This Data Processing Agreement ("DPA") forms part of the Terms of Service between Innovatex Digital FZCO, operating as ixnodes ("Processor", "ixnodes", "we"), and the customer ("Controller", "Customer", "you"). It applies where ixnodes processes Personal Data on behalf of the Customer in the course of providing the Services. In the event of a conflict between this DPA and the Terms of Service in respect of data protection, this DPA prevails.
Capitalized terms not defined in this DPA have the meaning given in the Terms of Service. "GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Data Subject", "Controller", and "Processor" have the meanings given in the GDPR. "SCCs" means the EU Standard Contractual Clauses approved by the European Commission.
1ROLES AND SCOPE
1.1As between the parties, the Customer is the Controller and ixnodes is the Processor of Personal Data contained in Customer Content processed through the Services.
1.2ixnodes processes such Personal Data only on documented instructions from the Customer, including as set out in this DPA and the Terms of Service, unless required to do otherwise by applicable law.
1.3This DPA does not apply to Personal Data for which ixnodes is the Controller (for example, Account and billing data), which is governed by our Privacy Policy.
2SUBJECT MATTER AND DETAILS OF PROCESSING
2.1Subject matter: provision of cloud infrastructure (compute, storage, database, networking) Services.
2.2Duration: for the term of the Services and any retention period thereafter as set out in this DPA or required by law.
2.3Nature and purpose: hosting, storage, transmission, and processing of Customer Content as necessary to provide the Services.
2.4Types of Personal Data and categories of Data Subjects: determined and controlled by the Customer through its use of the Services. ixnodes does not control what Personal Data the Customer places into the Services.
3PROCESSOR OBLIGATIONS
ixnodes will:
3.1Process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required by law (in which case it will inform the Customer unless legally prohibited).
3.2Ensure that persons authorized to process Personal Data are bound by confidentiality.
3.3Implement appropriate technical and organizational measures as described in Annex A.
3.4Respect the conditions for engaging sub-processors set out in Section 5.
3.5Taking into account the nature of processing, assist the Customer by appropriate measures, insofar as possible, in responding to Data Subject requests.
3.6Assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to ixnodes.
3.7At the Customer's choice, delete or return Personal Data at the end of the Services and delete existing copies, unless retention is required by law.
3.8Make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits on reasonable notice, subject to confidentiality and security constraints.
4SECURITY
ixnodes implements and maintains the technical and organizational measures described in Annex A, appropriate to the risk. The Customer is responsible for the security configuration of its own deployments, including operating systems, applications, access controls, and encryption of Customer Content at rest within its instances.
5SUB-PROCESSORS
5.1The Customer provides general authorization for ixnodes to engage sub-processors to provide the Services. Current sub-processors include those listed in our Privacy Policy and in Annex B.
5.2ixnodes will impose data protection obligations on sub-processors that are no less protective than those in this DPA and remains responsible for their performance.
5.3ixnodes will inform the Customer of intended changes to sub-processors, giving the Customer the opportunity to object on reasonable data protection grounds.
6INTERNATIONAL TRANSFERS
6.1Primary processing infrastructure is currently located in Germany (EU).
6.2Where Personal Data of Data Subjects in the EU/EEA is transferred to a country without an EU adequacy decision (including the UAE, where ixnodes is domiciled), such transfers are governed by the EU Standard Contractual Clauses, which are incorporated into this DPA by reference. The relevant modules and selections are set out in Annex C.
6.3CLOUD Act position: ixnodes is operated by Innovatex Digital FZCO, a UAE free zone entity. ixnodes is not a US person and is not subject to the jurisdiction of the United States Clarifying Lawful Overseas Use of Data (CLOUD) Act. ixnodes does not voluntarily disclose Customer Personal Data to any government authority except as required by validly applicable law binding on ixnodes, and will, where lawfully able, notify the Customer of any binding legal demand for Customer Personal Data.
7PERSONAL DATA BREACH
ixnodes will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its breach notification obligations.
8RETURN AND DELETION
On termination of the Services, ixnodes will, at the Customer's choice, delete or make available for return the Customer Personal Data, and will delete remaining copies after a reasonable period unless retention is required by law. Standard deletion follows our normal data lifecycle once the Account is closed.
9LIABILITY
The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
10GOVERNING LAW
This DPA is governed by the same law and jurisdiction as the Terms of Service, except where the SCCs require otherwise for the purposes of the relevant transfer.
ANNEX A — TECHNICAL AND ORGANIZATIONAL MEASURES
- Network segmentation and encrypted internal transport between infrastructure nodes.
- Default-deny firewalling on infrastructure hosts with maintained allowlists.
- Access controls and key-based administrative authentication.
- Continuous abuse and security monitoring with alerting.
- Vulnerability and security-update monitoring across infrastructure nodes.
- Logging and time-limited forensic retention for security investigation.
- Regular backups of platform configuration and management databases.
- Encryption in transit for management and customer-facing endpoints.
(The Customer is responsible for measures within its own instances, including in-instance encryption, OS/application patching, and access management.)
ANNEX B — SUB-PROCESSORS
- Hetzner — infrastructure / data center (Germany)
- Stripe — card payment processing
- Cryptomus — cryptocurrency payment processing
- Mailgun — transactional email
- Cloudflare — DNS, network, and security services
(Current list available on request; subject to change with notice per Section 5.)
ANNEX C — STANDARD CONTRACTUAL CLAUSES
Where required under Section 6, the EU SCCs (Commission Implementing Decision (EU) 2021/914) apply as follows:
- Module Two (Controller to Processor) applies to transfers from the Customer as Controller to ixnodes as Processor.
- Module Three (Processor to Processor) applies to onward transfers to sub-processors where applicable.
- Docking clause (Clause 7): applicable.
- Sub-processor changes (Clause 9): Option 2, general written authorization, with a minimum of thirty (30) days' notice of intended changes.
- Governing law of the SCCs (Clause 17): the law of Ireland.
- Forum for disputes (Clause 18): the courts of Ireland.
- Annexes to the SCCs are populated by Annexes A and B above and the processing details in Section 2.
These Standard Contractual Clauses are incorporated into this DPA by reference and take effect automatically for any restricted transfer, with no further signature required. A separately executed copy of this DPA incorporating the SCCs is available to Business customers on request at privacy@ixnodes.com.