Legal
Data Processing Agreement
When a business hands its operation to us, it is handing us its customers' data. This is how we hold it.
Last updated: June 2026
This page summarizes the terms under which Auctus Apex LLC processes personal data on behalf of its clients. The executable Data Processing Agreement, which forms part of the engagement, is provided and signed on request. Where it and an individual engagement differ, the signed agreement governs.
1. Roles
In most engagements the client is the controller of the personal data that moves through the systems we build, and Auctus Apex acts as the processor. We handle that data only to operate the service the client has asked us to run, on the client's documented instructions, and for no other purpose.
2. What we process
The data depends on the operation. It is usually the information that arrives at the front door of a business: a caller's name and number, a booking, a message, an inquiry, the context attached to it, and the record it becomes. We process the minimum required to run the service and to keep it secure and accountable.
3. Purpose limitation
Customer data is used to provide, secure, and operate the service, and for nothing else. It is not sold, not shared across unrelated clients, and not used to train foundation models. The one exception is described on our security page, and it applies only where a client has agreed to it in writing.
4. Security
Data is encrypted in transit and at rest. Access is scoped to a client's tenant, granted on a need-to-know basis, and logged. Inbound surfaces are protected by rate limiting, challenge verification, and abuse detection. Controls are reviewed and tightened as the operation grows.
5. Sub-processors
We use a small, deliberately selected set of sub-processors to run the service. The current list, what each one touches, and where it sits is maintained and provided to clients under agreement. See the Sub-processors page.
6. Data location and retention
Data location and retention are set per engagement and stated in the agreement. We hold data only as long as it is needed to run the service or as the client instructs, and we delete or return it on termination, on the terms agreed in writing.
7. Incident notification
If a personal data breach affecting a client's data occurs, we notify the client without undue delay, with what we know and what we are doing about it, so they can meet their own obligations.
8. Data subject requests and audits
We assist clients in responding to requests from the people whose data they control, and we make available the information reasonably necessary to demonstrate compliance, on the terms set out in the agreement.
Request the agreement
To review or sign the Data Processing Agreement, contact privacy@auctusapex.com.