Legal

Data Processing Agreement

How we process personal data on our customers' behalf: instructions, security, subprocessors, breach notification, international transfers and audits.

Last updated: 4 September 2026 · Effective: 4 September 2026

This Data Processing Agreement (“DPA”) forms part of the Customer Terms of Service between Salex Hub Commercial Brokers L.L.C (“SalexHub”, “Processor”) and the customer that agreed to them (“Customer”, “Controller”). It applies whenever SalexHub processes personal data on the Customer's behalf in connection with the SalexHub platform.

This DPA is effective without signature: by accepting the Customer Terms of Service, or by using the Service, both parties accept it. A countersigned copy is available on request for customers whose procurement requires one.

1Definitions and roles

“Data Protection Law” means all laws applicable to the processing of personal data under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and UAE Federal Decree-Law No. 45 of 2021 (“PDPL”). “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach” and “Supervisory Authority” have the meanings given in the GDPR.

“Customer Personal Data” means Personal Data contained in Customer Data that SalexHub processes on the Customer's behalf. “Subprocessor” means a third party engaged by SalexHub to process Customer Personal Data.

Roles. The Customer is the Controller (or a Processor acting for another controller) of Customer Personal Data. SalexHub is the Processor. Where the Customer is itself a Processor, SalexHub is a Subprocessor, and the Customer warrants it has the controller's authority to enter into this DPA.

SalexHub acts as an independent Controller for account, billing, support and website data described in the Privacy Policy; that processing is outside this DPA.

2Scope and instructions

SalexHub processes Customer Personal Data only on the Customer's documented instructions, which comprise: the Customer Terms of Service and this DPA; the configuration and use of the Service by the Customer's users and by agents and API keys acting under its workspace; and any further written instruction the parties agree.

SalexHub will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless prohibited from doing so by law. SalexHub is not obliged to carry out an instruction that would require it to breach the law.

Where SalexHub is required by law to process Customer Personal Data beyond the Customer's instructions, it will inform the Customer of that requirement before processing, unless the law prohibits it on important grounds of public interest.

SalexHub does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, does not use it for its own purposes, and does not use it to train its own or any third party's machine-learning models.

The Customer is responsible for the lawfulness of the Personal Data it submits, for the notices given and the legal basis relied on, and for the accuracy of the data and its instructions.

3Duration

This DPA takes effect when the Customer accepts the Customer Terms of Service and continues until SalexHub has ceased all processing of Customer Personal Data and deleted or returned it under section 10.

4Confidentiality of personnel

SalexHub grants access to Customer Personal Data only to personnel who need it to provide, secure or support the Service, who are bound by written confidentiality obligations surviving the end of their engagement, and who have received guidance on their data-protection responsibilities. Production access is limited, individually attributed, and logged.

5Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risk to Data Subjects, SalexHub implements and maintains the technical and organisational measures described in Annex II, which are also published, with operational detail, in the Security Overview.

SalexHub may update those measures as technology develops, provided it does not materially reduce the overall level of protection during a subscription term.

The Customer is responsible for the security configuration available to it in the Service: user and role management, permission and sharing settings, API key handling, connected mailboxes and integrations, and the autonomy granted to automated agents.

6Subprocessors

The Customer gives SalexHub general written authorisation to engage Subprocessors. The current list, with the processing each performs and its location, is published at /legal/subprocessors and forms Annex III.

SalexHub will give at least thirty (30) days' notice before a new Subprocessor starts processing Customer Personal Data, by updating that page and notifying customers who subscribe to notifications at start@salexhub.ai.

The Customer may object on reasonable data-protection grounds within thirty (30) days of notice. The parties will work in good faith to resolve the objection; if they cannot, the Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused period.

SalexHub imposes on each Subprocessor data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for a Subprocessor's performance.

7Assisting with data subject requests

The Service provides the Customer with tools to access, correct, export, restrict, suppress and erase Personal Data in its workspace, so that in most cases the Customer can respond to a Data Subject without SalexHub's involvement.

Where a Data Subject contacts SalexHub directly about data held for a Customer, SalexHub will not respond substantively but will, without undue delay, forward the request to the Customer and, where it can identify them, tell the Data Subject who the Controller is.

Taking into account the nature of the processing, SalexHub will assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests to exercise Data Subject rights.

8Impact assessments and prior consultation

SalexHub will provide the Customer, on request, with the information reasonably necessary for the Customer to carry out data protection impact assessments and prior consultations with Supervisory Authorities, insofar as that information is available to SalexHub and relates to processing under this DPA. The Security Overview, the Subprocessors list and Annex I are intended to answer most such requests without further correspondence.

9Personal data breach

SalexHub will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice goes to the workspace administrators of record.

The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where full detail is not available immediately, SalexHub will provide it in phases without further undue delay.

SalexHub will take reasonable steps to contain and remediate the breach, and will cooperate with the Customer's own notification obligations. A notification is not an admission of fault or liability.

10Return and deletion

The Customer may export Customer Personal Data from the Service at any time during the term, and for thirty (30) days after termination.

After that period, SalexHub deletes Customer Personal Data from live systems, and from backups as those backups expire on their rolling cycle, except where storage is required by law. Data retained on legal grounds is isolated and protected from further processing.

SalexHub will certify deletion in writing on request.

11Audits and information

SalexHub will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, primarily through the Security Overview, the Subprocessors list, and written answers to reasonable security questionnaires.

Where that information is not sufficient, the Customer may audit SalexHub's compliance, itself or through an independent auditor bound by confidentiality and not a competitor of SalexHub, at most once in any twelve (12) month period (and additionally after a Personal Data Breach or where a Supervisory Authority requires it), on thirty (30) days' written notice, during business hours, without unreasonable disruption, and at the Customer's cost.

An audit does not extend to other customers' data, to SalexHub's multi-tenant infrastructure in a way that would compromise it, or to information covered by third-party confidentiality obligations.

12International transfers

The primary storage location for Customer Personal Data is the European Union (Frankfurt, Germany); files are stored in the European Union; compute is served from globally distributed edge regions including Frankfurt, Dubai and Washington, D.C.. Certain Subprocessors process data in the United States and other countries, as stated on the Subprocessors page.

European Economic Area. Where the transfer of Customer Personal Data protected by the GDPR to SalexHub or a Subprocessor is a restricted transfer, the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference and apply: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is itself a processor. Clause 7 (docking) applies; under Clause 9, option 2 (general written authorisation) applies with a thirty (30) day notice period; under Clause 11 the optional independent dispute-resolution body does not apply; under Clause 17 the Clauses are governed by the law of Ireland; under Clause 18(b) disputes are resolved before the courts of Ireland. Annexes I, II and III of this DPA populate the corresponding annexes of the Clauses.

United Kingdom. The UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated and applies to transfers subject to the UK GDPR, with Tables 1 to 3 populated by this DPA and its annexes, and with the Importer able to end the Addendum under Section 19.

Switzerland. For transfers subject to the Swiss FADP, the Standard Contractual Clauses apply with references to the GDPR read as references to the FADP, the Swiss Federal Data Protection and Information Commissioner as the competent authority, and “member state” not excluding Data Subjects in Switzerland from suing in their place of habitual residence.

If a transfer mechanism is invalidated, the parties will cooperate in good faith to implement a valid alternative without undue delay.

13United Arab Emirates

Where the PDPL applies, the Customer is the Controller and SalexHub the Processor within the meaning of that law. SalexHub processes Personal Data only on the Customer's instructions, applies the measures in Annex II, notifies the Customer of a breach as set out in section 9, assists with Data Subject rights under section 7, and engages Subprocessors under section 6. Cross-border transfers are made on the bases permitted by Articles 22 and 23 PDPL, including transfers to jurisdictions with an adequate level of protection and transfers made under contractual clauses providing appropriate safeguards.

14Liability, precedence and changes

Each party's liability under this DPA is subject to the limitations and exclusions in the Customer Terms of Service, except to the extent Data Protection Law prohibits limiting it.

If this DPA conflicts with the Customer Terms of Service, this DPA prevails on matters of data protection. If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.

SalexHub may update this DPA where required by law, by a Supervisory Authority, by a change in transfer mechanisms, or to reflect a change in the Service, provided the update does not materially reduce the protections it gives the Customer. Material updates are notified at least thirty (30) days before they take effect.

Annex IParties, processing and competent authority

A. List of parties

Data exporter (Controller): the Customer, as identified in its workspace registration and billing records; contact: the workspace administrator of record; activities: use of the SalexHub platform for customer relationship management, sales, marketing, service and business automation; role: Controller (or Processor, where Module Three applies).

Data importer (Processor): Salex Hub Commercial Brokers L.L.C, Dubai, United Arab Emirates; contact: start@salexhub.ai; activities: provision of the SalexHub platform as described in the Customer Terms of Service; role: Processor.

B. Description of the transfer

ItemDetail
Categories of Data SubjectsThe Customer's contacts, leads and prospects; its customers' employees and representatives; suppliers and partners; visitors to the Customer's websites and recipients of its campaigns; people who submit its forms; correspondents in mailboxes the Customer connects; the Customer's own personnel and users.
Categories of Personal DataIdentity and contact details (name, email, telephone, address, job title, employer); business relationship data (deals, quotes, invoices, tasks, notes, custom fields the Customer defines); communications content (emails, messages, call notes, attachments, voice messages); behavioural data (page views, form submissions, document views, campaign interactions); identifiers (pseudonymous visitor keys, record identifiers); and any other Personal Data the Customer chooses to store.
Special categoriesNot requested and not required by the Service. The Customer is contractually asked not to submit special-category data; where it nevertheless does, it remains the Controller and is responsible for the additional safeguards its processing requires.
Frequency of transferContinuous, for the duration of the Customer's use of the Service.
Nature and purpose of processingHosting, storage, organisation, structuring, retrieval, indexing and search; transmission of messages the Customer sends; generation of AI output on request; analytics and reporting; backup, security monitoring and support — all to provide the Service.
Duration of processingFor the term of the Customer Terms of Service, plus the deletion period in section 10.
Subprocessor transfersAs listed at /legal/subprocessors, for the purposes and durations stated there.

C. Competent supervisory authority

For Module Two and Module Three transfers, the supervisory authority of the EEA member state in which the data exporter is established; where the exporter is not established in the EEA but has appointed a representative under Article 27 GDPR, the authority of the member state where that representative is established; otherwise the Irish Data Protection Commission, consistent with the choice of Irish law in section 12. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.

Annex IITechnical and organisational measures

The measures below are maintained by SalexHub as the data importer. Operational detail is published in the Security Overview.

MeasureImplementation
Pseudonymisation and encryptionTLS 1.2+ for all data in transit, including between internal services. Encryption at rest for the database, object storage and backups. Third-party credentials (mailbox passwords, connector headers, webhook secrets) are encrypted with an envelope key held outside the database. Website visitor identifiers are pseudonymous hashes computed from a daily rotating salt and are not reversible to an IP address.
Confidentiality, integrity, availability and resilienceTenant isolation enforced on every data-access path, with row-level security available and enabled on deployments configured for it. Least-privilege access control with per-user roles. Managed, replicated database and object storage. Application-level audit trail of record changes.
Restoring availability after an incidentPoint-in-time recovery on the primary database, documented recovery procedures with defined recovery point and recovery time objectives, and periodic restore verification.
Testing and evaluating effectivenessAutomated security and correctness gates in the delivery pipeline, dependency and secret scanning, code review before merge, and periodic review of access rights.
User identification and authorisationIndividual named accounts, password hashing with a modern algorithm, session cookies that are HTTP-only and same-site, granular role-based permissions, field-level restrictions, and scoped API keys the Customer can revoke.
Protection of data during transmission and storageContent Security Policy and strict transport security on the application, private object storage with time-limited signed URLs, and no storage of full payment card data.
Physical securityInherited from the infrastructure providers listed as Subprocessors, each operating certified data centres.
Event loggingAuthentication, administrative and agent actions are logged with actor, time and target; logs are access-restricted and retained as stated in the Privacy Policy.
System configuration and default settingsEnvironments separated between development, test and production; production configuration held in a secret store; secure defaults, including refusal to start with an unsafe configuration.
Governance and personnelConfidentiality obligations for all personnel, access granted on a need-to-know basis, and prompt revocation on role change or departure.
CertificationSalexHub does not currently hold SOC 2 or ISO/IEC 27001 certification. Its infrastructure providers do; their reports are available directly from them.
Measures for SubprocessorsWritten data-protection terms with each Subprocessor, no less protective than this DPA, with transfer mechanisms in place where required, and periodic review.

Annex IIIAuthorised subprocessors

The list of authorised Subprocessors, the processing each performs, the categories of data involved and its location, is maintained at /legal/subprocessors and forms part of this DPA.