This Data Processing Agreement ("DPA") forms part of the subscription agreement between Radiqx ("Processor") and the Customer ("Controller") and governs the processing of personal data by Radiqx on behalf of the Customer in connection with the Radiqx Ledger platform, RDX Planning, ChatRDX, and associated services (the "Services").
This DPA applies where Customer Data submitted to the Services includes personal data subject to applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent legislation in other jurisdictions.
Radiqx processes Personal Data solely to provide the Services described in the subscription agreement and as directed by the Customer. The subject matter, nature, purpose, and duration of processing are determined by the Customer's use of the Services and the applicable subscription term.
Personal Data processed through the Services may relate to the following categories of data subjects: Customer employees and contractors who are provisioned as users of the Services; individuals whose identity information appears in Customer-managed metadata structures, hierarchies, or organizational data submitted to the Services.
Categories of Personal Data that may be processed include: user account information (name, email address, job title, organizational role); access logs and activity records associated with named user accounts; and any personal data embedded in Customer-submitted metadata structures, governance records, or change request content.
Radiqx processes Personal Data only on documented instructions from the Customer, including as set forth in the subscription agreement and this DPA. Radiqx will promptly notify the Customer if it believes an instruction violates applicable data protection law.
Radiqx ensures that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
Radiqx implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, taking into account the nature of the data and the risks involved. Measures include:
Radiqx provides reasonable assistance to the Customer in responding to data subject requests to exercise rights under applicable data protection law, taking into account the nature of the processing and the information available to Radiqx. Customer is responsible for handling data subject requests directed to it.
Radiqx provides reasonable assistance to the Customer in carrying out data protection impact assessments and prior consultations with supervisory authorities where required, to the extent such assistance relates to Radiqx's processing activities.
Customer authorizes Radiqx to engage the following sub-processors in connection with the Services:
Radiqx will notify Customers of any intended addition or replacement of sub-processors at least thirty (30) days in advance. If Customer reasonably objects to a new sub-processor on data protection grounds, the parties will work in good faith to resolve the objection.
Radiqx imposes data protection obligations on all sub-processors that are no less restrictive than those set forth in this DPA and remains liable to the Customer for the performance of sub-processors' obligations.
Radiqx primarily operates infrastructure in the United States. Where Personal Data of data subjects located in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside those regions, such transfers are made in accordance with applicable transfer mechanisms, including Standard Contractual Clauses (SCCs) as adopted by the European Commission or equivalent mechanisms under UK or Swiss law.
Enterprise customers with specific data residency requirements should contact Radiqx to discuss available dedicated infrastructure configurations that may address jurisdiction-specific requirements.
Radiqx maintains incident detection and response procedures appropriate to the nature and scale of its processing activities. In the event of a confirmed security incident involving Personal Data, Radiqx will:
Upon Customer's written request, and no more than once per calendar year unless a security incident has occurred, Radiqx will provide information reasonably necessary to demonstrate compliance with this DPA. Radiqx may satisfy audit requests by providing relevant third-party audit reports, certifications, or attestations in lieu of direct Customer audits, where such documentation reasonably addresses the scope of the request.
Upon termination or expiration of the subscription, Radiqx will make Customer Data, including Personal Data, available for export for thirty (30) days following the termination date. After this period, Radiqx will delete or anonymize Personal Data from production systems within ninety (90) days, subject to backup retention cycles. Radiqx will, upon request, provide written confirmation of deletion. Radiqx may retain Personal Data where required by applicable law, for the minimum period required.
Customer, as Controller, represents and warrants that: it has a lawful basis for processing Personal Data and for instructing Radiqx to process Personal Data on its behalf; it has provided all required notices and obtained all required consents from data subjects as required by applicable law; and its instructions to Radiqx comply with applicable data protection law.
This DPA is governed by the same law as the underlying subscription agreement. For customers subject to GDPR, this DPA incorporates the applicable Standard Contractual Clauses by reference, and in the event of conflict between this DPA and the SCCs, the SCCs shall prevail with respect to GDPR-regulated processing.
For DPA inquiries, sub-processor questions, or data protection matters:
Radiqx · privacy@radiqxledger.com
info.radiqxledger.com · Radiqx Ledger Platform