • Segregation of production and non-production environments
  • Regular vulnerability scanning of externally exposed services

4. Operational Security

  • Documented change management procedures
  • Documented incident response procedures, including breach detection, containment, and notification workflows
  • Regular backups with the ability to restore Client Personal Data in the event of loss
  • Retention of backups for a rolling ninety (90) day cycle, after which backup data is overwritten

5. Personnel Security

  • Written confidentiality obligations for all personnel with access to Client Personal Data
  • Data protection and security awareness training upon onboarding and periodically thereafter
  • Background checks where legally permissible and relevant to the role

6. Vendor Security

  • Due diligence on Sub-processors before engagement, including review of publicly available security certifications and privacy commitments
  • Contractual data protection obligations imposed on Sub-processors substantially equivalent to those in this DPA

7. Physical Security

  • Cloud infrastructure hosted in facilities that maintain industry-standard physical access controls, environmental controls, and 24/7 monitoring, as documented by the relevant cloud provider

8. Data Minimization and Retention

  • Collection and processing of Personal Data limited to what is necessary for the Services
  • Retention periods aligned with the Neuzenix Privacy Policy and the Client’s documented instructions

9. Continuous Improvement

  • Periodic review and update of these measures to reflect evolving threats, technology, and regulatory expectations

The Client acknowledges that these measures are subject to technical progress and development and that Neuzenix may update them from time to time, provided that the overall level of protection is not reduced.


ANNEX III — LIST OF SUB-PROCESSORS

The following Sub-processors are engaged by Neuzenix as of the Effective Date. This list may be updated in accordance with Section 6 of this DPA.

Sub-processorPurposeLocation of Processing
Stripe, Inc.Payment processing for Client billingUnited States (global availability)
OpenAI, L.L.C.AI language model processingUnited States
Anthropic, PBCAI language model processingUnited States
Google LLC (Google AI, Analytics, Cloud)AI processing, analytics, cloud infrastructureUnited States (global availability)
Twilio Inc.Voice, SMS, and messaging infrastructureUnited States (global availability)
Make (Celonis SE / Make.com)Workflow automationEuropean Union
Perplexity AIAI research and content assistanceUnited States
WordPress hosting provider (as engaged from time to time)Website hostingUnited States

Additional Sub-processors may be engaged from time to time in accordance with Section 6 of this DPA. The current list of Sub-processors will be maintained and made available upon request to contact@neuzenix.com.


End of Data Processing Addendum.

SIGNATURE PAGE

The Parties agree to be bound by the terms of this Data Processing Addendum.

For Neuzenix LLC:

Signature: ________________________

Name: Md Tarikuzzaman
Title: CEO
Date: ________________________

For the Client:

Signature: ________________________

Name: ________________________
Title: ________________________
Company: ________________________
Date: ________________________