Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other agreement governing the use of the BillingHub service (the "Agreement") between Evax LLC, a Wyoming limited liability company, with its principal place of business at Cheyenne, Wyoming, United States ("Company", "BillingHub") and the customer using the Service ("Customer").
This DPA applies only to the extent Company processes Personal Data on behalf of Customer that is subject to Applicable Data Protection Laws.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor" and "supervisory authority" have the meanings given in the General Data Protection Regulation (EU) 2016/679 (GDPR).
"Applicable Data Protection Laws" means the GDPR and, where applicable, the UK GDPR.
2. Roles of the Parties
2.1 Customer as Controller. Customer is the Controller of Personal Data processed using the Service.
2.2 Company as Processor. Company acts as a Processor and processes Personal Data solely on documented instructions of Customer, including for the purposes of generating, storing, and delivering invoices and related billing communications.
2.3 Company does not process Customer Personal Data for its own purposes.
2.4 Company does not use Customer Personal Data to train, develop, or improve general-purpose artificial intelligence or machine learning models.
3. Description of Processing
The subject matter, duration, nature, and purpose of processing, as well as the types of Personal Data and categories of Data Subjects, are described in Schedule 1.
4. Processor Obligations
Company shall:
a) process Personal Data only in accordance with Customer's documented instructions;
b) ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations;
c) implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage;
d) notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data;
e) provide reasonable assistance to Customer, taking into account the nature of processing, to enable Customer to respond to requests from data subjects and supervisory authorities under Applicable Data Protection Laws;
f) provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, where required by Applicable Data Protection Laws.
5. Subprocessors
Customer grants Company a general authorization to engage subprocessors for the provision of the Service, including hosting providers, email delivery services, and infrastructure vendors.
A current list of subprocessors is available at https://billinghub.online/legal/subprocessors or upon request.
6. International Data Transfers
6.1 To the extent Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to countries not recognized as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses (EU 2021/914), which are incorporated into this DPA by reference, together with the applicable UK Addendum where required.
6.2 The applicable module shall be Module Two (Controller to Processor).
7. Deletion or Return of Personal Data
Upon termination of the Services, Company shall delete or return all Customer Personal Data in accordance with applicable law.
Unless otherwise agreed in writing, such deletion shall occur within 90 days following termination.
8. Audits and Compliance
Company shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA. Any audits shall be limited to documentation review and shall not include on-site inspections, unless required by law.
9. Scope Limitation
This DPA does not apply to personal data processed by Company as an independent controller, including account registration data, billing and payment information relating to Customer, usage metrics, security logs, and fraud prevention data.
10. Governing Law
This DPA shall be governed by and construed in accordance with the governing law specified in the Agreement.
Schedule 1 — Processing Details
Subject Matter: Generation, storage, and delivery of billing invoices and related transactional communications.
Duration: For the term of the Agreement.
Purpose of Processing: Providing the Service to Customer.
Types of Personal Data: Names, email addresses, postal addresses, invoice details, payment references, and other data submitted by Customer through the Service.
Categories of Data Subjects: Customer's customers, end users, or business contacts.