CEDX Systems · Legal
Data Processing Addendum
Pre-signed Article 28 / CCPA service-provider addendum. Fixes the instruction clause to the Union-or-Member-State-law standard, adds the missing CCPA compliance and same-level-of-protection undertakings, adds the network provider to Annex 3, separates the payment processor as an independent controller, corrects th
Last updated: 8 August 2026 · Version 1.0
This addendum is pre-signed. You do not need to negotiate it.
In short
- This addendum covers the personal data you put into CEDX apps. You own it. You decide what happens to it. We only handle it to run the service you bought.
- We do not sell it, share it, or use it for our own purposes. CEDX Corporation does not use it to train or improve AI models. What a third-party model provider may do with content sent through the AI gateway is governed by that provider's own terms, which we state in Annex 3 rather than paraphrase.
- We tell you who else touches it. Every subprocessor is listed in Annex 3, and we give you at least 30 days' notice before we add one.
- Cross-border rules switch themselves on. If you or the people whose data you hold are in the EEA, the UK or Switzerland, the Standard Contractual Clauses in Annex 4 and the UK Addendum in Annex 5 apply automatically. You do not have to ask for them.
- We tell you about a security incident without undue delay after we become aware of it, with what we know at the time.
- When you leave, you get your data out and then we delete it, on the timetable in the "End of the relationship" section.
- What we don't offer today: we don't hold a SOC 2 report or an ISO 27001 certificate, we don't commission third-party penetration tests, we don't run a round-the-clock staffed on-call, and we don't maintain an establishment in the EU or UK. We put it here so it reaches you before a security review does.
The summary above is not the contract. The sections below are.
Who this is between
This Data Processing Addendum ("Addendum") is between CEDX Corporation, a New York corporation doing business as CEDX Systems ("CEDX Corporation", "we", "us"), with its registered office at 307 W 38th St, 16th Floor, New York, NY 10018, and the customer named on the account ("you"). CEDX Corporation is the legal entity you contract with; CEDX Systems is the name it trades under and the name on cedxsystems.com, and the rest of this Addendum uses it.
CEDX Corporation is a separate company from CEDX (the 501(c)(3) research institution at cedx.org). The CEDX 501(c)(3) is not a party to this Addendum, has no obligations under it, and none of its systems are covered by it.
This Addendum forms part of the CEDX Corporation Terms of Service or other written agreement under which you use the Services (the "Agreement"). It applies from the date you first accept the Agreement, or from the date you countersign this Addendum, whichever is earlier.
How to put it in place. Accepting the Agreement accepts this Addendum. If your procurement process needs a signed copy, download this page, sign it, and email it to CEDX Corporation, Attn: Legal, 307 W 38th St, 16th Floor, New York, NY 10018, or legal@cedxsystems.com; we will return a countersigned copy. Our signature is set out at the end of this document, executed by Shreya Aher, Legal Counsel.
The words we use
Services — has the meaning given to "Service" in the Terms of Service: the CEDX Corporation platform and the CEDX apps you have bought, including CEDX CRM, CEDX Desk and CEDX Invoicing. We use the plural in this Addendum only for readability; it means the same thing.
Customer Personal Data — personal data inside the Services that belongs to you: the records, contacts, tickets, invoices, files, directory entries, calendar events, messages, and AI prompts and outputs that you and your users put in. Service logs that record how your users interact with the Services — sign-in events, request and error logs, and feature-usage counts — are data we control in our own right for security, fault diagnosis and product development, and are covered by our Privacy Policy rather than by this Addendum. We do not use the content of Customer Personal Data for product analytics.
Data Protection Law — whichever of these applies to a given piece of processing: the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended and its regulations, other US state privacy laws, Canada's PIPEDA, and Quebec's Law 25.
Controller, processor, personal data, processing, data subject and personal data breach carry the meanings given in the GDPR. Where a US state law uses different words for the same idea — business and service provider in California, controller and processor elsewhere — those words apply instead.
SCCs — the Standard Contractual Clauses approved by the European Commission on 4 June 2021 (Implementing Decision (EU) 2021/914).
UK Addendum — the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Who is controller and who is processor
You are the controller of Customer Personal Data. We are your processor. You decide why it is collected and what is done with it. We handle it to run the Services for you and for nothing else. Under California law, we are your service provider; under other US state laws, we are your processor.
We are a controller for our own data — your account and administrator contact details, billing records, support correspondence with your staff, security and audit logs, service logs and aggregate usage figures, website visitors and sales prospects. Our Privacy Policy governs that data. This Addendum does not.
If we ever decide the purpose and means of processing Customer Personal Data, we become a controller for that processing and Article 28(10) GDPR applies. We do not intend to, and the AI features section below is the specific commitment that keeps this from happening quietly.
What we do with your data, and what we do not
We process Customer Personal Data only on your documented instructions, including in relation to transfers of personal data to a third country or an international organisation, unless we are required to do otherwise by Union or Member State law — or, where the UK GDPR applies, by the law of the United Kingdom — to which we are subject. Where neither the GDPR nor the UK GDPR governs the processing, we may also depart from your instructions where another applicable law compels us to.
If such a law requires us to process Customer Personal Data other than on your instructions, we will inform you of that legal requirement before we process, unless that law prohibits us from doing so on important grounds of public interest. A demand from a public authority for access to Customer Personal Data is not an instruction, and is handled under "Where your data is processed" below.
Your documented instructions are:
- the Agreement and this Addendum;
- how you configure and use the Services, including the apps you enable and the automations you build; and
- any further written instruction you give us through support.
If we think an instruction of yours breaks Data Protection Law, we will tell you straight away. We may pause that instruction until we have agreed how to proceed.
We do not sell Customer Personal Data. We do not share it for cross-context behavioural advertising. We do not use it for our own marketing, benchmarking, product analytics or model training. We do not combine it with personal data from other sources, except where California's regulations allow a service provider to do so on your instruction.
You must not put special category personal data (Article 9 GDPR — health, race or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation), criminal offence data, or the personal data of children into the Services unless we have agreed it in writing first. The Services are not built for it and this Addendum does not cover it.
The people who handle it
Everyone at CEDX Corporation who can reach Customer Personal Data is bound by a written duty of confidentiality that survives the end of their engagement with us, and we limit that access to the people who need it to do their job. Everyone with access to Customer Personal Data is bound by written confidentiality obligations. — Article 28(3)(b) requires this commitment to be real before it is contracted for, so this Addendum does not publish without it, and the same marker is carried on our Security page until it is answered.
Security
We keep appropriate technical and organisational measures in place to protect Customer Personal Data, taking account of the state of the art, the cost, and the risk to the people the data is about. What those measures are today is set out in Annex 2. We can change them, and we will as the product changes — but not in a way that reduces the overall level of protection.
Annex 2 also sets out what we don't offer today. Read it before you rely on this section.
Subprocessors
You give us general written authorisation to use the subprocessors listed in Annex 3.
Before we add or replace a subprocessor, we will give you at least 30 days' notice by email to your account's administrator contacts, and we will update Annex 3. If you want the notices sent somewhere else, tell us at privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018.
You may object to a new subprocessor within 15 days of our notice, on reasonable grounds relating to data protection. If you do, we will try to offer you a commercially reasonable alternative — a different provider, a different region, or a configuration that keeps your data away from that subprocessor. If we cannot, you may terminate the affected Service without penalty and we will refund fees you have paid for the unused part of the term.
We do not claim this until we can produce the agreements. Once we can, this section reads: every subprocessor is engaged under a written contract that puts the same data protection obligations on it that this Addendum puts on us. We remain fully liable to you for a subprocessor's failure to meet those obligations.
AI features
Some CEDX apps can send content to an external AI model provider through our AI gateway. This only happens when a user triggers a feature that needs it.
- You own your inputs. As between you and us, you own the outputs too.
- CEDX Corporation does not use Customer Personal Data — including prompts and outputs — to train, fine-tune or improve any model. We are not in a position to warrant what a model provider does with what we send it; their contractual position on training and retention is recorded in Annex 3, and we give at least 30 days' notice before changing provider.
- We only send what the feature needs, and only when a user asks for it.
- The model providers are subprocessors and are named in Annex 3, with the region they process in and their own retention and training terms: CEDX AI is CEDX Corporation's own assistant layer. It is not trained or fine-tuned on customer content. It calls third-party frontier models — Anthropic (Claude) and OpenAI — which process in the United States. Content you send to AI features reaches those providers, and what they may retain or train on is governed by their terms, which we name in Annex 3 rather than paraphrase..
- Outputs are generated by a model. They can be wrong. You must not use AI features as the sole basis for a decision about a person's legal rights, finances, employment, credit, housing, insurance, education, immigration status or medical care. A person must meaningfully review the output before the decision is made.
Helping you answer data subject requests
The Services give your administrators tools to search, export, correct and delete Customer Personal Data, which is how most requests are answered fastest: Administrators can export account data and request deletion through the account portal. Where an app has no self-service export, we produce one on written request within 10 business days..
Where those tools are not enough, we will help you — by appropriate technical and organisational measures, and as far as we reasonably can — to respond to requests from data subjects exercising rights of access, rectification, erasure, restriction, portability and objection.
If a data subject contacts us directly about data that belongs to you, we will not respond to the substance. We will tell them to contact you, and we will tell you, unless the law says otherwise.
Helping you with security, breaches, DPIAs and regulators
Taking account of what the processing involves and the information available to us, we will give you reasonable help with:
- keeping the processing secure (Article 32);
- notifying a personal data breach to a supervisory authority and to affected people (Articles 33 and 34);
- carrying out a data protection impact assessment (Article 35), including a privacy impact assessment under Quebec's Law 25; and
- consulting a supervisory authority in advance where one is required (Article 36).
We keep a record of the categories of processing we carry out for you, of transfers to other countries, and a general description of our security measures (Article 30(2)). We will make the relevant parts available to you or to a supervisory authority on request.
Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay. We treat ourselves as aware once we have a reasonable degree of certainty that a security incident has occurred and that personal data was compromised — not once the investigation has finished. We will give you what we know at the time, and the rest as we learn it: what happened, the categories and approximate number of people and records involved, the likely consequences, what we are doing about it, and who to talk to.
We deliberately do not promise a fixed number of hours. The 72-hour deadline in Article 33(1) is your obligation to your supervisory authority as controller, not ours. A rigid clock on our side would turn a careful investigation into a contract breach without making you any safer.
There is one outside limit that does bind us. Where we maintain Customer Personal Data that you own or license, New York General Business Law § 899-aa(3) requires us to notify you of a breach of the security of the system immediately following discovery, and in no case later than thirty days after discovery. We are bound by that in addition to, and not in place of, the notification timetable set out in this Addendum, and where two deadlines apply we work to the earlier one.
We keep a record of every security incident affecting Customer Personal Data, whether or not it needs to be notified, for Six years from the close of the incident..
We will not make a public statement identifying you in connection with a breach without your consent, unless the law requires it.
Audits and information
We will make available the information you reasonably need to show that we are meeting our obligations under Article 28. In practice:
- Start with the published material. Annex 2, Annex 3 and our Security page answer most vendor questionnaires.
- Then ask us. Send a written questionnaire to security@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018, the same address our Security page publishes, and we will answer it within 10 business days.. We answer the questions we can answer and write "no" against the ones we cannot, rather than leaving them blank.
- Then audit, if you still need to. You, or an independent auditor you appoint who is not a competitor of ours, may audit our processing of your Customer Personal Data once in any 12-month period, on 30 days' written notice, during business hours, without unreasonable disruption, at your cost, and under a confidentiality agreement. You may audit more often if we have confirmed a personal data breach affecting your data, or if a supervisory authority requires it.
An audit must not give you access to another customer's data, and we may redact anything that would.
US state privacy laws
Where you are a business subject to the CCPA, or a controller subject to another US state privacy law, we are your service provider or processor, and the following terms apply.
- We process Customer Personal Data only for the limited and specified business purposes set out in Annex 1, only on your behalf, and only under this Addendum.
- We will comply with every obligation applicable to a service provider or processor under the CCPA and its regulations, and under the other US state privacy laws, and we will provide the same level of privacy protection to Customer Personal Data as the CCPA requires of you as the business.
- We do not sell Customer Personal Data and we do not share it, using those words as the CCPA defines them — "sharing" meaning disclosure for cross-context behavioural advertising.
- We do not retain, use or disclose Customer Personal Data outside the direct business relationship between you and us, or for any purpose other than the business purposes specified, including for a commercial purpose of our own.
- We do not combine Customer Personal Data with personal information we receive from anyone else, or collect ourselves, except where the CCPA regulations permit a service provider to do so.
- We certify that we understand the restrictions in this section and the obligations in the paragraph above, and that we will comply with them.
- You may take reasonable and appropriate steps to confirm that we are using Customer Personal Data consistently with your obligations, and to stop and remediate any unauthorised use.
- If we determine we can no longer meet these obligations, we will tell you without undue delay.
- We pass these same restrictions down to every subprocessor in writing.
We are not a data broker. We do not collect personal information about people with whom we have no direct relationship in order to sell it, and we are not registered as a data broker in any state because we are not one.
Canada
We remain accountable to you for Customer Personal Data we transfer to a subprocessor, and we use written contracts to give it a comparable level of protection, as PIPEDA requires. The section below on where your data is processed is our openness disclosure under PIPEDA: your data may be processed outside Canada and is subject to the law of the country it sits in, including lawful access by authorities there. This is a use, not a disclosure, and we do not treat it as a consent question.
If you do business in Quebec, we will give you the information you reasonably need to complete a privacy impact assessment before personal information is communicated outside Quebec, and the terms of this Addendum — purpose limitation, no onward communication, incident notification, audit, and return or deletion at the end — are intended to meet section 17 of Quebec's Law 25.
End of the relationship
When the Agreement ends, you choose: we return Customer Personal Data to you, or we delete it. If you do not tell us which, we delete it.
- Export. You can export your data through the Services for 30 days from the end of the subscription, during which you can export your data through the account portal or ask us to produce an export. after the Agreement ends.
- Live systems. We delete Customer Personal Data from live systems within Within 30 days of the end of the export window, so no later than 60 days after termination. after the export window closes.
- Backups. Backups are not deleted on demand. They age out on our normal rotation, within 30 days, after which backups are deleted automatically. from the date each backup was taken, and nothing is restored from them except to recover the whole system.
We may keep Customer Personal Data for longer where a law requires it. If that happens, we keep it only for that purpose, protected as described in Annex 2, and we delete it once the requirement ends.
Liability
The limitation of liability in the Agreement applies to this Addendum. Claims under the Agreement and under this Addendum count towards the same cap; they do not each get their own.
Nothing in this section limits either party's liability to a data subject under Clause 12 of the SCCs, or any liability that cannot be limited by law.
Where your data is processed, and how transfers are covered
Customer Personal Data is stored and processed by Customer data is hosted on dedicated virtual infrastructure provided by Hostinger International Limited, in a data centre in Vilnius, Lithuania. The servers run in UTC.. Our subprocessors and the regions they process in are listed in Annex 3. Data held in another country is subject to that country's law, including lawful access by its authorities.
These transfer terms switch themselves on. Where you are established in the European Economic Area, the United Kingdom or Switzerland, or where you use the Services to process the personal data of people located there, this section and Annexes 4 and 5 apply to that processing. You do not need to sign anything else and we do not need to publish a new version.
- EEA and Switzerland to us. The SCCs in Annex 4 apply. Module Two (controller to processor) applies where you are the controller. Module Three (processor to processor) applies where you are yourself acting as a processor for someone else. For Swiss transfers, the SCCs apply with the amendments described in Annex 4.
- UK to us. The SCCs apply as amended by the UK Addendum in Annex 5, in whichever version the Information Commissioner has approved at the time, so a reissued version applies automatically without amending this Addendum.
- EEA to the UK, and UK to the EEA. No transfer mechanism is needed for as long as the European Commission's UK adequacy decisions remain in force.
- Where a subprocessor is established in Canada. The European Commission's adequacy decision for Canada (Decision 2002/2/EC) covers only private-sector organisations subject to PIPEDA in respect of their commercial activities. Where a subprocessor is a Canadian organisation within that scope, that decision covers the transfer to it and the SCCs are not needed for that leg. It does not cover transfers to us. CEDX Corporation is a New York corporation and the data importer named in Annex 1; the fact that our staff may access data from outside the United States does not make us a Canadian importer or bring us inside that decision. Every transfer to CEDX Corporation is covered by the SCCs in Annex 4 and, where the UK GDPR applies, by the UK Addendum in Annex 5.
- We do not rely on the EU–US Data Privacy Framework. We are not self-certified under it and we display no badge for it. The SCCs are our mechanism.
Us to our subprocessors. Where a subprocessor is outside the EEA, the UK or Switzerland and no adequacy decision covers it, we put the SCCs (Module Three) or the UK Addendum in place with that subprocessor before any Customer Personal Data reaches it.
Government access. If we receive a legally binding request from a public authority for Customer Personal Data, we will tell you before we respond, unless we are prohibited from doing so — in which case we will use reasonable efforts to get the prohibition lifted so we can tell you as much as we can, as soon as we can. We will challenge a request where we have reasonable grounds to think it is unlawful. We keep a record of these requests and will share what the law allows us to share.
Where we are established. CEDX Corporation has no establishment in the European Union or the United Kingdom. We have not appointed a Data Protection Officer; our processing is not the large-scale monitoring or large-scale special category processing that Article 37 requires one for. On Article 27: No. CEDX Corporation offers the Services worldwide with the exception of the European Economic Area, the United Kingdom and Switzerland. We do not target, market to, or accept customers established in those territories, and the Services are not offered to data subjects there.. If it does, Article 3(2) applies to that processing and a representative is required unless the Article 27(2) derogation applies; we will appoint one and publish its details in the "Where your data is processed" section of our Privacy Policy before taking such a customer. We will not state that a representative is unnecessary until that question is settled. Until then, contact us at privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018 for anything you would otherwise send to a representative or a DPO.
Which document wins, and how this one changes
If they conflict on the processing of personal data, the order is: the SCCs (and the UK Addendum) first, this Addendum second, the Agreement third. On everything else, the Agreement governs.
We version this Addendum. Every version carries an effective date and stays available at a stable URL from this version onwards, and the change log at the bottom of this page says what changed.
If we make a material change, we will give you at least 30 days' notice by email to your account's administrator and billing contacts before it takes effect. If you do not accept a material change, tell us before it takes effect and you may terminate the affected Service without penalty, with a refund of fees paid for the unused part of the term.
We cannot and do not vary the SCCs unilaterally. They change only as the SCCs themselves permit, or when the European Commission or the Information Commissioner replaces them.
Contact
Privacy and data protection: privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018 Security questionnaires and vulnerability reports: security@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018 Legal notices, including a signed copy of this Addendum: CEDX Corporation, Attn: Legal, 307 W 38th St, 16th Floor, New York, NY 10018, or legal@cedxsystems.com
Signed for CEDX Corporation
Shreya Aher, Legal Counsel, for and on behalf of CEDX Corporation, effective 8 August 2026.
Your acceptance of the Agreement is your signature. No countersignature is needed unless you want one.
Annex 1 — What we process, and why
This Annex is also Annex I.A and I.B of the SCCs.
The parties. Data exporter: you, the customer named on the account, acting as controller (or as processor for your own customer, in which case Module Three applies). Data importer: CEDX Corporation, a New York corporation trading as CEDX Systems, acting as processor. Contact details for each party are those on the account and in the Contact section above.
Subject matter. Our provision of the Services to you under the Agreement.
Duration. For as long as the Agreement is in force, plus the periods in the "End of the relationship" section.
Nature of the processing. Collecting, recording, organising, structuring, storing, retrieving, using, transmitting, displaying, backing up, restoring, restricting, erasing and destroying — by automated means — as needed to operate the Services.
Purposes. To do the things you bought the Services to do, specifically:
- authenticate your users and keep their accounts secure;
- run the workspace and the apps you have enabled, including CEDX CRM, CEDX Desk and CEDX Invoicing;
- store and serve the records, files, messages, events and directory entries you put in;
- send email and notifications you trigger through the Services;
- generate invoices and take payment from your clients where you use CEDX Invoicing;
- run AI features when a user asks for one;
- provide support when you ask for it;
- keep security and audit logs, take backups, and investigate incidents; and
- meet our legal obligations.
Categories of data subjects. Because the Services are configurable, you decide whose data goes in. It typically includes: your employees, contractors and other authorised users; your clients, customers and prospects, and their staff; your suppliers; job applicants, where you use the Services for recruiting; and anyone else you choose to record.
Categories of personal data. Again, you decide. It typically includes: names and contact details; employer, job title and role; account credentials and authentication data; the content of messages, tickets, notes, call notes and files; calendar and event data; billing, invoice and transaction details relating to your own clients; identifiers such as user IDs and IP addresses; usage and log data tied to a user; and AI prompts and the outputs generated from them.
This list is not exhaustive, and it cannot be — a shared platform records whatever its customer configures it to record.
Sensitive data. None is permitted. Special category data under Article 9 GDPR, criminal offence data and children's data must not be put into the Services without our prior written agreement.
Frequency. Continuous, for as long as you use the Services.
Your rights and obligations as controller. You decide what data goes into the Services and why. You are responsible for having a lawful basis for it, for giving the people concerned the notices they are owed, for the accuracy of what you upload, for who you give access to, and for responding to data subject requests — with our help as set out above.
Subprocessors. See Annex 3. This is also Annex III of the SCCs.
Competent supervisory authority (Annex I.C of the SCCs). The supervisory authority of the EEA Member State in which you are established. If you are not established in the EEA but have appointed an Article 27 representative, the supervisory authority of the Member State where that representative is established. Otherwise, the supervisory authority of the Member State where the data subjects covered by the transfer are located.
Annex 2 — Technical and organisational measures
This Annex is also Annex II of the SCCs. These are the measures in place as of 8 August 2026. We may update them; we will not reduce the overall level of protection.
| Area | What we do |
|---|---|
| Encryption in transit | Traffic between you and the Services is encrypted using HTTPS. TLS 1.2. TLS 1.0 and 1.1 are refused; TLS 1.2 and TLS 1.3 are accepted. Verified against the live configuration on 8 August 2026. |
| Encryption at rest | Customer data is stored on the server's own filesystem. There is no full-disk or volume-level encryption layer in place today, and backups are compressed rather than encrypted. Data is encrypted in transit. |
| Data store | Customer data is held in Postgres and separated logically: every record is scoped to the customer account it belongs to, and we do not run a separate database or a separate instance per customer. Tenant separation is enforced in the application layer, which scopes every query to the signed-in account.. Customer data is held in SQLite databases inside the application containers, not in Postgres, and Supabase is not in use for the Services covered by this agreement. |
| Payment card data | We do not store or transmit full card numbers through the payment path. Card details are collected and processed by JPMorgan Chase Bank, N.A. (Chase Payment Solutions). Card details are entered into Chase's own payment components and go to Chase directly. We do not store, process or transmit full card numbers, so we are not the party that holds the card-network attestation for that processing. |
| User authentication | Sign-in is handled by the platform identity service. Two-factor authentication using an authenticator app is available on customer accounts. |
| Staff access to production | Limited to the people who need it to do their job. Our staff do not read customer data as routine work. Production access is by SSH to a single host, restricted to two registered public keys. Key-based authentication is in use and access is limited to the root account. |
| Joiner and leaver process | Production access is granted by adding a named key and removed by deleting it. Access is reviewed whenever someone joins or leaves, and shared credentials are rotated at the same time. |
| Access control inside the product | Role-based permissions and entitlements, administered by your own administrators. |
| Backups | Backup integrity is verified weekly and the most recent verification passed. A full restore-to-a-clean-host drill has not been recorded. |
| Dependency management | Operating-system packages are patched automatically through unattended-upgrades. Automated application-dependency scanning is not in place today. |
| Data minimisation on the website | The cedxsystems.com marketing site loads no analytics, tag manager, session recorder, advertising pixel, A/B tool or chat widget. There is nothing non-essential to consent to, which is why there is no cookie banner. |
| Confidentiality | Everyone with access to Customer Personal Data is under a written confidentiality obligation that survives their engagement with us, subject to the confirmation marked in "The people who handle it" above. |
| Subprocessor management | Written contracts with data protection terms equivalent to these, and the notice and objection process in the Subprocessors section, subject to the confirmation marked there. |
| Incident handling | We keep a record of every security incident affecting Customer Personal Data, notified or not, for Six years from the close of the incident., and we notify you without undue delay after becoming aware of one. |
| Deletion | On the timetable in the "End of the relationship" section. |
What we don't offer today. Stated here so you don't have to ask for it:
- no SOC 2 report of any type;
- no ISO 27001 certificate;
- no third-party penetration test report;
- no round-the-clock staffed on-call rotation;
- no appointed Data Protection Officer, and no EU or UK representative — see "Where we are established";
- no EU–US Data Privacy Framework self-certification.
If your procurement process requires one of these, tell us and we will tell you honestly where we stand.
Annex 3 — Subprocessors
This Annex is also Annex III of the SCCs, and it is the authoritative list of every third party that can touch Customer Personal Data. Last updated 8 August 2026.
| Provider | What it does | Data it can access | Where it processes |
|---|---|---|---|
| Cloudflare sits in front of the site and the product as CDN, DNS and reverse proxy, terminating TLS at its edge and serving from the Cloudflare network globally. Verified against response headers on 8 August 2026. | Content delivery, TLS termination, bot management, rate limiting and denial-of-service protection in front of the website and the platform | Request metadata for every request, including IP address, user agent and requested URL, and the content of requests and responses while in transit, because TLS is terminated there | Cloudflare sits in front of the site and the product as CDN, DNS and reverse proxy, terminating TLS at its edge and serving from the Cloudflare network globally. Verified against response headers on 8 August 2026. |
| Hosting | Runs the platform and stores the Postgres database | All Customer Personal Data | Customer data is hosted on dedicated virtual infrastructure provided by Hostinger International Limited, in a data centre in Vilnius, Lithuania. The servers run in UTC. |
| Email delivery | Sends transactional and notification email triggered through the Services | Recipient name and email address, message content | None. CEDX Corporation operates its own mail server; product and transactional email is not handed to a third-party delivery provider. |
| Error monitoring | Captures application errors so we can fix them | Whatever appears in an error report, which can include identifiers and fragments of content | Application errors are logged on our own infrastructure in the same region as the Services. We do not send error data to a third-party monitoring service. |
| AI model provider | Generates output for AI features when a user triggers one | Prompt content and any records the user includes | CEDX AI is CEDX Corporation's own assistant layer. It is not trained or fine-tuned on customer content. It calls third-party frontier models — Anthropic (Claude) and OpenAI — which process in the United States. Content you send to AI features reaches those providers, and what they may retain or train on is governed by their terms, which we name in Annex 3 rather than paraphrase. |
| Supabase | Supabase is not in use for the Services covered by this agreement. | — | — |
Third parties that are not our subprocessors. Chase processes payment and billing data as an independent controller for its own payment, fraud-prevention, anti-money-laundering and identity-verification purposes. It is not our subprocessor for that processing, the general authorisation and the liability commitment in the Subprocessors section do not apply to it, and the processor's own terms and data processing agreement govern. It receives billing contact details, transaction data, and card details collected directly by the processor, and processes in the United States with onward processing by JPMorgan Chase group companies. We name it here because it is a third party that touches personal data connected to your account, and you should read its terms alongside ours.
Change notices. We give at least 30 days' notice before adding or replacing a subprocessor, by email to your account's administrator contacts. To have notices sent to a different address, email privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018. Your right to object, and what happens if you do, is in the Subprocessors section above.
Annex 4 — EU Standard Contractual Clauses
The SCCs approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this Addendum by reference and form part of it. They are available in full on the European Commission's website.
Which module applies. Module Two (controller to processor) where you are a controller. Module Three (processor to processor) where you are a processor acting for your own customer. Where Module Three applies, references to the controller's instructions mean the instructions passed to you by your own controller.
How the optional clauses are completed:
| Clause | Selection |
|---|---|
| Clause 7 (docking) | Included. A new party may accede with both parties' agreement. |
| Clause 9 (subprocessors) | Option 2 — general written authorisation. Notice period for changes: 30 days, as set out in the Subprocessors section. |
| Clause 11 (redress) | The optional independent dispute resolution body is not selected. |
| Clause 13 (supervision) | The competent supervisory authority is identified in Annex 1. |
| Clause 17 (governing law) | Option 1 — the law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Annex I.A (parties) | As set out in Annex 1 of this Addendum. |
| Annex I.B (description of transfer) | As set out in Annex 1 of this Addendum. |
| Annex I.C (supervisory authority) | As set out in Annex 1 of this Addendum. |
| Annex II (security measures) | As set out in Annex 2 of this Addendum. |
| Annex III (subprocessors) | As set out in Annex 3 of this Addendum. |
Clause 14 (local laws). Clause 14 requires both parties to warrant that they have no reason to believe the destination country's laws prevent us meeting our obligations, having assessed the specific circumstances of the transfer, and Clause 14(d) requires that assessment to be documented and available to a supervisory authority on request. Not applicable. We do not offer the Services in the EEA, the United Kingdom or Switzerland, so no Chapter V transfer assessment arises.. We are not signing a Clause 14 warranty before the assessment exists.
When it exists, it will record: that we are not an "electronic communication service provider" within the meaning of 50 U.S.C. § 1881a(b)(4) and have never received a directive under section 702, a national security letter, or a request under Executive Order 12333 8 August 2026; the type, volume and sensitivity of the data transferred; the measures in Annex 2; and the supplementary measures we apply to transferred data Data is encrypted in transit. Access to production is limited to two administrators using key-based authentication.. We will publish the date of that assessment here and give it to you on request, and we will tell you promptly if any of it changes, in which case you may suspend the transfer or terminate the affected Service. If our assessment is not enough for your own accountability under Article 5(2), tell us and we will complete your transfer impact assessment questionnaire.
Clause 15 (government access). Our commitments on notifying you about, recording and challenging government access requests are in the "Where your data is processed" section above and apply as Clause 15 requires.
Switzerland. Where the Swiss Federal Act on Data Protection applies, the SCCs apply with these adjustments: the competent authority is the Federal Data Protection and Information Commissioner; references to the GDPR are read as references to the FADP; and "member state" is not read so as to prevent data subjects in Switzerland from enforcing their rights in their place of habitual residence. The revised FADP, in force since 1 September 2023, no longer protects the data of legal entities, so the SCCs are not extended to legal-entity data. If Swiss law changes on this point, we will extend them.
If the SCCs conflict with anything else here, the SCCs win.
Annex 5 — UK International Data Transfer Addendum
Where the UK GDPR applies to a transfer, the SCCs in Annex 4 apply as amended by the ICO's International Data Transfer Addendum (version B1.0, or the then-current version the Commissioner has approved). Its Mandatory Clauses are incorporated, and they make the substitutions the UK requires — including that the governing law is the law of England and Wales and the courts are the courts of England and Wales.
Table 1 — Parties. Start date: the date this Addendum takes effect. Exporter: you, as named on the account, with the contact details on the account. Importer: CEDX Corporation, trading as CEDX Systems, 307 W 38th St, 16th Floor, New York, NY 10018, contact privacy@cedxsystems.com, or CEDX Corporation, 307 W 38th St, 16th Floor, New York, NY 10018.
Table 2 — Selected SCCs. The Approved EU SCCs incorporated at Annex 4, including the module and optional-clause selections in the table there, and their Appendix Information.
Table 3 — Appendix Information. Annex 1A (parties): Annex 1 of this Addendum. Annex 1B (description of transfer): Annex 1 of this Addendum. Annex II (security measures): Annex 2. Annex III (subprocessors): Annex 3.
Table 4 — Ending the Addendum when the Approved Addendum changes. The Importer may end the UK Addendum as set out in Section 19 of its Mandatory Clauses.
Change log
| Effective | Version | What changed |
|---|---|---|
| 8 August 2026 | 1.0 | First publication. This Addendum replaces all earlier data processing terms published by CEDX Corporation, which were adopted from a third-party template and did not describe this company. We review this page at least once every 12 months. |
CEDX SYSTEMS
Talk to sales