15X Labs · Juridik
Databehandling
The terms that apply when we process personal data on behalf of a business partner, including security measures, subprocessors and international transfer safeguards.
- Gäller från
- 27 July 2026
- Senast uppdaterad
- 27 July 2026
1. When this addendum applies
This addendum applies where Rekify Enterprises LLP, trading as 15X Labs, processes personal data on behalf of and on the documented instructions of a counterparty, referred to here as the Customer, under a services agreement, an insertion order, a distribution agreement or a comparable arrangement, referred to here as the Agreement. It forms part of the Agreement and takes precedence over anything in the Agreement that conflicts with it on data protection.
Where we process personal data for our own purposes, as when someone downloads and uses one of our consumer applications, we act as a controller and our privacy policy governs instead, not this addendum.
2. Definitions
Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority carry the meanings given in the General Data Protection Regulation (EU) 2016/679. Applicable Data Protection Law means the GDPR, the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, the Digital Personal Data Protection Act, 2023 of India, and any other data protection or privacy law that applies to the processing.
3. Roles of the parties
For the processing covered by this addendum the Customer is the controller, or a processor acting for another controller, and we are the processor, or the subprocessor accordingly. Under the California Consumer Privacy Act we act as a service provider, and we do not sell or share personal data, and do not retain, use or disclose it for any purpose other than performing the services or as the law otherwise permits. Each party complies with the obligations that Applicable Data Protection Law places on it in its own role.
4. Subject matter, duration, nature and purpose
- Subject matter: the processing of personal data necessary to provide the services described in the Agreement.
- Duration: for the term of the Agreement, plus the deletion or return period set out below.
- Nature and purpose: hosting, storage, transmission, analysis, support, troubleshooting, measurement and other operations needed to deliver the services and to keep them secure.
- Categories of data subject: the Customer's end users, employees, contractors and other individuals whose data the Customer provides or causes to be provided.
- Categories of personal data: identifiers and contact details, account and authentication data, device and technical data, usage and interaction data, transaction and billing references, support correspondence, and any other data the Customer chooses to submit.
- Special category data: not processed unless the parties agree it in writing in advance and put the additional safeguards in place that Article 9 of the GDPR requires.
5. Processing on documented instructions
We process personal data only on the Customer's documented instructions, including the Agreement, this addendum and any further written instruction the Customer gives, unless a law we are subject to requires otherwise, in which case we inform the Customer before processing unless that law forbids it on important grounds of public interest. If we consider an instruction to infringe Applicable Data Protection Law we tell the Customer without undue delay and may suspend that instruction until it is resolved.
6. Confidentiality of personnel
We ensure that every person authorised to process personal data is bound by an appropriate duty of confidentiality, receives data protection training proportionate to their role, and is granted access only on a need to know basis, under least privilege, with access removed promptly when it is no longer needed.
7. Security measures
Taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the risk to individuals, we implement appropriate technical and organisational measures under Article 32 of the GDPR. These include, as applicable to the service:
- Encryption of personal data in transit over public networks using current TLS, and encryption at rest on the storage layers we control.
- Access control with unique accounts, least privilege, multi factor authentication for administrative access, and prompt revocation on role change or departure.
- Network segregation, hardened configurations, patching of known vulnerabilities and managed secrets, with credentials never committed to source control.
- Logging and monitoring of administrative and security relevant events, retained for a period appropriate to the risk.
- Backups with restoration testing, and documented resilience and recovery procedures.
- A secure development process including code review, dependency scanning and change management before release.
- Vendor due diligence before a subprocessor is engaged, and periodic review afterwards.
- A documented incident response procedure covering detection, triage, containment, notification and post incident review.
8. Subprocessors
The Customer gives general written authorisation for us to engage subprocessors. The current categories are published on our subprocessors page, and a named list for a specific engagement is available on request. We will give the Customer at least 30 days notice before adding or replacing a subprocessor that processes the Customer's personal data, and the Customer may object on reasonable data protection grounds within that period. If the objection cannot be resolved, either party may terminate the affected part of the services without penalty.
We impose data protection obligations on each subprocessor that are no less protective than those in this addendum, and we remain fully liable to the Customer for the performance of each subprocessor's obligations.
9. Assistance to the Customer
- Data subject requests: we implement appropriate measures to help the Customer respond to requests to access, rectify, erase, restrict, port or object, and we forward any request we receive directly to the Customer without undue delay rather than answering it ourselves.
- Impact assessments: we provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority under Articles 35 and 36 of the GDPR, taking into account the information available to us.
- Security and breach: we assist the Customer in complying with its obligations under Articles 32 to 34 of the GDPR.
10. Personal data breach
We notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's personal data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned where known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not available at once we provide it in phases as it becomes known. Notification is not an acknowledgement of fault or liability.
11. International transfers
Where the processing involves a transfer of personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 are incorporated into this addendum by reference and apply to that transfer. Module Two applies where the Customer is a controller and we are a processor, and Module Three applies where the Customer is a processor and we are a subprocessor. The optional docking clause applies, the audit and subprocessor options are exercised as set out in this addendum, and the governing law and forum are those of the Republic of Ireland where the clauses require an EU member state.
For transfers subject to UK law, the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 is incorporated and amends the clauses accordingly. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner is the competent authority. We carry out a transfer impact assessment where one is required and apply supplementary measures where the assessment calls for them.
12. Audit
We make available to the Customer the information reasonably necessary to demonstrate compliance with this addendum, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. Audits take place no more than once in any 12 month period unless a supervisory authority requires otherwise or a personal data breach has occurred, on at least 30 days written notice, during business hours, subject to confidentiality, and in a way that does not disrupt our operations or the security of other customers. We may satisfy an audit request by providing a current third party report, questionnaire response or security documentation where that reasonably answers the request.
13. Deletion or return
On termination or expiry of the Agreement, and at the Customer's choice, we delete or return all personal data processed on the Customer's behalf and delete existing copies, unless a law we are subject to requires storage. Where no choice is communicated within 30 days of termination, we delete. Backup copies are deleted on the normal backup expiry cycle and remain protected by this addendum until they are.
14. Liability, order of precedence and signature
Each party's liability under this addendum is subject to the limitations and exclusions of liability in the Agreement. In the event of a conflict, the Standard Contractual Clauses prevail over this addendum, and this addendum prevails over the rest of the Agreement, in each case on data protection matters only.
This addendum is effective without signature where the Agreement incorporates it by reference. A countersigned copy, and a named subprocessor list for a specific engagement, are available on request to hello@15xlabs.com with the subject line "DPA".
15. Governing law
These matters, and any dispute, claim or proceeding arising out of or connected with them, whether contractual or non contractual, are governed by the laws of India, without regard to conflict of law rules. The competent courts at Bareilly, Uttar Pradesh, India shall have exclusive jurisdiction and shall be the exclusive venue, and you submit to the personal jurisdiction of those courts and waive any objection based on venue or inconvenient forum. To the fullest extent the law allows, disputes must be brought individually, and class, collective, consolidated and representative proceedings are waived. Nothing here prevents us from seeking injunctive or equitable relief in any competent court to protect our intellectual property or to stop unauthorised use of the Services. If you are a consumer resident in a country whose mandatory law does not permit this choice of court, that law prevails to that limited extent, and only to that extent, so you keep any right you have to bring proceedings where you live and to the protection of the mandatory consumer laws of that place.
This applies to this website and to every mobile application and service published by 15X Labs, without exception.
