Data Processing Agreement
Version 1.0 · Last updated: 29 July 2026 · Provided by Pyraxis Solutions ("Pyraxis", "Processor", "we", "us").
This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the agreement between Pyraxis Solutions and the customer that has licensed the Pyraxis application (the "Agreement"). It governs the Processing of Personal Data by Pyraxis on behalf of the Customer and reflects the parties' agreement on data protection, in a form intended to be equivalent in substance and coverage to the Microsoft Products and Services Data Protection Addendum.
Read this first — Pyraxis is local-first. The Pyraxis application, its AI models, and its data storage run entirely on the Customer's own devices. In normal use Pyraxis does not receive, transmit, or store Customer Content on servers we operate. As a result, most Customer Personal Data is Processed only on-device, under the Customer's sole control. The limited Processing that Pyraxis performs as a Processor is described in Appendix A and is confined to (i) licensing and account administration and (ii) any third-party accounts the Customer chooses to connect.
Notice. This document is a contractual template provided for transparency and to support enterprise procurement. It is not legal advice. Customers with specific regulatory obligations should have this DPA reviewed by their own counsel, and — where a countersigned instrument is required — request an executed copy from privacy@pyraxis.dev.
Contents
1. Definitions 2. Roles & scope 3. Processing instructions 4. Compliance & confidentiality 5. Security 6. Sub-processors 7. Data subject rights 8. Breach notification 9. DPIA & consultation 10. International transfers 11. Return & deletion 12. Audits 13. CCPA / US state laws 14. General Appendix A — Details of Processing Appendix B — Security Measures Appendix C — Sub-processors
1. Definitions
Capitalised terms not defined here have the meaning given in Data Protection Laws or the Agreement.
- "Data Protection Laws" means all laws applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Singapore Personal Data Protection Act 2012 ("PDPA"), and the California Consumer Privacy Act as amended by the CPRA ("CCPA").
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing" and "Personal Data Breach" have the meanings given in the GDPR.
- "Customer Content" means the documents, mail, calendar, records, and other data the Customer or its users create, process, or connect within the Pyraxis application, which resides on the Customer's devices.
- "Customer Personal Data" means Personal Data contained in Customer Content or in account/licensing data, Processed by Pyraxis on the Customer's behalf under the Agreement.
- "Sub-processor" means a third party engaged by Pyraxis to Process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the clauses annexed to EU Commission Implementing Decision (EU) 2021/914, and, for UK transfers, the UK International Data Transfer Addendum.
2. Roles and scope of Processing
- Roles. As between the parties, the Customer is the Controller (or a Processor acting on behalf of its own controllers) of Customer Personal Data, and Pyraxis is the Processor. Where Pyraxis Processes Personal Data for its own business administration (e.g. to invoice, provide support, ensure security, and comply with law), Pyraxis acts as an independent Controller for that limited purpose, as described in its Privacy Policy.
- Scope. Because Pyraxis is local-first, the great majority of Customer Content is Processed only on the Customer's devices and is never transmitted to Pyraxis. Pyraxis's Processing as a Processor is limited to the categories, purposes, data subjects, and duration set out in Appendix A.
- Duration. Pyraxis will Process Customer Personal Data for the term of the Agreement and until deletion in accordance with Section 11.
3. Processing on documented instructions
- Pyraxis will Process Customer Personal Data only on the Customer's documented instructions, including as set out in the Agreement, this DPA, and the Customer's use and configuration of the application (including which third-party accounts it connects). Operating the application is a documented instruction.
- Pyraxis will not sell Customer Personal Data, and will not use or Process it for advertising, or to train, develop, or improve any generalised or non-personalised AI or machine-learning model.
- If Pyraxis is required by applicable law to Process Customer Personal Data other than on the Customer's instructions, it will inform the Customer of that legal requirement before Processing, unless the law prohibits such notice on important grounds of public interest.
- Pyraxis will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Compliance and confidentiality of personnel
- Each party will comply with its obligations under Data Protection Laws. Pyraxis will provide the Customer with the information reasonably necessary to demonstrate compliance with Article 28 GDPR.
- Pyraxis ensures that personnel authorised to Process Customer Personal Data are bound by an appropriate obligation of confidentiality and receive data-protection and security training.
- Pyraxis limits access to Customer Personal Data to personnel who require access to perform the Agreement.
5. Security
- Taking into account the state of the art, costs, and the nature, scope, context, and purposes of Processing, Pyraxis implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Appendix B.
- The local-first architecture is itself a core security measure: Customer Content stays on Customer devices, under Customer operating-system controls, and is not aggregated on Pyraxis-operated servers.
- Pyraxis regularly tests and evaluates the effectiveness of these measures and may update them provided the level of protection is not materially reduced.
6. Sub-processors
- The Customer provides general authorisation for Pyraxis to engage the Sub-processors listed in Appendix C to Process Customer Personal Data for the purposes stated there.
- Pyraxis imposes on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains liable to the Customer for a Sub-processor's performance.
- Pyraxis will give the Customer prior notice of the addition or replacement of a Sub-processor (by updating this page and/or by email to the Customer's designated contact), allowing the Customer a reasonable period to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected part of the Agreement.
- Connected accounts. Third-party services the Customer connects (e.g. Google, Microsoft, Slack, HubSpot, Salesforce, Notion) are engaged directly by the Customer under the Customer's own agreements with those providers; they are the Customer's processors, not Pyraxis's Sub-processors. Pyraxis accesses them only via OAuth tokens the Customer authorises and stores on the Customer's device.
7. Assistance with Data Subject rights
- Because Customer Content resides on Customer devices, the Customer can fulfil most Data Subject requests (access, rectification, erasure, restriction, portability, objection) directly within the application, without Pyraxis's involvement.
- Taking into account the nature of the Processing, Pyraxis will provide reasonable assistance by appropriate technical and organisational measures, insofar as possible, to help the Customer respond to Data Subject requests. If Pyraxis receives a request directly from a Data Subject, it will advise the Data Subject to submit it to the Customer and, where identifiable, forward it to the Customer.
8. Personal Data Breach notification
- Pyraxis will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data Processed by Pyraxis or its Sub-processors.
- The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Pyraxis will provide further information in phases as it becomes available.
- A breach confined to a Customer's own device (e.g. loss or theft of that device) is outside Pyraxis's awareness and control and is the Customer's responsibility to assess; Pyraxis will assist on request.
9. Data Protection Impact Assessments and prior consultation
Taking into account the nature of Processing and the information available to it, Pyraxis will provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Articles 35–36 GDPR.
10. International data transfers
- On-device Processing does not, by itself, transfer Customer Content across borders — the data stays on the Customer's device.
- Where Pyraxis Processes limited account/licensing data through Sub-processors located outside the Customer's jurisdiction (see Appendix C), and such transfer requires a transfer mechanism, the parties agree that the Standard Contractual Clauses (Module Two: Controller-to-Processor, and Module Three where applicable) are incorporated into this DPA by reference and apply to that transfer, together with the UK Addendum for UK transfers. Appendices A, B, and C populate the corresponding Annexes of the SCCs.
11. Return and deletion of Customer Personal Data
- Customer Content is deleted by the Customer at any time by removing it in the application, clearing the application's data folder, or uninstalling Pyraxis. Because it is stored locally, deletion is within the Customer's direct control.
- On termination or expiry of the Agreement, Pyraxis will, at the Customer's choice, delete or return the limited account/licensing Personal Data it holds, and delete existing copies, unless retention is required by applicable law. Deletion of such data will occur within 90 days of termination.
12. Audits and inspections
- Pyraxis will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, including relevant certifications, security documentation, and Sub-processor information.
- The Customer may audit compliance no more than once per year (and following a Personal Data Breach) on reasonable prior written notice, subject to confidentiality, during business hours, and in a manner that does not disrupt Pyraxis's operations or compromise other customers' data. Where the SCCs apply, their audit provisions govern.
13. CCPA and US state privacy laws
- To the extent the CCPA applies, Pyraxis acts as a "service provider" and Customer Personal Data is "personal information" disclosed for a business purpose.
- Pyraxis will not: (a) sell or share such personal information; (b) retain, use, or disclose it for any purpose other than performing the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with personal information from other sources, except as permitted by the CCPA. Pyraxis certifies that it understands and will comply with these restrictions.
14. General
- Order of precedence. In case of conflict between this DPA and the Agreement on data protection, this DPA prevails. Where the SCCs apply and conflict with this DPA, the SCCs prevail.
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement.
- Governing law. Except where Data Protection Laws or the SCCs require otherwise, this DPA is governed by the laws of Singapore, consistent with the Pyraxis Terms.
- Changes. We may update this DPA; material changes affecting Sub-processors or the substance of protections will be reflected here with a new version number and date.
Appendix A — Details of Processing (SCC Annex I)
A.1 Parties
Data exporter: the Customer (Controller). Data importer: Pyraxis Solutions (Processor), operating Pyraxis.
A.2 Nature and purpose of Processing
- On-device application processing — providing the licensed features (chat, document analysis, dashboards, meeting summaries, planner, DLP, etc.) using on-device AI models. Performed on the Customer's devices; Customer Content is not transmitted to Pyraxis.
- Licensing & account administration — validating licenses, binding a license to a device, and supporting the Customer.
- Connected accounts — where enabled by the Customer, accessing third-party account data via Customer-authorised OAuth tokens stored on the Customer's device, to deliver the requested feature.
A.3 Categories of Data Subjects
The Customer's authorised users; and any individuals whose Personal Data appears in Customer Content the Customer chooses to process (e.g. correspondents, contacts, leads, customers of the Customer).
A.4 Categories of Personal Data
| Processing area | Categories of Personal Data | Location |
|---|---|---|
| On-device application | Any Personal Data present in the Customer's documents, mail, calendar, contacts, notes, and records that the Customer processes in the app | Customer device only |
| Licensing & account | Licensee name, email address, organisation, license identifier, and a derived device identifier for license binding | Sub-processor (Cloudflare) + Customer device |
| Connected accounts | OAuth tokens and the account data the Customer authorises the feature to access | Customer device (tokens); third-party provider (source data) |
A.5 Special categories of Personal Data
Not intentionally Processed by Pyraxis. Customer Content may contain special-category data at the Customer's discretion; it remains on the Customer's device. The Customer is responsible for any additional safeguards such data requires.
A.6 Frequency and duration
Continuous for the term of the Agreement; retention as set out in Section 11.
Appendix B — Technical and Organisational Security Measures (SCC Annex II)
- Data minimisation by architecture — local-first design keeps Customer Content on Customer devices; Pyraxis operates no server that receives or stores Customer Content.
- On-device AI — inference runs locally; prompts and content are not sent to external model providers.
- Credential protection — OAuth tokens and secrets are stored using the operating system's secure facilities on the Customer's device; the local network API is protected by a per-install token so only paired devices can reach it.
- Encryption — TLS for all network calls the app makes; encryption of sensitive configuration at rest; encryption in transit and at rest for the limited data held by Sub-processors.
- Egress protection (DLP) — for licensed tiers, an on-device Data Leakage Protection guard scans outbound content for personal data and secrets before any external send.
- Software integrity — the application is code-signed and notarised, and distributed only through official channels; releases are verified for integrity.
- Access control & confidentiality — least-privilege access, confidentiality obligations, and security training for personnel.
- Sub-processor assurance — Sub-processors are contractually bound to equivalent measures and maintain recognised security certifications.
- Resilience & testing — measures are reviewed and tested; the Customer controls backups of on-device data.
Appendix C — Authorised Sub-processors
Pyraxis engages the following Sub-processors for the limited Processing described. Connected third-party accounts are engaged directly by the Customer and are not listed here (see Section 6).
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Cloudflare, Inc. | License portal & installer delivery (Pages, D1, R2, CDN) | Licensee name, email, organisation, license identifier, device identifier | Global (EU/US; transfers under SCCs) |
| Apple Inc. | Application notarisation and macOS distribution/verification | Software artefacts and integrity/notarisation metadata (no Customer Content) | United States |
This list reflects Sub-processors as of the "last updated" date and may change under Section 6.
Contact
Data protection enquiries and requests for a countersigned DPA: Pyraxis Solutions — privacy@pyraxis.dev.