Foxy Audit ← Back to home

Data Processing Agreement

Version 1.4 · Effective date set when first executed

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Master Service Agreement (the "Agreement") between the customer entering an order for the Service ("Customer") and Foxy Audit, operated by FOXY AUDIT, a company incorporated in the Islamic Republic of Pakistan ("Foxy Audit," "we," "us"). Capitalized terms not defined here have the meaning given in the Privacy Policy.

Where Customer has not signed a Master Service Agreement, this DPA forms part of the Terms of Service, which incorporate it by reference (Terms of Service Section 5), and "the Agreement" means those Terms.

Notices: written notices, instructions and requests to Foxy Audit under this DPA are given to legal@foxyaudit.tech.

Document details

Contents

  1. Roles
  2. Subject matter and nature of processing
  3. Duration
  4. Customer instructions
  5. Sub-processors
  6. Security measures
  7. Personnel
  8. Assistance with data subject rights
  9. Deletion and return of data
  10. Security incident notification
  11. International transfers
  12. Audit rights
  13. Liability
  14. Order of precedence

1. Roles

Where Customer's use of the Service involves the processing of personal data on Customer's behalf, Customer is the data controller (or "business," under CCPA/CPRA) and Foxy Audit is the data processor (or "service provider"). Foxy Audit processes personal data only on Customer's documented instructions, as set out in this DPA and the Agreement.

2. Subject matter and nature of processing

Foxy Audit processes the categories of data described in Privacy Policy Section 4 — principally cryptographic Commitments (hashes) of AI interactions, never the underlying prompt or response text, which is structurally never transmitted to Foxy Audit (see Privacy Policy Section 3). Where Customer enables optional client-side PII-signal labeling, only the resulting labels not the underlying values are transmitted.

3. Duration

This DPA remains in effect for as long as Foxy Audit processes personal data on Customer's behalf under the Agreement, and terminates automatically on expiry or termination of the Agreement, subject to Section 9 (Deletion).

4. Customer instructions

Foxy Audit will process personal data only to provide the Service as configured by Customer (including Customer's Policy settings) and as otherwise instructed in writing by Customer, unless required to do otherwise by applicable law — in which case Foxy Audit will inform Customer of that legal requirement before processing, unless the law prohibits such notice.

5. Sub-processors

Customer provides general authorization for Foxy Audit to engage the sub-processors listed in Privacy Policy Section 8 (currently: Google LLC and/or OpenAI, L.L.C. for interaction grading; Paddle.com Market Ltd ("Paddle") for payments, invoicing, tax handling, and as merchant of record for Customer's purchase; Payoneer, Inc. for manual invoicing on select arrangements and as the method by which Foxy Audit receives its own revenue from Paddle; Google Identity for optional sign-in; Brevo SAS for transactional email; and Google Cloud (Ubuntu VM) for infrastructure and hosting). Foxy Audit will:

6. Security measures

Foxy Audit implements the technical and organizational measures described in Privacy Policy Section 10, including: TLS in transit; salted/peppered hashing of API keys and one-time passcodes; Fernet-encrypted, rotation-capable storage of BYOK provider keys with organization- and provider-bound context; PostgreSQL row-level security enforcing per-organization tenant isolation; and security-hardening HTTP headers.

The audit ledger, staff-action log, and blockchain-anchor receipt trail are read-only within Foxy Audit's administrative tools — there is no edit path. Where anchoring is enabled, the customer audit ledger goes further: an undisclosed edit is independently detectable by Customer, rather than only prohibited by Foxy Audit's policy. The staff-action log is hash-chained and anchored the same way, so an entry removed from the end is detectable by Customer rather than only by Foxy Audit. Neither trail is immune to change; an anchor establishes what a record looked like at a point in time rather than preventing an edit.

7. Personnel

Foxy Audit limits access to personal data to personnel who need it to perform the Service, subjects administrative access to step-up authentication and a staff audit trail that is tamper-evident and independently verifiable — an entry that is edited, removed from the middle, re-ordered, or removed from the end breaks the chain against a head published to a public blockchain; entries recorded before the chain existed are not covered by it (Privacy Policy Section 11) — and requires personnel to be bound by confidentiality obligations.

8. Assistance with data subject rights and impact assessments

Taking into account the nature of the processing, Foxy Audit will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to respond to data subject requests (Privacy Policy Section 14) and, where required, to Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent such information is available to Foxy Audit and not otherwise available to Customer through the Compliance Passport export.

9. Deletion and return of data

On termination of the Agreement, or on Customer's written request, Foxy Audit will make Customer's data available for export through the Compliance Passport for a reasonable period, and will delete or anonymize remaining personal data in accordance with Privacy Policy Section 9, save where retention is required by applicable law or to preserve audit-trail integrity for other customers.

10. Security incident notification

Foxy Audit will notify Customer without undue delay after becoming aware of a security incident affecting Customer's personal data, consistent with Privacy Policy Section 15, and will provide information reasonably available to it about the incident's nature and scope, and the steps taken in response, to support Customer's own regulatory notification obligations.

11. International transfers

Where personal data is transferred from the EEA to a country not deemed to offer an adequate level of protection, the parties rely on the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference. Where personal data is transferred from the UK, the parties rely on the UK International Data Transfer Addendum to the EU SCCs; where transferred from Switzerland, on the equivalent safeguards under the Swiss Federal Act on Data Protection together, consistent with Privacy Policy Section 13.

12. Audit rights

On reasonable prior written notice, and no more than once per 12-month period (except following a confirmed security incident), Foxy Audit will make available information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through: (a) the Compliance Passport export; (b) a copy of the most recent third-party security assessment then held by Foxy Audit, if any; or (c) a mutually scheduled written questionnaire response, before any on-site or systems-level audit is considered.

13. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Agreement.

14. Order of precedence

In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA prevails. Where the Agreement is the Master Service Agreement, this is the express exception to the general order of precedence in Section 1 of that agreement, which otherwise ranks the Master Service Agreement above this DPA; on every other subject matter that order governs.

Appendix A — Details of processing

Home · Terms · Privacy · Cookies · Report Abuse · All legal documents
© 2026 Foxy Audit. Cryptographic compliance, not a promise.