Data Processing Agreement (DPA)
Last updated: August 24, 2026 · Version 2026-08-24 · Supersedes the April 12, 2026 version · GDPR Article 28
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between AKAXA (“Processor”) and the Customer (“Controller”) who uses the AKAXA Services. In the event of a conflict between the Terms of Service and this DPA regarding personal data processing, this DPA shall prevail.
Status: AKAXA Limited (Hong Kong SAR) is in formation and has not yet been incorporated. Until incorporation is complete, the Services are operated by AKAXA's founders, who hold the processor obligations set out here; those obligations transfer to the incorporated company on formation. This document is offered as a template and binds AKAXA only when executed with a customer. AKAXA has no executed customer DPA at the date of this version.
Applicable laws. This DPA is drafted against the Personal Data (Privacy) Ordinance, Cap. 486 (Hong Kong SAR) — including DPP2(3) and DPP4(2), under which AKAXA as a data user remains responsible for personal data entrusted to it and must use contractual means to prevent excess retention and unauthorised access by any data processor it engages — together with the GDPR, the UK Data Protection Act 2018 and UK GDPR, the Swiss Federal Data Protection Act, and the CCPA/CPRA as modified for a processor context.
Note on terminology. The PDPO uses “data user” where the GDPR uses “data controller”. Where this DPA says “controller” or “processor”, the equivalent PDPO concepts apply in Hong Kong.
1. Subject Matter and Duration
AKAXA processes personal data on behalf of the Controller solely to provide the Services as described in the Terms of Service, for the duration of the subscription.
2. Nature and Purpose of Processing
AKAXA processes personal data to: (a) provide AI-powered due diligence analysis; (b) operate and maintain the platform; (c) provide technical support; (d) comply with legal obligations.
3. Categories of Data and Data Subjects
Data Subjects: employees and representatives of the Controller and its portfolio companies, deal targets, and other individuals whose data may be included in uploaded documents.
Data Types: account information (name, email, phone, company, job title), company financial and operational data, usage data, communication data, and technical data.
4. Processor Obligations (GDPR Art. 28(3))
AKAXA shall:
- Process personal data only on documented instructions from the Controller
- Ensure that authorized personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures (Art. 32)
- Not engage sub-processors without prior written authorization
- Assist the Controller in responding to data subject rights requests
- Assist with security breach notification (Art. 33/34) within 72 hours
- Delete or return personal data upon termination of services
- Provide all information necessary to demonstrate compliance
5. AI Data Processing
AKAXA shall not:
- Use Customer personal data for any purpose other than providing Services
- Train, fine-tune, enhance, or develop machine learning models on Customer personal data for any third-party access or general model improvement without explicit written consent
- Combine Customer data with data from other customers (except aggregated, de-identified benchmarking)
- Sell personal data or use it for behavioral targeting or profiling
AI sub-processors are engaged under commercial API terms that do not permit content submitted through those APIs to be used to train the provider's models. Those providers may retain content for a limited period for abuse monitoring under their own published terms. AKAXA does not represent that zero data retention (ZDR) terms are in force. Any provider-specific zero-retention configuration will be identified individually rather than described as a general property of the platform.
6. Authorized Sub-processors
| Sub-Processor | Location | Function |
|---|---|---|
| Railway | Provider-operated regions, primarily United States | Cloud infrastructure, hosting |
| Anthropic | Provider-operated regions, primarily United States | AI/LLM analysis |
| OpenAI | Provider-operated regions, primarily United States | AI/LLM analysis |
| Google (Gemini) | Provider-operated regions | AI analysis when enabled for a workflow |
| Perplexity | Provider-operated regions, primarily United States | Web research enrichment (search queries only) |
| Cloudflare | Provider-operated regions | CDN, DDoS protection, R2 storage |
| Vercel | Provider-operated regions | Web front-end hosting |
| Resend | Provider-operated regions | Email delivery |
| Sentry | Provider-operated regions | Error monitoring (anonymized) |
| GitHub | Provider-operated regions | Source control and CI/CD; the nightly production-database backup runs inside a GitHub-hosted runner |
AKAXA will notify the Controller of intended sub-processor changes with at least 30 days' notice, giving the Controller the opportunity to object. AKAXA relies on each sub-processor's published data processing terms, which require processing on AKAXA's instructions, appropriate security measures, and breach notification.
7. Data Location and International Transfers
Data location: AKAXA does not operate its own data centre and does not guarantee that data is stored in, or restricted to, any single jurisdiction. Processing takes place on the providers listed above, primarily in the United States. A specific data residency position must be agreed in writing for a deployment before confidential material is accepted.
Transfer safeguards: transfers from the EU/EEA are protected by Standard Contractual Clauses (Module 2: Controller to Processor) as adopted by the European Commission under GDPR Article 46, incorporated into this DPA and effective on execution. The same applies to Module 3 (Processor to Processor) for onward transfers; until this DPA is executed, the operative protection for that leg is each provider's own published transfer terms.
8. Security Measures (Art. 32)
- Encryption at rest applied by our infrastructure providers (AES-256 or equivalent) and in transit (TLS 1.2+)
- API key encryption using Fernet symmetric encryption
- Role-based access controls (RBAC) with principle of least privilege
- Multi-factor authentication available in the product; no written policy yet enforces it on administrative accounts
- A hash-chained audit trail over analysis, provisioning, sync and agent events. It is not a blanket record of every read of personal data, and is not claimed as one
- Application and error monitoring with alerting, reviewed by the founders. Automated breach detection is not implemented
- Internal security review of platform changes. Independent external security assessment and penetration testing are planned and have not yet been performed
- 72-hour breach notification obligation. A written incident response plan is planned and does not exist yet
- Logical data isolation: each Customer's data processed in isolated environment
9. Data Subject Rights
AKAXA will assist the Controller in fulfilling data subject requests within the statutory periods that apply to the Controller. AKAXA does not offer a shorter contractual service level, because no request-handling process, queue or named owner exists yet; a service level will be agreed when one does. AKAXA does not engage in automated individual decision-making with legal effects under GDPR Article 22. All Analysis Reports are advisory and require independent human judgment.
10. Breach Notification
AKAXA notifies the Controller without undue delay and no later than 72 hours of becoming aware of a confirmed data breach. Notification includes: description of the breach, approximate number of affected records, likely impact, and measures taken to mitigate harm.
11. Termination
Upon termination, AKAXA will, at the Controller's election, delete or return personal data within 30 days, and confirm in writing what was deleted or returned. Backup copies are removed on the backup rotation, within a further 90 days.
Stated plainly, because a contract should not promise a capability that does not exist: AKAXA has no deletion procedure that has been executed or witnessed. Deletion is performed by the founders against the storage surfaces known to hold the data. AKAXA does not claim cryptographic erasure, does not claim that recovery is impossible, and does not offer a third-party deletion certificate. Building and testing a deletion procedure — including its propagation to object storage, backups and provider-side retention — is a ranked item on AKAXA's security work list, and this clause will be re-executed when it exists.
12. Audit Rights
Customer may request audits or inspections of AKAXA's processing (up to one full audit per calendar year). AKAXA is not SOC 2 certified and is not ISO 27001 certified. SOC 2 readiness sits on AKAXA's security roadmap; no examination has been scheduled and no completion date is committed. Until an examination report exists, AKAXA provides an Internal Security Self-Assessment Report on request, labelled as a self-assessment rather than independent assurance.
13. Governing Law and Dispute Resolution
This DPA is governed by the laws of Hong Kong SAR, consistent with the Terms of Service. Disputes relating to data protection or processing are to be resolved first by good-faith negotiation for 30 days, and failing that under the dispute-resolution provisions of the Terms of Service. Nothing here limits a data subject's right to complain to a supervisory authority, including the Office of the Privacy Commissioner for Personal Data (PCPD) in Hong Kong.
Enterprise DPA Execution
Enterprise customers requiring a countersigned DPA should contact legal@akaxa.io. Note that until AKAXA Limited is incorporated the contracting party would be AKAXA's founders, and the agreement is to be re-executed naming the company once it is formed.
Contact
AKAXA — operated by its founders pending incorporation of AKAXA Limited (Hong Kong SAR)
Legal: legal@akaxa.io
DPA inquiries: dpa@akaxa.io
Escalation: dpo@akaxa.io (no statutory Data Protection Officer has been appointed)