top of page

Data Processing Agreement

Last updated: July 7, 2026

This Data Processing Agreement ("DPA") forms part of the AxoTrax, Inc. Terms of Service (the "Agreement") and applies to all customers of the TermTrax service ("Services"). It governs AxoTrax's processing of Customer Personal Data on the customer's behalf. No signature is required — by using the Services under the Agreement, both parties are bound by this DPA. A countersigned copy for your records is available on request (hello@axotrax.com).
 

1. Roles and Definitions

  • You (the customer) are the data controller: you decide what data goes into the Services and why.

  • AxoTrax, Inc. is the data processor: we process Customer Personal Data only to provide the Services to you.

  • "Customer Personal Data" means personal data contained in Customer Data (as defined in the Agreement) that AxoTrax processes on your behalf.

  • "Data Protection Laws" means the laws applicable to the processing of Customer Personal Data under this DPA, which may include the GDPR, UK GDPR, and US state privacy laws (e.g., CCPA/CPRA), in each case as applicable to the parties.
     

2. Scope of Processing

  • Nature and purpose: Hosting, storage, analysis, and display of data submitted to the Services; providing, securing, and supporting the Services

  • Categories of data: User account data (names, work email addresses, authentication records); personal data incidentally contained in review context, comments, and edits; usage and log data

  • Data subjects: The customer's authorized users; individuals incidentally referenced in submitted content

  • Duration: The term of the Agreement, plus the deletion schedule in Section 6

Note: the primary documents TermTrax analyzes are software vendors' published legal terms — public materials. The Services do not require submission of the customer's executed contracts, client files, or privileged communications.
 

3. Processor Obligations

AxoTrax will:

  1. Process Customer Personal Data only on your documented instructions (the Agreement, this DPA, and your configuration and use of the Services constitute those instructions), unless required otherwise by law — in which case we will inform you unless the law prohibits it.

  2. Ensure that personnel and contractors authorized to process Customer Personal Data are bound by confidentiality obligations.

  3. Implement and maintain the technical and organizational measures described in Section 4.

  4. Not train AI models on identifiable Customer Personal Data or on your confidential content (playbooks, edits, comments, intake context). De-identified usage signals and publicly available vendor documents may be used to improve the Services.

  5. Taking into account the nature of the processing, assist you with reasonable requests relating to data subject rights (access, correction, deletion, portability) under applicable Data Protection Laws.

  6. Notify you without undue delay, and in any case within 72 hours of becoming aware, of a personal data breach affecting Customer Personal Data, with the information reasonably available to us at the time. 

  7. Make available information reasonably necessary to demonstrate compliance with this DPA, and respond to reasonable written security inquiries and questionnaires (send to security@axotrax.com). This written-response process satisfies audit-related obligations to the extent permitted by applicable law.
     

4. Security Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256)

  • Logical tenant isolation with tenant-scoped access enforcement on every query

  • Role-based access control; two-factor authentication available and tenant-enforceable; passwords hashed and salted

  • Login rate-limiting, failed-attempt lockout, and audit logging of administrative actions

  • Encrypted backups; dependency scanning and a regular patching cadence

  • Access to Customer Personal Data limited to personnel with a need to know

​​

5. Subprocessors

You provide general authorization for the following subprocessors:

  • Anthropic: Document Discovery and AI analysis (API; does not train on API data)

  • Amazon Web Services (USA): Hosting, storage, and backups

  • Twilio SendGrid: Transactional email delivery

  • Google: Business email and support communications (Google Workspace); sign-in (Google OAuth)

  • Stripe: Payment processing

We will maintain the current list on our Security Page and notify tenant administrators by email before adding a subprocessor that will process Customer Personal Data. If you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected Services and receive a pro-rata refund of prepaid fees.

Each subprocessor is bound by data protection obligations materially consistent with this DPA. AxoTrax remains responsible for its subprocessors' performance.
 

6. Deletion and Return

  • Customer Personal Data is retained while your account is active.

  • Upon a valid deletion request, or termination of the Agreement, Customer Personal Data is deleted from production systems within 30 days; backup copies cycle out in the normal course of operations and in no case persist beyond 365 days.

  • Before deletion, you may export your data using the Services' export features.

  • We may retain data where required by law, and de-identified or anonymized data as described in the Agreement.

​​

7. International Transfers

Customer Personal Data is processed in the United States. Where Data Protection Laws require a transfer mechanism for data originating from the EEA, UK, or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (processor module) by reference, with this DPA's terms supplying the required annexes.

​

8. General

  • Liability: each party's liability under this DPA is subject to the limitations of liability in the Agreement.

  • Term: this DPA applies for as long as AxoTrax processes Customer Personal Data under the Agreement.

  • Conflict: if this DPA conflicts with the Agreement regarding the processing of Customer Personal Data, this DPA controls.

  • Changes: we may update this DPA to reflect changes in law or the Services; material changes will be posted on this page with an updated date, and continued use constitutes acceptance. Updates will not reduce the protections in Sections 3–6 without notice.

  • Governing law and disputes: as set out in the Agreement (Michigan law; AAA arbitration).
     

Questions: hello@axotrax.com · Security: security@axotrax.com · Privacy rights requests: privacy@axotrax.com
 

bottom of page