Pixiera

Legal

Data Processing Addendum

Effective 30 August 2026Last updated 30 August 2026

NEXUS / Pixiera

Effective Date: 30 August 2026 Last Updated: 30 August 2026

This Data Processing Addendum (“DPA”) applies where Pixiera processes personal data on behalf of a Customer in connection with the Services.

This DPA supplements the Pixiera Terms of Service and applies to processing of Customer Personal Data where Pixiera acts as a Processor, Service Provider, or equivalent role under applicable data protection law.


1. DEFINITIONS

For purposes of this DPA:

“Customer Personal Data” means personal data processed by Pixiera on behalf of Customer through the Services.

“Data Protection Laws” means applicable laws governing the processing and protection of personal data, including, where applicable, the EU General Data Protection Regulation (“GDPR”) and applicable national implementing laws.

“Controller”, “Processor”, “Personal Data”, and “Processing” have the meanings assigned under applicable Data Protection Laws.


2. ROLES OF THE PARTIES

Customer acts as Controller, or equivalent business responsible for the relevant processing, and Pixiera acts as Processor or Service Provider, to the extent required by applicable law.

Customer determines the purposes and means of processing Customer Personal Data.

Pixiera processes Customer Personal Data only as necessary to provide the Services, in accordance with Customer's documented instructions, the applicable Agreement, and applicable law.


3. SUBJECT MATTER OF PROCESSING

The subject matter of processing is the provision of Pixiera Services.

Depending on the Services used, processing may include:


4. DURATION

Processing continues for the duration of the applicable Customer relationship and for any additional period reasonably necessary to satisfy legal, security, backup, dispute-resolution, or other lawful retention requirements.


5. CATEGORIES OF PERSONAL DATA

Depending on the Services used, Customer Personal Data may include:

Customer should not submit special categories of personal data or other highly sensitive personal data unless the applicable Pixiera Service expressly supports such processing and Customer has established a lawful basis for doing so.


6. CATEGORIES OF DATA SUBJECTS

Data subjects may include:


7. CUSTOMER RESPONSIBILITIES

Customer is responsible for:


8. PIXIERA OBLIGATIONS

Pixiera will:


9. SUBPROCESSORS

Customer authorizes Pixiera to engage subprocessors necessary to provide the Services.

Pixiera's current technology environment includes the following principal service providers:

Subprocessor / ProviderPrimary Function
OpenAIAI and machine-learning processing
SupabaseDatabase, authentication, storage and backend infrastructure
StripePayment processing and subscription billing
ResendEmail delivery
VercelHosting, deployment and edge infrastructure
CloudflareDNS, network, security, performance and related infrastructure

The precise processing performed by each provider may depend on the feature, configuration, and Customer's use of the Services.

Pixiera may add, replace, or remove subprocessors where reasonably necessary to provide or improve the Services.

Where applicable law or contract requires notice of material subprocessor changes, Pixiera will provide such notice.


10. SUBPROCESSOR REQUIREMENTS

Pixiera will require relevant subprocessors to provide appropriate contractual commitments concerning:

Where an applicable subprocessor processes data in Pixiera's capacity as a processor, Pixiera remains responsible for its contractual obligations concerning that subprocessor to the extent required by applicable law.


11. AI PROCESSING

Where AI functionality is enabled, Pixiera may transmit relevant information to OpenAI or another authorized AI service provider necessary to provide the applicable AI functionality.

Pixiera will use Customer Personal Data in connection with AI functionality in accordance with:

Pixiera does not intend to use Customer Personal Data for independent training of third-party general-purpose AI models unless such use is separately disclosed and permitted under the applicable Agreement.


12. INTERNATIONAL DATA TRANSFERS

Where Customer Personal Data is transferred to a jurisdiction subject to transfer restrictions under applicable Data Protection Laws, Pixiera will use an appropriate lawful transfer mechanism where required.

Such mechanisms may include:


13. SECURITY

Pixiera will maintain technical and organizational measures appropriate to the risks associated with the processing.

Measures may include:


14. DATA SUBJECT RIGHTS

Where reasonably necessary and required by applicable law, Pixiera will assist Customer in responding to requests concerning Customer Personal Data.

Customer remains primarily responsible for handling requests from its own data subjects where Customer acts as Controller.


15. PERSONAL DATA BREACHES

Where Pixiera becomes aware of a qualifying personal data breach affecting Customer Personal Data, Pixiera will notify Customer without undue delay where required by applicable law or the applicable Agreement.

Where reasonably available, the notification may include:


16. DELETION AND RETURN OF DATA

Following termination of the Services, Pixiera will delete or return Customer Personal Data in accordance with the applicable Agreement and applicable law.

Data may be retained where:


17. AUDIT AND COMPLIANCE INFORMATION

Where required by applicable Data Protection Laws, Customer may request reasonable information necessary to demonstrate compliance with this DPA.

Audit activity must be:

Pixiera may satisfy reasonable assurance requests through:

Nothing in this Section requires Pixiera to disclose confidential information, trade secrets, security-sensitive architecture, or information concerning other customers where such disclosure is not required by applicable law.


18. CONFIDENTIALITY

Pixiera will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.


19. CUSTOMER INSTRUCTIONS

Customer instructions relating to processing must be consistent with:

Pixiera may refuse an instruction where compliance would violate applicable law or create a material security or operational risk.


20. CONFLICT

If there is a conflict between this DPA and another contractual document concerning data protection obligations, this DPA controls to the extent of that conflict.


21. CONTACT

NEXUS / Pixiera

Skyview Terrace Clifton, NJ 07013 USA

Email: hello@pixiera.com

ANNEX I — PROCESSING DETAILS

Subject Matter: Provision of Pixiera Services.

Nature of Processing: Collection, hosting, storage, transmission, analysis, organization, retrieval, generation, support, integration, automation, and deletion of Customer Personal Data as necessary to provide the Services.

Purpose: To provide, secure, maintain, support, and improve the Services in accordance with the applicable Customer agreement.

Duration: For the duration of the Customer relationship and any legally required or reasonably necessary retention period.

Categories of Personal Data: As described in Section 5.

Categories of Data Subjects: As described in Section 6.


ANNEX II — CURRENT PRINCIPAL SUBPROCESSORS

ProviderPurposePotential Processing Context
OpenAIAI processingAI prompts, contextual information, generated Output
SupabaseDatabase / authentication / backendAccount and application data
StripePayments / subscriptionsBilling and payment-related information
ResendEmail deliveryRecipient and email delivery information
VercelHosting / deployment / edge infrastructureTechnical request and application information
CloudflareDNS / network / security / performanceNetwork and technical request information

The actual information processed by each provider depends on the feature used, technical configuration, and Customer instructions.

ANNEX III — TECHNICAL AND ORGANIZATIONAL MEASURES

Pixiera maintains technical and organizational measures appropriate to the nature and risk of processing.

These may include:

Pixiera may update these measures as its architecture and security practices evolve.