1. Parties, scope, and execution
This DPA is offered between Cyber Infrastructure LLC and the customer identified in an executed order or agreement. It applies only where CXRove processes personal data on the customer's behalf to provide the authorized service.
Publication does not execute this DPA. The applicable agreement or accepted electronic process must identify the parties, effective date, governing agreement, service scope, and exact version.
2. Controller and processor roles
The customer would be the controller or a processor acting for another controller. CXRove would be the processor or subprocessor for customer-directed communications, content, and related service data.
Each party may act as an independent controller for its own account, security, billing, legal, and business records where applicable law assigns that role. The final data map must distinguish those activities rather than treating every field the same.
3. Documented instructions and lawful processing
CXRove would process customer personal data only on documented instructions in the agreement, order, configured service, and lawful support requests, unless law requires otherwise. Where legally permitted, CXRove would inform the customer of a conflicting legal requirement.
The customer would ensure its instructions, data, notices, lawful basis, consents, and appointment of CXRove and subprocessors comply with applicable law. CXRove would notify the customer if it reasonably believes an instruction violates applicable data-protection law and may suspend the affected processing.
4. Processing details schedule
- Subject matter: providing the exact CXRove services named in the executed order and signed manifest.
- Duration: the service term plus the documented return, deletion, backup, dispute, security, and legal-retention periods approved for each category.
- Nature and purpose: hosting, routing, generating, storing, securing, supporting, metering, and deleting data under customer instructions.
- Data subjects: customer users, administrators, contacts, communication participants, support contacts, and other people represented in customer-directed content.
- Data categories: account identifiers, contact and communications metadata, customer content, call artifacts when enabled, technical and audit data, and any additional category expressly approved in the live data map.
- Sensitive data: not authorized by default; any approved category requires an exact purpose, access, security, retention, provider, and transfer schedule.
5. Confidentiality and personnel
CXRove would limit personal-data access to authorized people and subprocessors who need it for the approved service and are bound by confidentiality and applicable data-protection duties.
Access would follow least privilege, role review, removal, and audit requirements proved by the activated security schedule.
6. Security schedule — evidence required
The executed DPA would require technical and organizational measures appropriate to the proved risk. This source records intended control families, not a certification or claim that they are active.
- Organization and tenant access controls, authentication, MFA where required, least privilege, and separation of service identities.
- Secure transport, protected secret and key handling, environment separation, and approved encryption controls for stored data where supported by evidence.
- Audit, security event, rate-limit, abuse, and privileged-change evidence with secret-safe logging.
- Backup, restore, recovery, deletion, legal-hold, and change-management controls tied to exact release and data identities.
- Incident detection, containment, investigation, notification, remediation, and post-incident review.
- Provider, subprocessor, vulnerability, access, and control review proportionate to the activated service.
7. Subprocessors
The customer would grant general authorization for subprocessors listed in the activated register. CXRove would contractually require applicable confidentiality, security, processing, incident, deletion, and transfer duties and remain responsible for its DPA obligations.
This DPA requires notice of additions or replacements and a reasonable objection process as stated in the applicable agreement. A planned vendor in the public register is not an appointed subprocessor until executed terms and production evidence identify it as active.
8. Personal-data incidents
After confirming a personal-data breach affecting customer personal data, CXRove would notify the customer without undue delay and provide information reasonably available for the customer's obligations, subject to security, legal, and investigation limits.
CXRove will notify the customer without undue delay after confirming a personal-data breach affecting customer data, subject to lawful restrictions, and will provide information reasonably available for the customer's obligations. Notification is not an admission of fault.
9. Rights, assessments, and regulatory assistance
Taking account of the processing and available information, CXRove would provide reasonable assistance with data-subject requests, security duties, breach notifications, impact assessments, and regulator consultations that relate to the authorized service.
The customer would remain responsible for responding as controller and for giving CXRove the information and lawful instructions needed to assist.
10. Return and deletion
At the customer's documented choice and subject to the final agreement, CXRove would return or delete customer personal data after service ends, unless law requires retention. The activated schedule must state export formats, request timing, backup behavior, provider copies, derived artifacts, legal holds, and deletion evidence.
No deletion period is promised here because the production workflow and vendor-specific limits must be proved before activation.
11. Information and audits
CXRove would make information reasonably necessary to demonstrate its applicable processor duties available through current documentation, independent reports where they exist, and a bounded audit process.
The final process must protect other customers, confidential information, security, personnel, and systems; avoid duplicate or disruptive audits; address material findings; and not imply a certification that has not been obtained.
12. International-transfer modules
Where an activated transfer requires safeguards, the parties may execute the applicable European Commission Standard Contractual Clauses, UK Addendum, or another approved mechanism and complete the required parties, modules, categories, regions, subprocessors, and security annexes.
No transfer module is incorporated or signed merely by visiting this page. A placeholder, vendor claim, or generic global-service statement cannot authorize a restricted transfer.
13. Precedence, liability, and changes
For processing within scope, an executed DPA would control over conflicting general service terms, while executed transfer clauses would control where they require it. The governing agreement would control other matters, including approved liability allocation.
The activated DPA must state its exact version, effective date, approver, signatures, prior version, and change record. A new processing purpose, sensitive category, provider, region, or transfer requires renewed review and manifest evidence.
Change record
Published the standard DPA form with processor duties, security schedule, subprocessor terms, and execution-gated transfer modules.
This is the first published version; no prior operative version exists.