Data Processing Addendum
Effective Date: June 12, 2026
Last Updated: June 12, 2026
This Data Processing Addendum (“DPA”) is entered into between Noviqo LLC (“Noviqo,” “Processor”) and the customer entity using the Noviqo Services (“Controller,” “Customer,” or “you”). This DPA is incorporated into and governed by the Noviqo Terms of Service. In the event of a conflict between this DPA and the Terms of Service, this DPA will control with respect to the processing of personal data.
This DPA applies to the extent that Noviqo processes personal data on behalf of the Customer in connection with providing the Services, and applicable data protection law (including GDPR, UK GDPR, CCPA/CPRA, or other applicable laws) requires a written data processing agreement.
1. Definitions
- “Applicable Data Protection Law” means all applicable laws and regulations relating to the processing of personal data, as amended or replaced from time to time, including without limitation the GDPR, UK GDPR, CCPA/CPRA, and other applicable privacy laws.
- “Controller” means the entity that determines the purposes and means of the processing of personal data.
- “Customer Data” means personal data submitted to, collected by, generated by, or processed through the Services on the Customer's behalf.
- “GDPR” means the General Data Protection Regulation (EU) 2016/679 and all subordinate legislation and regulations implementing the GDPR.
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law.
- “Processor” means the entity that processes personal data on behalf of the Controller.
- “Subprocessor” means any third party engaged by Noviqo to process Customer Data in connection with the Services.
- “UK GDPR” means the GDPR as retained in UK law under the European Union (Withdrawal) Act 2018.
Other capitalized terms have the meanings given in the Terms of Service.
2. Roles of the Parties
As between the parties, the Customer is the Controller and Noviqo is the Processor of Customer Data processed in connection with the Services.
Each party is responsible for compliance with Applicable Data Protection Law in its respective role. The Customer determines the purposes and means of processing; Noviqo processes Customer Data only as directed by the Customer or as necessary to provide the Services.
3. Noviqo's Processing Obligations
Noviqo will:
- Process Customer Data only on documented instructions from the Customer (including as set out in these Terms and the DPA) and as necessary to provide the Services, unless required to do so by applicable law.
- Ensure that authorized personnel with access to Customer Data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organizational measures to protect Customer Data against unauthorized or unlawful processing, accidental loss, destruction, or damage.
- Not engage Subprocessors without appropriate data processing agreements and security protections.
- Provide reasonable assistance to the Customer in connection with the Customer's obligations to respond to data subject requests, conduct data protection impact assessments, implement security measures, and notify supervisory authorities or data subjects of personal data breaches, to the extent Noviqo's assistance is required and technically feasible.
- Notify the Customer without undue delay after becoming aware of a personal data breach involving Customer Data, including information reasonably available to Noviqo about the nature, scope, and likely consequences of the breach.
- Upon termination of the Services or upon written request, delete or return Customer Data as directed by the Customer, subject to applicable legal retention obligations.
- Make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA upon written request.
4. Customer's Processing Obligations
The Customer is responsible for:
- The lawfulness of the instructions it provides to Noviqo for processing Customer Data.
- Having a lawful basis for the collection and processing of all Customer Data submitted to the Services.
- Providing required notices and obtaining required consents from data subjects whose personal data is processed through the Services.
- Ensuring that the categories of personal data submitted to the Services and the purposes for which they are processed are consistent with Applicable Data Protection Law.
- Responding to data subject requests in respect of Customer Data (with Noviqo's assistance where required).
- Maintaining its own records of processing activities as required by Applicable Data Protection Law.
5. Subprocessors
The Customer authorizes Noviqo to engage Subprocessors to assist in providing the Services. Noviqo will ensure that each Subprocessor is bound by data processing obligations that are at least as protective as those in this DPA.
Noviqo's current Subprocessors include AI model providers, telephony infrastructure providers, messaging aggregators, cloud hosting providers, payment processors, and email delivery services. A current list of Subprocessors is available upon written request.
If Noviqo intends to engage a new Subprocessor that will process Customer Data, Noviqo will provide reasonable prior notice to the Customer. The Customer may object in writing within 14 days; if the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty.
6. International Data Transfers
Noviqo is based in the United States. Customer Data may be transferred to and processed in the United States and other countries where Noviqo's Subprocessors operate.
Where Applicable Data Protection Law requires a mechanism for lawful international data transfers (such as EU Standard Contractual Clauses or UK IDTA), Noviqo will implement or rely on an appropriate transfer mechanism. The parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor, as adopted by the European Commission) are hereby incorporated into this DPA to the extent required for transfers of Customer Data from the EEA. The UK IDTA or UK Addendum to the EU SCCs applies as required for transfers from the UK.
7. Security Measures
Noviqo will implement and maintain appropriate technical and organizational measures to protect Customer Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects. Such measures may include:
- Encryption of data in transit and at rest.
- Access controls and authentication requirements for systems that process Customer Data.
- Procedures for regularly testing and evaluating the effectiveness of security measures.
- Policies and training for personnel with access to Customer Data.
- Physical and environmental safeguards for systems that store or process Customer Data.
The specific measures in place may be updated from time to time to reflect technological changes and evolving security standards. Security measure details are available upon written request.
8. Data Subject Rights
Noviqo will provide reasonable technical assistance to the Customer in responding to data subject requests (including requests for access, rectification, erasure, restriction, portability, and objection). The Customer is responsible for handling and responding to data subject requests; Noviqo will provide assistance to the extent technically feasible and as directed by the Customer.
If a data subject contacts Noviqo directly with a request, Noviqo will notify the Customer and direct the data subject to the Customer for response.
9. Audit and Compliance
Upon written request and subject to reasonable conditions, Noviqo will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA. The Customer may request an audit of Noviqo's data processing activities no more than once per year, subject to reasonable notice and confidentiality requirements, and at the Customer's expense. Noviqo may satisfy audit rights by providing relevant third-party audit reports, certifications, or other documentation.
10. Term and Termination
This DPA remains in effect for as long as Noviqo processes Customer Data under the Terms of Service. Upon expiration or termination of the Terms of Service, Noviqo will delete or return Customer Data in accordance with Section 3(7) and the Terms of Service, unless applicable law requires retention.
11. Order of Precedence
In the event of a conflict between this DPA and the Terms of Service with respect to data processing matters, this DPA will control. In the event of a conflict between this DPA and applicable Standard Contractual Clauses or IDTA, the Standard Contractual Clauses or IDTA will control.
12. Contact
For data protection inquiries or to request a countersigned DPA for enterprise compliance purposes:
Noviqo LLC
California, United States
Email: privacy@noviqoai.com