Aller au contenu principal

Data Processing Addendum (DPA) - Noxys Security SAS

Last Updated: 16 May 2026

This Data Processing Addendum ("Addendum") forms part of the Master Service Agreement or Terms of Service (the "Agreement") between:

  1. NOXYS SECURITY SAS, a French company ("Processor" or "Noxys"); and
  2. The legal entity subscribing to Noxys services ("Controller" or "Customer").

1. Definitions

"Personal Data", "Processing", "Data Subject", "Controller" and "Processor" shall have the meanings given to them in the EU General Data Protection Regulation 2016/679 ("GDPR").

2. Scope of Processing

Processor shall process Personal Data only for the purposes of providing the AI Firewall services as described in the Agreement and this Addendum.

3. Processor Obligations

3.1. Instructions: Processor shall process Personal Data only on documented instructions from the Controller. 3.2. Confidentiality: Processor ensures that persons authorized to process the Personal Data have committed themselves to confidentiality. 3.3. Security: Processor shall implement technical and organizational measures as specified in Annex 2. 3.4. Data Subject Rights: Processor shall assist Controller in fulfilling its obligation to respond to requests for exercising data subject rights. 3.5. Data Breach: Processor shall notify Controller without undue delay (and no later than 72 hours) after becoming aware of a Personal Data breach.

4. Sub-processors

Controller grants a general authorization for Noxys to engage sub-processors. Noxys shall inform Controller of any intended changes concerning the addition or replacement of sub-processors. A list of current sub-processors is in Annex 3.

5. Data Transfers

All Personal Data processed by Noxys is hosted within the European Union (France). No transfers to third countries are performed without Controller's prior written consent or standard contractual clauses.


ANNEX 1: DESCRIPTION OF THE PROCESSING

  • Subject matter: Providing a security layer for Generative AI usage.
  • Duration: Duration of the Agreement.
  • Nature and Purpose: Real-time filtering, redaction, and risk scoring of AI prompts and responses.
  • Categories of Data Subjects: Employees and contractors of the Controller.
  • Types of Personal Data: Business contact info (email), professional identity, and any PII contained in AI interactions (filtered/redacted by Noxys).

ANNEX 2: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

  1. Data Minimization: Raw prompt content is never stored. Only SHA-256 hashes are retained.
  2. Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  3. Local Inference: PII detection (Tier 1/2) is performed on the endpoint to avoid transferring raw text.
  4. Isolation: Logical tenant isolation via Row-Level Security (RLS).
  5. Access Control: Multi-Factor Authentication (MFA) required for all administrative access.

ANNEX 3: LIST OF SUB-PROCESSORS

  • Scaleway (FR): Cloud Infrastructure and Hosting.
  • OVHcloud (FR): Key Management System (KMS) and Backup.
  • Stripe (IE/US): Billing and Subscription management (Metadata only).
  • Resend (US): Transactional Email (Email addresses only).