This Data Processing Agreement ("DPA") forms part of the subscription agreement between Radiqx ("Processor") and the Customer ("Controller") and governs the processing of personal data by Radiqx on behalf of the Customer in connection with the Radiqx Ledger platform, RDX Planning, ChatRDX, and associated services (the "Services").

This DPA applies where Customer Data submitted to the Services includes personal data subject to applicable data protection laws, including but not limited to the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and equivalent legislation in other jurisdictions.

This DPA is incorporated by reference into the Customer's subscription agreement and Order Form. By executing a subscription agreement, Customer agrees to the terms of this DPA.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is included in Customer Data submitted to the Services.
  • "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, or deletion.
  • "Controller" means the Customer, who determines the purposes and means of processing Personal Data.
  • "Processor" means Radiqx, who processes Personal Data on behalf of the Controller.
  • "Sub-processor" means any third party engaged by Radiqx to assist in processing Personal Data.
  • "Data Subject" means the natural person to whom Personal Data relates.
  • "Supervisory Authority" means the competent data protection regulatory authority in the applicable jurisdiction.

2.1 Subject Matter

Radiqx processes Personal Data solely to provide the Services described in the subscription agreement and as directed by the Customer. The subject matter, nature, purpose, and duration of processing are determined by the Customer's use of the Services and the applicable subscription term.

2.2 Categories of Data Subjects

Personal Data processed through the Services may relate to the following categories of data subjects: Customer employees and contractors who are provisioned as users of the Services; individuals whose identity information appears in Customer-managed metadata structures, hierarchies, or organizational data submitted to the Services.

2.3 Categories of Personal Data

Categories of Personal Data that may be processed include: user account information (name, email address, job title, organizational role); access logs and activity records associated with named user accounts; and any personal data embedded in Customer-submitted metadata structures, governance records, or change request content.

3.1 Instructions

Radiqx processes Personal Data only on documented instructions from the Customer, including as set forth in the subscription agreement and this DPA. Radiqx will promptly notify the Customer if it believes an instruction violates applicable data protection law.

3.2 Confidentiality

Radiqx ensures that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

3.3 Security Measures

Radiqx implements and maintains appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, taking into account the nature of the data and the risks involved. Measures include:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest;
  • Post-quantum cryptographic protections for audit ledger records (ML-DSA-65);
  • Role-based access controls and Row Level Security enforced at the database layer;
  • Dedicated database instances for enterprise-tier customers;
  • Regular access reviews and principle of least privilege;
  • Incident detection and response procedures.

3.4 Data Subject Rights

Radiqx provides reasonable assistance to the Customer in responding to data subject requests to exercise rights under applicable data protection law, taking into account the nature of the processing and the information available to Radiqx. Customer is responsible for handling data subject requests directed to it.

3.5 Data Protection Impact Assessments

Radiqx provides reasonable assistance to the Customer in carrying out data protection impact assessments and prior consultations with supervisory authorities where required, to the extent such assistance relates to Radiqx's processing activities.

4.1 Authorized Sub-processors

Customer authorizes Radiqx to engage the following sub-processors in connection with the Services:

  • Supabase, Inc. — database infrastructure, storage, and Row Level Security enforcement. Data residency: United States.
  • Vercel, Inc. — application hosting, serverless function execution, and edge delivery. Data residency: United States and global edge network.
  • Clerk, Inc. — identity management, authentication, and user provisioning. Data residency: United States.
  • Anthropic, PBC — AI Governance Advisor query processing. Anthropic processes governance queries submitted through the AI Advisor feature; it does not receive or retain Customer Data for model training purposes.

4.2 Sub-processor Changes

Radiqx will notify Customers of any intended addition or replacement of sub-processors at least thirty (30) days in advance. If Customer reasonably objects to a new sub-processor on data protection grounds, the parties will work in good faith to resolve the objection.

4.3 Sub-processor Obligations

Radiqx imposes data protection obligations on all sub-processors that are no less restrictive than those set forth in this DPA and remains liable to the Customer for the performance of sub-processors' obligations.

Radiqx primarily operates infrastructure in the United States. Where Personal Data of data subjects located in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside those regions, such transfers are made in accordance with applicable transfer mechanisms, including Standard Contractual Clauses (SCCs) as adopted by the European Commission or equivalent mechanisms under UK or Swiss law.

Enterprise customers with specific data residency requirements should contact Radiqx to discuss available dedicated infrastructure configurations that may address jurisdiction-specific requirements.

Radiqx maintains incident detection and response procedures appropriate to the nature and scale of its processing activities. In the event of a confirmed security incident involving Personal Data, Radiqx will:

  • Notify the Customer without undue delay and no later than seventy-two (72) hours after becoming aware of the incident;
  • Provide available information regarding the nature of the incident, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the incident;
  • Cooperate with the Customer and provide reasonable assistance in notifying relevant supervisory authorities and affected data subjects where required.

Upon Customer's written request, and no more than once per calendar year unless a security incident has occurred, Radiqx will provide information reasonably necessary to demonstrate compliance with this DPA. Radiqx may satisfy audit requests by providing relevant third-party audit reports, certifications, or attestations in lieu of direct Customer audits, where such documentation reasonably addresses the scope of the request.

Upon termination or expiration of the subscription, Radiqx will make Customer Data, including Personal Data, available for export for thirty (30) days following the termination date. After this period, Radiqx will delete or anonymize Personal Data from production systems within ninety (90) days, subject to backup retention cycles. Radiqx will, upon request, provide written confirmation of deletion. Radiqx may retain Personal Data where required by applicable law, for the minimum period required.

Customer, as Controller, represents and warrants that: it has a lawful basis for processing Personal Data and for instructing Radiqx to process Personal Data on its behalf; it has provided all required notices and obtained all required consents from data subjects as required by applicable law; and its instructions to Radiqx comply with applicable data protection law.

This DPA is governed by the same law as the underlying subscription agreement. For customers subject to GDPR, this DPA incorporates the applicable Standard Contractual Clauses by reference, and in the event of conflict between this DPA and the SCCs, the SCCs shall prevail with respect to GDPR-regulated processing.

Data Protection Contact

For DPA inquiries, sub-processor questions, or data protection matters:

Radiqx · privacy@radiqxledger.com

info.radiqxledger.com · Radiqx Ledger Platform