Legal & compliance
Data Processing Addendum
These are the Article 28 processing terms between Axon and customer organizations. They form part of the Terms of Service and take effect on acceptance of those terms.
Last updated: August 12, 2026 · 19 sections
Parties and Scope
This Data Processing Addendum ('DPA') is entered into between HERSTELLUNG SRL, a company registered in Romania, trading as XDBX Europe ('Axon', 'we', 'us'), and the customer organization that has accepted the Axon Terms of Service ('Customer', 'you').
This DPA applies whenever Axon processes personal data on Customer's behalf in connection with the Axon platform, and forms part of the Terms of Service. It is accepted at the same time as those terms and requires no separate signature.
Where Customer is subject to the GDPR, UK GDPR, or the Swiss FADP, this DPA is the written contract required by Article 28(3) GDPR and its equivalents.
Definitions
'Customer Personal Data' means personal data contained in Customer's workspace and processed by Axon on Customer's behalf under the Terms of Service.
'Controller', 'Processor', 'Data Subject', 'Personal Data Breach', 'Processing', and 'Supervisory Authority' have the meanings given in the GDPR.
'Data Protection Law' means the GDPR, the UK GDPR, the Swiss FADP, and any other data protection law applicable to a party's processing under this DPA.
'Subprocessor' means a third party engaged by Axon to process Customer Personal Data.
Roles of the Parties
Customer is the Controller of Customer Personal Data and Axon is the Processor, except where Customer is itself a processor acting for a third-party controller, in which case Axon is a subprocessor and Customer warrants that it has the authority to instruct Axon on that controller's behalf.
Axon acts as an independent Controller for the limited data it collects in its own right, including account registration data, billing records, support and privacy requests, and security and audit logs. That processing is governed by the Axon Privacy Policy rather than this DPA.
Customer is responsible for the lawfulness of the personal data it submits to the platform, for establishing a legal basis for the processing, and for providing any notices or obtaining any consents required from its own personnel and users.
Processing Instructions
Axon shall process Customer Personal Data only on Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law. Where such a legal requirement applies, Axon shall inform Customer before processing unless that law prohibits it on important grounds of public interest.
The Terms of Service, this DPA, Customer's configuration of the platform, and Customer's use of platform features constitute Customer's complete documented instructions. Any additional instruction requires written agreement between the parties.
Axon shall not sell Customer Personal Data, shall not use it for its own purposes, and shall not use it to train machine learning models.
Axon shall inform Customer without delay if, in its opinion, an instruction infringes Data Protection Law.
Confidentiality of Personnel
Axon shall ensure that persons authorized to process Customer Personal Data are bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that the obligation survives the end of their engagement.
Axon shall limit access to Customer Personal Data to personnel who require it to deliver, support, or secure the platform.
Security of Processing
Axon shall implement and maintain the technical and organisational measures set out in Annex II, which are designed to provide a level of security appropriate to the risk in accordance with Article 32 GDPR.
Axon may update those measures over time provided that the overall level of security is not reduced.
Customer is responsible for its own configuration of the platform, including role assignment, permission scoping, multi-factor authentication policy, and the secure handling of credentials within its organization.
Subprocessors
Customer grants Axon general authorization to engage Subprocessors. The Subprocessors engaged as at the effective date of this DPA are listed in Annex III and on the Axon subprocessor page.
Axon shall give Customer at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data. Customer may subscribe to those notices through the legal contact listed on this page.
Customer may object to a new Subprocessor on reasonable data protection grounds within the notice period. If the parties cannot agree on a resolution, Customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees for the remainder of the term.
Axon shall impose on each Subprocessor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor's performance.
Assistance with Data Subject Rights
Taking into account the nature of the processing, Axon shall assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
The platform provides self-service access, export, correction, and deletion tooling that allows Customer to respond to most requests without Axon's involvement. Axon shall provide additional assistance where a request cannot be fulfilled through those features.
If Axon receives a request directly from a data subject relating to Customer Personal Data, Axon shall not respond to it substantively and shall refer the data subject to Customer, informing Customer without undue delay.
Personal Data Breach
Axon shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notification shall describe, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not available at once, it shall be provided in phases without further undue delay.
Axon shall take reasonable steps to contain and remediate the breach, and shall assist Customer in meeting its own notification obligations under Articles 33 and 34 GDPR.
Axon's notification is not an acknowledgement of fault or liability.
Impact Assessments and Prior Consultation
Taking into account the nature of the processing and the information available to it, Axon shall provide reasonable assistance to Customer with data protection impact assessments under Article 35 GDPR and with prior consultation of a Supervisory Authority under Article 36 GDPR.
That assistance is limited to the processing carried out by Axon on Customer's behalf, and may be provided in the form of the documentation Axon makes generally available.
Return and Deletion
Customer may export its data at any time during the term using the platform's export features.
Following termination or expiry of the Terms of Service, Axon shall, at Customer's choice, return or delete Customer Personal Data. Customer may make that choice at any time up to 30 days after termination; if Customer makes no choice within that period, Axon shall delete the data.
Axon shall complete deletion within 60 days of termination, except where retention is required by Union or Member State law, in which case Axon shall retain only what that law requires and only for as long as it requires.
Residual copies held in routine backups are isolated from production access and are deleted on expiry of the applicable backup cycle.
Certain records that Axon holds as an independent Controller, including security audit logs and privacy or support request records, are retained on the schedules described in the Privacy Policy and are not affected by this section.
Audits and Information
Axon shall make available to Customer the information necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
Customer's audit right is satisfied in the first instance by the documentation Axon makes available, including the security overview, the subprocessor list, and Axon's responses to a reasonable security questionnaire, which Customer may request once in any 12-month period.
An on-site inspection may be conducted where required by a Supervisory Authority, where a Personal Data Breach has occurred, or where the documentation provided is demonstrably insufficient. Such inspections shall be conducted on at least 30 days' written notice, during business hours, subject to confidentiality obligations, and in a manner that does not disrupt the platform or the data of other customers.
International Transfers
Axon is established in the European Union, and Customer Personal Data is stored in the European Union: database and file storage run in Google Cloud's eur3 European multi-region, with application hosting in Frankfurt. The processing of Customer Personal Data by Axon does not itself involve a transfer to a third country.
Where a Subprocessor processes Customer Personal Data outside the European Economic Area, Axon shall ensure that the transfer is covered by an appropriate transfer mechanism under Chapter V GDPR, which for onward transfers to Subprocessors means the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Three, or another mechanism recognised as providing an adequate level of protection.
For Customer Personal Data subject to the UK GDPR, the UK International Data Transfer Addendum applies to those transfers. For data subject to the Swiss FADP, the Standard Contractual Clauses apply with the amendments required by the Swiss Federal Data Protection and Information Commissioner. Executed copies are available from the legal contact below.
Liability, Precedence, and Governing Law
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
In the event of a conflict between this DPA and the Terms of Service in relation to the processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
This DPA is governed by the laws of Romania, and the courts of Romania have jurisdiction over disputes arising from it, without prejudice to the jurisdiction and governing law provisions of the Standard Contractual Clauses where those apply.
If any provision of this DPA is held invalid or unenforceable, the remainder continues in effect.
Changes to this DPA
Axon may update this DPA where required to reflect a change in Data Protection Law, guidance from a Supervisory Authority, a change in Subprocessors, or a change in the platform, provided that the update does not reduce the protections afforded to Customer Personal Data.
Material changes are notified in advance through the effective date on this page and, where Customer has subscribed to them, through Subprocessor change notices.
Requesting a Signed Copy
This DPA is binding on acceptance of the Terms of Service, and no signature is required for it to take effect.
Customers whose procurement process requires a countersigned copy, or who require the UK Addendum or Swiss annex executed separately, may request one from the legal contact below, including the organization's full legal name, registered address, and contracting entity details.
Annex I — Description of the Processing
Subject matter: provision of the Axon platform for shared spaces and teams, comprising the Orbis (scheduling), Locus (bookings and availability), Atlas (floorplan and space mapping), and Civitas (people workflows) modules, together with the web application and the Axon mobile apps.
Duration: for the term of the Terms of Service, plus the deletion period described under Return and Deletion.
Nature and purpose: hosting, storage, transmission, and display of Customer Personal Data in order to operate the modules Customer has enabled; authentication and access control; delivery of notifications; and the security, availability, and support of the platform.
Categories of data subjects: Customer's personnel, administrators, and other individuals to whom Customer grants access to its workspace, and individuals whose details Customer records in the platform, such as booking participants and applicants.
Categories of personal data: identity and contact data (name, work email); account and authentication data (credentials metadata, multi-factor authentication state, login events, session and device identifiers); organizational data (team, role, permissions, and directory attributes received via SSO or SCIM); product data submitted to the enabled modules (bookings, schedules, availability, space assignments, people workflow records and attachments); and notification data (push subscription endpoints and device tokens).
Where Customer enables the Civitas module, the categories additionally include employee record data: extended identity data (legal and maiden name, gender, date of birth, national identification number), personal contact data (home address, personal email address, phone number), a bank account number recorded as a payroll reference, employment and contract data (position, department, contract type and dates, employing entity, country of origin and residence, seniority), leave balances and requests, benefit entries, and documents uploaded to an employee file. Customer determines which of these fields it uses. Axon stores and displays them and performs no payment, payroll, or onward transmission of the bank account field.
Special categories of data: not requested by the platform and not required for its operation. The platform provides no field designated for special category data, and Axon does not derive or infer it. Customer is responsible for any special category data it chooses to submit through free-text fields, custom leave type labels, benefit notes, request descriptions, or uploaded documents, including any health data implied by an absence category it defines, and for the lawful basis and additional safeguards such data requires under Articles 9 and 32 GDPR. Customer is likewise responsible for the safeguards that national law may attach to identifiers of general application, such as national identification numbers, where it records them.
Frequency of processing: continuous for the duration of the Terms of Service.
Annex II — Technical and Organisational Measures
Access control: session-based authentication with multi-factor authentication and organization-level policy controls; optional enterprise single sign-on via SAML or OIDC; SCIM directory provisioning with automatic deactivation, where deprovisioning a user revokes that user's sessions; role-based permissions with scoped authorization; user-visible active device sessions with per-device and global sign-out.
Tenant isolation: every org-scoped read and write is bound to an organization identifier, and referenced entities are verified to belong to the same organization before they are acted on.
Application security: state-changing endpoints are protected by origin checks, application attestation, authenticated identity verification, and schema validation of payloads; rate limiting and CAPTCHA verification protect abuse-prone and public endpoints; a content security policy and related security headers are enforced on all pages.
Encryption: data is encrypted in transit using TLS, and encrypted at rest by the underlying Google Cloud storage infrastructure.
Logging and traceability: privileged operations are recorded to an audit log including the acting identity, IP address, and user agent, and those records expire automatically after two years.
Data minimisation and retention: privacy requests, support requests and their message history, and audit logs carry automatic expiry after two years.
Availability and resilience: the platform runs on managed Google Cloud and Vercel infrastructure with the redundancy and backup characteristics of those services.
Incident management: service behaviour is monitored, suspected security issues are investigated, and affected customers are notified in accordance with the Personal Data Breach section of this DPA.
Personnel: access to Customer Personal Data is limited to personnel who require it, under confidentiality obligations.
Annex III — Authorized Subprocessors
Google (Firebase and Google Cloud) — authentication, database, file storage, push notification delivery, product analytics, and platform infrastructure. Processing location: European Union (eur3 multi-region).
Google (reCAPTCHA) — abuse and bot protection on public forms and application attestation.
Vercel — application hosting, serverless execution, and content delivery. Primary compute region: Frankfurt, European Union.
Stripe — subscription billing and payment processing.
Resend — transactional, notification, and inbound support email processing where configured.
Apple and Google — distribution of the Axon mobile apps and delivery of push notifications to enrolled devices.
The current list is maintained on the Axon subprocessor page, which prevails over this annex where the two differ.
Contact
For legal, privacy, or compliance requests
Email: [email protected]
Product URL: https://axon.xdbx.eu
Related docs: Subprocessor List, Security Overview, Privacy Policy, Terms of Service.
This DPA forms part of the Axon Terms of Service and is binding on acceptance of those terms. Customers requiring a countersigned copy, or the UK Addendum or Swiss annex executed separately, can request one at the address above.