This DPA forms part of the Terms of Service between Trafyx (Processor) and the customer (Controller). It governs how we handle personal data on your behalf.
This is the public reference version. To execute a signed DPA with your organisation on the letterhead, email dpa@trafyx.ai — we'll send a countersigned PDF within one business day.
Controller means you, the Trafyx customer. Processor means Trafyx (Riser Technologies LLC). Sub-processor means a third party engaged by the Processor to process Personal Data on the Controller's behalf. Other terms (Personal Data, Data Subject, Processing) carry the meanings given to them in the applicable data protection law.
The Processor will process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country. Processing types and purposes are described in Schedule A below.
The Processor ensures that personnel authorised to process Personal Data are bound by confidentiality obligations. This includes contractual NDAs and role-based access control preventing unauthorised staff from accessing customer data.
The Processor implements appropriate technical and organisational measures, including but not limited to: encryption at rest (AES-256) and in transit (TLS 1.3), row-level security enforcing tenant isolation at the database layer, mandatory 2FA for admin access, audit logging of every mutation, quarterly penetration testing, and 24-hour incident response commitment. Full detail on our security page.
The Controller consents to the Processor engaging the sub-processors listed below. The Processor will notify the Controller at least 30 days in advance of any intended additions or replacements, giving the Controller opportunity to object.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase Inc. | Managed Postgres hosting | EU (Ireland) |
| Vercel Inc. | Application delivery / edge | Global CDN |
| Anthropic PBC | Mira AI (zero-retention mode) | US |
| Resend Inc. | Transactional email | US / EU |
| Telr Payment Services | Payment gateway (UAE) | UAE |
| PayTabs Payment Solutions | Payment gateway (MENA) | UAE / Saudi Arabia |
The Processor will assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights (access, rectification, erasure, restriction, portability, objection).
The Processor will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach affecting the Controller's data. The notification will describe the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed.
The Processor will provide the Controller with reasonable assistance in carrying out any data protection impact assessment and prior consultations with supervisory authorities that the Controller reasonably considers to be required.
Where Personal Data is transferred outside the UAE or EEA, the Processor will ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) where applicable and adequacy decisions where they exist.
On termination of the underlying service agreement, the Processor will (at the Controller's choice) return or delete all Personal Data. The Controller has 60 days to export data before automatic deletion. Backup copies are purged within 30 days of that deletion.
The Processor will make available to the Controller all information necessary to demonstrate compliance, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller. In practice, this is satisfied by the Processor's annual SOC 2 report (available under NDA).
Provision of the Trafyx B/OSS platform to the Controller.
The term of the underlying service agreement, plus 60 days for data export.
Subscriber lifecycle management, billing, RADIUS authentication and accounting, support ticketing, AI-assisted operations.
The Controller's end-users (typically internet subscribers) and the Controller's own staff and reseller accounts.
For an executed DPA on your organisation's paper, email dpa@trafyx.ai with your legal entity name and jurisdiction. We countersign and return within one business day.