PhiXenia Data Processing Addendum
U.S. controller-processor and business-service-provider terms.
- Effective date
- July 16, 2026
- Version
- Attorney Review Draft 0.9
This Data Processing Addendum (“DPA”) forms part of the PhiXenia Service Agreement between PhiXenia LLC (“PhiXenia”) and the Customer identified in the account record (“Customer”). It applies when PhiXenia processes Customer Personal Data on Customer’s behalf. Capitalized terms not defined here have the meaning given in the Service Agreement.
1. Definitions
Applicable Data Protection Law. a law that applies to a party’s processing of Customer Personal Data under the Agreement, including applicable U.S. comprehensive state privacy laws and their regulations.
Controller. the entity that determines the purposes and means of processing personal data, including a “business” under the California Consumer Privacy Act (“CCPA”) when applicable.
Customer Personal Data. personal data or personal information that PhiXenia processes on Customer’s behalf through the Services, excluding data for which PhiXenia acts as an independent Controller as described in the Privacy Policy.
Data Subject. an identified or identifiable individual to whom Customer Personal Data relates, including a “consumer” under Applicable Data Protection Law.
Process or Processing. any operation performed on Customer Personal Data, including collection, access, use, storage, disclosure, transmission, alteration, retrieval, deletion, or destruction.
Processor. an entity that processes personal data on behalf of a Controller, including a “service provider” or “contractor” under the CCPA when applicable.
Security Incident. a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in PhiXenia’s possession or control. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans, pings, failed logins, or denial-of-service attempts.
Subprocessor. a third party engaged by PhiXenia to process Customer Personal Data to provide the Services.
2. Roles and Customer instructions
Customer is the Controller and PhiXenia is the Processor for Customer Personal Data. Customer instructs PhiXenia to process Customer Personal Data to provide, secure, support, maintain, and improve the subscribed Services; enable Customer-configured integrations; prevent fraud and abuse; comply with law; and perform the processing described in Appendix A and the Agreement. The Agreement, Customer’s documented configuration and use, support requests, and other lawful written instructions constitute Customer’s complete instructions.
PhiXenia will process Customer Personal Data only on documented instructions unless law requires otherwise. If legally permitted, PhiXenia will notify Customer before processing required by law. PhiXenia will promptly inform Customer if it believes an instruction violates Applicable Data Protection Law, and may suspend the affected processing while the parties resolve the issue.
Customer is responsible for the lawfulness of its instructions and collection, including providing notices, identifying a lawful basis, obtaining consent, honoring rights, minimizing data, and ensuring that configured fields and retention are appropriate. Customer will not instruct PhiXenia to process data prohibited by the Agreement.
3. Processing restrictions
PhiXenia will not:
- sell or share Customer Personal Data;
- retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the limited and specified purposes in the Agreement;
- use Customer Personal Data for targeted or cross-context behavioral advertising;
- combine Customer Personal Data with personal information received from another person or collected from PhiXenia’s own interaction with a Data Subject, except as permitted by Applicable Data Protection Law to provide the requested business purpose; or
- attempt to reidentify deidentified Customer Personal Data except to test whether deidentification processes comply with law.
PhiXenia certifies that it understands and will comply with these restrictions. PhiXenia will provide the same level of privacy protection for Customer Personal Data required of service providers or processors under Applicable Data Protection Law.
4. Confidentiality and personnel
PhiXenia will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security awareness training, and access Customer Personal Data only as necessary for their roles. PhiXenia will maintain access controls designed to enforce least privilege and will review access as reasonably appropriate.
5. Security
Taking into account the nature, scope, context, and purpose of processing and the risk to individuals, PhiXenia will maintain reasonable administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of Customer Personal Data. The baseline program includes:
- documented security ownership, risk assessment, incident response, business continuity, and vendor review appropriate to the size and maturity of the Services;
- logical access controls, unique user identification, privileged-access restriction, secure authentication, and timely access removal;
- encryption in transit using current industry-standard protocols and encryption at rest for production databases and backups where technically supported;
- secure development, code review, dependency and vulnerability management, environment separation, change control, and timely remediation based on risk;
- logging, monitoring, backups, recovery testing, malware and abuse defenses, and protections against unauthorized access; and
- Payment Provider-hosted card-entry components designed so PhiXenia does not intentionally store full card numbers or card security codes.
Customer remains responsible for its user permissions, endpoints, networks, exports, local copies, integration credentials, data fields, and other configurations under its control.
6. Security Incidents
PhiXenia will notify Customer without undue delay and, when reasonably practicable, within 72 hours after confirming a Security Incident. Notice will be sent to Customer’s owner or security contact and will include information then reasonably available about the nature of the incident, affected data and individuals, likely consequences, containment and remediation, and a PhiXenia contact. Information may be provided in phases as the investigation progresses.
PhiXenia will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident and will reasonably cooperate with Customer’s legally required notice and response. PhiXenia’s notice or cooperation is not an admission of fault. Customer is responsible for determining whether notice to individuals, regulators, or others is legally required, except for notices PhiXenia must make for its own processing.
7. Subprocessors
Customer generally authorizes PhiXenia to use Subprocessors for hosting, security, communications, analytics, support, payments integration, AI features, document handling, and other functions needed for the Services. PhiXenia will maintain an up-to-date Subprocessor list at a designated legal or trust page before general availability and will provide at least 15 days’ notice of a new Subprocessor that will materially process Customer Personal Data when practicable.
Customer may object within the notice period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may stop using the affected optional feature or terminate the affected Services without penalty and receive a refund of prepaid subscription fees for the unused period. PhiXenia will bind each Subprocessor by written obligations that provide at least the data-protection level required for the relevant processing and remains responsible for the Subprocessor’s performance to the extent required by law and this DPA.
8. Data Subject requests
Taking into account the nature of processing, PhiXenia will provide reasonable technical and organizational assistance for Customer to respond to verified Data Subject requests to access, correct, delete, obtain, or restrict Customer Personal Data or exercise an applicable opt-out. If PhiXenia receives a request relating to Customer Personal Data, it will direct the requester to Customer or notify Customer and will not independently respond except on Customer’s instruction or as legally required. Customer is responsible for verifying the requester and deciding the response.
9. Compliance assistance
PhiXenia will provide information reasonably necessary for Customer to demonstrate compliance with applicable processor-contract requirements and, considering the nature of processing and information available, will reasonably assist with data-protection assessments, regulator consultations, and security inquiries. Assistance beyond standard documentation or caused by Customer’s instructions may be charged at a mutually agreed rate unless required because of PhiXenia’s breach.
10. Audits and monitoring
Upon written request no more than once annually, PhiXenia will provide then-current security and privacy documentation reasonably sufficient to evaluate compliance, subject to confidentiality. If that material is insufficient and Applicable Data Protection Law requires further verification, Customer may request a remote audit by an independent, qualified auditor mutually agreed by the parties, during normal business hours, with reasonable notice, without access to another customer’s data or creating security risk. Customer bears audit costs unless the audit identifies a material breach by PhiXenia. Additional audits are permitted after a material Security Incident or regulator request.
Customer has the right to take reasonable and appropriate steps to help ensure PhiXenia uses Customer Personal Data consistently with Customer’s obligations and to require PhiXenia to stop and remediate unauthorized use. PhiXenia will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Law.
11. Return, deletion, and retention
During the Term, Customer may access and export Customer Personal Data using available functionality. Following termination and a 30-day standard export period, PhiXenia will delete or return active Customer Personal Data at Customer’s choice, unless law requires retention. PhiXenia may retain limited copies in backups until overwritten in the ordinary backup cycle and may retain data necessary for security, fraud prevention, legal claims, consent records, tax, or regulatory obligations, provided retained data remains protected and is not used for another purpose.
12. Government requests
Unless prohibited by law, PhiXenia will notify Customer of a binding government demand for Customer Personal Data before disclosure and will provide reasonable information so Customer may seek protection. PhiXenia will disclose only data it reasonably believes the demand requires and may challenge overbroad or unlawful demands when appropriate.
13. International processing
Customer acknowledges that the Services are operated from the United States and instructs PhiXenia to process Customer Personal Data in the United States and other locations identified in the Subprocessor list. Customer may not use the Services for processing subject to the European Economic Area, United Kingdom, or Swiss international-transfer rules until the parties execute an appropriate international data-transfer addendum. If such law later applies, the parties will cooperate in good faith to implement required transfer terms before the regulated processing continues.
14. CCPA-specific terms
To the extent the CCPA applies, the parties agree that Customer discloses personal information to PhiXenia only for the limited and specified business purposes stated in this DPA and Appendix A. PhiXenia is a service provider and contractor; will comply with applicable CCPA obligations and provide the same level of privacy protection required by the CCPA; grants Customer the monitoring, stop-processing, and remediation rights described in Section 10; and will not sell, share, retain, use, disclose, or combine the personal information except as expressly permitted by the CCPA and this DPA.
15. Liability, precedence, and term
The Service Agreement’s disclaimers, indemnities, and liability limits apply to this DPA except to the extent prohibited by Applicable Data Protection Law. If this DPA conflicts with the Service Agreement on Customer Personal Data, this DPA controls. This DPA begins with the Service Agreement and remains in effect while PhiXenia processes Customer Personal Data, including any limited post-termination retention period.
Appendix A — Processing details
Subject matter. Operation of a multi-tenant business software platform for booking, scheduling, customer and staff management, waivers and electronic records, communications, payments integration, store credit, loyalty, reporting, analytics, support, and Customer-enabled features.
Duration. The Term of the Service Agreement plus the export, deletion, backup, legal-retention, and dispute periods described in this DPA.
Nature and purpose. Collection, organization, hosting, retrieval, display, transmission, calculation, analysis, support, security, backup, export, deletion, and other processing necessary to perform Customer’s documented instructions and provide the Services.
Data Subjects. Customer owners, administrators, staff, applicants, contractors, franchisees, partners, vendors, end customers, guests, booking participants, waiver signers, parents or guardians, minor participants, emergency contacts, and persons communicating with Customer through the Services.
Personal-data categories. Identifiers and contact information; account and authentication data; business and employment information; booking, attendance, purchase, refund, payment-token, payout, dispute, store-credit, loyalty, promotion, and transaction data; waiver, age, date-of-birth, signature, guardian, and minor data; messages, notes, tasks, support, preferences, and uploaded content; device, usage, audit, security, and approximate-location data; and optional accessibility, safety, emergency-contact, or accommodation information configured by Customer.
Sensitive data. Account credentials, financial account and payment-token information, identity-verification information, precise age or date of birth, electronic signatures, minor information, and any sensitive information Customer lawfully configures. Protected health information subject to HIPAA is prohibited unless the parties execute a Business Associate Agreement.
Frequency. Continuous or event-driven according to Customer’s use of the Services.
Appendix B — Acceptance and contacts
Customer accepts this DPA through the separate signup checkbox. PhiXenia may retain the signer and Customer identifiers, document title and version, full accepted text or tamper-evident copy, checkbox text, timestamp, IP address, and device or session information.
Privacy: privacy@phixenia.com. Security incidents: security@phixenia.com. Legal notices: legal@phixenia.com and PhiXenia LLC, Attn: Legal, [PUBLIC BUSINESS MAILING ADDRESS], Herriman, Utah 84096.