Skip to content

Data processing agreement

The agreement under which Infraexa processes personal data on your servers on your behalf.

Updated October 2026

Pending legal review. This document describes how Infraexa intends to operate and will be finalised by counsel before customer signature.

1. Roles

You are the controller of personal data stored or processed on your servers. Infraexa is a processor in so far as the operations layer touches that data, for example when restoring a backup. Infraexa does not access application data except on your instruction or where strictly necessary to deliver the service.

2. Instructions

Infraexa processes personal data only on your documented instructions, including the package description, support requests and approved change proposals.

3. Security

Infraexa applies the measures described on the security page: hardened systems, encrypted backups, access control, audit logging and vulnerability management.

4. Sub-processors

Infraexa uses the sub-processors listed on the sub-processors page and gives 30 days notice of changes, during which you may object.

5. Location

All processing takes place within the European Union. No transfers outside the EU occur unless you initiate them.

6. Assistance and deletion

Infraexa assists with data subject requests, impact assessments and breach notifications within 48 hours of becoming aware of an incident. On termination data is deleted or returned as you instruct, and erased from backups at the end of the retention period.