This Data Processing Addendum ("DPA") forms part of the agreement between Joltclick Limited trading as Volexi (company number 15175103, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, UK) ("Processor", "Volexi") and the customer identified in the applicable Terms of Service or order form ("Controller", "Customer") (together the "Agreement"), and applies to the extent Volexi processes Personal Data on the Customer's behalf.
"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and, where applicable, the EU GDPR. Terms such as "Personal Data", "processing", "controller", "processor", and "data subject" have the meanings in Data Protection Law.
1.1 The Customer is the controller (or, where the Customer is an agency acting for its own clients, a processor acting on its clients' behalf, in which case Volexi is a subprocessor) of Customer Personal Data — the Personal Data described in Annex 1 that the Customer submits to the Service.
1.2 Volexi processes Customer Personal Data only as a processor on the Customer's documented instructions, as set out in the Agreement, this DPA, and the Customer's configuration and use of the Service, unless required otherwise by law (in which case Volexi will inform the Customer unless legally prohibited).
1.3 This DPA does not apply to Personal Data for which Volexi is a controller (e.g. the Customer's own account users' registration data, billing, and product analytics), which is governed by the Volexi Privacy Policy.
1.4 The Customer warrants it has a lawful basis for, and has given any required notices in respect of, the Customer Personal Data it submits, and that its instructions comply with Data Protection Law.
Volexi will:
(a) process Customer Personal Data only for the purposes in Annex 1;
(b) ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations;
(c) implement and maintain the technical and organisational measures in Annex 2;
(d) engage subprocessors only as permitted by section 3;
(e) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in responding to data subject requests (access, rectification, erasure, restriction, portability, objection), including via the Service's built-in export and deletion features; if a data subject contacts Volexi directly about Customer Personal Data, Volexi will refer them to the Customer without undue delay;
(f) assist the Customer with its obligations under Articles 32–36 UK GDPR (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and information available to Volexi;
(g) notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing information reasonably required for the Customer's own notification obligations as it becomes available;
(h) at the Customer's choice, delete or return Customer Personal Data on termination of the Agreement in accordance with section 4; and
(i) make available information reasonably necessary to demonstrate compliance with this DPA and, subject to section 5, allow for audits.
3.1 The Customer gives general written authorisation for Volexi to engage the subprocessors listed in Volexi's Subprocessor List (current version attached as Annex 3).
3.2 Volexi will give at least 14 days' notice (by email or in-app) before adding or replacing a subprocessor that processes Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.
3.3 Volexi will impose data protection obligations on subprocessors materially equivalent to those in this DPA and remains liable for their performance.
3.4 Optional providers. Some subprocessors are engaged only when the Customer enables the corresponding feature (e.g. specific AI answer engines, CMS, analytics, or messaging integrations); connecting or enabling a feature constitutes an instruction to use the corresponding provider.
4.1 During the term, the Customer can export Customer Personal Data and content via the Service's export features (CSV, JSON, and document exports) and can permanently delete individual workspaces in-app (which deletes the associated Customer Personal Data, including uploaded files).
4.2 On termination or expiry, Volexi will, upon the Customer's written request, delete Customer Personal Data (including from file storage), except to the extent retention is required by law. Absent a deletion request, data remains stored subject to the Agreement so the Customer can retrieve it. Residual copies in encrypted backups are deleted in the ordinary course of backup expiry.
5.1 Volexi will make available, on written request no more than once per 12 months, information reasonably necessary to demonstrate compliance (including summaries of security measures, subprocessor terms, and relevant third-party attestations where held).
5.2 Where Article 28(3)(h) UK GDPR requires more, the Customer may conduct (itself or via an independent auditor bound by confidentiality) an audit on at least 30 days' notice, during business hours, no more than once per 12 months (except following a Personal Data Breach or where required by a supervisory authority), at the Customer's cost, and without access to other customers' data.
6.1 Customer Personal Data is stored at rest in the EU (Frankfurt, Germany). Certain subprocessors process data outside the UK/EEA as identified in the Subprocessor List.
6.2 Volexi will not transfer Customer Personal Data outside the UK/EEA without a valid transfer mechanism under Data Protection Law (adequacy regulations, the UK International Data Transfer Agreement/Addendum, or EU Standard Contractual Clauses with the UK Addendum, as applicable).
Liability under this DPA is subject to the exclusions and limitations in the Agreement. In case of conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA prevails.
Subject matter and duration: processing of Customer Personal Data to provide the Volexi service for the term of the Agreement (plus any retrieval/deletion period).
Nature and purpose: hosting and storage; monitoring of AI answer engines using Customer-configured prompts; analysis and report generation; content generation (briefs, articles, outreach drafts); operation of agency client portals and digest emails; delivery of drafts to Customer-connected systems; data export.
Categories of data subjects:
Categories of Personal Data: names, business email addresses, business context, communication drafts, portal usage timestamps (e.g. last login), OAuth tokens/credentials for Customer-connected systems (encrypted), and any personal data incidentally contained in uploaded documents or free-text fields. No special category data is intended to be processed, and the Customer agrees not to submit it.
Processing operations: collection, storage, retrieval, analysis (including via the AI providers in the Subprocessor List), generation of derived content, transmission to Customer-connected systems and recipients configured by the Customer, deletion.
See the Volexi Subprocessor List, which is incorporated into this DPA.
Accepted and agreed by acceptance of the Terms of Service and use of the Service, or:
Customer: ______________________ Name/title: ______________________ Date: ________
Joltclick Limited t/a Volexi: ______________________ Name/title: ______________________ Date: ________