Data Processing Addendum

Sales Axis. Last updated 2026-10-09.

This is a starting point, not legal advice. Have a lawyer review it before you offer it to a customer.

Roles

The customer is the controller of personal data they submit. Sales Axis is the processor, and acts on their documented instructions.

Subprocessors

We use the third parties listed on our subprocessors page. We will give notice before adding a new one.

Where data is kept

Application data is stored in the United States. Some subprocessors operate elsewhere; the subprocessors page says which, and what data each one handles.

Retention

Backups let the database be restored to any point in the last 7 days, after which earlier states are gone. Activity logs are kept for 7 days.

Security

Data is encrypted in transit and at rest. Access is limited to people who need it, and changes are written to an append-only audit trail.

Breach notification

We will notify the customer without undue delay after becoming aware of a personal data breach affecting their data.

Deletion and return

On request or on termination, we will delete or return personal data, except where we are required to keep it.