LEGAL · DATA PROCESSING ADDENDUM · EFFECTIVE AUGUST 15, 2026
Data Processing Addendum
This Data Processing Addendum (DPA) applies when Diversa Solutions LLC processes personal data on behalf of a VEXONYX customer in connection with the service. It forms part of the VEXONYX agreement where applicable.
1. Parties and roles
The VEXONYX customer is the controller or business for Customer Personal Data and Diversa Solutions LLC is the processor, service provider or contractor to the extent it processes that data on the customer's documented instructions. Each party remains independently responsible for personal data it processes for its own purposes.
2. Customer instructions
Customer instructs Diversa Solutions LLC to process Customer Personal Data as necessary to provide, secure, maintain and support VEXONYX; perform the security workflows initiated or configured by Customer; process files, evidence, findings, usage and reports; prevent abuse; and comply with further lawful written instructions that are consistent with the service and this DPA.
3. Subject matter and duration
Processing concerns the provision of the VEXONYX cybersecurity platform for the term of the customer's use of the service and any limited period afterward needed for return, deletion, backup aging, security, legal obligations or dispute handling.
4. Nature and purpose
Processing may include collection, receipt, hosting, organization, storage, retrieval, analysis, scanning, transformation, transmission, logging, reporting, restriction, deletion and other operations needed to provide authorized cybersecurity analysis, evidence handling, collaboration, billing support and platform security.
5. Categories of data
Customer Personal Data may include identifiers, business contact details, usernames, account or device identifiers, IP addresses, application or network records, logs, code, support data, security findings, files, evidence, credentials or secrets submitted by Customer, and other personal data contained in authorized engagement material. Customer should minimize sensitive and special-category data and submit it only when necessary and lawful.
6. Data subjects
Data subjects may include Customer personnel, contractors, authorized security testers, users of systems within an authorized engagement, customer end users, business contacts and other individuals whose data is legitimately included in Customer-provided security material.
7. Customer obligations
Customer is responsible for the lawfulness of its instructions; determining the scope and lawful basis for processing; providing required notices; obtaining required permissions; ensuring the security engagement itself is authorized; responding to data-subject requests as controller; and avoiding submission of personal data that is unnecessary for the engagement.
8. Processor obligations
Diversa Solutions LLC will process Customer Personal Data only on documented instructions unless law requires otherwise; ensure persons authorized to process it are subject to confidentiality obligations; apply appropriate technical and organizational measures; assist Customer with data-subject, security and compliance obligations where reasonably possible; and notify Customer if an instruction appears to violate applicable data-protection law.
9. Security measures
VEXONYX security measures are designed around tenant isolation, least privilege, authentication and authorization controls, audit logging, separation of privileged service operations, encryption provided by platform infrastructure in transit and at rest where supported, controlled file handling, security monitoring, incident response, backup and recovery practices, and fail-closed boundaries around sensitive execution capabilities.
10. Personnel confidentiality
Diversa Solutions LLC limits access to Customer Personal Data to personnel and service providers that need access for authorized duties. Persons with such access are subject to confidentiality obligations or an appropriate statutory duty of confidentiality.
11. Subprocessors
Customer gives general authorization for Diversa Solutions LLC to use subprocessors needed to provide VEXONYX. Material subprocessors are listed on the VEXONYX Subprocessors page. We will impose data-protection obligations appropriate to the processing and remain responsible for our obligations under this DPA. Where required by contract or law, we will provide reasonable notice of a new material subprocessor and a mechanism to raise a legitimate data-protection objection.
12. Data-subject requests
If Diversa Solutions LLC receives a request from a data subject relating to Customer Personal Data, we will, where legally permitted, direct the request to Customer or notify Customer. Taking into account the nature of processing, we will provide reasonable assistance through available product capabilities and information so Customer can respond to applicable requests.
13. Security incidents
Diversa Solutions LLC will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data where notification is required by applicable law. We will provide information reasonably available about the nature of the incident, affected data, likely consequences and remediation, and will take reasonable steps to contain and mitigate the incident.
14. DPIAs and regulatory assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with data-protection impact assessments, prior consultations and regulator inquiries relating specifically to VEXONYX processing, subject to confidentiality, security and reasonable cost limitations where the assistance exceeds standard service obligations.
15. International transfers
Customer acknowledges that Diversa Solutions LLC is established in the United States and that approved subprocessors may process data internationally. Where GDPR, UK GDPR or another applicable law requires a transfer mechanism, the parties will rely on an available lawful mechanism, including applicable standard contractual clauses or an equivalent approved mechanism where appropriate. The parties will cooperate in completing required transfer information.
16. U.S. state service-provider terms
To the extent an applicable U.S. state privacy law treats Diversa Solutions LLC as a service provider, contractor or processor, we will process covered Customer Personal Data only for the business purposes and services specified by the agreement, will not sell it or use it for cross-context behavioral advertising, and will not retain, use or disclose it outside the permitted relationship except as allowed by applicable law.
17. Return and deletion
At the end of the services, Customer may use available product capabilities to export eligible Customer data. We will delete or render inaccessible Customer Personal Data in accordance with the service's deletion and backup lifecycle unless retention is required by law, necessary for security or legal claims, or otherwise permitted by the agreement. Data retained for those limited purposes remains protected by this DPA.
18. Audit information
We will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, architecture information, policies or independent assurance materials when available. On-site audits are subject to reasonable advance notice, confidentiality, security constraints, non-disruption requirements and limits designed to protect other customers.
19. Conflicts
If this DPA conflicts with the general Terms of Service on processing of Customer Personal Data, this DPA controls for that subject. A mandatory transfer instrument controls over conflicting terms to the extent required by that instrument.
20. Contact
Data-protection and DPA questions can be sent to info@vexonyx.com. Processor: Diversa Solutions LLC, 30 N Gould St, Sheridan, Wyoming 82801, United States.