Effective Date: 30 August 2026 Last Updated: 30 August 2026
This Data Processing Addendum (“DPA”) applies where Pixiera processes personal data on behalf of a Customer in connection with the Services.
This DPA supplements the Pixiera Terms of Service and applies to processing of Customer Personal Data where Pixiera acts as a Processor, Service Provider, or equivalent role under applicable data protection law.
1. DEFINITIONS
For purposes of this DPA:
“Customer Personal Data” means personal data processed by Pixiera on behalf of Customer through the Services.
“Data Protection Laws” means applicable laws governing the processing and protection of personal data, including, where applicable, the EU General Data Protection Regulation (“GDPR”) and applicable national implementing laws.
“Controller”, “Processor”, “Personal Data”, and “Processing” have the meanings assigned under applicable Data Protection Laws.
2. ROLES OF THE PARTIES
Customer acts as Controller, or equivalent business responsible for the relevant processing, and Pixiera acts as Processor or Service Provider, to the extent required by applicable law.
Customer determines the purposes and means of processing Customer Personal Data.
Pixiera processes Customer Personal Data only as necessary to provide the Services, in accordance with Customer's documented instructions, the applicable Agreement, and applicable law.
3. SUBJECT MATTER OF PROCESSING
The subject matter of processing is the provision of Pixiera Services.
Depending on the Services used, processing may include:
- hosting;
- storing;
- authentication;
- database operations;
- website and business analysis;
- generating recommendations;
- processing reviews;
- processing CRM information;
- managing workflows;
- generating AI Output;
- providing integrations;
- customer communications;
- analytics;
- authorized automation;
- support; and
- service security.
4. DURATION
Processing continues for the duration of the applicable Customer relationship and for any additional period reasonably necessary to satisfy legal, security, backup, dispute-resolution, or other lawful retention requirements.
5. CATEGORIES OF PERSONAL DATA
Depending on the Services used, Customer Personal Data may include:
- names;
- email addresses;
- telephone numbers;
- customer identifiers;
- business contact information;
- review information;
- booking information;
- loyalty information;
- CRM information;
- marketing information;
- communication records;
- website interaction information;
- analytics information;
- user-generated content; and
- other personal data submitted or connected by Customer.
Customer should not submit special categories of personal data or other highly sensitive personal data unless the applicable Pixiera Service expressly supports such processing and Customer has established a lawful basis for doing so.
6. CATEGORIES OF DATA SUBJECTS
Data subjects may include:
- Customer's customers;
- leads;
- prospects;
- subscribers;
- reviewers;
- website visitors;
- employees;
- contractors;
- business contacts; and
- other individuals whose personal data Customer makes available through the Services.
7. CUSTOMER RESPONSIBILITIES
Customer is responsible for:
- determining the lawful basis for processing;
- providing required privacy notices;
- obtaining required consent;
- responding to data subject requests where applicable;
- ensuring processing instructions are lawful;
- ensuring Customer Personal Data can lawfully be provided to Pixiera;
- complying with applicable communications and marketing laws; and
- configuring and using the Services appropriately.
8. PIXIERA OBLIGATIONS
Pixiera will:
- process Customer Personal Data according to documented instructions;
- ensure authorized personnel are subject to appropriate confidentiality obligations;
- implement appropriate technical and organizational measures;
- assist Customer where reasonably required by applicable law;
- provide reasonable assistance concerning data subject requests;
- provide reasonable assistance concerning security obligations;
- notify Customer of qualifying personal data breaches where required;
- delete or return Customer Personal Data as required by the applicable Agreement; and
- comply with applicable processor obligations.
9. SUBPROCESSORS
Customer authorizes Pixiera to engage subprocessors necessary to provide the Services.
Pixiera's current technology environment includes the following principal service providers:
| Subprocessor / ProviderPrimary Function | |
|---|---|
| OpenAI | AI and machine-learning processing |
| Supabase | Database, authentication, storage and backend infrastructure |
| Stripe | Payment processing and subscription billing |
| Resend | Email delivery |
| Vercel | Hosting, deployment and edge infrastructure |
| Cloudflare | DNS, network, security, performance and related infrastructure |
The precise processing performed by each provider may depend on the feature, configuration, and Customer's use of the Services.
Pixiera may add, replace, or remove subprocessors where reasonably necessary to provide or improve the Services.
Where applicable law or contract requires notice of material subprocessor changes, Pixiera will provide such notice.
10. SUBPROCESSOR REQUIREMENTS
Pixiera will require relevant subprocessors to provide appropriate contractual commitments concerning:
- confidentiality;
- security;
- data protection;
- processing limitations; and
- other obligations required by applicable law.
Where an applicable subprocessor processes data in Pixiera's capacity as a processor, Pixiera remains responsible for its contractual obligations concerning that subprocessor to the extent required by applicable law.
11. AI PROCESSING
Where AI functionality is enabled, Pixiera may transmit relevant information to OpenAI or another authorized AI service provider necessary to provide the applicable AI functionality.
Pixiera will use Customer Personal Data in connection with AI functionality in accordance with:
- the applicable Customer agreement;
- this DPA;
- the Privacy Policy;
- applicable product configuration; and
- applicable law.
Pixiera does not intend to use Customer Personal Data for independent training of third-party general-purpose AI models unless such use is separately disclosed and permitted under the applicable Agreement.
12. INTERNATIONAL DATA TRANSFERS
Where Customer Personal Data is transferred to a jurisdiction subject to transfer restrictions under applicable Data Protection Laws, Pixiera will use an appropriate lawful transfer mechanism where required.
Such mechanisms may include:
- an adequacy decision;
- Standard Contractual Clauses;
- supplementary contractual, technical, or organizational safeguards; or
- another legally recognized mechanism.
13. SECURITY
Pixiera will maintain technical and organizational measures appropriate to the risks associated with the processing.
Measures may include:
- access control;
- authentication;
- encryption;
- tenant isolation;
- logging;
- monitoring;
- backup;
- incident response;
- least-privilege access;
- confidentiality controls;
- vendor management; and
- other risk-appropriate measures.
14. DATA SUBJECT RIGHTS
Where reasonably necessary and required by applicable law, Pixiera will assist Customer in responding to requests concerning Customer Personal Data.
Customer remains primarily responsible for handling requests from its own data subjects where Customer acts as Controller.
15. PERSONAL DATA BREACHES
Where Pixiera becomes aware of a qualifying personal data breach affecting Customer Personal Data, Pixiera will notify Customer without undue delay where required by applicable law or the applicable Agreement.
Where reasonably available, the notification may include:
- the nature of the incident;
- categories of data affected;
- likely consequences;
- mitigation measures; and
- relevant contact information.
16. DELETION AND RETURN OF DATA
Following termination of the Services, Pixiera will delete or return Customer Personal Data in accordance with the applicable Agreement and applicable law.
Data may be retained where:
- required by law;
- necessary for security;
- necessary for fraud prevention;
- necessary for dispute resolution;
- necessary for legal claims; or
- stored temporarily in backups subject to reasonable deletion procedures.
17. AUDIT AND COMPLIANCE INFORMATION
Where required by applicable Data Protection Laws, Customer may request reasonable information necessary to demonstrate compliance with this DPA.
Audit activity must be:
- proportionate;
- reasonable;
- subject to confidentiality;
- conducted in a manner that protects other customers;
- designed to avoid disclosure of sensitive security information; and
- scheduled so as to avoid unreasonable operational disruption.
Pixiera may satisfy reasonable assurance requests through:
- security documentation;
- questionnaires;
- certifications;
- audit summaries;
- independent reports where available; or
- other appropriate evidence.
Nothing in this Section requires Pixiera to disclose confidential information, trade secrets, security-sensitive architecture, or information concerning other customers where such disclosure is not required by applicable law.
18. CONFIDENTIALITY
Pixiera will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
19. CUSTOMER INSTRUCTIONS
Customer instructions relating to processing must be consistent with:
- the applicable Services;
- applicable Agreement;
- applicable law; and
- the technical capabilities of the relevant Pixiera feature.
Pixiera may refuse an instruction where compliance would violate applicable law or create a material security or operational risk.
20. CONFLICT
If there is a conflict between this DPA and another contractual document concerning data protection obligations, this DPA controls to the extent of that conflict.
21. CONTACT
NEXUS / Pixiera
Skyview Terrace Clifton, NJ 07013 USA
Email: hello@pixiera.com
ANNEX I — PROCESSING DETAILS
Subject Matter: Provision of Pixiera Services.
Nature of Processing: Collection, hosting, storage, transmission, analysis, organization, retrieval, generation, support, integration, automation, and deletion of Customer Personal Data as necessary to provide the Services.
Purpose: To provide, secure, maintain, support, and improve the Services in accordance with the applicable Customer agreement.
Duration: For the duration of the Customer relationship and any legally required or reasonably necessary retention period.
Categories of Personal Data: As described in Section 5.
Categories of Data Subjects: As described in Section 6.
ANNEX II — CURRENT PRINCIPAL SUBPROCESSORS
| ProviderPurposePotential Processing Context | ||
|---|---|---|
| OpenAI | AI processing | AI prompts, contextual information, generated Output |
| Supabase | Database / authentication / backend | Account and application data |
| Stripe | Payments / subscriptions | Billing and payment-related information |
| Resend | Email delivery | Recipient and email delivery information |
| Vercel | Hosting / deployment / edge infrastructure | Technical request and application information |
| Cloudflare | DNS / network / security / performance | Network and technical request information |
The actual information processed by each provider depends on the feature used, technical configuration, and Customer instructions.
ANNEX III — TECHNICAL AND ORGANIZATIONAL MEASURES
Pixiera maintains technical and organizational measures appropriate to the nature and risk of processing.
These may include:
- authentication;
- authorization;
- access control;
- least-privilege principles;
- tenant separation;
- encryption in transit;
- encryption at rest where appropriate;
- logging;
- monitoring;
- security incident response;
- backup and recovery;
- confidentiality requirements;
- controlled administrative access;
- third-party vendor controls; and
- data deletion procedures.
Pixiera may update these measures as its architecture and security practices evolve.
