Version: 1.1 · Effective date: September 2026
Pursuant to Article 28 of Regulation (EU) 2016/679
1. Parties and Scope
This Data Processing Addendum (the “DPA”) forms part of the Claix General Terms and Conditions of Use (the “Terms”) and applies where Claix processes Personal Data on behalf of a Customer in connection with the Claix Platform, Dashboard, API, document-processing services, AI Features, document-context features, Knowledge Spaces, Claix Managed AI, Bring Your Own Key (“BYOK”), and related services.
This DPA is entered into between:
1.1 Controller
The natural or legal person, company, developer, agency, organization, or B2B entity that contracts for or uses Claix services under the Terms (the “Controller” or “Customer”).
Where the Customer processes Personal Data on behalf of another controller, the Customer may act as a processor and Claix may act as a subprocessor. In that case, the Customer represents and warrants that it has authority to appoint Claix as a subprocessor and bind the relevant controller to this DPA as applicable.
1.2 Processor
ANAYA CARBALLO GAEL Trading as: Claix Tax ID (NIF): 51030923H Address: Ronda Sur 203, 3º 3ª Der, 28053 Madrid, Spain Privacy and Processor contact: info@claix.dev
Claix is referred to in this DPA as the “Processor” or “Claix”.
1.3 Definitions
Capitalized terms not defined in this DPA have the meanings given in the Terms, the Privacy Policy, or the GDPR.
For the purposes of this DPA:
- “AI Features” means Claix capabilities that use AI-assisted processing, including structured extraction, semantic mapping, Agent Mode, Document Context, Knowledge Spaces, and related functions.
- “BYOK” means Bring Your Own Key, an optional Claix feature through which the Customer selects a third-party AI provider and provides a credential for that provider.
- “BYOK Credential” means an API key, token, deployment credential, or similar credential supplied by the Customer for a supported third-party AI provider.
- “BYOK Provider” means the third-party AI provider selected by the Customer through BYOK.
- “Claix Managed AI” means the AI-processing mode in which Claix selects and manages the applicable AI provider and model configuration.
- “Customer Content” means any file, document, spreadsheet, image, text, prompt, question, HTML, XML, JSON, schema, agent definition, metadata, instruction, input, or Output submitted by or on behalf of the Customer through the Claix Platform, Dashboard, API, integrations, AI Features, or BYOK workflows.
- “Document Context” means the optional Claix feature through which processed document content may be retained temporarily or persistently and queried later by the Customer.
- “Knowledge Space” means the optional Claix feature through which related documents or Customer Content may be grouped and queried together.
- “Output” means any result generated or returned by the Service, including structured JSON, spreadsheet files, extracted information, Agent Mode results, document-context responses, Knowledge Space responses, or other generated content.
- “Personal Data” means personal data as defined in Article 4(1) GDPR processed by Claix on behalf of the Customer.
- “Processing” means processing as defined in Article 4(2) GDPR.
- “Subprocessor” means a third party engaged by Claix to process Personal Data on behalf of the Customer in connection with the Service.
2. Subject Matter, Duration, Nature, and Purpose
2.1 Subject Matter
The subject matter of Processing is the provision of the Claix Service, including document processing, structured data extraction, transformation, standardization, semantic mapping, Agent Mode, Document Context, Knowledge Spaces, Claix Managed AI, BYOK functionality, secure credential handling, account administration, security, support, and related SaaS and API operations.
2.2 Duration
Claix will process Personal Data for the duration of the Customer’s use of the Service and for any additional period required by the Customer’s selected retention settings, applicable law, security requirements, backup procedures, dispute-resolution requirements, or legal obligations.
2.3 Nature of Processing
Processing may include receiving, collecting, accessing, recording, organizing, structuring, storing where selected by the Customer, retrieving, consulting, transmitting, transforming, extracting, analyzing, mapping, normalizing, classifying, generating, restricting, deleting, and otherwise processing Customer Content as necessary to provide the Service.
2.4 Purpose of Processing
Claix processes Personal Data only to provide the Service to the Customer, including:
- receiving and processing Customer-initiated API and Dashboard requests;
- extracting, transforming, mapping, structuring, normalizing, classifying, or generating Output from Customer Content;
- processing PDFs, spreadsheets, CSV files, text documents, images, plain text, HTML, XML, JSON, and other supported content;
- providing schema-based structured outputs;
- providing Agent Mode processing;
- providing Document Context and Knowledge Space features where enabled by the Customer;
- providing Claix Managed AI or BYOK processing selected by the Customer;
- authenticating users, API Keys, workspaces, and account access;
- securely storing and using BYOK Credentials when enabled by the Customer;
- maintaining Service security, reliability, performance, logging, troubleshooting, support, abuse prevention, and incident response;
- complying with applicable legal obligations; and
- carrying out other documented instructions from the Customer that are consistent with the Terms, this DPA, and Applicable Data Protection Law.
2.5 Data Subjects and Data Categories
The categories of data subjects and Personal Data that may be processed are described in Annex A.
3. Documented Instructions
3.1 Customer Instructions
Claix shall process Personal Data only on the documented instructions of the Customer, including instructions contained in:
- the Terms;
- this DPA;
- authenticated API requests;
- Dashboard actions;
- Schema settings;
- Agent Mode settings;
- Document Context settings;
- Knowledge Space settings;
- retention settings;
- Claix Managed AI settings;
- BYOK provider, model, and credential settings;
- supported integrations; and
- other written instructions agreed between Claix and the Customer.
The Customer instructs Claix to process Personal Data as necessary to provide the Service features that the Customer selects, enables, configures, or invokes.
3.2 Instructions That May Infringe Applicable Law
If Claix considers that an instruction infringes Applicable Data Protection Law, Claix shall inform the Customer without undue delay unless prohibited by applicable law.
Claix may suspend or refuse to carry out an instruction where reasonably necessary to comply with Applicable Data Protection Law, protect data subjects, protect the Service, prevent security harm, or comply with a lawful authority request.
3.3 Customer Responsibilities
The Customer represents and warrants that:
- it has a valid legal basis to process Personal Data and submit it to Claix;
- it has provided required privacy notices to affected individuals;
- it has obtained any required consents, authorizations, permissions, or approvals;
- it has complied with Articles 6 and, where applicable, 9 GDPR;
- it has authority to instruct Claix and authorize relevant Subprocessors;
- it will use the Service in compliance with Applicable Data Protection Law;
- it will configure retention, Document Context, Knowledge Spaces, Claix Managed AI, and BYOK appropriately for its use case;
- it will not submit Personal Data that is unlawful, unnecessary, or prohibited by law;
- it will independently validate Outputs before using them in consequential workflows; and
- it will maintain appropriate human review and safeguards for high-impact, regulated, legal, financial, employment, healthcare, insurance, safety, or similar decisions.
4. Confidentiality
Claix shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Access to Personal Data shall be limited to authorized personnel and Subprocessors who have a legitimate need to access it for the purpose of providing, securing, maintaining, supporting, troubleshooting, or improving the Service in accordance with this DPA and the Terms.
5. Technical and Organizational Measures
5.1 Appropriate Security Measures
Claix shall implement and maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk, taking into account:
- the state of the art;
- implementation costs;
- the nature, scope, context, and purposes of Processing;
- the categories of Personal Data processed; and
- the risk to the rights and freedoms of natural persons.
The measures currently implemented by Claix are described in Annex B.
5.2 Security Improvements
Claix may modify, replace, or update its technical and organizational measures from time to time, provided that such modifications do not materially reduce the overall level of protection for Personal Data processed through the Service.
6. Subprocessors
6.1 General Authorization
The Customer grants Claix general authorization to engage Subprocessors to process Personal Data in connection with the Service, provided that Claix complies with this Section 6.
The current categories of authorized Subprocessors are listed in Annex C. Claix may also publish a current subprocessor list at:
[https://claix.dev/legal/subprocessors](https://claix.dev/legal/subprocessors)6.2 Subprocessor Obligations
Claix shall enter into a written agreement with each Subprocessor that imposes data-protection obligations no less protective than those imposed on Claix by this DPA, to the extent required by Applicable Data Protection Law.
Claix remains responsible for its Subprocessors’ compliance with data-protection obligations to the extent required by Applicable Data Protection Law.
6.3 Notice of Subprocessor Changes
Claix shall notify the Customer of any intended addition or replacement of a Subprocessor at least fifteen (15) calendar days before the change takes effect.
The Customer may object to the proposed change on reasonable data-protection grounds by notifying Claix in writing within the notice period.
The parties shall work in good faith to resolve the objection. If the objection cannot be resolved and the proposed Subprocessor is reasonably necessary for Claix to provide the Service, the Customer may terminate the affected Service feature or its account without penalty before the Subprocessor change takes effect.
Claix may provide less than fifteen (15) days’ notice where a shorter period is reasonably necessary to address urgent security, legal, operational, or service-continuity requirements. In such case, Claix will provide notice as soon as reasonably practicable.
6.4 Claix Managed AI Providers
When Claix Managed AI is selected, Claix may use one or more AI inference providers as Subprocessors to process Customer Content necessary to provide the selected AI Feature.
The current primary Managed AI provider is Google Gemini.
Claix may maintain and use alternative AI inference providers, including OpenAI and Anthropic, for service resilience, continuity, provider outage handling, or material service availability issues.
Where an alternative provider may process Personal Data in connection with Claix Managed AI, that provider shall be identified in Annex C, the current subprocessor list, or relevant customer-facing provider documentation.
6.5 BYOK Providers
When the Customer enables BYOK, the Customer instructs Claix to transmit Customer Content necessary to perform the requested AI-processing operation to the BYOK Provider selected by the Customer, using the Customer-provided BYOK Credential.
The Customer acknowledges that the BYOK Provider is selected by the Customer and is generally governed by the Customer’s direct relationship, account configuration, selected product tier, regional settings, and contractual terms with that provider.
The Customer is responsible for evaluating whether the selected BYOK Provider is appropriate for the Customer’s Personal Data, including the provider’s:
- data-processing location;
- international-transfer safeguards;
- retention practices;
- security measures;
- training and evaluation practices;
- data-use policies;
- availability;
- pricing;
- quotas;
- rate limits; and
- applicable legal and regulatory requirements.
To the extent Claix acts as a Processor in transmitting Personal Data to a BYOK Provider under the Customer’s instruction, the Customer authorizes that transmission as a documented instruction under Section 3 of this DPA.
7. Assistance to the Customer
7.1 Data Subject Rights
Taking into account the nature of Processing, Claix shall provide reasonable assistance to the Customer, through appropriate technical and organizational measures where possible, to enable the Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Law.
Where Claix receives a data-subject request directly relating to Personal Data processed on behalf of the Customer, Claix shall, where legally permitted and reasonably practicable, notify or redirect the request to the Customer without undue delay.
Claix shall not respond directly to the request except where required by law or authorized by the Customer.
7.2 Security, DPIAs, and Consultations
Taking into account the nature of Processing and the information available to Claix, Claix shall provide reasonable assistance to the Customer with the Customer’s obligations under:
- Article 32 GDPR, concerning security of processing;
- Article 33 GDPR, concerning notification of Personal Data Breaches to supervisory authorities;
- Article 34 GDPR, concerning communication of Personal Data Breaches to data subjects;
- Article 35 GDPR, concerning Data Protection Impact Assessments; and
- Article 36 GDPR, concerning prior consultation with supervisory authorities.
Where such assistance requires substantial time, costs, or resources beyond the ordinary scope of the Service, Claix may charge reasonable fees after providing notice where reasonably practicable.
8. Personal Data Breaches
Claix shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Customer.
Where reasonably practicable, Claix aims to provide initial notification within forty-eight (48) hours after confirming that:
- a Personal Data Breach has occurred; and
- the breach affects Personal Data processed on behalf of the Customer.
The notification shall include information reasonably available to Claix, including:
- the nature of the Personal Data Breach;
- the categories and approximate number of affected data subjects, where known;
- the categories and approximate number of affected Personal Data records, where known;
- the likely consequences of the breach, where known;
- measures taken or proposed to address the breach and mitigate possible adverse effects; and
- a contact point for further information.
Claix may provide information in phases where it cannot reasonably be provided at the same time.
9. International Data Transfers
9.1 General
Claix seeks to operate relevant core application infrastructure within the European Economic Area where possible.
However, Personal Data may be processed, accessed, or transferred outside the EEA where necessary to provide the Service, including through Claix Managed AI providers, BYOK Providers, cloud infrastructure providers, support providers, transactional email providers, payment providers, monitoring providers, or other Subprocessors.
9.2 Transfer Mechanisms
Where Claix transfers Personal Data subject to the GDPR outside the EEA to a country that is not subject to an adequacy decision, Claix shall ensure that the transfer is made in accordance with Chapter V GDPR and shall use an appropriate transfer mechanism, including, where applicable:
- a European Commission adequacy decision;
- the European Commission’s Standard Contractual Clauses;
- the EU–U.S. Data Privacy Framework, where applicable;
- Binding Corporate Rules; or
- another lawful transfer mechanism under Applicable Data Protection Law.
9.3 Claix Managed AI Transfers
When Claix Managed AI is used, Claix may transmit Customer Content necessary to provide the requested AI Feature to the applicable Claix Managed AI provider.
Claix currently uses Google Gemini as the primary AI inference provider for Claix Managed AI.
Claix may use OpenAI or Anthropic as alternative providers for service resilience, continuity, outage handling, or material availability issues, where applicable and identified in the current subprocessor information.
The processing location, transfer mechanism, data-processing terms, retention, and other provider-level practices are governed by the applicable provider service, configuration, and contractual terms.
9.4 BYOK Transfers
When the Customer chooses a BYOK Provider, the Customer instructs Claix to transmit Customer Content to that provider as necessary to provide the requested BYOK feature.
The Customer is responsible for determining whether its selected BYOK Provider, model, deployment, region, and provider account configuration are compatible with the Customer’s privacy, transfer, localization, confidentiality, regulatory, contractual, and compliance obligations.
Claix does not represent that every BYOK Provider offers the same processing location, international-transfer safeguards, retention settings, training policies, security posture, or data-use practices as Claix Managed AI.
10. Retention, Deletion, and Return of Personal Data
10.1 Processing Without Document or Context Persistence
Where the Customer does not enable temporary or persistent document/context retention, Claix processes Customer Content only for the duration necessary to complete the Customer’s requested operation.
In this configuration, Claix does not intentionally create a persistent document or context record containing Customer Content after the requested processing operation is complete.
This does not mean that every technical trace is removed instantly from all systems. Limited operational metadata, security information, error data, logs, backups, billing data, legal records, and provider-level records may be retained for limited periods where necessary for security, abuse prevention, incident response, debugging, service reliability, backup, legal obligations, dispute resolution, or compliance.
10.2 Temporary and Persistent Document Context
Where the Customer enables temporary Document Context, Claix may retain the applicable Customer Content and associated metadata for the duration selected by the Customer.
Where the Customer enables persistent Document Context, Knowledge Spaces, or another persistent retention feature, Claix may retain Customer Content and associated metadata until:
- the configured expiration date;
- deletion by the Customer;
- disabling or modification of the relevant retention setting;
- account closure;
- a valid deletion request; or
- another applicable deletion event.
Retention remains subject to lawful security, backup, incident-response, legal, and compliance exceptions.
10.3 Return or Deletion at Termination
Upon termination of the Service, and at the Customer’s election where technically feasible, Claix shall delete or return Personal Data processed on behalf of the Customer, unless continued storage is required by Applicable Data Protection Law.
The Customer is responsible for exporting or retrieving any Customer Content or Output it wishes to retain before termination or account closure.
10.4 Retention Exceptions
Notwithstanding this Section 10, Claix may retain limited Personal Data, metadata, account records, billing records, contractual records, security information, logs, backups, and other information where necessary for:
- legal, accounting, tax, regulatory, or record-keeping obligations;
- security, fraud prevention, abuse prevention, or incident response;
- dispute resolution;
- enforcement of the Terms;
- backup and disaster-recovery procedures; or
- other legitimate and lawful business purposes.
Any retained information remains subject to appropriate confidentiality and security protections and shall not be used for purposes incompatible with this DPA.
10.5 BYOK Credentials
BYOK Credentials are retained in encrypted form only while the relevant BYOK connection remains active or until the Customer replaces, disables, deletes, or requests deletion of the connection.
Limited technical, security, backup, legal, and audit-related records may remain for the period reasonably necessary for those purposes.
Claix does not intentionally retain the full plaintext value of a BYOK Credential in ordinary account records, Dashboard views, or ordinary API responses.
11. Audits and Demonstration of Compliance
11.1 Information Rights
Claix shall make available to the Customer information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and this DPA.
Such information may include:
- relevant Documentation;
- privacy and security information;
- a summary of technical and organizational measures;
- current Subprocessor information;
- applicable provider documentation;
- available third-party audit reports or certifications; and
- written responses to reasonable data-protection questionnaires.
11.2 Audit Rights
The Customer may audit Claix’s compliance with this DPA no more than once per twelve (12)-month period, unless:
- required by a competent supervisory authority;
- a confirmed Personal Data Breach affects the Customer’s Personal Data; or
- the Customer has a material and credible indication of Claix’s non-compliance with this DPA.
An audit must:
- be requested with at least thirty (30) calendar days’ prior written notice;
- be conducted during normal business hours;
- be carried out in a manner that does not unreasonably interfere with Claix operations, security, confidentiality, or other customers;
- be conducted by the Customer or an independent auditor bound by written confidentiality obligations;
- avoid access to other customers’ information, Claix trade secrets, source code, security-sensitive systems, full BYOK Credentials, or information that could compromise the security of the Service; and
- be limited to information reasonably necessary to assess compliance with this DPA.
Where reasonable, Claix may satisfy an audit request through Documentation, written responses, independent audit reports, certifications, security summaries, or other evidence before permitting a remote or on-site audit.
The Customer shall bear its own audit costs and reimburse Claix for reasonable costs incurred in supporting an audit, unless the audit demonstrates a material breach of this DPA by Claix.
12. No Training on Customer Content
Claix does not use Personal Data contained in Customer Content to train or retrain Claix models.
Claix does not use Customer Content, including files, documents, prompts, payloads, schema content, questions, document context, or Outputs, as a dataset for training, fine-tuning, or evaluating Claix models.
For Claix Managed AI, Claix currently uses Google Gemini as its primary AI inference provider. Claix uses a paid Google Gemini service configuration under which Google does not use Customer Content, including prompts, payloads, documents, or Outputs submitted through Claix Managed AI, to train or improve Google’s generative AI models.
Claix may use alternative AI providers, including OpenAI and Anthropic, solely for service resilience, continuity, outage handling, or material availability issues where such providers are identified in the current subprocessor list or applicable customer documentation.
Where an alternative provider is used, Claix will use a service configuration intended not to use Customer Content for training or improving that provider’s general-purpose AI models.
When Customer Content is processed through BYOK, the processing, retention, training, evaluation, and data-use practices of the BYOK Provider are governed by the Customer’s direct agreement, selected product tier, account configuration, and settings with that provider.
The Customer is responsible for reviewing the BYOK Provider’s applicable terms and settings before submitting Personal Data through BYOK.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms, except to the extent such limitations are prohibited by Applicable Data Protection Law.
Nothing in this DPA limits a data subject’s rights under Applicable Data Protection Law, including Article 82 GDPR.
14. Term and Termination
This DPA takes effect when the Customer accepts the Terms, creates an account, uses the Service, submits Customer Content, enables Claix Managed AI or BYOK, or otherwise instructs Claix to process Personal Data.
This DPA remains in effect for as long as Claix processes Personal Data on behalf of the Customer.
Termination of the Terms automatically terminates this DPA, except that this DPA remains in effect for as long as Claix retains Personal Data in accordance with Section 10.
15. Order of Precedence
In the event of a conflict:
- a separately signed agreement between Claix and the Customer prevails to the extent it expressly states that it overrides this DPA;
- this DPA prevails with respect to the Processing of Personal Data;
- the Terms prevail with respect to all other matters; and
- the Privacy Policy and Documentation apply to the extent they do not conflict with the Terms or this DPA.
16. Governing Law and Jurisdiction
This DPA is governed by Spanish law and Applicable Data Protection Law.
To the extent permitted by Applicable Data Protection Law, the parties submit disputes arising from this DPA to the Courts and Tribunals of Madrid, Spain.
Annex A — Details of Processing
A. Controller
The Customer using the Claix Platform, Dashboard, API, Claix Managed AI, BYOK, Document Context, Knowledge Spaces, or related Services.
B. Processor
ANAYA CARBALLO GAEL, trading as Claix.
C. Subject Matter
Provision of document intelligence, document and content processing, structured data extraction, transformation, semantic mapping, Agent Mode, Document Context, Knowledge Spaces, Claix Managed AI, BYOK, and related SaaS/API services.
D. Duration
For the duration of the Customer’s use of the Service, plus any configured, technically necessary, contractually required, or legally required retention period.
Where no document or context persistence is enabled, Customer Content is processed for the duration necessary to complete the requested operation and is not intentionally retained as a persistent document/context record after processing, subject to limited operational, security, backup, legal, and provider-level retention described in this DPA, the Privacy Policy, and applicable provider terms.
E. Nature and Purpose of Processing
| Processing Activity | Nature and Purpose |
|---|---|
| API and Dashboard processing | Receive, authenticate, process, and return Customer-initiated Service requests |
| Document and content processing | Extract, transform, structure, normalize, classify, and generate Output from supported Customer Content |
| Schema-based processing | Produce requested fields, types, categories, and structured outputs based on Customer configuration |
| AI Features | Perform semantic mapping, Agent Mode evaluations, Document Context responses, and Knowledge Space responses |
| Document Context | Retain and query document content when enabled by the Customer |
| Knowledge Spaces | Group and query related documents or content when enabled by the Customer |
| Claix Managed AI | Send necessary Customer Content to Claix-selected AI providers to perform requested Service features |
| BYOK | Send necessary Customer Content to the Customer-selected AI provider using the Customer-provided credential |
| BYOK Credential handling | Securely store, access, validate, use, replace, disable, and delete Customer-provided AI-provider credentials |
| Security and operations | Authenticate access, prevent abuse, monitor the Service, troubleshoot, maintain reliability, and respond to incidents |
| Support | Respond to Customer support requests where access is necessary, authorized, and proportionate |
F. Categories of Data Subjects
Depending on the Customer’s use of the Service, data subjects may include:
- Customer employees, administrators, contractors, and authorized users;
- customers, prospects, leads, suppliers, vendors, and business contacts;
- end users of the Customer’s product or service;
- applicants, employees, and former employees;
- representatives, signatories, counterparties, and beneficiaries;
- visitors, patients, students, policyholders, claimants, or other individuals whose information the Customer submits; and
- any other individuals whose Personal Data is included in Customer Content.
G. Categories of Personal Data
Depending on the Customer’s use of the Service, Personal Data may include:
- identity and contact information;
- professional and employment information;
- business and commercial information;
- account, contract, purchase, invoice, payment, transaction, and tax-related information;
- communications and correspondence;
- documents, images, forms, reports, notes, and files;
- technical and usage data;
- authentication and account metadata;
- Customer-defined Schema fields;
- information contained in prompts, text, HTML, XML, JSON, and document-context questions; and
- Outputs generated from Customer Content.
H. Special Categories and Sensitive Data
The Service is not designed specifically for the processing of:
- special categories of Personal Data under Article 9 GDPR;
- criminal-offence data under Article 10 GDPR;
- payment-card data;
- authentication secrets;
- credentials;
- highly sensitive confidential information; or
- other highly regulated information.
If the Customer chooses to submit such information, the Customer is responsible for ensuring it has an appropriate legal basis, has completed any required assessment, has configured the Service appropriately, and has implemented all required safeguards.
The Customer should not submit special-category or highly sensitive Personal Data through BYOK unless it has independently assessed the selected BYOK Provider, including its contractual, technical, security, retention, training, and transfer settings.
I. Processing Frequency
Processing may occur continuously, intermittently, or on an ad hoc basis depending on the Customer’s API requests, Dashboard actions, integrations, selected Service features, retention settings, and AI processing mode.
Annex B — Technical and Organizational Measures
Claix implements technical and organizational measures designed to protect Personal Data and Customer Content, taking into account the nature of the Service and risks associated with Processing.
1. Access Control and Authentication
Claix uses measures designed to control access to the Service, including:
- Dashboard and API authentication controls;
- confidential API Key management;
- role, account, workspace, and authorization checks where applicable;
- least-privilege principles for personnel access where appropriate;
- logging and monitoring of security-relevant authentication events;
- mechanisms designed to support credential rotation, revocation, replacement, disabling, and deletion; and
- controls designed to prevent unauthorized cross-tenant access.
2. Secure Transmission and Credential Protection
Claix uses measures designed to protect data during transmission and credential handling, including:
- encrypted transmission between Customers and Claix using HTTPS/TLS;
- encryption at rest where supported by the relevant infrastructure and configuration;
- secure handling of sensitive credentials;
- encrypted secret-management mechanisms for BYOK Credentials, including Supabase Vault where applicable; and
- masked display of credential hints instead of full BYOK Credentials in ordinary customer-facing interfaces.
3. Tenant Separation and Data Isolation
Claix uses measures designed to separate Customer data and access, including:
- logical separation of Customer accounts and workspaces;
- authorization checks designed to restrict Customer Content access to the relevant account or workspace;
- controlled execution environments for processing operations where applicable;
- authorization controls for Document Context, Knowledge Spaces, API requests, and Customer settings; and
- controls designed to prevent one Customer from accessing another Customer’s Customer Content, Outputs, API configuration, or BYOK settings.
4. Retention and Deletion Controls
Claix uses measures designed to support Customer-selected retention and deletion controls, including:
- configuration settings for temporary or persistent Document Context and Knowledge Space retention;
- deletion controls for retained documents and Knowledge Spaces;
- no intentional creation of a persistent document/context record where the Customer has not enabled such retention;
- procedures designed to support account closure, Customer Content deletion, and BYOK Credential deletion; and
- retention of limited operational, security, backup, legal, and compliance information only where necessary and permitted.
5. Security Monitoring and Incident Response
Claix uses measures designed to identify, investigate, and respond to security and reliability issues, including:
- logging and monitoring designed to identify security events, abuse, errors, and service reliability issues;
- rate limiting, input validation, and controls designed to reduce malicious requests and abuse;
- incident-response procedures;
- processes designed to investigate, contain, and remediate confirmed incidents; and
- notification procedures for Personal Data Breaches as described in this DPA.
6. Availability and Resilience
Claix uses measures designed to support Service availability and resilience, including:
- use of cloud and infrastructure providers designed to support availability and resilience;
- backup and recovery procedures where applicable;
- operational monitoring;
- maintenance procedures; and
- processes for service improvement and incident remediation.
7. BYOK-Specific Measures
Claix uses measures designed to protect BYOK Credentials, including:
- encrypted storage of BYOK Credentials through secure secret-management mechanisms where applicable;
- separation of BYOK configuration metadata from the underlying credential;
- use of BYOK Credentials only to execute Customer-initiated requests to the selected BYOK Provider;
- no intentional inclusion of full BYOK Credentials in ordinary API responses or Dashboard views;
- support for credential replacement, disabling, and deletion; and
- provider/model compatibility checks where applicable.
8. Personnel and Organizational Measures
Claix uses organizational measures designed to protect Personal Data, including:
- confidentiality obligations for authorized personnel;
- access limited to personnel with a legitimate business need;
- procedures for security, privacy, and support matters;
- review of security and operational measures; and
- use of Subprocessors subject to data-protection obligations where required by Applicable Data Protection Law.
Annex C — Authorized Subprocessors
The following Subprocessors or categories of Subprocessors may process Personal Data depending on the Customer’s selected configuration, Service features used, and current Claix infrastructure.
Not every Subprocessor processes every Customer’s Personal Data.
| Subprocessor / Category | Service Provided | When Processing May Occur | Location / Transfer Basis |
|---|---|---|---|
| Supabase | Database, authentication, Edge Functions, application infrastructure, and secure secret-management capabilities | Core Claix account, API, configuration, document-context, and application operations | EEA configuration where applicable; subject to Supabase terms and applicable transfer safeguards |
| Amazon Web Services | Underlying cloud infrastructure used by Supabase and/or other infrastructure providers where applicable | Supporting infrastructure operations | Depends on the applicable service and configured region; subject to provider terms and applicable transfer safeguards |
| Google / Gemini | AI inference for Claix Managed AI | When Customer uses Claix Managed AI and the applicable feature routes Customer Content to Google Gemini | Subject to applicable Google service configuration, provider terms, and lawful transfer mechanism where required |
| OpenAI | AI inference for Claix Managed AI contingency or other configured Managed AI path | Only when Claix Managed AI routes Customer Content to OpenAI for resilience, continuity, outage handling, or a configured service path | Subject to applicable OpenAI service configuration, provider terms, and lawful transfer mechanism where required |
| Anthropic | AI inference for Claix Managed AI contingency or other configured Managed AI path | Only when Claix Managed AI routes Customer Content to Anthropic for resilience, continuity, outage handling, or a configured service path | Subject to applicable Anthropic service configuration, provider terms, and lawful transfer mechanism where required |
| Claix-operated self-hosted n8n instance | Internal workflow automation for registration, account administration, billing, accounting, payment-related operations, transactional communications, service notifications, support operations, and other internal Claix operational processes | Only where Personal Data is necessary for a Claix-operated internal workflow; the self-hosted n8n instance is not part of the ordinary document-processing or AI inference path unless a specific Claix workflow requires it | Hosted in Frankfurt, Germany. The underlying hosting, database, storage, email, payment, and other third-party providers used by the relevant workflow are separately identified as applicable Subprocessors and are subject to their applicable data-processing terms and transfer safeguards |
| Customer-selected BYOK Provider | AI inference selected and configured by the Customer | Only when the Customer enables BYOK and initiates a request using that provider | Determined by the selected provider, Customer account configuration, provider terms, and applicable transfer safeguards |
| Payment processor | Payment, billing, invoicing, and subscription processing | Where the Customer purchases paid Claix services | Subject to selected payment processor terms and applicable transfer safeguards |
| Transactional email provider | Account communications, password resets, operational notices, API alerts, and support notifications | Where Claix sends email communications | Subject to selected provider terms and applicable transfer safeguards |
| Monitoring, security, and support providers | Security, observability, incident response, support, and Service operations | Only where necessary to operate, secure, support, and maintain the Service | Subject to applicable provider terms and transfer safeguards |
The then-current list of named Subprocessors, where published, is available at:
[https://claix.dev/legal/subprocessors](https://claix.dev/legal/subprocessors)Claix may update this list in accordance with Section 6.3 of this DPA.