1.1As between the parties, the Customer is the Controller and ixnodes is the Processor of Personal Data contained in Customer Content processed through the Services.

1.2ixnodes processes such Personal Data only on documented instructions from the Customer, including as set out in this DPA and the Terms of Service, unless required to do otherwise by applicable law.

1.3This DPA does not apply to Personal Data for which ixnodes is the Controller (for example, Account and billing data), which is governed by our Privacy Policy.

2.1Subject matter: provision of cloud infrastructure (compute, storage, database, networking) Services.

2.2Duration: for the term of the Services and any retention period thereafter as set out in this DPA or required by law.

2.3Nature and purpose: hosting, storage, transmission, and processing of Customer Content as necessary to provide the Services.

2.4Types of Personal Data and categories of Data Subjects: determined and controlled by the Customer through its use of the Services. ixnodes does not control what Personal Data the Customer places into the Services.

3.1Process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required by law (in which case it will inform the Customer unless legally prohibited).

3.2Ensure that persons authorized to process Personal Data are bound by confidentiality.

3.3Implement appropriate technical and organizational measures as described in Annex A.

3.4Respect the conditions for engaging sub-processors set out in Section 5.

3.5Taking into account the nature of processing, assist the Customer by appropriate measures, insofar as possible, in responding to Data Subject requests.

3.6Assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to ixnodes.

3.7At the Customer's choice, delete or return Personal Data at the end of the Services and delete existing copies, unless retention is required by law.

3.8Make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits on reasonable notice, subject to confidentiality and security constraints.

5.1The Customer provides general authorization for ixnodes to engage sub-processors to provide the Services. Current sub-processors include those listed in our Privacy Policy and in Annex B.

5.2ixnodes will impose data protection obligations on sub-processors that are no less protective than those in this DPA and remains responsible for their performance.

5.3ixnodes will inform the Customer of intended changes to sub-processors, giving the Customer the opportunity to object on reasonable data protection grounds.

6.1Primary processing infrastructure is currently located in Germany (EU).

6.2Where Personal Data of Data Subjects in the EU/EEA is transferred to a country without an EU adequacy decision (including the UAE, where ixnodes is domiciled), such transfers are governed by the EU Standard Contractual Clauses, which are incorporated into this DPA by reference. The relevant modules and selections are set out in Annex C.

6.3CLOUD Act position: ixnodes is operated by Innovatex Digital FZCO, a UAE free zone entity. ixnodes is not a US person and is not subject to the jurisdiction of the United States Clarifying Lawful Overseas Use of Data (CLOUD) Act. ixnodes does not voluntarily disclose Customer Personal Data to any government authority except as required by validly applicable law binding on ixnodes, and will, where lawfully able, notify the Customer of any binding legal demand for Customer Personal Data.