1. Overview
Many Business Users use Repaxio to process personal data of their own customers ("End Consumers"). In that context, the Business User is the data controller (or "Data Fiduciary" under India's DPDP Act) and FoundHex Inc. acts as a data processor on the Business User's behalf. Our Data Processing Addendum ("DPA") governs that relationship and supplements our Terms of Service and Privacy Policy.
2. What the DPA Covers
- Roles and scope: Controller/processor responsibilities and the subject matter, nature, and purpose of processing.
- Sub-processors: Authorization and our current list of sub-processors, plus notice of changes.
- Security measures: The technical and organizational measures described on our Security page.
- International transfers: Where applicable, EU/UK Standard Contractual Clauses and equivalent safeguards.
- Data subject requests: Assistance with access, correction, deletion, and portability requests.
- Breach notification: Our commitment to notify you of personal data breaches without undue delay.
- Return and deletion: Handling of personal data on termination, consistent with our retention schedule.
- Audit rights: Reasonable rights to verify our compliance.
3. Requesting a Signed DPA
A copy of our DPA is available to Business Users on request. To request or execute a DPA, email privacy@repaxio.com with the subject line "DPA Request," including your account and signatory details.
© 2026 FoundHex Inc. All rights reserved.