Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Luminorix, Inc. ("Luminorix" or "Processor") and the customer identified in the applicable workspace ("Customer" or "Controller") and applies where Luminorix processes Personal Data on Customer's behalf and data-protection law applies to that processing.
1. Definitions
"Data Protection Law" means all laws applying to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP and the California Consumer Privacy Act as amended (CCPA). "Personal Data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in Data Protection Law. "Customer Data" has the meaning in the Terms. "Sub-processor" means a third party engaged by Luminorix to process Personal Data.
2. Roles and instructions
2.1 Customer is the controller (or a processor acting for its own controller) and Luminorix is the processor of Personal Data in Customer Data. Under the CCPA, Luminorix is a service provider.
2.2 Luminorix will process Personal Data only on Customer's documented instructions, which are: the Terms, this DPA, the configuration Customer sets in the Service (including which systems are connected, what agents may do and which actions require approval), and any further written instructions. Luminorix will inform Customer if it believes an instruction infringes Data Protection Law.
2.3 Luminorix will not sell Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Service, or combine it with Personal Data from other sources except as the CCPA permits for a service provider.
3. Confidentiality and personnel
Luminorix restricts access to Personal Data to personnel who need it to provide the Service and who are bound by confidentiality obligations and trained on data protection.
4. Security
Luminorix maintains the technical and organisational measures in Annex 2 and will not reduce their overall level of protection during the term. Customer is responsible for the security of its own systems and credentials, and for the permissions and approval settings it configures.
5. Sub-processors
5.1 Customer authorises the Sub-processors listed in Annex 3. Luminorix will give at least 15 days' notice by email to workspace admins before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected part of the Service without penalty.
5.2 Luminorix imposes data-protection obligations on each Sub-processor that are no less protective than this DPA and remains responsible for their performance.
6. Data subject requests
Luminorix will promptly forward to Customer any request it receives from a data subject relating to Customer Data and will assist Customer, through the Service's features and, where needed, additional reasonable assistance, in responding.
7. Assistance
Taking into account the nature of the processing, Luminorix will assist Customer with security, breach notification, data protection impact assessments and prior consultations required by Data Protection Law.
8. Personal data breach
Luminorix will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data, with the information reasonably available at the time and updates as the investigation proceeds.
9. Deletion and return
On termination or on Customer's request, Luminorix will delete Customer Data within 30 days and make it available for export in a common format before deletion, except for copies in routine backups, which expire within 90 days, and data Luminorix must retain by law, which stays protected under this DPA.
10. Audit
Luminorix will make available the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and summaries of third-party assessments when available, and will allow audits by Customer or an independent auditor mandated by Customer no more than once a year (or after a breach), on 30 days' notice, during business hours, under confidentiality, and without unreasonable disruption.
11. International transfers
Luminorix processes Personal Data in the United States. For Personal Data transferred from the EEA, UK or Switzerland, the parties enter into the EU Standard Contractual Clauses (Module Two, controller to processor, or Module Three where Customer is a processor), the UK Addendum and the Swiss amendments, which are incorporated by reference and available on request, with Annexes 1 to 3 of this DPA serving as the annexes to those clauses.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms, this DPA prevails for the processing of Personal Data.
Annex 1 · Details of processing
Subject matter: operation of the Luminorix platform, including reading connected business systems and running AI agents within Customer-configured permissions.
Duration: the term of the Customer's subscription plus the deletion period in Section 9.
Nature and purpose: connecting to and reading Customer's business systems; producing operating views, findings and recommendations; drafting, preparing and, with Customer's configuration or approval, performing tasks such as messages, records updates and follow-ups; supporting Customer.
Categories of data subjects: Customer's employees and contractors; Customer's customers, patients, clients, leads, borrowers and vendors and their staff; other individuals whose data appears in connected systems.
Categories of Personal Data: identification and contact details; account, order, invoice, payment status and transaction records; communications (email, chat, call transcripts); scheduling and appointment data; case, ticket and file records; and, where Customer connects such systems and has a written agreement covering it, special-category data such as health information.
Frequency: continuous while the Service is used.
Annex 2 · Technical and organisational measures
Encryption of credentials and secrets at rest (AES-256) and of data in transit (TLS 1.2 or higher). Tenant isolation: every workspace's data, connections and agents are separated by tenant identifier at the application and data layers. Read-only connections by default; write actions require Customer configuration and, where offered, human approval. Permission scopes per agent; per-agent and per-workspace usage and cost limits. Audit logging of agent actions, approvals, connection tests and administrative access. Live verification of every connection at save time. Access control: role-based access for Customer users; production access limited to authorised Luminorix staff with named accounts. Vulnerability management, dependency updates and backups with defined retention. Sub-processor contracts prohibiting model training on Customer Data. Incident response procedure with 72-hour customer notification.
Annex 3 · Sub-processors
Infrastructure and hosting: phoenixNAP (United States) and Amazon Web Services (United States). Edge, DNS and security: Cloudflare (United States). AI model providers: Anthropic, OpenAI, Cerebras, DeepSeek (United States and, for DeepSeek, China; used only where Customer enables that model tier). Voice and telephony: Cartesia, Vapi (United States). Email delivery: Amazon Web Services (SES), Resend (United States). Payments: Stripe (United States). Business messaging integrations, where Customer connects them: Microsoft (Teams and Microsoft 365), Unipile (LinkedIn connectivity). Current list and changes: available on request from [email protected].