Fruxon logo
Fruxon

Data Processing Addendum

The terms governing how Fruxon Inc. processes personal data on behalf of customers.

Last updated: July 2026


This Data Processing Addendum ("DPA") forms part of the Fruxon Terms of Service. For an individually executed copy of this DPA, please contact support@fruxon.com.

1. Scope & Applicability

This DPA applies when Fruxon Inc.("Processor") processes personal data on behalf of the customer ("Controller") in the course of providing the Services under the Terms of Service.

This DPA is incorporated by reference into the Terms of Service and applies to the extent that the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act ("CCPA/CPRA"), or other applicable data protection laws require a data processing agreement.

2. Definitions

Terms used in this DPA have the meanings given in the GDPR unless otherwise defined:

  • "Controller" means the customer who determines the purposes and means of processing personal data.

  • "Processor" means Fruxon Inc., which processes personal data on behalf of the Controller.

  • "Sub-processor" means a third party engaged by the Processor to process personal data on the Controller's behalf.

  • "Data Subject" means an identified or identifiable natural person whose personal data is processed.

  • "Personal Data" means any information relating to a Data Subject.

  • "Processing" means any operation performed on personal data.

  • "Supervisory Authority" means the competent data protection authority.

3. Data Processing

The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by applicable law. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes applicable data protection law.

Details of processing:

  • Subject matter: Provision of the Fruxon AI agent infrastructure platform.

  • Duration: The term of the agreement between the Controller and the Processor.

  • Nature and purpose: Processing of personal data to provide, maintain, and support the Services, including agent execution, conversation processing, and knowledge base operations.

  • Categories of data: Account data, conversation content, agent memory, uploaded files and media, execution traces, and any personal data contained in content processed by the Controller's agents.

  • Categories of data subjects: The Controller's end users, employees, and any individuals whose personal data is submitted to the Services.

4. Sub-processors

The Controller authorizes the Processor to engage the sub-processors listed at fruxon.com/subprocessors. The Processor shall:

  • Impose data protection obligations on each sub-processor no less protective than those in this DPA.

  • Notify the Controller at least 30 days in advance before engaging a new sub-processor or replacing an existing one.

  • Provide the Controller an opportunity to object to the new sub-processor within 30 days of notification. If the Controller objects on reasonable grounds and the parties cannot resolve the objection, either party may terminate the affected Services.

5. Security Measures

The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).

  • Per-tenant envelope encryption with Cloud KMS-managed keys; customer-managed keys (BYOK) available for Enterprise.

  • Role-based access controls and per-agent collaborator roles (least-privilege).

  • Append-only, fail-closed credential-access audit logging for sensitive data tiers.

  • Incident response procedures with defined escalation paths.

  • Regular security reviews, dependency scanning, and CASA Tier 2 verification.

For additional detail, see our Security page.

6. Data Subject Rights

The Processor shall assist the Controller, by appropriate technical and organizational measures, in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, restriction, portability, objection). The Processor shall promptly notify the Controller if it receives a Data Subject request directly.

7. Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours where required by applicable law, after becoming aware of a confirmed personal data breach. The notification shall include:

  • The nature of the breach, including categories and approximate numbers of Data Subjects and records affected.

  • The likely consequences of the breach.

  • The measures taken or proposed to address the breach and mitigate its effects.

  • The name and contact details of the Processor's point of contact.

8. International Transfers

Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, the Processor shall ensure that appropriate safeguards are in place, including the EU Standard Contractual Clauses (SCCs) or other approved transfer mechanisms. The Processor conducts Transfer Impact Assessments where required.

DeepSeek — data processing in China

If the Controller configures DeepSeek as an LLM provider, prompts and agent data may be transmitted to and processed on servers in China. The Controller is responsible for ensuring an appropriate legal basis and safeguards for such transfers under applicable data protection law. See the Sub-processor List for provider locations.

9. Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

The Processor makes SOC 2 Type 1 reports, CASA Tier 2 attestation, and pre-filled security questionnaire responses available under NDA via the Trust Center. On-site audits may be conducted by reasonable arrangement with advance written notice.

10. Data Deletion & Return

Upon termination of the agreement, the Processor shall, at the Controller's election, delete or return all personal data and delete existing copies within 90 days, except to the extent that applicable law requires retention.

The Controller may export Customer Data during a reasonable transition period following termination. For Enterprise customers with customer-managed encryption keys (BYOK), disabling the key provides immediate cryptographic erasure of stored credentials.

11. Term & Termination

This DPA takes effect on the date the Controller first accesses the Services and remains in effect for the duration of the Processor's processing of personal data on the Controller's behalf. The obligations of this DPA survive termination to the extent the Processor retains any personal data.

12. Contact

Questions about this DPA? Contact us at support@fruxon.com.