Data Processing Agreement
How Axelize processes personal data on your behalf. Part of the Terms of Service for every business customer.
Last updated 2026-09-18
This Data Processing Agreement ("DPA") is between the customer that has accepted the Axelize Terms of Service ("Customer", "you") and Axelize ("Axelize"). It applies whenever Axelize processes personal data on your behalf. Where this DPA and the Terms conflict on data protection, this DPA wins. If you need a signed copy, email [email protected].
1. Definitions
"Data Protection Law" means every law that applies to the processing of personal data under this DPA, including the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act (CCPA). "Customer Data" means personal data you or your users submit to the Service or that the Service captures on your behalf, including meeting transcripts, CRM records, uploaded files and web page content. "Standard Contractual Clauses" or "SCCs" means the clauses adopted by the European Commission in Decision 2021/914. "Sub-processor" means a third party Axelize engages to process Customer Data. Other capitalised terms have the meaning given in Data Protection Law.
2. Roles
For Customer Data, you are the controller and Axelize is the processor. Where you act as a processor for someone else, you are the processor and Axelize is your sub-processor, and you warrant that your instructions are authorised by the controller. For account, billing and website data, Axelize is an independent controller and the Privacy Policy applies.
3. Your instructions
Axelize processes Customer Data only on your documented instructions. Using the Service, the Terms and this DPA are your instructions. You may give further written instructions where reasonable. Axelize will tell you if it believes an instruction breaches Data Protection Law. You are responsible for the lawfulness of the Customer Data you process, including any notice or consent that meeting participants must receive.
4. Axelize's obligations
- Confidentiality. Everyone Axelize authorises to process Customer Data is bound by confidentiality.
- Security. Axelize maintains the technical and organisational measures in Annex II and will not reduce their overall level of protection during the term.
- No training. Axelize does not use Customer Data to train or improve AI models and does not use one customer's data to serve another.
- Assistance. Axelize will help you respond to data subject requests and, taking into account the nature of the processing, help you meet your obligations on security, breach notification, impact assessments and consultation with authorities.
- Breach notification. Axelize will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Data, and will give you the information you need to meet your own notification duties.
- Records and audits. Axelize will keep the records Data Protection Law requires and will make available the information needed to demonstrate compliance. Once a year, or after a breach, you may audit Axelize's compliance, on 30 days' notice, during business hours, at your cost, and without disrupting the Service. Axelize may satisfy an audit by providing a recent third party assessment where one exists.
5. Sub-processors
You authorise Axelize to use the Sub-processors listed on the subprocessors page. Axelize imposes data protection terms on each Sub-processor that are no less protective than this DPA and remains responsible for their performance. Axelize will publish any new Sub-processor on that page at least 30 days before it processes Customer Data and will email workspace owners. If you object on reasonable data protection grounds within that period and Axelize cannot resolve the objection, you may terminate the affected Service and receive a pro rata refund of prepaid fees.
6. International transfers
Customer Data is stored in the European Economic Area. It may be accessed by Axelize from Georgia and processed by Sub-processors in the locations listed on the subprocessors page. Where a transfer of Customer Data from the EEA, the UK or Switzerland requires a safeguard under Data Protection Law, the parties agree as follows:
- The SCCs are incorporated into this DPA. Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) applies where you are a processor. You are the data exporter and Axelize is the data importer.
- Clause 7 (docking) is included; Clause 9 option 2 applies with the notice period in section 5; Clause 11 optional language is not included; Clause 13 applies according to the exporter's establishment; Clause 17 selects the law of Ireland; Clause 18 selects the courts of Ireland. Annexes I, II and III of the SCCs are the Annexes of this DPA.
- For transfers from the UK, the UK International Data Transfer Addendum to the SCCs, issued by the Information Commissioner under s.119A of the Data Protection Act 2018, is incorporated, with the Tables completed by reference to this DPA and its Annexes.
- For transfers from Switzerland, the SCCs apply with the adaptations required by the Federal Data Protection and Information Commissioner, including references to the Swiss Act and the Commissioner as competent authority.
If a transfer mechanism above is invalidated, the parties will cooperate in good faith to agree a replacement.
7. Data subject requests
If a data subject contacts Axelize directly about Customer Data, Axelize will refer them to you and will not respond on the substance except on your instruction or where the law requires. Where a participant on a call contacts Axelize, Axelize will tell you within five business days.
8. Deletion and return
During the term, you can delete Customer Data through the Service. At the end of the term you have 30 days to export Customer Data, after which Axelize deletes it, except where law requires retention. Copies in backups are overwritten within 30 days after that.
9. Liability and term
Liability under this DPA is subject to the limits in the Terms, except where the SCCs provide otherwise for data subjects. This DPA lasts as long as Axelize processes Customer Data.
10. United States state law addendum
Where Customer Data includes personal information of residents of a US state with a privacy law, Axelize acts as your service provider or processor and: (a) processes personal information only for the business purpose of providing the Service; (b) does not sell or share personal information; (c) does not retain, use or disclose personal information outside the direct business relationship or for any purpose other than providing the Service; (d) does not combine personal information from your workspace with personal information from other sources except as permitted; (e) will notify you if it can no longer meet its obligations; and (f) permits you to take reasonable steps to stop and remediate unauthorised use. Axelize certifies that it understands these restrictions.
Annex I. Description of processing
| Data exporter | The Customer, a business using Axelize for sales meetings. Contact: the workspace owner's account email. |
|---|---|
| Data importer | Axelize, Georgia. Contact: [email protected]. |
| Subject matter | Capturing Google Meet caption transcripts and generating AI suggestions for the Customer's sales conversations, plus the CRM records and materials the Customer attaches. |
| Duration | The term of the Terms of Service, plus the deletion period in section 8. |
| Nature and purpose | Storage, retrieval, text analysis by an AI model, and display to the Customer's users, for the purpose of assisting the Customer's users during and after sales meetings. |
| Data subjects | The Customer's users. Participants in the Customer's meetings. Contacts and employees of companies in the Customer's CRM. Authors named on web pages and documents the Customer attaches. |
| Personal data | Names as displayed by Google Meet and the words spoken, as captions. Contact details: names, email addresses, phone numbers, job titles, LinkedIn URLs. The Customer's notes. Content of uploaded files and web pages. Prompts and AI output. |
| Special categories | None intended. Transcripts may incidentally contain whatever participants say, and the Customer is responsible for limiting that where necessary. |
| Frequency | Continuous while the Service is in use. |
| Retention | Until deleted by the Customer, or at the end of the term as set out in section 8. |
| Competent supervisory authority | Determined under Clause 13 of the SCCs by the exporter's establishment or, where the exporter is outside the EEA, by the member state whose authority is competent for the exporter's representative or the data subjects concerned. |
Annex II. Technical and organisational measures
- Hosting. Customer Data is stored on dedicated infrastructure in Hetzner's Helsinki data centre, which holds ISO 27001 certification. Access to servers is over SSH, restricted to authorised Axelize personnel, behind the Hetzner Cloud Firewall.
- Encryption in transit. All traffic between users, the Service and Sub-processors uses TLS 1.2 or higher.
- Access control. Users authenticate with Google sign-in. Every request is scoped to the user's own workspace at the API layer. There is no shared or anonymous access to Customer Data.
- Minimisation. The extension reads only Google Meet caption text and only on meet.google.com. No audio, video, screen content or biometric data is captured.
- AI processing. Customer Data sent for inference goes to Google's Gemini API on paid terms under which Google does not use it to train models and deletes it after a limited abuse detection period.
- Backups. Databases are backed up nightly and retained for seven days.
- Secrets. Credentials are stored outside source control and rotated on suspected exposure.
- Deletion. Customers can delete meetings, transcripts, contacts, companies and files from the Service. Deletion removes the records from the live database and from object storage.
- Personnel. Everyone with access to Customer Data is bound by confidentiality and accesses it only to resolve a problem the Customer has reported.
- Incident response. Suspected incidents are triaged on receipt and affected Customers are notified as set out in section 4.
Annex III. Sub-processors
The current list, with purpose and location for each, is maintained at axelize.com/subprocessors and forms part of this DPA.