Data processing agreement
The agreement under which Infraexa processes personal data on your servers on your behalf.
Updated October 2026
Pending legal review. This document describes how Infraexa intends to operate and will be finalised by counsel before customer signature.
1. Roles
You are the controller of personal data stored or processed on your servers. Infraexa is a processor in so far as the operations layer touches that data, for example when restoring a backup. Infraexa does not access application data except on your instruction or where strictly necessary to deliver the service.
2. Instructions
Infraexa processes personal data only on your documented instructions, including the package description, support requests and approved change proposals.
3. Security
Infraexa applies the measures described on the security page: hardened systems, encrypted backups, access control, audit logging and vulnerability management.
4. Sub-processors
Infraexa uses the sub-processors listed on the sub-processors page and gives 30 days notice of changes, during which you may object.
5. Location
All processing takes place within the European Union. No transfers outside the EU occur unless you initiate them.
6. Assistance and deletion
Infraexa assists with data subject requests, impact assessments and breach notifications within 48 hours of becoming aware of an incident. On termination data is deleted or returned as you instruct, and erased from backups at the end of the retention period.