Legal
Data Processing Agreement.
This forms part of the daXos Sales Terms and applies whenever daXos processes personal data on your behalf. You accept it with the same tick that accepts the Sales Terms. Larger customers can sign a negotiated version instead — ask us.
daXos LLC · Greensboro, North Carolina · version 2026.09, effective 12 September 2026 · permanent link to this version
Why this exists: telematics data tied to a vehicle is personal data in most regimes, because it can be linked to the person driving. So every daXos subscription needs data-processing terms, including one bought by card in five minutes.
1 · Definitions
Customer Data — all data generated by daXos equipment on your vehicles or assets (telemetry, location, movement, environmental and cargo-condition readings, sensor data) and everything you or your users put into the service.
Customer Personal Data — Customer Data that identifies, or is reasonably linkable to, an identifiable person: vehicle location and movement linkable to a driver, driver or personnel identifiers you associate with vehicles, and platform account data.
Data Protection Laws — every law applicable to this processing, including US state privacy laws (the CCPA as amended by the CPRA, and the comprehensive laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states), and where applicable the GDPR, the UK GDPR, the Swiss FADP and Canada’s PIPEDA.
Customer AI Agents — AI agents, assistants, models or automated tooling used by or for you, whether provided by daXos, built by you, or supplied by a third party at your direction, including anything you connect through your own MCP endpoint.
Non-Customer AI Training — using Customer Data to train, fine-tune or improve AI agents or models that are not used by or made available to you.
Subprocessor — a third party daXos engages to process Customer Personal Data on its behalf.
2 · Roles
As between us, you are the controller (or business, or a processor where you act for someone else) and daXos is the processor (or service provider) of Customer Personal Data. Annex 1 sets out the details of the processing.
Each of us complies with its own obligations under Data Protection Laws. You are responsible for the lawfulness of the data you make available — including every driver and personnel notice and any consent your law, your employment policies or a works council requires — and you confirm you have a lawful basis for the processing described here.
3 · How daXos processes
daXos processes Customer Personal Data only on your documented instructions, including as to international transfers, unless a law it is subject to requires otherwise — in which case it tells you first, unless that law forbids it. The Sales Terms, this DPA, and your own configuration and use of the service (dashboards, the MCP endpoint, your AI agents) are your complete documented instructions. Anything further needs written agreement.
daXos will tell you promptly if it thinks an instruction breaks the law. Everyone at daXos with access is bound by confidentiality and uses the data only to provide the service.
4 · What daXos may use the data for
Only these purposes:
- Providing the service — hosting, operating, securing, supporting and maintaining the platform, the equipment and the connectivity, and providing exports, alerts and support.
- Dashboards you ask for — building, populating and running the dashboards and reports you request or configure.
- Your AI agents — making the data available to, and processing it through, the agents you use, including answering queries on your MCP endpoint and running AI features of the service you use. Adapting a model to your own fleet is included.
- Aggregated data — creating and using de-identified, aggregated data, provided it does not identify and cannot reasonably be re-linked to you, your people, your customers or your vehicles. daXos will not attempt re-identification and contractually forbids recipients from doing so.
- Legal compliance — complying with law, a court order or a government request, subject to section 3.
5 · What daXos will not do — including AI training
daXos will not sell or share Customer Personal Data as US state privacy laws define those words, will not retain, use or disclose it outside our direct business relationship or for any purpose beyond section 4 — never for cross-context behavioural advertising — and will not combine it with personal data from other sources except as section 4 permits. daXos will not use it for its own marketing, for profiling, or for resale in identifiable form. daXos understands these restrictions and will comply with them, as the CCPA requires it to certify.
The AI training gate. daXos will not use Customer Data — personal or not — for Non-Customer AI Training unless we first sign a separate written agreement naming the data in scope, the purpose, the de-identification standard, and any consideration. daXos may ask; you may decline in your sole discretion, and declining changes nothing about your service, your fees or your support. An email does not satisfy this section. Aggregated data under section 4 is not caught by it.
6 · Retention and deletion
Standard rolling retention — three months. daXos keeps raw Customer Data (telemetry, sensor readings, location and event data) for a rolling three months from collection, then deletes or de-identifies it. Dashboards, summaries and statistics you have generated may outlive the raw window. A longer period can be agreed in an order form.
Export. During the term and for thirty days after it ends, you can export your then-retained data through the service or ask daXos for a one-time export at no charge.
Deletion on termination. daXos will delete or return Customer Personal Data at your choice, and in any event within ninety days of termination — except aggregated data under section 4, records it must keep by law (kept only as long as required, under this DPA’s protections), and data in routine backups, which is overwritten on the ordinary cycle and not restored to a live system. daXos will confirm deletion in writing on request.
7 · Security
daXos maintains appropriate technical and organizational measures against accidental or unlawful destruction, loss, alteration and unauthorized disclosure or access. The current measures are in Annex 2. daXos may update them so long as overall protection is not materially reduced.
In particular, daXos encrypts Customer Personal Data in transit and at rest, enforces role-based least-privilege access with multi-factor authentication on administrative access, and logs administrative access to production systems.
8 · If there is a breach
daXos will notify you without undue delay and within seventy-two hours of becoming aware of a personal data breach affecting Customer Personal Data, with the nature of the breach, the categories and approximate volumes affected, the likely consequences, and the measures taken or proposed, as they become available.
daXos will act to contain and remediate, and will cooperate with your own notification duties. It will not notify regulators or individuals on your behalf, or describe the incident publicly as yours, without your written consent unless the law requires it. Notifying you is not an admission of fault.
9 · Helping you answer requests
daXos will assist you, by appropriate technical and organizational measures and so far as possible, in responding to access, deletion, correction, portability and opt-out requests. If a request comes to daXos directly it will not answer on the merits — it forwards it to you and points the person to you.
daXos will give reasonable help with your impact assessments and consultations with supervisory authorities, so far as the law requires of a processor. Help beyond that may be charged at standard rates agreed in advance.
10 · Europe, the UK and Switzerland
Where Customer Personal Data is subject to the GDPR, the UK GDPR or the Swiss FADP, this DPA is the contract Article 28(3) GDPR requires, and sections 3 to 9 and 11 to 12 are read accordingly.
For transfers to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), with you as exporter and daXos as importer, Clause 7 included, Clause 9(a) Option 2 with the notice period in section 11, and Annexes I–III completed by the Annexes below. For UK transfers the UK IDTA Addendum (B1.0) applies on the same information; for Swiss transfers the SCCs apply as adapted for the FADP.
If daXos certifies under the EU–US Data Privacy Framework, we may rely on that instead, with the SCCs remaining as a fallback. daXos will tell you if it can no longer meet the transfer mechanism, and you may suspend the affected transfer if compliance cannot be restored.
11 · Subprocessors
You generally authorize daXos to engage subprocessors for hosting, connectivity, communications and platform infrastructure. The current categories are in Annex 3, and daXos will name its current providers on request. Each is bound by written contract to obligations no less protective than this DPA, and daXos stays fully liable for them.
daXos gives you at least fifteen days’ notice before adding one. You may object in writing on reasonable data-protection grounds within that period; we then work in good faith on a solution, and failing one you may terminate the affected service without penalty and get a pro-rata refund of prepaid fees.
12 · Audit
daXos will make available what is reasonably necessary to show it complies with this DPA, including answers to a reasonable written security questionnaire once a year (more often after a breach) and, when available, summaries of third-party audits or certifications.
Where the law gives you a mandatory audit right that this does not satisfy, you or an independent auditor — not a daXos competitor, under NDA — may audit the relevant controls once every twelve months, on thirty days’ notice, in business hours, without access to any other customer’s data, at your cost. Findings are daXos confidential information.
13 · Liability and precedence
Liability under this DPA is subject to the exclusions and limits in the Sales Terms, and this DPA does not enlarge either side’s total liability beyond that cap — except that the cap does not limit liability for a breach of the AI training gate in section 5.
If documents conflict: the SCCs prevail over this DPA where they apply; this DPA prevails over the Sales Terms for the processing of Customer Personal Data; the Sales Terms govern everything else. A DPA we have both signed replaces this one entirely.
14 · Term and general
This DPA takes effect when you accept the Sales Terms and runs until deletion under section 6 is complete. daXos may update Annexes 2 and 3 as set out above; other changes need agreement in writing, and a change in Data Protection Laws is handled by negotiating in good faith.
It binds our permitted successors. daXos may assign it together with the Sales Terms to a successor arising from a conversion, merger or reorganization — including conversion of the LLC into a corporation — on notice and without your consent.
Governing law and venue follow the Sales Terms, except where the SCCs require otherwise for themselves.
Annex 1 · Details of the processing
Also serves as Annex I of the SCCs where they apply.
- Subject matter — provision of the daXos IoT/telematics platform and related services.
- Duration — the term of the subscription, plus the deletion period in section 6.
- Nature and purposes — collection via daXos hubs and sensors; hosting, storage, analysis and display; dashboards and Customer AI Agents including the customer-scoped MCP endpoint; support; security; aggregated data under section 4.
- Categories of data subjects — your drivers, employees and contractors operating monitored vehicles or assets; your platform users and business contacts.
- Categories of personal data — vehicle location, movement, speed and trip data linkable to drivers; driving-event data such as harsh braking and acceleration; vehicle and asset identifiers you associate with individuals; environmental and cargo readings linked to trips; platform account data (name, business email, role, log data).
- Special categories — none intended. You must not configure the service to submit special-category data.
- Frequency — continuous, for the term.
- Retention — rolling three months for raw data; deletion within ninety days of termination.
Annex 2 · Technical and organizational measures
- Encryption — TLS 1.2 or better in transit; AES-256 or equivalent at rest; encrypted device-to-cloud transport.
- Access control — role-based, least privilege, need-to-know; multi-factor authentication on administrative and production access; unique accounts, no shared credentials; prompt de-provisioning on role change or departure.
- Network and platform — segregated production environment; firewalling; hardened cloud configuration; customer-scoped API and MCP authentication, so each customer’s endpoint reaches only that customer’s data.
- Logging and monitoring — logging of administrative access and security-relevant events; alerting on anomalous access.
- Device security — signed over-the-air updates; device authentication; no write access to any vehicle system.
- Data lifecycle — automated enforcement of the three-month retention period; documented deletion procedures; encrypted backups overwritten on cycle.
- Organizational — confidentiality undertakings for personnel; security awareness training; subprocessor security review; documented incident response with defined severity levels.
- Resilience and testing — backups, redundancy within the hosting provider’s infrastructure, restore testing at reasonable intervals; periodic vulnerability scanning with risk-prioritized remediation.
Annex 3 · Authorized subprocessors
By category, as at the version date above. daXos will name the current provider in each category on request, and gives fifteen days’ notice before adding one.
- Cloud hosting and storage — the platform and its databases. United States.
- Telematics gateway — receives and normalises data from the devices.
- Cellular connectivity — the network the devices report over. United States.
- Payments — Stripe, for subscriptions, invoices and card processing. United States.
- Website hosting — Netlify. United States.
- Email and support tooling — Google Workspace. United States.
Annex 4 · AI training addendum
There is no AI training addendum in force, and there will not be one unless you sign it. If daXos ever asks, the form will name the datasets and date ranges in scope, the specific models to be trained, the de-identification standard applied before use, any consideration to you, and a revocation right on thirty days’ notice. Declining, or revoking later, has no effect on your service, fees or support.
Accepting this
You accept this DPA when you tick the box accepting the daXos Sales Terms at checkout. daXos records the version and the moment of acceptance against your subscription. If your organization needs a signed copy, or a negotiated DPA with your own paper, write to info@daXosdigit.com.
