Tovanix
Tovanix

Tovanix Data Processing Agreement (DPA)

The Tovanix Data Processing Agreement (DPA) is a formal compliance contract between Tovanix as Data Processor and enterprise customers as Data Controllers, designed for organizations that require GDPR / CCPA processor terms. Core clauses include:

  • Purpose and scope: personal data is processed only on documented customer instructions, strictly limited to delivering the contracted services (payments, email, SMS, cloud)
  • Sub-processor management: a published sub-processor list (cloud infrastructure, email delivery, SMS channels) with advance change notifications and the right to object
  • Technical and organizational measures (TOMs): AES-GCM encryption at rest for sensitive data, role-based access control, audit logging, TLS in transit
  • Cross-border transfers: safeguarded via Standard Contractual Clauses (SCCs) and equivalent lawful transfer mechanisms
  • Data subject rights assistance: support for access, rectification, erasure and portability requests
  • Breach notification: prompt notification of personal data breaches with incident details and remediation steps
  • Deletion and return: on termination, all personal data is deleted or returned per customer instruction with written confirmation

To execute a signed DPA or obtain the current sub-processor list, contact us via support ticket or the official email channels.

Tovanix Data Processing Agreement (DPA)

Effective Date: May 20, 2026 · Last Updated: October 4, 2026

This Data Processing Agreement (this "Agreement" or "DPA") is entered into by and between Astrenix Inc. (File #20261586266 · 1500 N GRANT ST STE R, Denver, CO 80203, US; the operating entity of Tovanix, hereinafter "Tovanix", "we" or "us") and the user of the Tovanix services (hereinafter the "User" or "you"). This Agreement supplements and forms an integral part of the Tovanix Terms of Service and the Tovanix Privacy Policy.

This Agreement applies to any scenario in which you process personal data of other individuals through Tovanix, including, typically:

You enable payment collection / email sending / SMS sending / AI service invocation for your end users on Tovanix

You are a business user processing the personal information of your employees / customers through Tovanix

You integrate Tovanix into your own products to provide services to third parties

If you use Tovanix solely in a personal capacity (and your account does not involve any data of other individuals), this Agreement applies automatically but the relevant provisions will not be triggered; you should primarily refer to the Privacy Policy.

---

1. Definitions and Legal Framework

1.1 Roles

| Term | Definition |

|---|---|

| Controller | The entity that determines the purposes and means of the processing of personal data. When you process end-user data through Tovanix, you are the Controller |

| Processor | The entity that processes personal data on behalf of the Controller. Tovanix is the Processor |

| Sub-processor | A downstream service provider engaged by Tovanix (see Annex B for details) |

| Data Subject | The natural person to whom the personal data relates |

| Personal Data | Any information relating to an identified or identifiable natural person |

1.2 Applicable Laws

This Agreement is intended to satisfy the requirements of the following data protection laws:

EU General Data Protection Regulation (GDPR), Article 28 / SCCs

UK Data Protection Act 2018 (UK GDPR)

California Consumer Privacy Act (CCPA / CPRA)

Brazilian General Data Protection Law (LGPD)

Singapore Personal Data Protection Act (PDPA)

Other applicable data protection laws

Where the law of a given jurisdiction imposes requirements higher than those of this Agreement, the law of that jurisdiction shall prevail.

2. Scope and Purposes of Processing

2.1 Purposes of Processing

Tovanix processes personal data on your behalf only within the scope of the following purposes:

Performance of the contractual obligations between you and Tovanix under the Tovanix Terms of Service

Instructions given by you through the console or the API

Mandatory requirements of applicable law

2.2 Types of Processing

| Type of Processing | Description |

|---|---|

| Collection | Receiving data submitted by you and generated by your end users |

| Storage | Retention on Tovanix infrastructure |

| Transmission | Forwarding to destinations via API, email, SMS or on-chain transactions |

| Encryption | Encryption of data at rest and in transit |

| Analysis | De-identified, aggregated statistics solely for service operations and security protection |

| Deletion | Deletion upon your instruction or upon expiry of the retention period |

2.3 Categories of Data and Categories of Data Subjects

| Data Subjects | Typical Data Categories |

|---|---|

| Your end users | Email address, phone number, IP address, device fingerprint, on-chain wallet address, order amount |

| Your employees | Console accounts, operation logs |

| Email recipients | Email addresses, email content (populated by you) |

| SMS recipients | Phone numbers, SMS content (populated by you) |

| On-chain transaction counterparties | Wallet addresses, on-chain hashes, amounts |

Tovanix does not proactively process the following "sensitive data": race, religion, political opinions, health, sexual orientation, or biometric data (unless you expressly declare such processing and provide a lawful basis).

3. Obligations of the Parties

3.1 Obligations of Tovanix (Processor)

We undertake to:

1. Process data only on your instructions, unless otherwise mandatorily required by law

2. Where disclosure is compelled by law, notify you in advance (where permitted)

3. Impose confidentiality obligations on, and provide regular training to, personnel involved in data processing

4. Implement the technical and organizational measures (TOMs) set out in Section 7

5. Assist you in fulfilling your obligations to respond to data subjects, in conducting data protection impact assessments (DPIAs), and in cooperating with regulatory inquiries

6. Engage Sub-processors only as authorized under this Agreement (see Section 6 for details)

7. Upon termination of the contract, delete or return all personal data at your election

8. Cooperate with audits at your request (see Section 9 for details)

9. Notify you within 72 hours in the event of a personal data breach (see Section 10 for details)

3.2 Your Obligations (Controller)

You undertake that:

1. The personal data you provide / process through Tovanix is supported by a valid legal basis (consent, contract, legitimate interest, etc.)

2. You have duly fulfilled your notification obligations to the data subjects

3. You shall provide data subjects with a link to a privacy policy consistent with this Agreement and inform them that Tovanix is your data processor

4. You shall not process, through Tovanix, data that exceeds what is necessary for your business, is unauthorized, or falls within sensitive categories

5. You shall ensure that the instructions you give comply with applicable law

6. You are responsible for the security of your Tovanix console account, and you shall bear responsibility for data security incidents caused by leakage of your passwords / API keys

4. Support for Data Subject Rights

Tovanix assists you in responding to data subject rights requests in the following respects:

| Data Subject Right | Support Provided by Tovanix |

|---|---|

| Right of access / right to data portability | One-click export via "Data Export" in the console |

| Right to rectification | Direct updates via the API / console |

| Right to erasure | Deletion instructions executed in real time; complete erasure from backups within 7 days |

| Right to restriction of processing | Suspension of business modules or API keys |

| Right to object | Disabling of specific data uses |

| Right not to be subject to automated decision-making | Disabling of the risk-control decision loop (where applicable) |

Where a data subject contacts Tovanix directly to exercise their rights, we will:

Promptly forward the request to you for handling (as you are the Controller)

Inform the data subject that the request has been forwarded and provide your contact details (if you are registered)

Not act on the request ourselves (unless expressly required by law)

5. Cross-Border Transfers

5.1 Standard Contractual Clauses (SCCs)

Where personal data is transferred from the EEA / the UK / Switzerland to Tovanix's infrastructure in the United States:

The EU Standard Contractual Clauses (EU SCCs, 2021/914), Module 2 (Controller-to-Processor), apply

You = data exporter; Astrenix Inc. = data importer

Execution of this DPA is deemed execution of the SCCs (the SCCs are automatically incorporated into this Agreement by reference)

Annexes A, B and C are provided at the end of this Agreement

5.2 UK International Data Transfer Addendum (UK IDTA)

For data exported from the UK, the SCCs shall apply together with the UK International Data Transfer Addendum.

5.3 Adequacy Jurisdictions

Transfers of data to jurisdictions covered by an adequacy decision under GDPR Art. 45 (such as Canada, Japan, the UK and Switzerland) are compliant without the SCCs.

5.4 Your Consent

You acknowledge and instruct Tovanix to transfer the necessary data to:

Astrenix Inc.'s infrastructure in the United States

The countries in which the Sub-processors listed in Section 6 are located (see Annex B for details)

Other third parties as necessary to carry out your instructions (viewable in the console under "Cross-Border Data Transfer Records")

6. Sub-processors

6.1 Authorization

You grant Tovanix a general authorization to use Sub-processors. The current list of Sub-processors is set out in Annex B.

6.2 Change Notifications

If a Sub-processor is added or replaced:

We will notify you via in-app message / email 30 days before the change takes effect

You have a right to object: if you have reasonable grounds for objection, you may object in writing within 14 days

If the parties are unable to reach a resolution, you are entitled to terminate the affected services and claim any unconsumed balance in accordance with the Refund Policy

6.3 Sub-processor Compliance Obligations

We enter into contracts with all Sub-processors imposing standards no less protective than those of this DPA, ensuring that they:

Process data only on instructions

Implement security measures equivalent to those under this Agreement

Do not further subcontract (unless authorized)

Comply with cross-border transfer rules

7. Technical and Organizational Measures (TOMs)

Tovanix implements the following security measures:

7.1 Encryption

In transit: TLS 1.2+ enforced, with deprecated cipher suites disabled

At rest: AES-256-GCM (sensitive fields), AES-256-CTR (object storage)

Keys: independently managed via HSM / KMS, with regular rotation

7.2 Access Control

Principle of least privilege based on RBAC

Company-wide SSO + MFA

Dual-person review for the production environment

Real-time alerts for anomalous access

7.3 Network Isolation

Databases are not directly exposed to the public internet

VPC isolation + private network communication

Cloudflare WAF / DDoS protection

7.4 Monitoring and Auditing

24×7 SOC monitoring

Centralized logging (SIEM)

Quarterly security drills

Annual third-party penetration testing

7.5 Business Continuity

Multi-region backups

RTO ≤ 4 hours / RPO ≤ 15 minutes

Disaster recovery drills at least twice per year

7.6 Personnel Security

Pre-employment background checks

Data processing confidentiality agreements

Immediate revocation of data access rights upon departure

Annual security awareness training

The complete list of TOMs is set out in Annex C.

8. Data Retention and Deletion

8.1 Retention Periods

| Data Category | Retention Period |

|---|---|

| Business data actively provided by you | Duration of the account |

| Billing / financial records | 7 years, as required by U.S. IRS / Colorado state law |

| AML compliance records | 5 years, in accordance with the Anti-Money Laundering and Compliance Policy |

| General operation logs | 90 days |

| Security audit logs | 180 days to 2 years |

| Backup data | Overwritten on a rolling 30-day basis |

8.2 Deletion Instructions

You may issue deletion instructions through the following means:

Console "Account Deletion" → business data deleted within 30 days (except data subject to statutory retention)

Ticket submission → deletion requests targeting specific data sets

API → programmatic deletion interfaces

Data within a statutory mandatory retention period will be frozen (rendered inaccessible) rather than physically deleted, and will be physically deleted upon expiry of that period.

8.3 Termination of the Contract

Upon termination of this DPA or the principal agreement:

You may export all business data within 30 days

After 30 days, we will delete or return all data at your election (except data subject to statutory retention)

We will issue a certificate of deletion (upon request)

9. Audit Rights

9.1 Documentation Audits

Upon your written request, we will provide:

The current TOMs documentation

Independent third-party audit reports (SOC 2 Type II, ISO 27001, etc., where obtained)

Penetration testing summaries

A maximum of 2 such audits per year; we bear the cost of the first, and you bear the cost from the second onward.

9.2 On-Site Audits

On-site audits are permitted only in the following circumstances:

Following a material security incident

Where required by a regulatory authority

Where the results of a documentation audit fail to resolve reasonable doubts

On-site audits require 30 days' prior written notice, must be conducted during business hours, must not interfere with our normal operations, and require the execution of a confidentiality agreement.

9.3 Regulatory Investigations

With respect to inspections/audits initiated directly against us by regulatory authorities, we will cooperate as required by law and will notify you to the extent permitted by law.

10. Personal Data Breach Response

10.1 Notification Timeline

Upon discovering an actual or suspected personal data breach, we will:

Notify you in writing within 72 hours

Provide the nature of the incident, its likely impact and the measures already taken

10.2 Content of Notification

The notification will include at least:

The nature of the incident and the categories of data potentially involved

The estimated scope of affected data subjects

The likely consequences

The mitigation measures taken or recommended

The contact details of the DPO or the incident coordinator

10.3 Duty to Assist

We will assist you in:

Fulfilling your obligation to notify supervisory authorities (GDPR Art. 33, within 72 hours)

Fulfilling your obligation to notify data subjects (GDPR Art. 34, in cases of high risk)

Initiating incident investigation and forensics

Responding to regulatory inquiries

10.4 Your Obligations

As the Controller, you are responsible for the final decision on whether to make external notifications to regulators / data subjects. We provide materials and recommendations, but we do not make external notification decisions on your behalf.

11. Allocation of Liability and Indemnification

11.1 Principles of Liability

Each party shall be liable only for its own breaches of this Agreement or of applicable law, and shall not be responsible for the other party's unlawful or non-compliant conduct.

11.2 Limitation of Liability

Tovanix's aggregate liability under this DPA shall not exceed the liability cap agreed in Section 9.2 of the Terms of Service (i.e., the service fees paid by you during the preceding 12 months), except for data breach compensation (which shall be governed by the scope of statutory liability).

11.3 GDPR Fines

Fines under GDPR Art. 83 shall be borne by each party in proportion to its respective fault.

12. Amendments to this Agreement

We may update this Agreement from time to time to reflect legal changes or business developments:

Material changes: 30 days' notice before taking effect; you may elect to terminate

General changes: 7 days' notice before taking effect

Continued use of the services constitutes acceptance of the amended Agreement.

13. Order of Precedence and Interpretation

In the event of a conflict between this Agreement and the Terms of Service, this Agreement shall prevail (with respect to data processing matters)

In the event of a conflict between this Agreement and the SCCs, the SCCs shall prevail

Matters not addressed in this Agreement shall be governed by the Privacy Policy and the Terms of Service

14. Effectiveness and Execution

Automatic execution: your acceptance of the Tovanix Terms of Service is deemed simultaneous execution of this Agreement

Enterprise-specific version: if you require a counter-signed PDF version (for your internal compliance records), please contact [email protected]

EEA / UK / GDPR-governed users: this Agreement is automatically incorporated into your compliance chain, and no separate execution is required

15. Contact Us

Data protection email: [email protected]

Data protection lead: Data Protection Officer · Tovanix Legal Team

Enterprise DPA execution: [email protected] (subject line prefix [DPA Signing])

Operating entity: Astrenix Inc. (File #20261586266)

Registered office address: 1500 N GRANT ST STE R, Denver, CO 80203, United States

---

Annex A: Details of Processing (Annex I)

A.1 Parties

Data Exporter (Controller): You (the Tovanix user)

Data Importer (Processor): Astrenix Inc.

A.2 Purpose of Processing

Performance of the services under the Tovanix Terms of Service; see the console for the specific business modules.

A.3 Categories of Data

See Section 2.3 of this Agreement.

A.4 Categories of Data Subjects

See Section 2.3 of this Agreement.

A.5 Duration of Processing

The service term plus the statutory retention period.

A.6 Supervisory Authorities

Lead Supervisory Authority (Controller-led supervision, for EEA users): the data protection authority of your country

For US-based Controllers: the California Privacy Protection Agency where the CCPA applies

Annex B: Authorized Sub-processors (Illustrative; the list published in the console prevails)

For the complete, real-time list, please refer to "Compliance Center → Sub-processor List" in the console.

| Sub-processor | Country | Processing Activities |

|---|---|---|

| Cloudflare, Inc. | US | CDN / WAF / reverse proxy |

| Amazon Web Services | US / SG / DE | Compute and storage infrastructure |

| Anthropic, PBC | US | AI API relay upstream |

| OpenAI, LLC | US | AI API relay upstream |

| Google LLC | US | AI API relay upstream |

| Alibaba Cloud | SG / DE / US | Overseas nodes |

| Twilio | US | SMS channels |

| Email ESPs (SendGrid, etc.) | US | SMTP delivery |

| Virtual card issuers | US / EU | VCard issuance, clearing and settlement |

| Upstream exchanges (Binance / OKX, etc.) | Multiple jurisdictions | Execution of crypto asset conversions |

| Chainalysis / Elliptic / TRM Labs | US | KYT / AML on-chain risk labeling |

Annex C: Technical and Organizational Measures (Annex II)

See the TOMs chapter in Section 7 of this Agreement.

Annex D: Regulatory Information (for the SCCs)

| Item | Detail |

|---|---|

| Data exporting jurisdiction | EEA / UK / Switzerland (as determined by you) |

| Data importing jurisdiction | United States (location of Astrenix Inc.'s primary infrastructure) |

| Data importer entity | Astrenix Inc. |

| Company number | 20261586266 |

| Registered office address | 1500 N GRANT ST STE R, Denver, CO 80203, United States |

| Applicable SCCs | EU SCCs 2021/914, Module 2 (Controller → Processor) |

| Governing law | Clause 17 of the EU SCCs — Republic of Ireland (applicable within the EU) |

| Supervisory authority (dispute resolution) | Irish Data Protection Commission (by default) |

Loading…