oryxa
OverviewYour agentHow it helpsMemoryTrust
Sign inBook a demo
ORYXA / LEGAL CENTERDATA PROCESSING ADDENDUM

Processing with responsibility.

The contractual safeguards that apply when Oryxa processes personal data on behalf of a customer.

Effective 18 July 2026Oryxa AI Private Limited
LEGAL DOCUMENTS
01Privacy Policy02Terms of Service03Cookie Policy04Acceptable Use05Data Processing Addendum06Subprocessors07Security & Disclosure
PLAIN-LANGUAGE NOTE

This document is intended to be readable. Headings help navigation but do not limit the meaning of the sections beneath them.

01

Application and definitions

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in an order form or account (“Customer”) and Oryxa AI Private Limited (“Oryxa”) when Oryxa processes Customer Personal Data on Customer’s behalf.

Customer Personal Data means personal data contained in Customer Content and processed by Oryxa as a processor or data processor. Data Protection Law means privacy and data-protection law applicable to the processing, including the Indian Digital Personal Data Protection framework and, where applicable, the GDPR or UK GDPR.

Terms such as controller, processor, data fiduciary, data processor, personal data, processing, and data subject or data principal have the meanings given by applicable law.

02

Roles and documented instructions

Customer is the controller or data fiduciary and Oryxa is the processor or data processor for Customer Personal Data, except where law requires a different role. Customer determines the purposes and means of processing and is responsible for lawful instructions, notices, permissions, and legal bases.

Oryxa will process Customer Personal Data only to provide, secure, support, and improve the contracted service according to the agreement, Customer’s documented configuration and instructions, and applicable law. If Oryxa believes an instruction violates Data Protection Law, it may pause the affected processing and notify Customer.

03

Details of processing

Subject matterProvision of AI-assisted coordination, work memory, task handling, drafting, integrations, support, and related Oryxa services.
DurationThe agreement term plus the limited period needed for deletion, return, backups, dispute resolution, security, or legal retention.
Nature and purposeHosting, organizing, retrieving, analyzing, transmitting, generating, securing, and deleting data to provide Customer-requested functions.
Data subjectsCustomer users, personnel, contractors, collaborators, business contacts, integration users, and other individuals whose data Customer submits.
Data categoriesIdentity and contact data, workspace membership, communications, tasks, prompts, documents, commitments, activity, integration content, device and log data.
Sensitive dataNot intended unless expressly agreed in writing with appropriate safeguards and a lawful basis.
04

Confidentiality and security

Oryxa will ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed for their role.

Oryxa will maintain reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures include access controls, protected credentials and secrets, encryption in transit, logging and monitoring, incident response, change and vulnerability management, and recovery practices appropriate to the service.

05

Subprocessors

Customer gives Oryxa general authorization to use subprocessors needed to provide the service. Oryxa will impose written data-protection obligations that are materially protective of Customer Personal Data and remains responsible for subprocessor performance to the extent required by law and the agreement.

Current provider categories and conditional deployment options appear on the Subprocessors page. Where required by contract, Oryxa will provide advance notice of a new material subprocessor. Customer may object on reasonable data-protection grounds within the stated notice period, and the parties will work in good faith toward a practical resolution.

06

Individual rights requests

Taking into account the nature of processing, Oryxa will provide reasonable assistance for Customer to respond to valid requests from data subjects or data principals. If Oryxa receives a request concerning Customer Personal Data, it will direct the person to Customer unless prohibited by law.

Customer is responsible for verifying requests, deciding the response, and using available product controls. Additional assistance that requires material custom work may be subject to reasonable fees where law permits.

07

Personal data incidents

Oryxa will notify Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (“Personal Data Incident”).

Notification will include available information reasonably necessary for Customer’s legal obligations, such as the nature of the incident, affected data, likely consequences, and mitigation steps. Notification is not an admission of fault. Customer remains responsible for notices to regulators and individuals unless otherwise required by law.

08

Compliance assistance and audits

Oryxa will provide information reasonably necessary to demonstrate compliance with processor obligations and assist with impact assessments or regulator consultations where required and relevant to the service.

Customer will first use available security documentation, reports, and written responses. If these are insufficient, Customer may request one reasonable audit per year by an independent auditor under confidentiality, during normal business hours, without accessing other customers’ data or disrupting the service. Customer bears its audit costs unless material non-compliance is found.

09

International transfers

Oryxa may process Customer Personal Data in locations where Oryxa or authorized subprocessors operate, subject to Customer’s agreement and applicable transfer restrictions.

Where a restricted international transfer requires contractual safeguards, the parties will incorporate the applicable standard contractual clauses or another lawful mechanism. If a transfer mechanism becomes invalid, the parties will cooperate to implement a lawful alternative.

10

Return and deletion

At the end of service, Oryxa will delete or return Customer Personal Data according to the agreement and Customer’s written choice, unless law requires retention. Data may remain in protected backups until overwritten through normal cycles, during which it remains subject to this DPA and is not used for another purpose.

11

Order of precedence and changes

If this DPA conflicts with the main agreement concerning processing of Customer Personal Data, this DPA controls. A signed or negotiated DPA controls over this online version. Liability under this DPA is subject to the agreement’s liability terms unless prohibited by Data Protection Law.

We may update this online DPA to reflect law or service changes. Material reductions in data-protection commitments will not apply during a committed term without Customer’s agreement.

LEGAL QUESTIONS

Talk to a person.

For privacy, contractual, security, or policy questions, contact hello@oryxa.in.

ORYXA / COORDINATION

Less chasing.
More real work.

Book a demo
oryxaAI
ExploreOverviewYour agentHow it helpsBook a demo
OryxaMemoryTrustContact
LegalPrivacyTermsSecurityAll legal
© 2026 Oryxa AI Private LimitedThe work around your work, handled.oryxa.in · hello@oryxa.in