AxonOps Data Processing Addendum
Last updated: July 9, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between AxonOps Limited ("AxonOps", "we", "us", or "our") and the customer entity that has entered into an agreement with AxonOps ("Customer") for the use of AxonOps products, services, support, or professional services.
This DPA applies where AxonOps processes Personal Data on behalf of Customer in connection with the services. If there is a conflict between this DPA and the agreement, this DPA will take precedence to the extent the conflict relates to the processing of Personal Data.
1. Definitions
In this DPA, "Data Protection Laws" means all applicable laws and regulations relating to privacy, data protection, and the processing of Personal Data, including the UK GDPR, the EU GDPR, and the Data Protection Act 2018 where applicable.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "processing", and "process" have the meanings given to them under applicable Data Protection Laws. "Customer Personal Data" means Personal Data that AxonOps processes on behalf of Customer as a Processor or Subprocessor.
2. Roles of the Parties
Customer is the Controller of Customer Personal Data, or acts as Processor on behalf of a third-party Controller. AxonOps acts as Processor, or as Subprocessor where Customer acts as Processor, when processing Customer Personal Data under this DPA.
3. Scope and Instructions
AxonOps will process Customer Personal Data only to provide, secure, support, maintain, and improve the services, to comply with Customer's documented instructions, and as otherwise required by applicable law.
Customer's documented instructions include this DPA, the agreement, applicable order forms, support requests, account configuration, and any other written instructions agreed by the parties.
4. Customer Responsibilities
Customer is responsible for:
- ensuring that Customer has a lawful basis for processing Customer Personal Data;
- providing required notices and obtaining required consents from Data Subjects;
- ensuring that Customer Personal Data is accurate, relevant, and lawful to provide to AxonOps;
- managing Customer users, permissions, and access to the services; and
- not submitting special category data unless expressly agreed in writing with AxonOps.
5. AxonOps Processing Obligations
AxonOps will:
- process Customer Personal Data only in accordance with Customer's documented instructions;
- ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organisational measures to protect Customer Personal Data;
- assist Customer with Data Subject requests where required by Data Protection Laws and where Customer cannot reasonably fulfil the request without AxonOps' assistance;
- assist Customer with data protection impact assessments and regulatory consultations where required by Data Protection Laws; and
- delete or return Customer Personal Data in accordance with this DPA and the agreement.
6. Security Measures
AxonOps will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. These measures include access controls, encryption in transit, logging and monitoring, vulnerability management, incident response procedures, personnel confidentiality controls, and supplier management.
More information about AxonOps security practices is available on the AxonOps security overview.
7. Subprocessors
Customer authorises AxonOps to appoint Subprocessors to support delivery of the services. AxonOps will enter into written agreements with Subprocessors that impose data protection obligations no less protective than those required by this DPA, to the extent applicable to the nature of the services provided by each Subprocessor.
AxonOps maintains its current cloud Subprocessor list at AxonOps Cloud Platform Subprocessors. AxonOps will update that page when it adds or replaces a Subprocessor. Where required by the agreement or Data Protection Laws, AxonOps will provide notice of material Subprocessor changes and give Customer a reasonable opportunity to object on data protection grounds.
8. International Transfers
Where Customer Personal Data is transferred outside the United Kingdom, European Economic Area, or Switzerland, AxonOps will ensure that an appropriate transfer mechanism is in place, such as an adequacy decision, the Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism recognised by applicable Data Protection Laws.
9. Personal Data Breach
AxonOps will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. AxonOps will provide information reasonably available to it to help Customer meet any notification obligations under applicable Data Protection Laws.
10. Audit and Information Rights
AxonOps will make available information reasonably necessary to demonstrate compliance with this DPA. Where required by Data Protection Laws, Customer may request an audit on reasonable written notice. Any audit must be conducted during normal business hours, subject to confidentiality obligations, and in a way that does not unreasonably disrupt AxonOps' business, systems, or other customers.
11. Deletion and Return
On termination or expiry of the services, AxonOps will delete or return Customer Personal Data in accordance with the agreement, unless applicable law requires continued retention. Customer Personal Data held in backups will be deleted in accordance with AxonOps' backup retention processes.
12. Assistance and Contact
Customer may contact AxonOps about this DPA or privacy matters at [email protected].
Annex 1: Processing Details
| Subject matter | Provision, support, security, maintenance, and operation of AxonOps services. |
|---|---|
| Duration | The term of the agreement, plus any period required for deletion, return, backup retention, legal compliance, or dispute resolution. |
| Nature and purpose | Hosting, processing, transmitting, analysing, securing, troubleshooting, and supporting service data submitted to or generated by AxonOps services. |
| Categories of Data Subjects | Customer users, administrators, technical contacts, support contacts, billing contacts, and individuals whose Personal Data may be included in Customer-provided content. |
| Categories of Personal Data | Names, business contact details, account identifiers, authentication data, service usage data, logs, support communications, and Customer-provided content or metadata. |
| Special category data | Not intended for processing under the services unless expressly agreed in writing with AxonOps. |
Annex 2: Technical and Organisational Measures
- Access control: role-based access, least privilege access, and access review processes.
- Encryption: encryption in transit for service communications where supported by the services.
- Confidentiality: confidentiality obligations for personnel with access to Customer Personal Data.
- Monitoring: logging, monitoring, and alerting for security and operational events.
- Vulnerability management: processes for identifying, assessing, and remediating security vulnerabilities.
- Incident response: procedures for investigating, escalating, and responding to security incidents.
- Availability: backup, recovery, and resilience measures appropriate to the services.
- Supplier management: due diligence and contractual controls for Subprocessors.
Annex 3: Subprocessors
The current list of AxonOps cloud Subprocessors is available at AxonOps Cloud Platform Subprocessors.