Legal / 05
Data Processing Addendum
Last updated · August 16, 2026
This addendum applies where Subject XYZ LLC, a California limited liability company (“Boxic”, “we”) processes personal data on behalf of a customer organisation (“Customer”, “you”) in the course of providing the Service. It forms part of the Terms of Service. Where the two conflict on data protection, this addendum controls.
1. Roles
For project content and workspace member data that you upload or generate, you are the controller and Boxic is the processor. For account registration, billing, and product operation data, Boxic acts as a controller as described in the Privacy Policy.
2. Scope and instructions
We process personal data only to provide, secure, and support the Service, and on your documented instructions — which include your use of the product's features. We will tell you if we believe an instruction conflicts with applicable law.
3. Categories
- Data subjects: your personnel, collaborators, and invited guests.
- Data: names, email addresses, profile images, project content, comments, team messages, activity records, and technical logs.
4. Confidentiality and security
Personnel with access are bound by confidentiality obligations. We apply the technical and organisational measures described on our Security page, including encryption in transit, row-level access controls scoped to project membership, and least-privilege administrative access.
5. Sub-processing
You authorise the sub-processors listed on our Sub-processors page. We remain responsible for their performance and will update that page before adding a new sub-processor for the Service.
6. Data subject requests
The product lets you access, correct, export, and delete project and account data directly. Where you need our help to answer a data subject request, contact us and we will assist within a reasonable period.
7. Incidents
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information available to us at that time and updates as the investigation progresses.
8. International transfers
Data is processed in the United States and other locations where our providers operate. Where transfers from the EEA, UK, or Switzerland require a transfer mechanism, the parties rely on the European Commission's Standard Contractual Clauses, incorporated here by reference, with this addendum supplying the required details.
9. Deletion and return
On termination, or on your request, we delete your project and account data within 30 days, except where retention is required by law. Backups age out on their normal cycle.
10. Audit
On reasonable written request, and no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this addendum. We do not currently hold third-party security certifications and make no claim to any.
11. Signing
Need a counter-signed copy for your procurement process? Email hello@boxic.io with your entity name and we'll return an executed version.