qyx.ai
Log in
    • Think
    • Create
    • Publish
    • Convert
    • Engage
  • Features
    • I run an online store
    • I do marketing
    • I create content
    • I'm a solo founder
    • I run a local business
  • Services
  • Pricing
  • Blog
  • FAQ

Languages

🇺🇸English 🇨🇿Čeština 🇩🇪Deutsch
🇺🇸English 🇨🇿Čeština 🇩🇪Deutsch
Sign In Start For $0 Start For $0

Data Processing Agreement (DPA)

Last updated: 11 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Customer" / "Controller") and Ai Data s.r.o., IČO 21824541, registered office at Grafická 3365/1, Smíchov, 150 00 Praha, Czech Republic ("Qyx" / "Processor"), together the "Parties".

It applies where the Processor processes Customer Personal Data on behalf of the Customer in the course of providing the Service.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "personal data breach" have the meanings in Regulation (EU) 2016/679 (GDPR). "Customer Personal Data" means personal data contained in Customer's Input or otherwise processed by the Processor on the Customer's behalf under the Service. "Sub-processor" means a third party engaged by the Processor to process Customer Personal Data. "Data Protection Law" means the GDPR and applicable national implementing laws.

2. Roles and scope

2.1. The Customer is the controller and the Processor is the processor of Customer Personal Data, except where the Processor determines the purposes and means of processing (for example, account, billing, and Service-improvement data), in which case the Processor acts as controller under its Privacy Policy.

2.2. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are set out in Annex 1.

3. Processor obligations

The Processor shall:

3.1. Process Customer Personal Data only on the documented instructions of the Customer, including for transfers, unless required otherwise by law (in which case it will inform the Customer, unless legally prohibited). The Customer's instructions are set out in the Terms, this DPA, and its use of the Service.

3.2. Ensure persons authorised to process Customer Personal Data are bound by confidentiality.

3.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2.

3.4. Respect the conditions for engaging sub-processors in Section 5.

3.5. Assist the Customer, taking into account the nature of the processing and the information available, in:

  • responding to data-subject requests (Section 6);
  • ensuring compliance with security, breach-notification, data-protection-impact-assessment, and prior-consultation obligations (Articles 32–36 GDPR).

3.6. At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of the Service, and delete existing copies, unless law requires storage.

3.7. Make available to the Customer information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as set out in Section 7.

3.8. Notify the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law.

4. Personal data breach

The Processor shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and shall provide information reasonably available to help the Customer meet its own notification obligations. The Processor shall take reasonable steps to mitigate and remediate the breach.

5. Sub-processors

5.1. The Customer provides general authorisation for the Processor to engage sub-processors to provide the Service, including AI model providers, hosting and infrastructure providers, payment providers, and communication and analytics providers.

5.2. A current list of sub-processors is available at our sub-processors page.

5.3. The Processor shall impose on each sub-processor data-protection obligations that are, in substance, no less protective than those in this DPA.

5.4. The Processor will give the Customer a means to receive notice of intended changes to sub-processors (for example by subscribing to updates on the sub-processors page), giving the Customer the opportunity to object on reasonable data-protection grounds. If the Parties cannot resolve a reasonable objection, the Customer may terminate the affected part of the Service.

5.5. The Processor remains liable for the acts and omissions of its sub-processors as for its own.

6. Data-subject rights

Taking into account the nature of the processing, the Processor shall assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests by data subjects to exercise their rights. If the Processor receives a request directly from a data subject relating to Customer Personal Data, it will, where lawful, direct the data subject to the Customer.

7. Audits

7.1. The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA.

7.2. The Customer may audit no more than once per year (and after a personal data breach affecting its data), on reasonable prior notice, during business hours, subject to confidentiality, and without unreasonably disrupting the Processor's operations. The Processor may satisfy audit requests by providing existing reports, certifications, or answers to a reasonable questionnaire where these adequately address the request.

8. International transfers

Where the Processor or a sub-processor processes Customer Personal Data outside the EEA, the Processor shall ensure an appropriate transfer mechanism is in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision, together with any supplementary measures required.

9. Liability and term

9.1. Each Party's liability under this DPA is subject to the limitations of liability in the Terms of Service.

9.2. This DPA takes effect when the Terms take effect and continues while the Processor processes Customer Personal Data. Provisions that by their nature should survive do so.

9.3. In case of conflict between this DPA and the Terms on data-protection matters, this DPA prevails.

Annex 1 — Details of processing

Subject matter: Provision of the Qyx.ai Service to the Customer.

Duration: For the term of the Customer's subscription and any retention period stated in the Terms/Privacy Policy.

Nature and purpose: Hosting, storing, transmitting, and processing Customer Input through AI models and platform features to generate Output and provide the Service.

Types of personal data: The personal data processed is determined by the Customer, who decides what to submit as Input. It may include, without limitation: identification and contact data (such as names, email addresses, phone numbers), content of communications, customer and marketing data, and any other personal data the Customer chooses to include in prompts, uploaded files, or generated content. The Customer decides what it submits and is responsible for the lawfulness of that data.

Categories of data subjects: Determined by the Customer. May include the Customer's own customers, prospects, contacts, employees, suppliers, and any other individuals whose personal data the Customer chooses to submit to the Service.

Special-category data: Not intended. The Customer should not submit special-category data as Input (see Privacy Policy).

Annex 2 — Technical and organisational measures

The Processor maintains technical and organisational measures appropriate to the risk, including:

  • Encryption in transit — data transmitted over the Service is protected using HTTPS/TLS.
  • Encryption at rest — data stored on the Processor's servers is encrypted at rest.
  • Access control and authentication — access to systems and data is restricted through role-based access controls and authentication; access is granted on a need-to-know basis.
  • EU data location — the Service is hosted within the European Union (Frankfurt, Germany).
  • Backups — regular backups are maintained to enable recovery.
  • Network security — a web application firewall and related protections are in place to detect and block malicious traffic.
  • Logging and monitoring — system activity is logged and monitored to detect and respond to security events.
  • Payment security — payment card data is handled exclusively by a PCI-DSS-compliant payment provider; the Processor does not store full card details.
  • Confidentiality — personnel with access to personal data are bound by confidentiality obligations.
  • Vendor due diligence — sub-processors are selected on the basis that they offer appropriate data-protection guarantees and are engaged under data-protection terms.

The Processor reviews and updates these measures as appropriate to maintain a level of security appropriate to the risk.

Ai Data s.r.o. · Grafická 3365/1, Smíchov, 150 00 Praha, Czech Republic · IČO: 21824541 · File no. C 406991, Municipal Court in Prague

Legal
  • Legal Notice
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Sub-processors

Every AI tool you need in one login

qyx.ai

Made in Europe

Start For $0

Support

  • Contact
  • hi@qyx.ai

Product

  • Think
  • Create
  • Publish
  • Convert
  • Engage

Use cases

  • I run an online store
  • I do marketing
  • I create content
  • I'm a solo founder
  • I run a local business

Company

  • About Us
  • Pricing
  • Blog
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Legal Notice
  • Acceptable Use Policy
  • Data Processing Agreement
  • Sub-processors
🇺🇸English 🇨🇿Čeština 🇩🇪Deutsch

© 2026 Qyx.ai. All rights reserved.