Version 1.0 · Effective upon execution with Customer
Parties:ESXPress Enterprise (“Processor”) and the Customer (“Controller”)
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between ESXPress Enterprise (“Processor,” “we,” “us”) and the Customer (“Controller,” “you”). It reflects the parties’ agreement on the processing of Personal Data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), UK GDPR, and California Consumer Privacy Act (CCPA/CPRA).
Capitalized terms not defined here have the meanings given in the Terms of Service.
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person processed by ESXPress on behalf of Controller |
| Controller | The entity that determines the purposes and means of processing Personal Data (the Customer) |
| Processor | The entity that processes Personal Data on behalf of the Controller (ESXPress) |
| Sub-Processor | Any third party engaged by the Processor to process Personal Data |
| Data Subject | The individual to whom Personal Data relates |
| SCCs | EU Standard Contractual Clauses for the transfer of personal data to third countries |
| Security Incident | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data |
The Processor shall process Personal Data only:
Personal Data is processed for the duration of the Service agreement and retained as follows:
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country.
The Processor ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
The Processor implements appropriate technical and organizational measures, including:
Authorized Sub-Processors
| Sub-Processor | Purpose | Location | Data Processed |
|---|---|---|---|
| Supabase | Database hosting | US | All account and conversion data |
| Stripe | Payment processing | US | Billing data (no card numbers) |
| DeepSeek | AI line-item extraction | US/China | PDF content (transient) |
| Google Gemini (Google LLC) | OCR / vision analysis | US | PDF page images & roof photos (transient) |
| Cloudflare | CDN, DDoS protection | Global | Network traffic, IP addresses |
| Hostinger | VPS hosting | US | Application logs |
| SMTP email relay (Google Workspace) | Transactional email delivery | US | Email addresses (outbound email) |
| Mailgun | Email delivery event webhooks | US | Delivery/bounce event metadata |
| Slack | Slack bot workspace integration | US | Workspace/tenant mapping, command payloads |
Sub-Processor Engagement
The Controller provides general authorization for the Processor to engage the Sub-Processors listed above. The Processor shall:
The Processor shall assist the Controller in fulfilling obligations to respond to Data Subject requests under GDPR/CCPA, including:
POST /api/v1/privacy/export-data)POST /api/v1/privacy/delete-data)The Processor shall notify the Controller without undue delay (within 48 hours) upon becoming aware of a Security Incident affecting Personal Data. The notification shall:
The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with supervisory authorities.
Upon termination of the Service, the Processor shall, at the Controller’s choice:
The Controller warrants that:
For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, the parties rely on the EU Standard Contractual Clauses (SCCs), Module Two (Controller-to-Processor), as incorporated by reference.
If the Controller is a “Business” under CCPA/CPRA and shares Personal Information with ESXPress:
The Processor makes available to the Controller all information necessary to demonstrate compliance with this DPA, including SOC 2 documentation and audit logs.
Upon reasonable notice (minimum 30 days) and no more than once per year, the Controller or its authorized auditor may conduct an on-site audit of the Processor’s data processing facilities, subject to:
Alternative: The Processor may provide a third-party audit report (e.g., SOC 2 report) in lieu of an on-site audit.
Each party’s liability arising out of or related to this DPA shall be subject to the limitations and exclusions set forth in the Terms of Service. Nothing in this DPA limits either party’s liability for:
This DPA remains in effect as long as the Processor processes Personal Data on behalf of the Controller under the Terms of Service. Provisions that by their nature should survive termination shall survive.
This DPA is governed by the law specified in the Terms of Service, except that data protection provisions for EEA/UK Data Subjects are governed by the laws of the Data Subject’s jurisdiction and the SCCs.
This DPA is entered into by the parties’ acceptance of the Terms of Service or by separate written agreement.
ESXPress Enterprise
Email: [email protected]
Website: https://esxpress.org