This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“you,” the Business) and Apexor Analytics & Consulting Pvt. Ltd. (“Apexor,” the Service Provider) and governs Apexor’s processing of personal information contained in Customer Data on your behalf. It takes effect when you accept the Terms or sign an Order.
1Roles & scope
You are the Business (controller) that determines the purposes and means of processing Customer Data. Apexor is your Service Provider (processor) and processes Customer Data only to provide the Services and on your documented instructions (the Terms, your Order, and your use of the Platform are your instructions). “Personal information” has the meaning given under the CCPA/CPRA.
2Apexor’s service-provider commitments
Apexor will:
- process Customer Data only to perform the Services for you, and not for any other purpose;
- not sell or share Customer Data (as “sell” and “share” are defined under the CPRA);
- not retain, use, or disclose Customer Data outside the direct business relationship with you, and not combine it with personal information from other sources except as permitted by the CCPA for a service provider;
- keep Customer Data confidential and ensure personnel with access are bound by confidentiality obligations; and
- notify you if it determines it can no longer meet these obligations.
Apexor certifies that it understands and will comply with these restrictions.
3Security
Apexor maintains technical and organizational measures designed to protect Customer Data, described in Annex B and summarized in our security & data-isolation overview, including encryption in transit, access controls, tenant isolation, and monitoring.
4Sub-processors
You authorize Apexor to engage the sub-processors listed in Annex C to help provide the Services. Apexor will impose data-protection terms on each sub-processor that are no less protective than this DPA, and remains responsible for their performance. Apexor will give notice of a new sub-processor before it begins processing Customer Data; you may object on reasonable data-protection grounds, and the parties will work in good faith to resolve the concern.
5Assistance & consumer requests
Taking into account the nature of the processing, Apexor will provide reasonable assistance so you can respond to verifiable consumer requests (access, deletion, correction) and meet your security and assessment obligations. If Apexor receives a request directly from a consumer, it will, unless legally required to act, direct them to you.
6Security incidents
Apexor will notify you without undue delay after becoming aware of a breach of security leading to the unauthorized access, disclosure, or loss of Customer Data, and will provide information reasonably available to help you meet your notification obligations.
7Return & deletion
On termination, you may export Customer Data. After a wind-down period stated in the Terms or your Order, Apexor will delete or de-identify Customer Data, except where retention is required by law.
8Audits & liability
On reasonable written request and no more than once per year (unless required by a regulator), Apexor will make available information necessary to demonstrate compliance with this DPA. Each party’s liability under this DPA is subject to the limitations in the Terms or MSA. If this DPA conflicts with those, this DPA controls for data-protection matters.
AAnnex A — Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Apexor Platform and related services. |
| Duration | The term of the agreement, plus the wind-down period. |
| Nature & purpose | Hosting, storing, organizing, and transmitting Customer Data; running CRM, scheduling, messaging, and AI features at your direction. |
| Data subjects | Your leads, prospects, customers, and your own users/staff. |
| Personal information | Names, contact details (email, phone, address), communications and call records, appointment and pipeline data, and other data you choose to store. |
BAnnex B — Security measures
- Encryption of data in transit (TLS); encryption at rest where provided by our infrastructure.
- Role-based access controls and least-privilege access for personnel.
- Multi-tenant isolation so one customer cannot access another’s data.
- Secrets management and environment separation.
- Logging, monitoring, and regular backups.
CAnnex C — Sub-processors
The following are representative current sub-processors; the live list may change with notice under Section 4.
| Sub-processor | Purpose |
|---|---|
| Vercel | Application hosting & delivery |
| Neon / Supabase | Managed database |
| Vercel Blob | File & media storage |
| Resend | Transactional & platform email |
| Twilio | SMS & WhatsApp messaging |
| Vapi | AI voice calling |
| Anthropic / OpenAI | AI model processing |
| Maps & sign-in (OAuth) | |
| Cashfree / Stripe | Payment processing |
