Legal
Data Processing Addendum
Last updated July 20, 2026
This addendum applies when DEIXIC processes personal data contained in customer content through the product at app.deixic.com. It supplements the agreement under which the customer uses Deixic. To execute a signed copy, email hello@deixic.com.
Parties and roles
The customer is the controller of personal data in its workspace. DEIXIC is the processor. Where the customer itself acts as a processor for a third party, DEIXIC acts as the customer’s subprocessor.
What processing this covers
DEIXIC hosts, stores, and displays customer data to operate the product: showing agent cost and status, running human approvals with recorded evidence, reading connected tools the customer authorizes, maintaining the activity trail, and answering questions in Dex chat against the same workspace data.
The personal data involved is what appears in account data for the customer’s users, agent and run metadata, evidence records, spend data, and data from connected tools. Data subjects are the customer’s users and the individuals whose information appears in the content those tools and runs touch. Processing lasts for the term of the agreement.
Instructions
DEIXIC processes customer personal data only on the customer’s documented instructions: the agreement, this addendum, and the configuration the customer sets in the product, including which tools are connected and which work is gated on approval. If DEIXIC believes an instruction violates applicable data protection law, it will tell the customer before proceeding.
Confidentiality
People authorized to process customer personal data are bound by confidentiality obligations, contractual or statutory, before they get access.
Security
DEIXIC restricts access to customer data to people who need it to operate the product, encrypts data in transit, and keeps an activity trail of agent actions and approval decisions that the customer can review. DEIXIC does not train models on customer content. A SOC 2 Type II audit is underway; see Trust for the controls customers can use directly.
Subprocessors
The customer authorizes the subprocessors listed at /subprocessors, which states what each one does. Changes to the list are posted on that page. DEIXIC imposes data protection obligations on subprocessors consistent with this addendum and remains responsible for their performance. A customer that objects to a change can raise it at security@deixic.com.
Model calls made under keys the customer brings go to the customer’s configured provider under the customer’s agreement with that provider; that traffic is outside this addendum’s subprocessor list.
Data subject requests
Taking into account the nature of the processing, DEIXIC assists the customer in responding to requests from individuals to access, correct, or delete their data. If DEIXIC receives such a request directly and can identify the customer, it forwards the request to the customer.
Breach notification
DEIXIC notifies the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, and shares what it knows about the scope, the data involved, and the remediation under way as that information becomes available.
Deletion and return
At termination of the agreement, DEIXIC deletes customer personal data or returns it to the customer, at the customer’s choice, except where law requires DEIXIC to retain a copy.
Audits
DEIXIC makes available information reasonably necessary to demonstrate compliance with this addendum, including summary security documentation and, once the audit completes, the SOC 2 Type II report under confidentiality terms.
International transfers
Where processing involves transfers of personal data across borders that require a transfer mechanism, the parties can execute standard contractual clauses; request them at hello@deixic.com.
Executing this addendum
This page is the current reference text and is a draft until signed. To execute a signed copy, email hello@deixic.com.