Data Processing Agreement

Last updated: 9/23/2025

1. Purpose and Scope

This Data Processing Agreement (DPA) governs the processing of personal data by AutoX B2B on behalf of our clients in connection with our automation services, ensuring compliance with applicable data protection laws including GDPR.

2. Definitions

  • Controller: The client who determines the purposes and means of processing
  • Processor: AutoX B2B, processing personal data on behalf of the Controller
  • Personal Data: Any information relating to an identified or identifiable person
  • Processing: Any operation performed on personal data

3. Processing Activities

AutoX B2B processes personal data for the following purposes:

  • Lead generation and scoring automation
  • CRM workflow automation and management
  • Communication automation (email, SMS, WhatsApp)
  • Appointment scheduling and reminder systems
  • Reporting and analytics generation

4. Data Subject Categories

Personal data may relate to the following categories of data subjects:

  • Prospective customers and leads
  • Existing customers and clients
  • Business contacts and partners
  • Website visitors and form submitters

5. Security Measures

AutoX B2B implements appropriate technical and organizational measures including:

  • Encryption of personal data in transit and at rest
  • Access controls and authentication mechanisms
  • Regular security assessments and penetration testing
  • Employee training on data protection and security
  • Incident response and breach notification procedures

6. Sub-processors

AutoX B2B may engage sub-processors to assist in providing services. Current sub-processors include:

  • Cloud infrastructure providers (AWS, Google Cloud, Azure)
  • Communication service providers (Twilio, SendGrid)
  • Analytics and monitoring tools

Clients will be notified of any changes to sub-processors with 30 days advance notice.

7. Data Subject Rights

AutoX B2B will assist clients in responding to data subject requests including:

  • Access requests and data portability
  • Rectification of inaccurate data
  • Erasure requests ("right to be forgotten")
  • Restriction of processing
  • Objection to processing

8. Data Retention and Deletion

Personal data will be retained only as long as necessary for the purposes outlined in the service agreement. Upon termination of services, AutoX B2B will delete or return all personal data within 90 days, unless legally required to retain certain data.

9. Contact Information

For questions about data processing or to exercise data subject rights, please contact:

Email: 20ucs195@lnmiit.ac.in

Subject: Data Processing Inquiry